Skip to main content
U.S. flag

An official website of the United States government

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Secure .gov websites use HTTPS
A lock ( ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

NIST Releases Tips & Tactics for Building Automation & Control System Cybersecurity

Man working in control room
Credit: Shutterstock
Building Automation and Control System Cybersecurity
Credit: Kristina Rigopoulos, NIST

Recent cyberattacks highlight the growing threat to operational technology (OT) used in critical infrastructure. Whether you work for an infrastructure owner/operator or are a consumer of an infrastructure service, the events of the past few weeks have made it clear that cybersecurity is an important factor in ensuring the safe and reliable delivery of critical goods and services. For OT owners/operators, it can be challenging to address the range of cybersecurity threats, vulnerabilities and risks that can negatively impact their operations, especially with limited resources.

Modern commercial and federal buildings rely heavily on Building Automation & Control Systems (BACS), to manage heating, ventilation, air conditioning (HVAC), lighting, access control, fire alarms, energy management, and other critical operations. These OT systems improve occupant comfort and safety, reduce energy consumption, and streamline facility management, but as BACS networks are integrated with corporate networks and the cloud, their risk of cyberattack increases significantly.

To help resource-constrained BACS owners/operators manage these risks, NIST developed a quick-start infographic outlining immediate, actionable security steps. While the infographic was developed in collaboration with the BACS community, the recommendations offer valuable protection for critical infrastructure sectors including water/wastewater, transportation, energy, manufacturing, healthcare, and food/agriculture.
 

In addition to the infographic, there are many OT cybersecurity resources available from NIST to help you, including:

  • Cybersecurity for Building Systems Project: Developing building services cybersecurity application profiles and guidance needed by building owners, designers, manufacturers and others involved in the lifecycle of the building, to understand threats, risks, countermeasures and governance approach and to ensure cyber-secure facilities.
  • Guide to Operational Technology (OT) Security: Guidance on how to secure OT while addressing their unique performance, reliability, and safety requirements. NIST is currently revising NIST SP 800-82 Guide to Operational Technology (OT) Security to reflect the state of practice in cybersecurity risk management approaches for OT.  We look forward to sharing a draft of the next revision for public comment later in 2026.
  • Cybersecurity Framework (CSF): Voluntary guidance, based on existing standards, guidelines, and practices for organizations to better manage and reduce cybersecurity risk.
  • CSF Manufacturing Profile: Provides CSF version 1.1 implementation details developed for the manufacturing environment. The “Manufacturing Profile” of the CSF can be used as a roadmap for reducing cybersecurity risk for manufacturers that is aligned with manufacturing sector goals and industry best practices.
  • CSF Manufacturing Profile Implementation Guide: Implementation guidance to help manufacturers to select and deploy cybersecurity tools and techniques that best fit their needs while minimizing operational impacts. The Guide provides general implementation guidance (Volume 1) and two complete example proof-of-concept solutions (Volume 2 and Volume 3) demonstrating how available open-source and commercial off-the-shelf products can be implemented in manufacturing environments to satisfy the Manufacturing Profile’s requirements.
  • Risk Management Framework (RMF): A comprehensive, flexible, repeatable, and measurable 7-step process that any organization can use to manage information security and privacy risk for organizations and systems and links to a suite of NIST standards and guidelines to support implementation of risk management programs to meet the requirements of the Federal Information Security Modernization Act (FISMA).
     

The collection of NIST OT cybersecurity resources is available on the Operational Technology Security website.

In addition to the OT-specific cybersecurity resources, NIST offers:
 

Ransomware protection and response Guidance.

Cybersecurity resources for small businesses: Small Business Cybersecurity Corner.

Preventing and recovering from cybersecurity incidents: Responding to a Cyber Incident.

About the author

Keith Stouffer

Keith Stouffer is a supervisory mechanical engineer and has been at the National Institute of Standards and Technology since 1989, focusing on industrial control system (ICS) and OT cybersecurity since 2000. He leads the Cybersecurity for Operational Technology Systems Team and is the lead author of NIST Special Publication 800-82, Guide to Operational Technology (OT) Security, which provides guidance on how to secure OT while addressing their unique performance, reliability and safety requirements.

Michael Galler

Michael A. Galler is a mechanical engineer in the Engineering Laboratory (EL) at the National Institute of Standards and Technology. He is an Investigator on the AI Optimized Building Controls project and is the founding Chair of the ASHRAE MTG for Cybersecurity for HVAC Systems and Related Infrastructure, protecting heating, ventilation, air conditioning (HVAC) systems, building management infrastructure, and associated digital interfaces from cyber threats.

Comments

Add new comment

CAPTCHA
This question is for testing whether or not you are a human visitor and to prevent automated spam submissions.
Please be respectful when posting comments. We will post all comments without editing as long as they are appropriate for a public, family friendly website, are on topic and do not contain profanity, personal attacks, misleading or false information/accusations or promote specific commercial products, services or organizations. Comments that violate our comment policy or include links to non-government organizations/web pages will not be posted.
Was this page helpful?