Critically Neglected: Cybersecurity for buildings
Thomas Pope (Head of Property Cyber Security)
DEF CON 33 · Day 1 · Main Stage
Overview
In an era where digital infrastructure underpins nearly every aspect of modern life, the cybersecurity of physical buildings remains a critically overlooked and dangerously vulnerable attack surface. Thomas Pope, Head of Property Cyber Security, delivered a compelling talk at DEF CON, shedding light on the alarming state of security within Building Management Systems (BMS), Building Automation Systems (BAS), and the burgeoning Internet of Things (IoT) devices integrated into commercial properties. His presentation underscored a fundamental disconnect: while industries like power, oil, and gas inherently recognize the need for robust control system security, buildings—complex ecosystems of interconnected operational technology (OT)—are often left exposed, operating on assumptions of isolation that no longer hold true.

Key moments
- 0:00 Introduction: Cybersecurity for critically neglected building systems
- 1:30 Overview of diverse building control systems and their complexity
- 2:50 Statistics on Building Management System adoption and data gaps
- 4:10 Emerging IoT applications and smart building technologies
- 6:15 Critical lack of basic cybersecurity controls in buildings
- 6:55 Common, insecure protocols in building automation systems
Critically Neglected: Cybersecurity for buildings
Speakers: Thomas Pope, Head of Property Cyber Security
Conference: DEF CON
YouTube: https://www.youtube.com/watch?v=-ElW725i8z4
Overview
In an era where digital infrastructure underpins nearly every aspect of modern life, the cybersecurity of physical buildings remains a critically overlooked and dangerously vulnerable attack surface. Thomas Pope, Head of Property Cyber Security, delivered a compelling talk at DEF CON, shedding light on the alarming state of security within Building Management Systems (BMS), Building Automation Systems (BAS), and the burgeoning Internet of Things (IoT) devices integrated into commercial properties. His presentation underscored a fundamental disconnect: while industries like power, oil, and gas inherently recognize the need for robust control system security, buildings—complex ecosystems of interconnected operational technology (OT)—are often left exposed, operating on assumptions of isolation that no longer hold true.
Pope’s insights are particularly timely given the rapid acceleration of smart building initiatives driven by sustainability goals and operational efficiency. These advancements, while beneficial, inadvertently introduce a myriad of new attack vectors into environments historically devoid of serious cybersecurity consideration. The talk serves as a stark warning and a call to action for cybersecurity professionals, real estate developers, and facility managers alike, urging them to recognize the profound risks associated with neglecting the digital defenses of our physical spaces. From environmental controls to access systems, the potential for disruption, data exfiltration, and even physical harm is substantial, making building cybersecurity a paramount concern that demands immediate attention and strategic investment.
Background
▶ Watch: Introduction: Cybersecurity for critically neglected building systems (0:00)
The evolution of modern buildings has seen a dramatic shift from purely mechanical operations to highly automated, digitally controlled environments. This transformation is driven by several factors, including the push for sustainability (e.g., LEED certification requirements), the demand for operational efficiency (e.g., remote monitoring, predictive maintenance), and the integration of diverse IoT devices. Consequently, a typical commercial building today relies on a complex web of interconnected systems: heating, ventilation, and air conditioning (HVAC), lighting, automated shades, fire life and safety systems, elevators, escalators, and access control. Each of these components, once standalone, is now increasingly networked, often sharing data and operational commands.
Historically, Operational Technology (OT) environments, including those found in buildings, were often considered "air-gapped" or isolated from traditional IT networks. This perception led to a complacency regarding patching, monitoring, and general cybersecurity hygiene. However, the advent of IoT and the desire for centralized management and data analytics have blurred these lines significantly. Systems designed for specific functions, often with proprietary protocols and minimal security features, are now routinely connected to wider networks, sometimes even the internet. Data from 2018 indicated that 15% of all commercial buildings in the US had a BMS or BAS, a figure expected to rise to 20-25% by now, with some portfolios showing as high as 65-70% adoption. This rapid integration, coupled with a lack of understanding among building owners and facility managers about cyber risks, has created a fertile ground for exploitation, turning buildings into a massive, yet largely undefended, attack surface. The problem is exacerbated by a lack of consistent data; government funding cuts have stalled updates to crucial surveys like the Commercial Building Energy Consumption Survey (CBECS), leaving a significant gap in understanding the true scale of this evolving threat landscape.
