search
Ask ACHR NEWS AI
cart
facebook twitter instagram linkedin youtube
  • Sign In
  • Subscribe
  • Sign Out
  • My Account
  • NEWS
  • TECHNOLOGY
    • Heating & Boilers
    • Cooling & Chillers
    • Pumps & Flow Controls
  • SECTORS
    • Commercial
    • Health Care
    • Data Center
    • Educational Facilities
  • DESIGN | CONSTRUCTION
  • OTHER TOPICS
    • High-Performance Buildings & Automation
    • Ventilation and IAQ
    • Commissioning
    • HVAC Retrofits
  • TODAY’S BOILER
    • Today’s Boiler Archives
    • Today’s Boiler Digital Edition
  • MORE
    • Case Studies
    • Podcasts
    • Videos
    • Directory
    • Webinars
    • ES NEWS Store
    • White Papers
  • SIGN UP
  • Back to The NEWS
Engineered Systems NEWSHVAC Engineering SectorsHigh-Performance Buildings & AutomationData Center HVAC

Is Your Building Cybersecure?

By Kevin Callahan, Pook-Ping Yao
Cybersecurity

It’s a new decade, and technology is advancing whether we’re ready or not. We must catch up with the cybersecurity demands — now.

October 16, 2020

This article originally appeared in the October issue of www.automatedbuildings.com. See the original article in its entirety by clicking here. 

 

In late 2019, Alerton hosted a conference for its partners in California. There, Eric O’Neill, a former FBI counter-terrorism and counter-intelligence operative, spoke about cybersecurity in our new age of smart technology and connectivity.

A question came from the audience, “How do we respond to customers who don’t worry about maintaining their operating systems or securing their networks because they aren’t connected to the internet?

O’Neill threw his head back and laughed. “If they think it’s secure, it’s not secure.”

That’s the attitude we need today: a healthy skepticism to fuel our cyber awareness.

We all know cyberattacks are a real threat in today's hyper-connected world, but so many folks don’t realize just what that entails. Unfortunately, cybersecurity techniques for traditional IT systems may not work for connected operational technology (OT) systems, as the National Institute of Standards and Technology (NIST) shared in a paper last year.

It’s a new decade, and technology is advancing whether we’re ready or not. We must catch up with the cybersecurity demands — now.


 
What Does Cybersecurity look like Today?

When it comes to cybersecurity, you can’t rest on your laurels. It’s not a one-and-done process, and there are no half-measures or shortcuts.

Cybersecurity’s a perpetual journey of learning and refining and reiterating. Today, where hacks are commonplace and take so many different forms, there’s no getting out of it.

Many attacks — malware, email phishing, distributed denial of service (DDOS), ransomware, and the like — capitalize on our connectivity. The NIST cybersecurity framework is a tremendously useful resource in guarding against those cyberattacks.

We shouldn’t discount the power of a confidence trick or social hacking. They might seem more old-fashioned, but they’re no less potent. There have also been cases where someone found sensitive information on a slip of paper, or even went dumpster-diving to get the credentials they needed to hack a system. If a hacker sees an opportunity — whether it’s social, physical, or digital — they won’t hesitate to use it.

Cybersecurity’s an evolving concern, but one tenet remains constant: We cannot take for granted that our system is secure. We must expect the worst in order to prepare for it.


 
Why Should I Update My Software?

Here’s an oxymoron for you: “My system’s mission critical, so I can’t update the operating system.”

That sentiment is oddly commonplace, and it speaks to a real misunderstanding about the importance of software updates.

Companies don’t push software updates for the heck of it. At the very least, software updates improve on the release that came before for a better user experience. More critically, many software updates address technical bugs and security vulnerabilities that might otherwise keep a system from running properly.

The system being critical isn’t an excuse not to push updates. It’s the exact reason to push them. The danger of cyberattacks makes it even more important to maintain and update the system. While we might think our systems are working just fine, vendors often get feedback from different customers on cybersecurity flaws. By updating our systems, we benefit from the result of many different “penetration tests” on other users’ networks.

Of course, we all know that updating software doesn’t always go smoothly. That’s why most large organizations don’t let software updates get pushed automatically as a standard policy. They vet the updates first and ensure it won’t mess up the system before they deploy. They still push those updates even if they’re a week or a month behind.

