NIST Releases Tips & Tactics for Building Automation & Control System Cybersecurity | NIST
Skip to main content
Official websites use .gov
A .gov website belongs to an official government organization in the United States.
Secure .gov websites use HTTPS
A lock (
) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.
NIST Releases Tips & Tactics for Building Automation & Control System Cybersecurity
August 19, 2026
By:Keith Stouffer and Michael Galler
Recent cyberattacks highlight the growing threat to operational technology (OT) used in critical infrastructure. Whether you work for an infrastructure owner/operator or are a consumer of an infrastructure service, the events of the past few weeks have made it clear that cybersecurity is an important factor in ensuring the safe and reliable delivery of critical goods and services. For OT owners/operators, it can be challenging to address the range of cybersecurity threats, vulnerabilities and risks that can negatively impact their operations, especially with limited resources.
Modern commercial and federal buildings rely heavily on Building Automation & Control Systems (BACS), to manage heating, ventilation, air conditioning (HVAC), lighting, access control, fire alarms, energy management, and other critical operations. These OT systems improve occupant comfort and safety, reduce energy consumption, and streamline facility management, but as BACS networks are integrated with corporate networks and the cloud, their risk of cyberattack increases significantly.
To help resource-constrained BACS owners/operators manage these risks, NIST developed aquick-start infographicoutlining immediate, actionable security steps.While the infographic was developed in collaboration with the BACS community, the recommendations offer valuable protection for critical infrastructure sectors including water/wastewater, transportation, energy, manufacturing, healthcare, and food/agriculture.
In addition to the infographic, there are many OT cybersecurity resources available from NIST to help you, including:
- Cybersecurity for Building Systems Project: Developing building services cybersecurity application profiles and guidance needed by building owners, designers, manufacturers and others involved in the lifecycle of the building, to understand threats, risks, countermeasures and governance approach and to ensure cyber-secure facilities.
- National Cybersecurity Center of Excellence (NCCoE): Security guidelines for Water/Wastewater, Transportation, Energy, and Manufacturing sectors.
- Guide to Operational Technology (OT) Security: Guidance on how to secure OT while addressing their unique performance, reliability, and safety requirements. NIST is currently revising NIST SP 800-82 Guide to Operational Technology (OT) Security to reflect the state of practice in cybersecurity risk management approaches for OT. We look forward to sharing a draft of the next revision for public comment later in 2026.
- Cybersecurity Framework (CSF): Voluntary guidance, based on existing standards, guidelines, and practices for organizations to better manage and reduce cybersecurity risk.
- CSF Manufacturing Profile: Provides CSF version 1.1 implementation details developed for the manufacturing environment. The “Manufacturing Profile” of the CSF can be used as a roadmap for reducing cybersecurity risk for manufacturers that is aligned with manufacturing sector goals and industry best practices.
- CSF Manufacturing Profile Implementation Guide: Implementation guidance to help manufacturers to select and deploy cybersecurity tools and techniques that best fit their needs while minimizing operational impacts. The Guide provides general implementation guidance (Volume 1) and two complete example proof-of-concept solutions (Volume 2 and Volume 3) demonstrating how available open-source and commercial off-the-shelf products can be implemented in manufacturing environments to satisfy the Manufacturing Profile’s requirements.
- Risk Management Framework (RMF): A comprehensive, flexible, repeatable, and measurable 7-step process that any organization can use to manage information security and privacy risk for organizations and systems and links to a suite of NIST standards and guidelines to support implementation of risk management programs to meet the requirements of the Federal Information Security Modernization Act (FISMA).
The collection of NIST OT cybersecurity resources is available on the Operational Technology Security website.
In addition to the OT-specific cybersecurity resources, NIST offers:
Ransomware protection and response Guidance.
Cybersecurity resources for small businesses: Small Business Cybersecurity Corner.
Preventing and recovering from cybersecurity incidents: Responding to a Cyber Incident.
About the author
Keith Stouffer is a supervisory mechanical engineer and has been at the National Institute of Standards and Technology since 1989, focusing on industrial control system (ICS) and OT cybersecurity since 2000. He leads the Cybersecurity for Operational Technology Systems Team and is the lead author of NIST Special Publication 800-82, Guide to Operational Technology (OT) Security, which provides guidance on how to secure OT while addressing their unique performance, reliability and safety requirements.
Michael A. Galler is a mechanical engineer in the Engineering Laboratory (EL) at the National Institute of Standards and Technology. He is an Investigator on the AI Optimized Building Controls project and is the founding Chair of the ASHRAE MTG for Cybersecurity for HVAC Systems and Related Infrastructure, protecting heating, ventilation, air conditioning (HVAC) systems, building management infrastructure, and associated digital interfaces from cyber threats.
Comments
Add new comment
Was this page helpful?