Key Findings
▶ Watch: Statistics on Building Management System adoption and data gaps (2:50)
Thomas Pope's talk highlighted several critical findings that underscore the severe vulnerability of modern building infrastructure:
- Massive, Neglected Attack Surface: Buildings represent an enormous and often forgotten component of an organization's attack surface. While IT and traditional OT (power, oil & gas) receive attention, the unique blend of systems within buildings is overlooked.
- Alarmingly Low Cybersecurity Maturity: A significant proportion of building networks lack even basic security controls. Pope estimates that only about 30% of assessed buildings have a firewall at the base level. Furthermore, the vast majority lack essential security tools like antivirus (AV), Endpoint Detection and Response (EDR), or a Security Information and Event Management (SIM) system, and critically, they do not log any events. This creates an environment where intrusions can occur undetected for extended periods.
- Prevalence of Flat Networks: Contrary to ideal network segmentation models, real-world building networks are overwhelmingly flat. This means that once an attacker gains access to one system, they often have unimpeded lateral movement across all connected building systems, from HVAC to access control and elevators.
- Vulnerable Protocols and Frameworks: Specific OT protocols commonly used in buildings, such as Backnet, Modbus, Fox protocol (from Tridium's Niagara framework, which holds about a 25% market share in HVAC control), and KN&X (an open standard prevalent in Europe and the Middle East), are frequently exposed and insecurely configured. KN&X, in particular, is often so poorly documented or understood that even tools like Census struggle to accurately identify its presence, despite past exploitation.
- Significant Increase in Exploitation Attempts: Data from OT/IoT security vendors like Armis indicates a sizable increase in observed exploitation attempts against IoT honeypots, including those targeting building systems. This trend is corroborated by FBI data, which identifies commercial facilities as the sixth most targeted sector for cyber incidents, often without public reporting.
- Lack of Incident Reporting and Evidence Preservation: When incidents occur, there is a pervasive issue of underreporting due to a lack of awareness, fear of reputational damage, or the immediate operational imperative to restore services. This often leads to the destruction of forensic evidence as systems are "ripped and replaced" without proper investigation, hindering learning and accountability.
- Discrepancy Between Ideal and Reality: Pope humorously highlighted a "government document" depicting a perfectly segmented building network with multiple firewalls – a scenario he claims to have "never seen one building look like this." His "pretty picture" of a typical building network illustrates a single, flat network with minimal to no segmentation, emphasizing the vast gap between theoretical security and practical implementation.
- Vendor and Management Challenges: The ecosystem of building vendors is often fragmented and lacks cybersecurity expertise. Many contractors operate on a "break-fix" model, with limited knowledge of secure configurations or incident response. Furthermore, internal building management often prioritizes cost-cutting over security, leading to resistance against necessary investments and reliance on unqualified personnel (the "brother Terry" problem).
- Absence of Documentation and Budget: A staggering 70-80% of buildings lack any documentation of their control systems, asset lists, or network diagrams. This fundamental gap, combined with severely constrained operating budgets that resist the "cost of doing business" for cybersecurity, leaves organizations blind and vulnerable.
Technical Deep Dive
▶ Watch: Emerging IoT applications and smart building technologies (4:10)
Modern buildings are intricate ecosystems, far removed from their analog predecessors. At their core are Building Management Systems (BMS) or Building Automation Systems (BAS), which act as the central nervous system, orchestrating various subsystems. These include HVAC for climate control, lighting systems (often smart and adaptive), automated shades for energy efficiency, fire life and safety systems (sprinklers, alarms), elevators, escalators, and access control systems. The speaker emphasized that many of these are often standalone systems, but the trend towards integration means they are increasingly interconnected, sometimes to their detriment.
The drive for sustainability and operational efficiency has led to the widespread adoption of IoT devices, further complicating the security landscape. Examples include:
- Predictive maintenance sensors: These monitor equipment like boilers and chillers for vibrations or anomalies, predicting failures and saving costs. While beneficial, they introduce networked sensors into critical infrastructure.
