Traditional IT security is built on several foundational assumptions that simply do not hold in smart building environments.
Assumption 1: Devices can run security agents.
Endpoint detection and response (EDR) tools, antivirus platforms, and host-based monitoring solutions all depend on software running directly on the device. In corporate IT environments, this is standard. In smart buildings, it is largely impossible. BMS controllers, field devices, access readers, and IoT sensors run proprietary firmware on hardware with no capacity for third-party software. You cannot install an EDR agent on a building controller.
Assumption 2: Devices can be patched regularly.
IT security programs are built around patch management — the systematic process of identifying, testing, and deploying software updates to address known vulnerabilities. Smart building devices operate on entirely different timescales. Many run firmware that has not been updated in years. Many cannot be patched without taking building systems offline. Some are running software from manufacturers that no longer exist.
Assumption 3: Active scanning is safe.
Vulnerability scanners work by actively probing devices — sending packets, requesting responses, and cataloguing what they find. In IT environments, this is routine. In smart building environments, it can be catastrophic. BMS controllers, industrial sensors, and building automation devices are frequently unable to handle the traffic generated by active scanning — crashing, freezing, or behaving unpredictably in ways that disrupt building operations.
Assumption 4: Standard protocols are in use.
IT monitoring tools are built around standard protocols — TCP/IP, HTTP/S, DNS, SMB. Smart buildings communicate using BACnet, Modbus, KNX, LonWorks, and a range of proprietary vendor protocols. A SIEM platform configured for IT infrastructure cannot interpret building automation traffic. It cannot distinguish normal BMS behavior from an attack. It generates noise rather than signal.
Learn more: IoT vs. OT vs. IT Security: What’s the Difference?


