Open to attack: minimising risks of cyberattack in building retrofits

With retrofits routinely connecting decades-old building systems to modern IP networks, there is a real risk of exposure to cyberattack unless digital security is included in the project scope from the outset, says OryxAlign’s Peter Schwartz

 

Peter Schwartz

Most building automation still runs on protocols drawn up decades ago, long before network security was considered. Standards such as BACnet and Modbus were built for reliable communication inside a closed environment, and they carry little authentication or encryption of their own.

A retrofit changes that environment completely. The moment these systems join a modern IP network, the operational technology that runs the building meets the information technology that runs the business, and devices that were only ever meant to communicate with one another become reachable from beyond the plantroom.

Smarter buildings now reach further still, with heating and power increasingly linked to the Grid and demand balanced in step with real-time energy signals.

Retrofit is where this happens most, because the work joins equipment of different ages to shared infrastructure. Building automation security reviews1 trace the problem to the technology itself, finding that many of these weaknesses ‘stem from the design of the underlying BAS protocol’.

A compromised controller on a network… can give an intruder a foothold

Where the weak points sit

The exposure tends to concentrate at a few predictable places. Older controllers often run firmware that can no longer be patched, sometimes because the manufacturer withdrew support years ago. Networks assembled piecemeal over a long period tend to be flat, with no real separation between the building services and the corporate systems. A single compromised controller on a network of that kind can disrupt heating or access for an entire floor, and can give an intruder a foothold from which to reach into business systems.

Responsibility adds a further complication. The building services team frequently specifies and commissions connected equipment without any formal handover to an IT or security function, which leaves the connected estate with no clear owner.

Cybersecurity usually enters the conversation once the equipment has been chosen – sometimes once it has already been installed. Procurement treats it as an IT concern sitting outside the building services package. Design budgets seldom account for it at concept stage. No standard obligation exists to write it into a services brief.

The question of who secures the connected estate then goes unasked until an incident forces an answer, by which point the cost and disruption of putting it right have climbed well beyond what early planning would have needed.

CIBSE has recognised the problem. Its DE6.1 guidance Cyber security in building services design2 points to the need for ‘dedicated security experts to review and feed into each design’, and it treats connected buildings as a growing part of national infrastructure.

The national security picture reinforces that position. The National Cyber Security Centre sets out principles for connecting operational technology safely3 that place hardening the network boundary and limiting its exposure at the centre of the work, and it frames secure connectivity as something to design in from the start.

That principle translates into a few practical moves on a live retrofit. An accurate inventory of what is being connected comes first, as nothing can be protected while it remains invisible to the people responsible for the network. Segmenting that network so the building services sit apart from corporate traffic then limits how far an intruder can move.

Hardening newly connected devices and maintaining them through regular updates helps close obvious openings. Equipment selection also matters and specifying products that support secure configuration spares a project the harder task of defending hardware that was never built to be defended.

Conversations need to begin at the brief and specification stage, with building services and IT working from a single plan agreed at the outset.

The expertise to lead this already sits with building services engineers, who decide what gets connected and how it runs. Treating the network and its security as core building infrastructure gives a retrofit the resilience to match its new capabilities. That work belongs in the brief, at the point where the design is still taking shape and the cost of getting it right is at its lowest.

About the author
Peter Schwartz is a senior technology consultant at OryxAlign

For more, visit here

REFERENCES

1 CIBSE DE6.1: Cyber security in building services design (2019) 

2 Morales-Gonzalez, C et al (2024) ‘On building automation system security’, High-Confidence Computing, 4(3), p.100236 

3 National Cyber Security Centre (2026) Secure connectivity (accessed: 11 September 2026)