---
title: Building automation and building management systems
canonical: https://www.secnostic.com/en/solutions/building-automation
language: en
dateModified: 2026-08-23
alternate-de: https://www.secnostic.com/de/solutions/building-automation
---

# Building automation and building management systems

- URL: https://www.secnostic.com/en/solutions/building-automation
- Audience: OT visibility for buildings and BMS
- Positioning: Building automation without blind spots

secnostic connects building automation, building management systems, and technical building services in a dependable OT view. Facilities, IT, and security teams can see assets, communication paths, remote access, vulnerabilities, and ownership without unnecessarily touching live building functions.

**See what controls a building and who can reach it**

NIST explicitly classifies building automation systems as [operational technology](https://csrc.nist.gov/pubs/sp/800/82/r3/final). The [BSI](https://www.bsi.bund.de/SharedDocs/Cybersicherheitswarnungen/DE/2023/2023-222993-1031.pdf?__blob=publicationFile&v=2) recommends starting with remote-maintenance access, IT crossings, and the device inventory; its [INF.14 implementation guidance](https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Grundschutz/Umsetzungshinweise/Umsetzungshinweise_2022/Umsetzungshinweis_zum_Baustein_INF_14_Gebaeudeautomation.pdf?__blob=publicationFile&v=2) adds segmentation, roles, and protected building-automation networks.

**Situation.** Management servers, automation stations, gateways, sensors, and actuators connect HVAC, energy, lighting, access, and other building disciplines. In existing buildings, BACnet, KNX, Modbus, M-Bus, proprietary interfaces, remote maintenance, and cloud connections meet divided responsibilities. Without current shared context, dependencies, changes, and risks across buildings, IT, and suppliers remain hidden.

**Challenges**

- incomplete or stale documentation across buildings, disciplines, and suppliers
- undocumented remote-maintenance paths, service accounts, gateways, and supplier changes
- flat networks, legacy components, and communication without modern authentication or encryption
- long lifecycles, EOL/EOS, and sensitive building functions where uncoordinated scans or changes need to be avoided
- divided responsibility across owner, operator, facilities, IT, security, and integrators

**Approach.** secnostic starts passive-first at approved network points and reconciles observations with BMS exports, network data, maintenance records, and vendor information. Assets are mapped to buildings, disciplines, zones, communication paths, owners, and lifecycles. Controlled queries run only after approval; the BMS remains the system responsible for control and regulation.

**Outcomes**

- a current view of BMS, automation, and field components
- traceable remote maintenance and supplier access
- vulnerabilities and EOL/EOS prioritized by building impact
- dependable documentation for risk assessment and modernization

**Four blind spots in building operations**

The technical function is visible, but inventory, access paths, and ownership are often split across several disciplines.

- **Remote access without an owner**: A permanent or forgotten supplier path remains risky when purpose, approval, and ownership are missing.
- **Plans without operating reality**: Retrofits, gateway replacements, and supplier changes cause documentation and the actual estate to diverge.
- **Legacy technology on a flat network**: Long-lived components and older communication need tightly controlled crossings when modern safeguards are unavailable.
- **A finding without building impact**: A vulnerability becomes actionable only when its building, discipline, dependency, maintenance window, and owner are known.

**In practice, four building situations**

Each situation starts with an observable signal or an existing source and ends with an accountable person.

- **A new controller or gateway**: Notice: An observation or import shows a previously unknown device or a new connection.; Place it: The asset is mapped to its building, room, discipline, zone, and communication partners.; Assess: Version, exposure, dependency, and intended function are reviewed together.; Assign: Facilities, IT, or the accountable integrator takes ownership of the clarification.
- **A supplier connects remotely**: Approve: Purpose, time window, supplier, and accountable person are set before access starts.; Reconcile: The permitted path is compared with known gateways, accounts, and communication relationships.; Observe: New IP devices or connections during the window become visible without actively querying field devices.; Close: Activity, changes, and the end of access remain traceably documented.
- **A vendor advisory or EOL notice**: Find matches: Vendor, model, software, or firmware state is reconciled with the estate.; Clarify impact: Building, discipline, dependent function, and maintenance window provide operating context.; Decide: Patching, replacement, segmentation, or compensation is agreed with the operator.; Track: Decision, exception, owner, and review date remain documented on the asset.
- **A BMS or security event**: Ingest: A suitable event from BMS, monitoring, network, or security tooling is received.; Add context: Affected building, discipline, asset, dependencies, and owner are added.; Route: focusAlert hands the event to the right group, shift, or on-call rotation.; Record: Acknowledgment, escalation, and handling history remain traceable.

**From network signal to building context**

The secnostic sensor observes approved IP segments passively. BMS exports, network data, and maintenance records add dormant or serial components; active queries run only after technical approval.

secnostic inventory connects devices to buildings, disciplines, communication paths, lifecycle, and owners. The secnostic platform governs tenants, roles, and access to secnostic applications. focusAlert routes suitable operational and security events, but does not replace certified fire, evacuation, or safety alerting.

**Deployment steps**

1. **Observe**: The sensor observes approved IP network segments passively. BMS exports, network data, and existing documentation add assets that communicate rarely or not at all.
2. **Classify**: Assets are mapped to buildings, rooms, disciplines, zones, communication paths, suppliers, and owners.
3. **Assess**: Firmware, vulnerabilities, EOL/EOS, exposure, and dependencies are connected to their impact on the building and its operation.
4. **Govern access**: Organizations, tenants, roles, and access to secnostic applications remain traceably separated for operators, portfolios, and suppliers.
5. **Respond**: Suitable operational and security events are routed, acknowledged, and escalated without replacing certified safety alerting.

**What becomes visible**

- **Building and discipline view**: Sites, buildings, rooms, BMS, automation stations, gateways, sensors, actuators, and technical disciplines are connected in one scope.
- **Communication and remote maintenance**: Observed connections, IT crossings, cloud links, and supplier access become distinguishable by purpose and ownership.
- **Lifecycle and risk**: Versions, firmware, vendor advisories, EOL/EOS, exposure, and operational dependencies are assessed together.
- **Measures and evidence**: Risks, exceptions, measures, owners, review dates, and sources remain connected to the affected assets.

**FAQ**

- Q: Does secnostic replace the BMS or building control system?
  A: No. The BMS remains responsible for control, regulation, and visualization. secnostic adds technical asset, communication, risk, and ownership context.
- Q: Can the environment be discovered without interrupting operations?
  A: The starting point is passive-first. Dormant, serial, or unobserved components may require additional exports, documentation, or approved queries. Active discovery is therefore never assumed by default.
- Q: Which systems belong in scope?
  A: The scope can include management and engineering systems, automation stations, controllers, gateways, network components, sensors, actuators, meters, and remote-maintenance paths. Safety systems are included only where real interfaces exist.
- Q: Does secnostic make BACnet or KNX secure automatically?
  A: No. Visibility and context show where segmentation, access controls, secure protocol variants, or replacement are needed. Technical protection must be implemented in the relevant building automation system.
- Q: Does the solution automatically meet GEG, IEC 62443, NIS2, or BSI requirements?
  A: No. secnostic can support evidence for assets, communication, measures, and ownership. Applicability and conformity must be assessed for the specific organization and system.

**Tim Bauer.** Solution Architect for OT and BAS security (Fachsprechpartner). Tim Bauer is an independent consultant and Solution Architect for OT and BAS security. His work focuses on the intersection of IT, OT, building automation, and security.
- Website: https://fachsprechpartner.de/

**Sources**

- [BSI INF.14 building automation](https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Grundschutz/IT-GS-Kompendium_Einzel_PDFs_2023/10_INF_Infrastruktur/INF_14_Gebaeudeautomation_Edition_2023.pdf?__blob=publicationFile&v=3): BSI IT-Grundschutz module for integrating information security into the planning, implementation, and operation of building automation.
- [BSI implementation guidance for INF.14 building automation](https://www.bsi.bund.de/SharedDocs/Downloads/DE/BSI/Grundschutz/Umsetzungshinweise/Umsetzungshinweise_2022/Umsetzungshinweis_zum_Baustein_INF_14_Gebaeudeautomation.pdf?__blob=publicationFile&v=2): BSI implementation guidance covering documentation, roles, remote maintenance, segmentation, and protection of building-automation networks such as BACnet, KNX, and M-Bus.
- [BSI information security in building automation](https://www.bsi.bund.de/SharedDocs/Cybersicherheitswarnungen/DE/2023/2023-222993-1031.pdf?__blob=publicationFile&v=2): BSI security information from 2023 on documentation gaps, ownership, patch management, IT crossings, and undocumented remote maintenance in building automation and management.
- [NIST SP 800-82 Rev. 3](https://csrc.nist.gov/pubs/sp/800/82/r3/final): NIST guide to operational technology and industrial control system security.
- [CISA OT asset inventory guidance](https://www.cisa.gov/resources-tools/resources/foundations-ot-cybersecurity-asset-inventory-guidance-owners-and-operators): Joint agency guidance published in August 2025 on building an OT asset inventory with taxonomy, data management, and lifecycle maintenance.
- [CISA definitive OT architecture view](https://www.cisa.gov/resources-tools/resources/creating-and-maintaining-definitive-view-your-operational-technology-ot-architecture): CISA and international partner guidance on creating and maintaining a definitive view of operational technology architecture.
- [ISO 16484-5:2022 BACS](https://www.iso.org/standard/84964.html): Official ISO page for the data communication protocol used to monitor and control HVAC/R and other building systems.
- [DKE IEC 62443](https://www.dke.de/de/arbeitsfelder/industry/iec-62443-cybersecurity-industrieautomatisierung): DKE overview of the IEC 62443 standard series for cybersecurity in industrial automation and control systems.
- [German Building Energy Act, Section 71a](https://www.gesetze-im-internet.de/geg/__71a.html): Current German statutory text on building automation and control in specified non-residential buildings, including energy monitoring and interoperability.
- [EU NIS2 directive](https://eur-lex.europa.eu/eli/dir/2022/2555): Consolidated text of EU Directive 2022/2555 (NIS2) on measures for a high common level of cybersecurity across the Union.
