ACHR News
search
Ask ACHR NEWS AI
cart
facebook twitter instagram linkedin youtube
  • Sign In
  • Subscribe
  • Sign Out
  • My Account
ACHR News
  • NEWS
    • Breaking News
    • New HVAC Products
    • Featured Products
    • Manufacturer Reports
    • HVAC Data
    • Legislation
    • ACHR NEWS Centennial
  • RESIDENTIAL
    • Air Conditioners
    • Furnaces
    • Residential Heat Pumps
    • Ductless
    • Residential IAQ
    • Testing, Monitoring, Tools
    • Components & Accessories
  • COMMERCIAL
    • Air Handlers
    • Rooftop Units
    • Chillers and Cooling Towers
    • Commercial Heat Pumps
    • Boilers and Hydronics
    • VRF/Ductless
    • Commercial IAQ
  • REFRIGERATION
    • Refrigerants
    • Refrigerant Regulations
    • Leak Management
  • CONTRACTOR PRO
    • Geothermal
    • Homeowner Study
    • VRF and VRV Ductless
    • Unitary Trends
  • EDUCATION
    • Training and Education
    • Business Management
    • Service and Maintenance
    • Continuing Education
    • Market Research >
      • HVAC Brand Awareness Report
      • VRV, VRF, VRVZ Report
      • Unitary Trends Report
      • Water Heat Professionals Report
    • Webinars
    • Sponsor Insights
    • eProducts Info
    • White Papers
  • EVENTS
    • HVAC Contractor Forum
    • Industry Events and Webinars
  • MEDIA
    • Videos
    • AHR Expo 2025 Videos
    • Podcasts >
      • ACHR News Podcast
      • HARDI Podcasts
      • AHR Expo Podcasts
      • ACCA Podcasts
    • Interactive Spotlights
    • Quizzes
    • eBooks
    • HVAC Talkback
  • HVAC GROUP
    • ACHR NEWS >
      • Current Issue
      • Digital Edition
      • Subscribe
    • Distribution Trends
    • SNIPS NEWS >
      • Join SNIPS NEWS
    • Engineered Systems News >
      • Join ES News
    • HVACR Directory
    • Contests
    • Newsletters
    • Contact
    • Advertise
    • My Account
NewsHVAC Residential Market

Best Practices for Easing Security Concerns Around Smart HVAC

User awareness “critical” to cybersecurity; HVAC contractors can lay the groundwork during install

By Hannah Belloli-Oster
Sensi Smart Homes
EDUCATE: Customers need to be informed about potential smart HVAC system security threats and how their contractors are working to mitigate them. (Courtesy of Sensi)
August 9, 2023
✕
Image in modal.

According to a recent study from Parks Associates, 72% of smart home product owners are concerns with the security of the personal data collected by their devices — and with so many smart HVAC products on the market today, HVAC customers have to make up a huge portion of those concerned about cybersecurity.

The security of a homeowner’s personal data is a significant barrier to the widespread adoption of smart home technology across the board, which means it’s up to HVAC contractors to educate their customers on which smart systems they can trust. And not only do contractors need to address actual security concerns for their customers, but they also need to understand and ease their potential cybersecurity worries.Through partnering with trusted, vetted manufacturers and implementing best practices on their own end, HVAC contractors can assist in the widespread adoption of smart HVAC systems that increase energy efficiency and build trust when it comes to the reliability, safety, and effectiveness of smart HVAC systems.

“The biggest concern is around the consumer’s personal contact and whether the company is sharing that data with others without their consent or knowledge.”
- Paul Williams
chief product officer
Nice North America

Concerns around Security

Increased connectivity and data collection capabilities of smart HVAC systems provide homeowners with energy efficiency, comfort, and lower bills each month. However, in some homeowners’ minds, it’s a double-edged sword; these increased capabilities introduce opportunities for security risks.

