search
Ask ACHR NEWS AI
cart
facebook twitter instagram linkedin youtube
  • Sign In
  • Subscribe
  • Sign Out
  • My Account
  • NEWS
  • TECHNOLOGY
    • Heating & Boilers
    • Cooling & Chillers
    • Pumps & Flow Controls
  • SECTORS
    • Commercial
    • Health Care
    • Data Center
    • Educational Facilities
  • DESIGN | CONSTRUCTION
  • OTHER TOPICS
    • High-Performance Buildings & Automation
    • Ventilation and IAQ
    • Commissioning
    • HVAC Retrofits
  • TODAY’S BOILER
    • Today’s Boiler Archives
    • Today’s Boiler Digital Edition
  • MORE
    • Case Studies
    • Podcasts
    • Videos
    • Directory
    • Webinars
    • ES NEWS Store
    • White Papers
  • SIGN UP
  • Back to The NEWS
Engineered Systems NEWSHVAC Engineering SectorsHigh-Performance Buildings & AutomationCommercial HVAC

Building Automation

Making BAS Accessible — But Protected From Cyberattack

The Target hacking debacle is still under investigation, but there are lessons to be learned on protecting personal information.

By Paul Ehrlich P.E.
Building Automations
April 1, 2014

Chances are you have heard about the data breach at Target that occurred late last year, in which customers’ information including credit card numbers were obtained through a cyberattack.

The details are still under investigation, and the results of what is found could have a major impact on both network and credit card security. During this ongoing investigation, information about the attack has been appearing online and in the media. Some of this information has been fairly accurate, while other parts have been speculation. For example, the website www.KrebsOnSecurity.com revealed that the credentials to access the Target network were stolen from an HVAC and refrigeration contractor. This information appears to be accurate, but the site then went on to speculate that the contractor may have had access to the Target network in order to monitor the control systems for HVACR and refrigeration. That turned out to be false; the contractor had access to get work orders and to submit invoices. But even having this issue raised has caused concern for many owners about control systems being a potential security weakness.

While this may not have been the case with the Target attack, there are several security concerns including protecting from attacks both within and from outside of the network.  Internal protection is best handled through the use of a VLAN within an enterprise network or with a protected, dedicated controls network. Remote access, however, is more complicated.

One of the benefits of today’s BAS solutions is that they can be readily accessed both on site and remotely. Most systems are web-based, so there isn’t even any software required. Remote access provides many benefits, including the ability for the building operator to see systems from anywhere, and to get support from contractors and the design team without having them on-site. The challenge is to provide remote access for those who are authorized but not to allow remote access to be an entry point for a hacker who may attempt unauthorized access to the control system or other network assets. Here are some solutions to consider.

 

IT-Controlled Access

When the control system is on the owner’s enterprise network, remote access is generally controlled by IT.  The owner’s IT group is generally able to provide remote access using standard tools. For example, a contractor may need to have network VPN access that may require special tokens, passwords, or in some cases, a dedicated laptop. This approach generally provides a good level of security but can take time to set up, and management can be a challenge.

 

BAS on the Internet

To simplify remote access, systems can be installed with a BAS router directly connected to the internet through a DSL, wireless, or cable modem. This approach makes access easy, but it can expose both the BAS and potentially other devices on the network to an attack. In the past, we have counted on this being “security through obscurity,” but as cyberattacks become more sophisticated, this is becoming a risky approach.

 

BAS Firewalls

Vendors are starting to offer specialized firewalls intended to provide limited network access for BAS systems. These firewalls are generally a combination of hardware and software to provide authentication and access. One product to evaluate is the Lynx Spring Cyber Pro (http://lynxcyberpro.com), which can be used either on an enterprise network or from a dedicated facilities network. The use of a specialized network security device may provide the best of both worlds — providing the security benefits of a VPN with the simplicity and flexibility of having the system directly on the netw

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

 

Paul Ehrlich is the founder and president of Building Intelligence Group LLC, a consulting firm focused on the delivery of energy efficient commercial buildings with a  focus on controls, systems integration, and building to grid integration. For more information, see www.buildingintelligencegroup.com.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • HVAC-enrollment

    The Trades Are Back: HVACR Programs See Nearly 30% Enrollment Spike

    A new wave of future technicians is entering the pipeline.  
    News
    By: Matt Jachman
  • 2025 Top 40 Under 40

    2025 Top 40 Under 40 HVACR Professionals List

    The 11th annual Top 40 Under 40 list highlights those...
    HVAC Light Commercial Market
    By: Hannah Belloli-Oster
  • LG Ductless Mini-Split Systems

    The 9 Types of Heat Pumps

    As the U.S. moves toward electrification, heat pumps are...
    HVAC Residential Market
    By: Joanna R. Turpin

More Videos

Today's Boiler

Spring 2026 Issue

Today's Boiler - Spring 2026 Cover

Read More from Today's Boiler

Case in Point Logo

Smarter Hydronic Design for Data Centers - Free Webinar - January 22, 2026

Related Articles

  • Building Automation: Making Commercial Controls Work

    See More
  • Building Automations

    The Lighting/BAS Convergence, Cont’d.

    See More
  • BuildingAutomation

    BAS History: A Look Back

    See More

Related Products

See More Products
  • Optimizing Social Media from a B2B Perspective

  • The ACHR News - March 2, 2026

    ACHR NEWS March 2, 2026, Issue

  • The ACHR News - October 6,  2025

    ACHR NEWS October 6, 2025, Issue

See More Products

Events

View AllSubmit An Event
  • November 13, 2025

    4 Lead Generation Mistakes You Might Be Making in Your Business & How to Fix Them

    On Demand From website gaps to follow-up breakdowns, you’ll walk away with practical tips to improve your lead flow process and turn your marketing investment into actual revenue results.
View AllSubmit An Event
×

Sign Up. Stay Informed.

The #1 trusted source for the HVACR industry since 1926

SUBSCRIBE
  • RESOURCES
    • Advertise
    • Contact Us
    • Advisory Board
    • Classifieds
    • Submit a Letter
    • Directories
    • Store
  • ACCOUNT CENTER
    • Create an Account
    • Start a Subscription
    • Manage My Account
    • Sign Up for Newsletters
    • Visit Customer Service
    • Update Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • Instagram
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing