Article Archives
Article Categories
Articles
Building Automation Doesn't Need a New Standard - It Needs an Owner...

As connected building systems multiply faster than the governance structures meant to secure them, the answer is not another framework. It is clear accountability for the ones that already exist.
A 332 percent jump in internet-exposed building automation devices and a widening pattern of critical vendor vulnerabilities are not, on their own, the story. The story is that most facilities management and commercial real estate organizations still cannot say who inside their walls is accountable for closing that gap.
The Numbers Are Not the Point
Two data points from 2026 describe the same industry from two directions. Joint research from Palo Alto Networks, Siemens, and the Idaho National Laboratory found that internet-exposed operational technology (OT) devices, the sensors and controls behind heating, cooling, lighting, and access systems, grew 332 percent between 2023 and 2024, reaching more than 19.6 million fingerprinted devices and services worldwide. In the same year, building automation products from at least five independently corroborated vendors, spanning access control, energy management, HVAC, and core automation software, disclosed critical or high-severity vulnerabilities, including a maximum-severity flaw in a widely deployed access control platform that left roughly 100,000 endpoints reachable from the open internet.
Read separately, these look like two more entries in an already crowded cybersecurity news cycle. Read together, they describe something more specific: building automation is being connected, networked, and opened to remote access faster than the organizations that own it are building the capacity to govern it.
That is a solvable problem, and it does not require anyone to invent a new standard to solve it.
The Frameworks Already Exist
The National Institute of Standards and Technology's Special Publication 800-82 has offered a risk management framework for industrial control systems, the category that includes building automation, for years. The International Electrotechnical Commission's IEC 62443 series remains the primary international standard for segmenting and securing automation networks. In January 2026, the Cybersecurity and Infrastructure Security Agency (CISA) published eight principles for managing connectivity into operational technology environments, and in April 2026, CISA joined the Department of Defense, the Department of Energy, the Federal Bureau of Investigation, and the Department of State in the first joint federal zero trust guidance written specifically for OT.
The core issue is organizational, not technical: None of this is new. What is missing is not guidance. It is the internal decision, inside individual facilities management (FM) and commercial real estate (CRE) organizations, to formalize who owns operational technology (OT) security when it falls between two departments that were never designed to share it: information technology (IT), which owns network security policy but rarely understands building-system operations, and FM, which understands the buildings but has not traditionally been asked to own cybersecurity.
A 2026 industry survey from OPSWAT and the SANS Institute found that 23 percent of organizations have visibility into only half or less of their own operational technology environment. That is not a patching problem. An organization cannot govern what it cannot see, regardless of how many frameworks it has adopted on paper.
One more caution belongs in this conversation. Security researchers increasingly warn that raw vulnerability counts are a weak stand-in for actual risk: a platform disclosing many low-consequence flaws is not automatically less secure than one disclosing few, if exploitation activity tells a different story. The building automation vulnerability pattern documented in 2026 matters not because six or more vendors were involved, but because the disclosures spanned access control, energy management, and core automation simultaneously, at the same moment the exposed surface grew by a third. Governance decisions should weigh exploitability and exposure alongside severity scores and counts, not counts alone.
What Ownership Looks Like in Practice
For an FM or CRE leader, closing this gap starts with a small number of concrete moves, in a specific order.
- Formalize shared ownership. First, assign accountability before the next disclosure, not after it. A documented Responsible, Accountable, Consulted, and Informed (RACI) structure between IT and FM, anchored in NIST SP 800-82, turns an implicit assumption into an explicit commitment.
- See the portfolio before prioritizing it. Second, inventory. A portfolio-wide count of internet-facing building automation endpoints is the prerequisite for every governance decision that follows it, not a parallel workstream to get to eventually.
- Harden before expanding. Third, apply IEC 62443 zone-and-conduit segmentation to the platforms with the broadest footprint, and extend the 2026 federal zero trust framework to every remote and vendor connection into building systems, starting with the connections already known to be internet-facing.
- Gate what comes next. Fourth, before extending any artificial intelligence (AI) driven analytics or maintenance platform's access into building automation systems, confirm the first three moves are already in place. The same connectivity that expanded internet exposure by 332 percent applies directly to any AI integration layered on top of it.
The Choice Ahead
The building lifecycle management community does not need to wait for a new framework, a new regulation, or a worse headline to act. Every tool required to close this gap, NIST SP 800-82, IEC 62443, and the 2026 federal zero trust guidance for operational technology, is already available and already free to adopt. What remains is a decision inside individual organizations: formalize ownership deliberately, or keep assigning it informally, one disclosure at a time.