“Some common concerns around cybersecurity in the context of smart HVAC systems include unauthorized access to personal data, potential breaches of sensitive information, and the risk of malicious actors gaining control over HVAC systems for harmful purposes,” said Rina Basholli, information security lead at Kode Labs, which provides software solutions for optimizing energy usage and overall operations in the real estate industry with the goal to enable sustainability, operational efficiencies, and comfort.

Paul Williams, chief product officer, Nice North America, said, “The biggest concern is around the consumer’s personal contact and whether the company is sharing that data with others without their consent or knowledge.”

The concerns are not surprisingly. With any piece of smart technology, consumers are expected to provide ample amounts of personal information that, in the event of a data breach, could leave them vulnerable.

Kode Labs Security Presentation.

PROTECT: Best practices during setup will help protect the customer’s security and privacy. (Courtesy of Kode Labs)

 

Easing Concerns

To address these concerns, there have been industry-wide efforts by most, if not all, major manufacturers of smart HVAC technology in order to protect user data. That being said, there are numerous steps contractors themselves can take to ease these concerns around the security of their customers’ smart home devices.

Looking for quick answers on air conditioning, heating and refrigeration topics? Try Ask ACHR NEWS, our new smart AI search tool. Ask ACHR NEWS →

“Contractors can ease customer concerns by relaying that when it comes to data and personal information, smart thermostats leverage trusted industry standards and proven encryption and security techniques to ensure customer data is safe,” said Brendan O’Toole, vice president, Sensi product platform at Copeland.

Another step HVAC contractors can make is recommending products from companies who care deeply about data privacy and security, according to Alex Dougherty, director of security at ecobee. In particular, Williams said contractors should avoid manufacturers who are concerned about monetizing the customer’s data.

“This opens up the customer to the possibility of that data getting exposed to a wider audience or being used without their consent,” he said. “Those manufacturers [that a contractor recommends] should also have a commitment and track record of protecting consumer privacy.”

In addition to partnering with reputable companies, Basholli said HVAC contractors can also provide transparency and education around the security features of the installed smart devices and software. A couple key steps here include:

  • Explaining how personal data is protected;
  • Emphasizing the importance of regularly updating the software installed on the smart HVAC systems, which often include security patches that address security concerns, whether new or existing; and
  • Implementing multi-factor authentication in order to add an extra layer of security by making it harder for unauthorized individuals to access the system through requiring additional verification beyond passwords.

 

Who’s Worried?

Concerns around cybersecurity will vary depending on the type of customer, their investment in data privacy, and their level to exposure of cyber risks.

Williams said, “High-net-worth individuals (HNWIs) are often high-value targets for cyber criminals, as they have substantial assets, personal information, and public profiles that can be exploited for financial or reputational gain.” Since HNWIs have demonstrated more concerns than the average customer, they should be approached with full transparency about the risks and also the mitigations that can be put in place to secure their privacy, he said.

Basholli said customers within industries that deal with sensitive information or individuals with heightened cybersecurity awareness tend to be among the more concerned.

“To approach the conversation with these customers, it is essential to highlight the advanced security measures implemented in [smart HVAC] products,” said Basholli. Showing customers that their specific concerns around cybersecurity are deeply understood, by addressing them with tailored solutions, will help build trust and confidence in the contractor’s commitment to protecting customer data.

While many smart device users are already concerned about the possibility of their data being compromised or shared, a lot of them don’t necessarily understand what kind of data is being shared with the manufacturer.

“In our Smart Home Data Privacy Survey, only 13% of smart thermostat owners researched their manufacturers’ data privacy policy before purchase,” said O’Toole. “Additionally, around 1 in 5 respondents (19% smart thermostat owners, 23% non-owners) admit that they’re not sure what kind of information is shared. However, after learning the truth about how certain smart thermostat manufacturers use their data, 2 in 3 smart thermostat owners were at least ‘somewhat more concerned’ about using their smart thermostats.”