Dealers and integrators need to adopt that process. Blend software screening into your workflows and ensure that updates won’t affect the network before you push them out. Consider setting up a clone of your customers’ systems to test software updates.

 

Can We Trust the Cloud?

It’s only in recent years that the perception of the cloud has begun to change, and there’s a long way to go yet. Many people still see the cloud as vulnerable and easily hacked, but, often, the cloud is actually more secure than anything folks are doing on the ground.

Think about it: securing the cloud is Amazon, Google, and Microsoft’s business. They have to be far more diligent about their security than any corporate IT on the ground because if their cloud services aren’t secure, they’re defunct. That’s why even the government has begun to adopt the cloud.
A few years ago, the U.S. government established a program called FedRAMP, which “facilitates the shift from insecure, tethered, tedious IT to secure, mobile, nimble, and quick IT.”

FedRAMP’s goal is to “promote the adoption of secure cloud services across the federal government by providing a standardized approach to security and risk assessment.” 

There are still lots of holdouts, but the FedRAMP program indicates a real shift for the cloud. People are increasingly placing their trust in the cloud, because they know Google, Amazon, and Microsoft are the experts. From their software to their server rooms and data centers, these companies take security seriously.

The question of securing data centers and server rooms is significant because many of the biggest hacks in recent years have actually been physical hacks, where someone found a way in. Your own server room is less likely to have the level of monitoring, physical security, and digital security that an organization like Amazon or Google has.

Their facilities are locked down with cameras everywhere. The moment someone adds a device to the network, they know. In fact, they can ensure that no outside, unregistered computers can connect to the network or system. They might even design the facilities so that the comms room is kept separate from the data center, and anyone doing maintenance on the comms room can’t access the data center.

The best of the best makes sure these cloud service companies deliver on their promise of security. How confident are you in your security systems?

Talk with experts about cybersecurity, learn all you can about best practices and ways to safeguard your systems, and approach cybersecurity with an attitude of humility. As Eric O’Neill so eloquently said, the moment you’re confident that your systems are secure, they aren’t.

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

 

Kevin callahan alerton 900x550

Kevin Callahan is a product evangelist at Alerton. 

Ping 900x550
Pook-Ping Yao is co-founder and CEO of Optigo Networks.

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • HVAC-enrollment

    The Trades Are Back: HVACR Programs See Nearly 30% Enrollment Spike

    A new wave of future technicians is entering the pipeline.  
    Training and Education
    By: Matt Jachman
  • 2025 Top 40 Under 40

    2025 Top 40 Under 40 HVACR Professionals List

    The 11th annual Top 40 Under 40 list highlights those...
    HVAC Commercial Market
    By: Hannah Belloli-Oster
  • LG Ductless Mini-Split Systems

    The 9 Types of Heat Pumps

    As the U.S. moves toward electrification, heat pumps are...
    Air Source Heat Pumps
    By: Joanna R. Turpin

More Videos

Today's Boiler

Spring 2026 Issue

Today's Boiler - Spring 2026 Cover

Read More from Today's Boiler

Case in Point Logo

Smarter Hydronic Design for Data Centers - Free Webinar - January 22, 2026

Related Articles

  • What Is Your Building Saying About You?

    See More
  • Is Your Own Office a Model of Comfort?

    See More
  • Cybersecurity.

    Ransomware is Rampant: Is Your HVAC Business Safe?

    See More

Related Products

See More Products
  • new cover.jpg

    Profit is An Attitude: The Strategies You Need to Optimize Profits

  • front cover only.jpg

    How to Market Your HVAC Business

  • Green Tips for Building Maintenance Engineers

See More Products

Related Directories

  • Your Bargain Mart

    We are a MRCOOL Dealer and carry contractor-grade HVAC equipment, air handlers, condensers, heat pumps, gas furnaces, evaporator coils and heat pumps, gas, and electric packaged units.
×

Sign Up. Stay Informed.

The #1 trusted source for the HVACR industry since 1926

SUBSCRIBE
  • RESOURCES
    • Advertise
    • Contact Us
    • Advisory Board
    • Classifieds
    • Submit a Letter
    • Directories
    • Store
  • ACCOUNT CENTER
    • Create an Account
    • Start a Subscription
    • Manage My Account
    • Sign Up for Newsletters
    • Visit Customer Service
    • Update Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • Instagram
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing