Connectivity has elevated the need for building management system (BMS) cybersecurity in critical infrastructure. Once isolated, BMS now communicates with the local network and sometimes the public internet, creating new exposures that must be mitigated. This is a key strategic security area for chief information officers (CIOs), chief operations officers (COOs), and chief information security officers (CISOs) responsible for business continuity, uptime, safety, and cybersecurity.
BMS, like other core areas of operational technology (OT), plays a key role in managing physical environmental controls, power distribution, fire safety systems, ventilation, elevators and escalators, and automated lighting. BMS also plays a role in ensuring the availability of key services in industries such as healthcare, retail cold chains, and data centers.
Having BMS available on local and public networks, however, expands the attack surface available to threat actors. Beyond exploitable vulnerabilities, BMS commonly utilize insecure communication protocols and run on legacy software and firmware that lack adequate security controls. Compounding the issue, many organizations struggle to gain visibility into BMS in order to understand the true extent of their exposures.
This blog will explain why BMS security is essential for overall operational resilience, including:
The challenges associated with BMS cybersecurity
Real-world attacks on BMS
Strategies for BMS protection
A building management system (BMS), building automation system (BAS) or building control system (BCS), is OT designed to control, monitor, manage, and optimize various aspects of building operations. BMS centrally controls and regulates facilities’ mechanical, electrical, and safety equipment through a single management interface. It does so by collecting data from field sensors, meters, and other internet-of-things (IoT) assets that monitor temperature controls, energy consumption and distribution. BMS also manages controllers, actuators, and relays that execute commands on physical operations.
BMS’ key objectives are to increase operational efficiency by centralizing the control and monitoring of diverse building systems, create a safer, more secure, and more comfortable environment for occupants, and help preserve the safety, availability, and integrity of the operations and processes occurring within the facility.
However, these systems are increasingly being connected to and controlled via the internet, which is creating new attack vectors for attackers looking to disrupt critical assets and systems.
Network-connected BMS introduces new accessibility for threat actors to target attack vectors that were previously unreachable. BMS cybersecurity faces several challenges, including some new ones introduced by connectivity, and others that have been elevated as technical debt:
BMS typically have multiple access points including web interfaces, wireless connections, and third party-integrations. These entry points can be tough to identify (much less secure), thereby increasing the attack surface and leaving the system more vulnerable to potential cyber threats.
Technical debt is a real problem for OT, and BMS is no exception. Outdated and unsupported software and firmware may carry vulnerabilities that will never be patched because vendor support has long ago ended. These forever-day vulnerabilities are exposed indefinitely to threat actors, and some of known exploited vulnerabilities (KEVs) may be vulnerable to publicly available exploits. Organizations that don’t have adequate visibility into these assets, the attack paths they present, and the vulnerabilities or configuration errors they carry are severely exposed and at risk. Without complete asset inventories, compensating controls such as virtual network segmentation cannot be properly implemented.
BMS environments typically use a diverse mix of proprietary and open-standards protocols to communicate, thereby complicating security teams’ ability to discover, protect, and manage BMS.
Additionally, many older protocols such BACnet, MODBUS, and others commonly used by BMS lack built-in encryption, authentication and other security features. As a result, building layouts, user credentials, HVAC configurations, or other sensitive data transmitted by or to BMS that use these protocols is far more susceptible to compromise.
Segmentation is the compensating control that limits the blast radius of a cybersecurity incident. Segmentation is used to virtually isolate network segments in the event of a breach, limiting not only the spread of an attack, but also an attacker’s ability to move laterally on the network and infect more assets.
BMS segmentation requires operators and engineers to have visibility into connected assets in order to map out the environment, understand which assets communicate, and how. Only then can subsystems be isolated, for example, keeping guest Wi-Fi networks from having access to cooling controls or physical security systems. BMS should also be kept isolated from the corporate network in order to ensure that any ransomware or other attacks against endpoints disrupt building operations.
Weak passwords or default credentials are commonplace in BMS components and make it easier for attackers to gain unauthorized access. Many times, access controls can also be improperly configured enabling unauthorized users to gain administrative privileges or access to critical systems.
Asset operators should ensure that access controls include strong passwords and multifactor authentication. Role-based access controls and privileged access management systems ensure that BMS is not over-privileged and access to BMS is limited to those who need it for their roles.