- Air quality sensors: Designed to monitor indoor air quality, these can also create liability if poor conditions are detected but not addressed.
- Bathroom cleaning sensors: Using occupancy data to optimize cleaning schedules, ensuring resources are deployed only when needed or urgently.
- Occupancy sensors: Low-visibility cameras that track motion for floor planning, space utilization, and optimizing heating/cooling based on actual presence.
These IoT devices, while offering significant benefits, are often deployed without security in mind, directly onto existing building networks.
The core of the problem, as highlighted by Pope, lies in the network architecture. The ideal, as depicted in a government document, envisions a highly segmented network with multiple firewalls isolating critical OT systems. The reality, however, is a flat network. "Do you see a firewall in there?" Pope challenges, showing a diagram of a typical building network where everything is interconnected with minimal or no segmentation. He notes that perhaps 30% of buildings might have a firewall, but it's often a single device, creating a "flat network for just the control systems" rather than true segmentation. This means that an initial compromise of a single endpoint can quickly lead to full network control.
Several OT protocols are central to these building systems:
- Backnet and Modbus: These are widely recognized industrial control system (ICS) protocols, often found in HVAC and other building automation components. Their age and design often mean limited inherent security features.
- Fox protocol: Developed by Tridium for its Niagara framework, this protocol is significant given Tridium's estimated 25% market share in HVAC and building automation. Like others, it can be exposed and vulnerable if not properly secured.
- KN&X: An open standard primarily used in Europe and the Middle East, KN&X allows for interoperability between different vendors' equipment. However, its open nature and sometimes poor implementation make it a target. Pope noted that Census struggled to pick up KN&X devices reliably, indicating a lack of visibility, and highlighted a 2021 malware incident that exploited its default configuration.
Vulnerabilities abound due to this architecture and protocol usage:
- Default or weak passwords: The KN&X malware incident involved attackers setting a universal default password for the BCU key, a security feature designed to protect admin access.
- Unpatched systems: The "air-gap" mentality persists, leading to a lack of patching, even as systems become internet-connected.
- Lack of monitoring: The absence of AV, EDR, SIM, and logging means that malicious activity goes unnoticed.
- Unrestricted outbound traffic: A significant case study involved a large company with strict inbound firewall rules but no outbound restrictions. Attackers leveraged AppleTalk for Command and Control (C2) communications, exploiting an access control system and embedding implants within interconnected elevators – a system rarely inspected for cyber threats.
- Direct access from management networks: Facility managers often access building systems directly from the enterprise IT network, creating a bridge for attacks and exposing critical OT to IT-borne threats.
Pope uses Showdown and Census not as exploitation tools, but as proof-of-concept for external visibility. "If I can see your problem from the outside, you probably got problems inside, too," he states, emphasizing how easily exposed and vulnerable these systems appear to external scanning. This external visibility, combined with insights from Armis honeypots showing increased sophisticated attacks (beyond simple botnets like Mirai), and FBI data ranking commercial facilities as a top target, paints a grim picture of widespread, active exploitation.
Demo / Proof of Concept
▶ Watch: Critical lack of basic cybersecurity controls in buildings (6:15)
While Thomas Pope's presentation did not include a live technical demonstration or "proof of concept" in the traditional sense, he effectively illustrated the pervasive vulnerabilities through compelling real-world examples and observational evidence. Rather than performing a hack, he leveraged publicly available data and recounted specific incidents he had personally investigated, providing concrete evidence of the neglect and its consequences.
Pope highlighted the use of tools like Showdown and Census to demonstrate external visibility into building systems. He uses these to "prove a point" to building owners and managers: "If I can see your problem from the outside, you probably got problems inside, too." This acts as a powerful, non-invasive "proof of concept" for the sheer exposure of these systems. He notes that for protocols like KN&X, even these tools struggle to gather reliable data, underscoring the lack of visibility and documentation within this sector.
