Facility OT is broader than one controller
Building automation, energy-management controls, access systems, smart meters, gateways and other programmable facility devices can form part of an operational-technology environment. NIST SP 800-82 Rev. 3 provides current final guidance for securing OT while accounting for performance, reliability and safety needs.
Know what is connected
Maintain an inventory of controllers, servers, gateways, engineering workstations, remote-access paths, software versions and responsible owners. Unknown devices and undocumented vendor connections make both maintenance and security harder.
Separate functions and control pathways
Network segmentation can reduce unnecessary reachability between office IT, vendor connections and control networks. Exact architecture should be designed with qualified IT/OT personnel because poorly planned controls can disrupt required building operations.
Control remote access
Remote support should be authorized, attributable and limited to the systems and time required. Shared permanent vendor accounts weaken accountability and make offboarding difficult.
Back up configurations, not just servers
Recovery may require controller programs, graphics, databases, licenses, certificates, network settings and device configuration. Periodically verify that critical configurations can actually be restored.
Coordinate cybersecurity with maintenance
Patching and firmware changes need asset criticality, vendor support and operational windows. A facility cannot safely treat every control device like a standard office laptop, but “never change it” is not a sustainable security strategy either.