Skip to main content
Log in

Intelligent building systems: security and facility professionals’ understanding of system threats, vulnerabilities and mitigation practice

  • Original Article
  • Published:
Security Journal Aims and scope Submit manuscript

Abstract

Intelligent Buildings or Building Automation and Control Systems (BACS) are becoming common in buildings, driven by the commercial need for functionality, sharing of information, reduced costs and sustainable buildings. The facility manager often has BACS responsibility; however, their focus is generally not on BACS security. Nevertheless, if a BACS-manifested threat is realised, the impact to a building can be significant, through denial, loss or manipulation of the building and its services, resulting in loss of information or occupancy. Therefore, this study garnered a descriptive understanding of security and facility professionals’ knowledge of BACS, including vulnerabilities and mitigation practices. Results indicate that the majority of security and facility professionals hold a general awareness of BACS security issues, although they lacked a robust understanding to meet necessary protection. For instance, understanding of 23 BACS vulnerabilities were found to be equally critical with limited variance. Mitigation strategies were no better, with respondents indicating poor threat diagnosis. In contrast, cybersecurity and technical security professionals such as integrators or security engineering design professionals displayed a robust understanding of BACS vulnerabilities and resulting mitigation strategies. Findings support the need for greater awareness for both security management and facility professionals of BACS vulnerabilities and mitigation strategies.

This is a preview of subscription content, log in via an institution to check access.

Access this article

Price excludes VAT (USA)
Tax calculation will be finalised during checkout.

Instant access to the full article PDF.

Institutional subscriptions

Fig. 1

(Brooks et al. 2018b, p. 200)

Fig. 2

(Brooks et al. 2018b, p. 125; Assante 2015, p. 11)

Fig. 3
Fig. 4
Fig. 5

Similar content being viewed by others

References

Download references

Acknowledgements

This article was made possible by research funding and membership participation from the ASIS Foundation, the Security Industry Association (SIA), and the Building Owners and Managers Association (BOMA). The research Report: Brooks, D. J., Coole, M., Haskell-Dowland, P., Griffith, M., & Lockhart, N. (2018b). Building automation & control systems: An investigation into vulnerabilities, current practice & security management best practice.

Author information

Authors and Affiliations

Authors

Corresponding author

Correspondence to David J. Brooks.

Additional information

Publisher's Note

Springer Nature remains neutral with regard to jurisdictional claims in published maps and institutional affiliations.

Rights and permissions

Reprints and permissions

About this article

Check for updates. Verify currency and authenticity via CrossMark

Cite this article

Brooks, D.J., Coole, M. & Haskell-Dowland, P. Intelligent building systems: security and facility professionals’ understanding of system threats, vulnerabilities and mitigation practice. Secur J 33, 244–265 (2020). https://doi.org/10.1057/s41284-019-00183-9

Download citation

  • Published:

  • Issue Date:

  • DOI: https://doi.org/10.1057/s41284-019-00183-9

Keywords

Navigation