He then delved into several detailed case studies of actual compromises:
- The KN&X Malware Incident (2021): Pope described an incident, picked up by Lime Security, where an attacker targeted KN&X systems. The attacker exploited the common practice of not setting the BCU key password, a critical security feature. Instead of demanding a ransom, the attacker simply set a single, universal password across hundreds of compromised buildings. The motivation remains unclear, but it demonstrated the ease of widespread compromise due to default configurations and the lack of basic security. This incident, while unusual in its lack of ransom, highlighted a significant vulnerability in a widely deployed protocol.
- Ransomware on a Building Firewall: In a more recent incident, Pope recounted working on a building that, unusually, did have a firewall – a brand he chose not to name but implied was well-known. This firewall was exploited, leading to data exfiltration and the encryption of nearly every system on the network (except those joined by workgroup, which AD wasn't connected to). The IT contractor contacted the firewall vendor (implied to be Fortinet based on the context of "Fortnet literally said, 'Oh crap, like we're seeing this a lot. This is not new.'"). The vendor advised reformatting and flashing the firewall, which, while resolving the immediate issue, destroyed all forensic evidence. This led to a contentious dispute between the building owner and the contractor, as the vendor subsequently denied fault. This case vividly demonstrated the challenges of incident response in this sector, including vendor accountability issues and the common destruction of evidence.
- Access Control System and Elevator C2: Pope described a large customer who repeatedly experienced infections originating from their buildings. The root cause was a firewall configuration that had restrictions only on inbound traffic, allowing anything to go outwards. Attackers exploited an access control system and used AppleTalk for their Command and Control (C2) communications – a protocol often overlooked in modern network monitoring. Crucially, the implants were found in the elevators, which were interconnected with the access control system. Elevator systems are typically considered isolated and are rarely scrutinized for cyber threats. The customer's usual response of "ripping everything out and putting in new" would have inadvertently fixed the problem in this specific instance, but it also highlights the prevalent practice of evidence destruction over thorough investigation. This case underscored the danger of flat networks, the use of obscure protocols for C2, and the unexpected compromise of critical physical infrastructure.
These narratives serve as potent "proofs of concept" of how building systems are actively being targeted and successfully compromised, often with significant financial and operational consequences that go largely unreported.
Defensive Implications
▶ Watch: Common, insecure protocols in building automation systems (6:55)
The insights shared by Thomas Pope demand a fundamental shift in how organizations approach the security of their physical assets. Defenders must recognize that building systems are no longer isolated and require the same rigor as traditional IT and OT environments.
- Comprehensive Asset Inventory and Mapping: The foundational step is to know what you own and what's connected. As Pope states, "you can't defend what you don't know." Organizations must create detailed asset lists for all building systems, including BMS/BAS, HVAC, lighting, access control, elevators, and all connected IoT devices. This inventory should map network connections, protocols used (e.g., Backnet, Modbus, Fox protocol, KN&X), and vendor information. This often means working closely with engineers and maintenance providers who possess the operational knowledge.
- Network Segmentation and Firewalls: The prevalence of flat networks is a critical vulnerability. Defenders must implement robust network segmentation, isolating building OT/IoT networks from the corporate IT network and segmenting different building systems from each other. Firewalls are not optional; they are essential. While budget is often cited as a barrier, the cost of a firewall (e.g., $5,000 as mentioned) pales in comparison to the cost of a major incident. These firewalls must be properly configured with both inbound and outbound restrictions to prevent C2 communications and data exfiltration, as demonstrated by the AppleTalk C2 example.
- Enhanced Monitoring, Logging, and Detection: The absence of AV, EDR, SIM, and logging is unacceptable. Organizations need to deploy these tools on any endpoints capable of supporting them within the building environment. Critical network traffic, especially from OT/IoT protocols, must be monitored for anomalies. Centralized logging is crucial for detecting incidents and providing forensic evidence. This requires investing in appropriate security solutions and the personnel or services to manage them.
- Robust Vendor Management and Contracts: The "brother Terry" problem highlights a significant risk. Organizations must vet building vendors and contractors for cybersecurity expertise. Contracts should explicitly include cybersecurity requirements, such as secure configuration practices, incident response procedures, and data retention policies. Moving beyond a "break-fix" model to a more proactive security partnership is essential. Consider retainers for incident response specialists with OT/ICS experience.
