Buildings as an Overlooked Attack Surface
Building control networks cover more than HVAC. A modern commercial building runs BMS or BAS, lighting, fire life safety (all sprinklers connect back to a central console), elevators, escalators, access control, and energy monitoring. In 2018, 15% of US buildings had a BMS. That number is likely 20-25% today. The EIA, which tracks this data, lost federal funding and won’t update the survey soon. Some large real estate portfolios run 65-70% BMS penetration across their holdings.
Protocols Nobody Patches
BACnet and Modbus are known quantities. The Fox protocol from Tridium’s Niagara framework covers roughly 25% of commercial HVAC. KNX is an open standard common in Europe and the Middle East that lets facilities mix vendors freely. All of these show up on Shodan and Censys. Across Pope’s building assessments, only about 30% have even a basic firewall. No AV, no EDR, no SIEM, no log collection. The FBI ranks commercial facilities as the sixth most targeted sector.
KNX Malware and a Ransomware Hit
In 2021, Lime Security found malware targeting KNX building systems. The attacker set the BCU key, a feature meant to lock admin access, across hundreds of buildings using the same password. No ransom was ever demanded. A second incident involved a building with a firewall (a rare find). The vendor told the IT contractor to flash and reload the device after an exploit. That wiped forensic evidence. The attacker had already exfiltrated data and encrypted every AD-joined system on the network.
C2 Hidden in Elevator Controllers
A large customer spent hundreds of thousands on IR firms to repeatedly clean infections they couldn’t trace. The source was their access control system, connected to the elevators. Attackers used AppleTalk for C2, a protocol nobody monitored, because the firewall only restricted inbound traffic. The implants lived in elevator controllers. No IR team looked there. Elevator vendors themselves say not to connect their systems to anything. The interconnection between access control and elevators made persistence possible.
What Building Networks Actually Look Like
A US government document depicts building networks as properly segmented, with firewalls between every subsystem. Pope has never seen that in practice. Real building networks run flat. Facilities staff pull reports directly from the BMS, giving their workstations credentials for production control systems. About 70-80% of buildings have zero documentation: no network diagram, no vendor list, no asset inventory. Every building is different. Two buildings built simultaneously in Chicago and New York, by different integrators, will have completely different architectures.
Building a Defensible Program
Pope’s first step with any building team is a vendor list. Most don’t have one. From there: document assets, understand who manages each system, and confirm whether cyber insurance minimums are actually met. Many buildings quietly rip and replace after incidents rather than report. Building engineers prioritize uptime and safety. They’ll restore operations fast and destroy forensic evidence in the process. Working with them means teaching first. Once they understand the risks, they’ll push the right questions back.
Notable Quotes
they’re going to destroy all your evidence. Thomas Pope · ▶ 17:47
attackers were actually kind of lazy. Thomas Pope · ▶ 10:56
It’s really not. I promise. Thomas Pope · ▶ 19:08
Key Takeaways
- Only about 30% of assessed buildings have a basic firewall, with no logging on the rest
- Building networks typically run flat, so any breach gives access across all interconnected systems
- Building engineers will restore operations before preserving forensic evidence, destroying incident data in the process
- Start every assessment with a vendor list and asset inventory because most buildings have neither
- Never assume two properties in the same portfolio share vendors or architecture; every building is built differently
About the Speaker(s)
Thomas Pope is the Head of Property Cybersecurity at Jones Lang Lasalle (JLL). His team secures control systems across properties and builds cybersecurity programs at portfolio scale. He previously led incident response engagements at Cisco Talos as Incident Commander, hunted ICS-specific adversaries at Dragos, and stood up cybersecurity programs at Duke Energy. His background spans power, oil and gas, water, manufacturing, and now commercial buildings.