Nor do they necessarily have a full understanding of what data to be concerned about. HVAC data collected by smart home devices (e.g. when the HVAC system powers on, temperature recovery time, indoor air quality, etc.) is valuable for energy efficiency, demand response, and grid management purposes, it’s data that, when standing alone, doesn’t expose the customer to many privacy concerns.

The real concern revolves around the customer’s personal information: name, address, phone number, email, etc.

“Which can be linked to the HVAC usage data and potentially reveal personal habits, preferences, or behaviors,” explained Williams. “Customers should be aware of how their contact information is collected, stored, and shared by the device manufacturer or service provider, and what options they have to opt out or delete their information if they wish.”

While privacy is important, there’s another thing that customer’s should be equally concerned about: the potential risks of cyberattacks on their smart devices.

“Unauthorized access to HVAC systems, for example, can lead to inefficient operation, increased energy consumption, or even physical damage,” said Basholli. “It is crucial to raise awareness among users that security encompasses not only the protection of personal data but also the overall operational safety of their smart devices.”

Another less nefarious concern is data collection for marketing.

“While most thermostat manufacturers follow these best practices, many customers don’t understand that their data could also be leveraged in other ways by these companies for targeting or marketing purposes, so it’s important for consumers to be informed when they are selecting the right thermostat for them,” said O’Toole.

 

Practices that Protect

Fortunately, there are already HVAC systems out there that protect against cyberattacks or security risks through steps like encryption, requiring passwords, updates, and not sharing personal information with anyone but the customer.

Ecobee starts its customer protection by ensuring their physical devices themselves are tamper-proof. In addition, passwords are required for the web portal and mobile app associated with their products, communications to and from the thermostat are encrypted, each device is designed with a unique security key only able to access their backend systems with an authenticated security key (called a PKI), and all systems have protections in place to block and detect anomalous activity.

“All data at rest in storage is also encrypted, meaning that it’s useless to someone that may have gained access to it, including our own internal staff,” said Andrew Gaichuk, senior director of technical operations at ecobee. “We can push out new security patches to our thermostats using over-the-air technology to address any weaknesses, even if the device is in the field. Firmware updates are cryptographically signed to prevent tampering with images.”

When it comes to the actual install of smart devices, there are a few best practices to follow to protect the customer’s security and privacy.

“As with any home network, ensure you are not using default login information/password and for added security hide your SSID name,” said Williams. “This will prevent unauthorized access to your network and devices.”

Kode Labs recommends the following to ensure robust cybersecurity when it comes to smart HVAC installations:

  • Conduct thorough risk assessments;
  • Implement strong access controls;
  • Regularly update software and firmware; and
  • Enable system monitoring and logging.

However, perhaps the important step revolves around educating customers on what they can do themselves when using their smart home systems on a daily basis.

“Contractors should educate end users on cybersecurity best practices, such as using strong passwords, being cautious of suspicious emails or links, and regularly reviewing access permissions,” said Basholli. “User awareness is critical in maintaining a secure environment.”

KEYWORDS: cybersecurity Security and HVACR smart buildings smart homes

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

 

Hannah belloli
Hannah Belloli is editor-in-chief of Plumbing & Mechanical and Supply House Times. She brings six years of experience as a trade journalist with BNP Media, including four years as an editor at The ACHR NEWS and two years with Walls & Ceilings. Hannah holds a bachelor’s degree in communications from Wayne State University, where she also earned minors in English, journalism, and creative writing. As the daughter of a carpenter, she has long held an appreciation for the skilled trades and the professionals who drive the industry forward.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • HVAC-enrollment

    The Trades Are Back: HVACR Programs See Nearly 30% Enrollment Spike

    A new wave of future technicians is entering the pipeline.  
    Training and Education
    By: Matt Jachman
  • 2025 Top 40 Under 40

    2025 Top 40 Under 40 HVACR Professionals List

    The 11th annual Top 40 Under 40 list highlights those...
    HVAC Contracting
    By: Hannah Belloli-Oster
  • LG Ductless Mini-Split Systems