- Incident Response Planning and Evidence Preservation: Develop and regularly test a specific incident response plan for building systems. This plan must account for the unique operational priorities of OT (safety and uptime) while ensuring that forensic evidence is preserved. Educate maintenance staff and engineers on the importance of not "ripping everything out" immediately after an incident, as this destroys crucial data. Establishing clear communication channels and roles during an incident is paramount.
- Budget Advocacy and Business Education: Cybersecurity for buildings needs dedicated funding. Security professionals must educate real estate, facilities, and executive teams on the tangible risks and potential costs of neglect. Frame it as a "cost of doing business" and highlight the regulatory, reputational, and operational consequences of compromise. Leverage examples from other critical infrastructure sectors and recent ransomware incidents to make the case for investment.
- Secure Configuration and Patch Management: Implement policies for changing default passwords and securely configuring all building systems. The KN&X BCU key incident is a prime example of the danger of default settings. Establish a patch management program for building systems, understanding that patching cycles may differ from IT but are equally critical.
- Do Not Assume: Pope's final advice is critical: "Do not assume someone is actually doing something." Do not assume buildings have the same vendors or configurations; treat each as a unique "snowflake." Do not assume documentation exists. Proactive verification and engagement are necessary.
By adopting these defensive measures, organizations can significantly reduce their exposure to attacks targeting building systems, protecting not just data but also physical assets, occupants, and operational continuity.
Key Takeaways
- Building Systems are a Critical, Neglected Attack Surface: Modern commercial buildings, with their interconnected BMS, BAS, and IoT devices, represent a vast and largely undefended attack surface. This neglect poses significant operational, financial, and safety risks.
- Flat Networks and Poor Security Hygiene are Rampant: The vast majority of building networks lack basic cybersecurity controls like firewalls, segmentation, AV, EDR, SIM, and logging. This creates flat networks where a single compromise can lead to widespread system control.
- IoT and Sustainability Initiatives Increase Risk: While beneficial for efficiency and environmental goals, the integration of IoT devices for predictive maintenance, air quality, and occupancy monitoring introduces numerous new attack vectors if not secured from the outset.
- OT Protocols are Exposed and Vulnerable: Common building protocols like Backnet, Modbus, Fox protocol (Tridium Niagara), and KN&X are frequently exposed externally and often configured with default or weak security settings, making them easy targets for exploitation.
- Lack of Documentation, Budget, and Cybersecurity Awareness: A significant challenge is the absence of asset inventories, network documentation, and dedicated cybersecurity budgets for building systems. Furthermore, building engineers and maintenance vendors often lack cybersecurity knowledge, hindering effective defense and incident response.
- Proactive Measures are Essential: Organizations must implement robust asset inventory, network segmentation, comprehensive monitoring, strong vendor management, and dedicated incident response plans. Educating stakeholders and advocating for cybersecurity budgets are crucial steps to mitigate these pervasive risks.
About the Speaker(s)
Thomas Pope is the Head of Property Cyber Security for his company, a role he self-funded to present at DEF CON, underscoring his personal commitment to raising awareness about this critical issue. His career has consistently involved control systems, even if serendipitously, through various high-stakes environments. He previously worked in incident response at Cisco and has held positions at Duke Energy and Draos. His extensive experience spans securing critical infrastructure in sectors such as power, oil and gas, water, and manufacturing, before transitioning his expertise to the unique challenges of building cybersecurity. Pope's background gives him a deep understanding of both IT and OT security challenges, making him a highly credible voice on the convergence of these domains within the built environment.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
Pope clearly knows this space and the case studies — AppleTalk C2 through elevators, KN&X mass-password-set, ransomware destroying forensic evidence via vendor advice — are genuinely useful war stories from someone who's been in these buildings. The problem is the talk stays at the survey layer: here's how bad the hygiene is, here's why nobody cares, here's the org-chart friction. That's a real contribution, but it's not DEF CON-tier research.
Heather Calloway (CISO) — SOLID
Pope is credible, the problem is real, and the case studies land. But the talk stays at awareness-raising when the audience — and the risk — demands more. It diagnoses a neglected attack surface without producing the governance scaffolding or institutional accountability framework that would actually move the needle for decision-makers.