BMS Platforms Are Increasingly Connected
Historically, BMS environments operated on isolated, proprietary networks — separate from corporate IT infrastructure and inaccessible from outside the building. This isolation provided a degree of security by default.
That separation has largely disappeared.
Modern BMS platforms are connected to corporate IT networks to enable centralized management, integrated with cloud services for remote monitoring and vendor support, and in many cases directly accessible via the internet through web-based management interfaces.
This connectivity brings significant operational benefits — but it also means that BMS environments are now reachable from anywhere that the corporate network or internet is reachable. The air-gap that once provided passive protection no longer exists.
BMS Environments Share OT Security Limitations
BMS systems share many of the security characteristics — and limitations — of operational technology environments.
Legacy devices in BMS environments may have been deployed years or decades ago, running firmware that is no longer supported and using communication protocols — such as BACnet, Modbus, and LonWorks — that were designed for reliability rather than security.
Patching is operationally complex. Updating BMS controllers or field devices may require taking building systems offline — disrupting HVAC, access control, or other operational functions. As a result, known vulnerabilities persist in BMS environments for extended periods.
Default credentials are common. BMS devices and management interfaces frequently retain factory-set credentials that are never changed during installation — one of the most commonly exploited vulnerabilities across all connected environments.
BMS Systems Sit Adjacent to Corporate IT Networks
In most modern commercial buildings, BMS platforms share network infrastructure — directly or indirectly — with corporate IT systems. This creates pathways for lateral movement in both directions.
An attacker who compromises a BMS device gains a foothold on a network segment that may provide visibility into — or direct connectivity to — corporate IT infrastructure. Conversely, an attacker who compromises corporate IT may be able to reach BMS platforms and the physical building systems they control.
Learn more: Lateral Movement in IoT Environments: How Attackers Pivot from IT to OT