    The 9 Types of Heat Pumps

    As the U.S. moves toward electrification, heat pumps are...
    Ground Source Heat Pumps
    By: Joanna R. Turpin
Subscription Center
  • Create an Account
  • Start a Subscription
  • Manage My Account
  • Sign Up for Newsletters
  • Visit Customer Service
  • Update Preferences

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to The News audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of The News or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Piggy Bank
    Sponsored byWatercress Financial

    Energy Prices, Inflation, and HVAC: What Today’s Homeowners Care About

  • Refrigerated Food
    Sponsored bySolstice Advanced Materials

    R-455A Refrigeration: A Cold Storage Solution for the Future

  • Airex Rooftop Units
    Sponsored byAirex Manufacturing Inc

    Consolidating Roof Penetrations: A Growing Trend in Multifamily HVAC Design

Popular Stories

HVAC-Price-Increase-graphic

HVAC Price Increase List: June 2026

Trump-Section-232.jpg

Trump Reduces Section 232 Tariffs on HVAC Equipment to 15%

Refrigerants-and-gauge.jpg

HVAC Industry Warns of Counterfeit Refrigerants Entering U.S. Supply Chain

U.S. Supreme Court building

95% Furnace Efficiency Rule to Get New Hearing

Midea-training.jpg

HVAC Workforce Crisis Expands Beyond Technicians to Instructor Shortages

View The ACHR NEWS
Centennial Anniversary Timeline

The ACHR News Timeline Chart
Submit a Letter
Submit a letter to our editors.

Events

November 6, 2025

Next-Gen Data Center Cooling: HVAC Innovation and Real-World Solutions

On Demand As AI workloads and high-density computing push traditional cooling methods to their limits, the data center industry is accelerating the adoption of next-generation HVAC technologies.

June 23, 2026

HVAC Duct Sealing Mastics: Why Selection Matters

In this webinar we will detail what HVAC material buyers and technicians need to know when selecting duct mastics, including matching mastic to substrate, alternatives to liquid mastic, and where UL 181 Listings fit into real world installations.

View All Submit An Event

Poll

Summer Staff

Are you fully staffed for the summer season?
View Results Poll Archive

Products

BNI Mechanical/Electrical Square Foot Costbook, 2026 Edition

BNI Mechanical/Electrical Square Foot Costbook, 2026 Edition

See More Products
HVAC Duct Sealing Mastics: Why Selection Matters - Free Webinar - 6/23/2026

Related Articles

  • Warehouse

    7 Best Practices for HVAC Warehouses

    See More
  • Gerald-Davis-Article-Photo.jpeg

    Navigating the Refrigerant Shift: Best Practices for Embracing the New HVAC Era

    See More
  • ai-training.jpg

    What Are the Best Practices for Training Teams on AI Readiness in HVAC?

    See More

Related Products

See More Products
  • SMACNA-logo8.gif

    Accepted Industry Practices for Sheet Metal Lagging

  • 0-88069-032-1-228x228.jpg

    HVAC Security & Safety for Vulnerability Assessment

See More Products

Related Directories

  • Veridify Security

    Veridify Security provides cybersecurity for BACnet building controls, building automation / BMS, smart buildings, IoT devices, and other networked OT equipment.
  • AirEase

    Residential central heating and air conditioning products, packaged units, and ductless split systems 5 tons and under.
  • Veridify Security (Software/Video)

    Veridify Security provides cybersecurity for BACnet building controls, building automation / BMS, smart buildings, IoT devices, and other networked OT equipment.
×

Sign Up. Stay Informed.

The #1 trusted source for the HVACR industry since 1926

SUBSCRIBE
  • RESOURCES
    • Advertise
    • Contact Us
    • Advisory Board
    • Classifieds
    • Submit a Letter
    • Directories
    • Store
  • ACCOUNT CENTER
    • Create an Account
    • Start a Subscription
    • Manage My Account
    • Sign Up for Newsletters
    • Visit Customer Service
    • Update Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • Instagram
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing