BAS Cybersecurity Is Now a Commissioning Issue
Connected building controls create operational value and operational risk. Commissioning can verify that practical cybersecurity requirements survive design, installation, turnover, and daily use.
Cybersecurity is not a substitute for functional performance, and functional performance is not proof of security. A modern commissioning process should connect the owner’s security requirements to observable controls, records, recovery procedures, and accountable acceptance decisions.
Technical overview
BAS Cybersecurity: field logic map
Connected buildings changed the commissioning boundary
Building automation and control systems now exchange information with enterprise networks, cloud services, mobile applications, analytics platforms, remote service organizations, utility programs, and other facility systems. That connectivity can improve visibility and performance, but it also creates pathways that were not part of many traditional controls checklists.
NIST’s 2026 building-systems work treats cybersecurity as a lifecycle concern for HVAC, lighting, security, elevators, and related services. Commissioning providers should not become the owner’s cybersecurity authority by default. They can, however, verify that defined security requirements have been translated into installed conditions and usable turnover information.
Start with ownership, architecture, and permitted connections
The owner should identify who owns the BAS network, who approves remote access, who administers accounts, which connections are permitted, and how incidents are escalated. A diagram should show controllers, supervisory devices, servers, workstations, gateways, cloud services, firewalls, enterprise connections, and vendor pathways. Unknown connections are findings, not documentation gaps to ignore.
Commissioning should compare the installed architecture with the approved design and current facility requirements. The review should confirm that critical functions do not depend on an undocumented internet connection and that loss of an external service produces a defined, safe operating state.
Verify practical controls rather than generic promises
Statements such as ‘the BAS is secure’ are not testable. Requirements should identify observable conditions: unique administrator accounts, changed default credentials, role-appropriate privileges, disabled obsolete accounts, approved remote-access methods, encrypted protocols where required, time synchronization, event logging, supported software versions, and controlled configuration changes.
Network segmentation and firewall rules remain the responsibility of qualified IT and OT personnel. The commissioning record can document that the approved boundaries exist, that permitted communication succeeds, and that prohibited or failed connections do not disable required local control. Sensitive passwords, keys, and network details should never be reproduced in the commissioning report.
- Confirm an owner-approved inventory of connected assets and software versions.
- Verify that default, shared, temporary, and departed-user accounts are addressed.
- Document every remote-support pathway and the party authorized to enable it.
- Confirm configuration backups, protected storage, restoration responsibility, and an actual recovery exercise.
- Test loss of cloud, supervisory, and network services without defeating local safeties.
Treat backups and recovery as functional requirements
A backup is useful only when it is current, complete, protected, and restorable. Controls turnover should include controller programs, databases, graphics, schedules, trend and alarm configuration, licenses, certificates where applicable, device addressing, and the procedure for rebuilding the system. The owner should know which files are authoritative and who can restore them.
A recovery test can be scoped without creating unacceptable operational risk. Examples include restoring a spare controller, rebuilding a test workstation, validating a database export, or demonstrating recovery in an isolated environment. The acceptance criterion should address recovery time, required tools, configuration integrity, and verification after restoration.
Make security sustainable after turnover
Security degrades when accounts accumulate, remote tunnels remain open, software ages, diagrams become obsolete, or service responsibilities are unclear. Final training should show the owner how to add and remove users, review logs, authorize vendors, update backups, preserve local operation, and report suspicious behavior.
The strongest outcome is not a one-time checklist. It is a controlled operating practice with named owners, review intervals, current documentation, and a safe method for applying changes. Recommissioning should revisit cybersecurity whenever the BAS network, cloud services, major equipment, or support organizations change.
Field application
A practical review checklist
- 01
Identify the owner’s IT, OT, controls, security, and facility decision-makers before testing.
- 02
Compare the installed network and remote-access architecture with the approved diagram.
- 03
Confirm asset inventory, software versions, account ownership, privileges, and removal procedures.
- 04
Verify default credentials are changed and sensitive credentials are transferred outside the Cx report.
- 05
Demonstrate approved communications and safe local operation during selected connection failures.
- 06
Confirm logging, time synchronization, alarm routing, configuration control, and incident escalation.
- 07
Inventory backups and demonstrate a risk-appropriate restoration exercise.
- 08
Document remaining risks, responsible parties, deadlines, and reverification requirements.
Related Free tools
Put the relationships to work.
Authoritative orientation
References and further reading
Use the current adopted or licensed edition applicable to the project. These links provide public orientation and do not reproduce protected standards.
Continue exploring
One article. 235 free engineering calculators.
Move from the concept to a transparent calculation, or return to the complete Insights collection.
