Why BMS Has Become a Cybersecurity Concern

Building Management Systems in UAE smart buildings are increasingly network-connected, often running on older protocols (BACnet, Modbus) not originally designed with cybersecurity in mind, and frequently maintained by facilities teams without deep IT security expertise — a combination that makes BMS a genuine, growing attack surface rather than the purely operational system it once was.

Common BMS Vulnerabilities

  • Default or weak credentials left unchanged on controllers and head-end software
  • BMS network segments bridged to corporate IT without adequate firewalling
  • Unpatched vendor software running for years without security updates
  • Remote access set up for vendor maintenance without adequate access controls

Design Mitigations

Network segmentation isolating BMS traffic from corporate IT (covered in more depth in ASDV's zero-trust smart building article), mandatory credential changes from vendor defaults, and controlled, logged, time-limited remote access for vendor maintenance rather than persistent open access are all practical, achievable mitigations that should be specified in the BMS design and procurement documentation.

Cybersecurity Is Ongoing, Not a One-Time Design Task

Good BMS cybersecurity design at handover degrades over time without ongoing patching, credential rotation and access review — ASDV's design documentation specifies an ongoing management responsibility (typically the client's FM or IT team) for the BMS's cybersecurity posture post-handover, rather than treating security as solved once commissioning is complete.