Organizations should rely on the principle of least privilege, which limits internal permissions to the bare minimum necessary to carry out respective roles and responsibilities. BMS also often manages physical entry points, and any unauthorized access attempts should be logged and trigger alerts.
BMS have been leveraged in several publicly known cyberattacks. Here are some examples and how they impacted overall operations and business:
A building automation engineering firm in Germany lost contact with hundreds of their BMS devices — including lighting, motion detectors, shutter controls, and others. All smart devices were considered to be bricked by the attack.
According to the co-founder of Limes Security, Thomas Brandstetter, “Everything was removed… completely wiped, with no additional functionality.”
Following the attack, the engineering company started to look for help externally in search of a way to regain access and control to their BMS. However, all vendors claimed that no reset was possible and suggested that the equipment should be completely ripped and replaced. This overhaul of BMS would have cost more than €100,000 considering hardware, installation and verification costs — and displayed the financial ramifications an attack of this nature can cause.
A 2017 attack on a casino took place via an IoT device in a lobby aquarium. The fish tank that was breached had sensors connected to a PC that regulated the room temperature, food, and cleanliness of the tank.
An attacker was able to move laterally through the network and compromise more than 10 gigabytes of proprietary personal and payment data from top patrons of the North American casino. This out-of-the-box hack raised concerns over the new and more imaginative ways that threat actors are taking advantage of vulnerable BMS devices. It also displayed the imminent need for a strong BMS cybersecurity strategy.
A hacking incident reportedly targeted a Massachusetts-based HVAC vendor that provides HVAC systems to several Boston-area hospitals. During the alleged attack, the threat actor tried to extort the vendor to pay a fee; however, Boston Children’s Hospital claimed that “there is no risk to either hospital operations or business operations as a result of this incident, and no patient information was affected.”
No patients were harmed during this incident, but the event did raise a call to action for healthcare organizations to better protect their building management systems. If an attack like this were successful, operating rooms and isolation rooms would be gravely affected, with temperature and humidity being a major factor controlling growth of bacteria and maintaining certain pressures to stop the risk of infectious diseases spreading.
The criticality of BMS operations, and the pathways they provide to other critical infrastructure must be secure in order to ensure no interruptions to operations. In order to eliminate many of the core challenges in BMS environments, organizations should adopt the following industrial cybersecurity principles:
Critical infrastructure organizations often lack the visibility into BMS assets. Maintaining a comprehensive inventory of all OT, IoT, IIoT, and BMS assets that underpin your OT environment is the foundation of effective industrial cybersecurity.
Security teams must understand how the assets under their control communicate, which carry KEVs or weak and exploitable configurations, or communicate over insecure protocols.
Visibility and asset management informs the remainder of the cybersecurity program; visibility into BMS assets is especially important given the legacy technology in play and the potential for exposures.
BMS exposure management is a programmatic way of identifying, mapping, and reducing cyber risks associated with smart building networks.
Facilities connecting lighting and power to the internet must consider the exposures they’re introducing and remediate or mitigate them. This requires complete asset discovery and management to be in place, which then informs the rest of the exposure management program.
Through visibility, asset operators may understand attack paths that are present and how an attacker could move about the network to disrupt operations and uptime. Only then can high-risk assets be prioritized according to exploitability or business harm in the event of a disruptive or damaging incident.
BMS’s oversight of physical operations, including cooling, power, and lighting, mandates strong cybersecurity controls be in place.
Connectivity is inevitable because of the business efficiencies it can introduce to BMS and other mission-critical infrastructure. Equally important, BMS cybersecurity is essential to the availability of key services in industries such as healthcare, retail cold chains, and data centers.
It’s important that business and technology leaders understand the risks of BMS’s availability on local and public networks and the exposures it creates. Managing exposures reduces risk, ensures uptime, and keeps services available, especially in critical industries.
Talk to an expert about BMS cybersecurity and Claroty xDome.
Protecting OT in Healthcare: Inside Claroty Edge
BMS 101: Securing Healthcare Building Management Systems
Securing Building Management Systems to Ensure Process Integrity
Interested in learning about Claroty's Cybersecurity Solutions?
Life, uninterrupted
We maximize your availability, strengthen your insurability, and support compliance to ensure operational resilience.