<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>News Archives - Smart Building Design</title>
	<atom:link href="https://www.smartbuildingdesign.com/category/news/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.smartbuildingdesign.com/category/news/</link>
	<description></description>
	<lastBuildDate>Mon, 21 Jul 2025 14:29:42 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9.4</generator>

<image>
	<url>https://www.smartbuildingdesign.com/wp-content/uploads/2022/08/favicon.png</url>
	<title>News Archives - Smart Building Design</title>
	<link>https://www.smartbuildingdesign.com/category/news/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Wireless Without Worries: A Conversation with LumenRadio on the Future of BAS Connectivity</title>
		<link>https://www.smartbuildingdesign.com/lumenradio-wireless-bacnet/</link>
					<comments>https://www.smartbuildingdesign.com/lumenradio-wireless-bacnet/#respond</comments>
		
		<dc:creator><![CDATA[Greg Fitzpatrick]]></dc:creator>
		<pubDate>Mon, 21 Jul 2025 14:27:54 +0000</pubDate>
				<category><![CDATA[Article]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[wireless BACnet]]></category>
		<guid isPermaLink="false">https://www.smartbuildingdesign.com/?p=3158</guid>

					<description><![CDATA[<p>As the demand for smarter, more flexible building systems grows, wireless technology is playing an increasingly critical role in the future of Building Automation Systems (BAS). Historically seen as less reliable than their wired counterparts, wireless solutions have made major advancements in reliability, scalability, and security. One of the companies leading this evolution is LumenRadio, [&#8230;]</p>
<p>The post <a href="https://www.smartbuildingdesign.com/lumenradio-wireless-bacnet/">Wireless Without Worries: A Conversation with LumenRadio on the Future of BAS Connectivity</a> appeared first on <a href="https://www.smartbuildingdesign.com">Smart Building Design</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>As the demand for smarter, more flexible building systems grows, wireless technology is playing an increasingly critical role in the future of Building Automation Systems (BAS). Historically seen as less reliable than their wired counterparts, wireless solutions have made major advancements in reliability, scalability, and security. One of the companies leading this evolution is LumenRadio, whose wireless BACnet solution is changing the way integrators and building owners approach system design and deployment.</p>



<p>In this interview, I sit down with Maciej Oldziej, the general manager of LumenRadio, to explore the current state of wireless in the BAS space, learn what sets their technology apart, and discuss how their wireless BACnet solution is enabling faster installations, reduced cabling costs, and more flexible building environments.</p>



<h3 class="wp-block-heading"><strong>Wireless adoption in BAS has historically been slow. Why do you think that’s been the case, and what’s changing now?</strong></h3>



<p>Reliability. Wireless is a household term, but within the BAS world, it is a term that sparks fear and uncertainty. At LumenRadio, we are educating the BAS community that there is a reliable wireless solution to meet their needs.</p>



<p>In my opinion, there are two primary factors driving wireless adoption for the retrofit market: limited labor force and decarbonization targets. The continued rising cost of building materials is a contributing factor.<br><br>For instance, in the education sector, approximately 79% of air handling units (AHUs) sold are for retrofit projects.</p>



<h3 class="wp-block-heading"><strong>What are some of the most common misconceptions about using wireless technology in building automation systems?</strong></h3>



<p>It doesn’t work, or that technology hasn’t evolved. The BAS industry is slow to adapt and accept new technologies, especially considering its historical sub-par experiences with wireless.</p>



<h3 class="wp-block-heading"><strong>From your perspective, what are the key advantages of wireless over traditional wired BAS installations?</strong></h3>



<p>Reduce Install Burden: costs and time of installation. Minimized tenant and space disruption. More predictable cost analysis. And easier troubleshooting vs. trying to find where a fault is on the wire trunk.</p>



<h3 class="wp-block-heading"><strong>What types of building environments are the best candidates for wireless BAS deployments?</strong></h3>



<p>We are seeing success in Hotels/Resort, Schools, and Medical Office Buildings. Historical buildings like courtrooms, churches, and museums. Warehouse and Manufacturing sites are also a great contender with wide open spaces that want to limit day-to-day disruption.</p>



<h3 class="wp-block-heading"><strong>How has wireless reliability and security evolved over the past five years in the BAS industry?</strong></h3>



<p>With the adoption of IoT and remote monitoring, the security and privacy concerns have shifted to the cloud. BACnet Secure has been part of the conversation, but the adoption has been slow. IT departments want to know everything and anything on their local networks. &nbsp;</p>



<h3 class="wp-block-heading"><strong>What should building owners and operators consider when deciding between wired and wireless BAS systems?</strong></h3>



<p>Wireless systems are more flexible. If the building owner and operator have leasable spaces that are prone to change, wireless has a distinct advantage vs. wires. If the space is actively used 24/7 or only accessible during specific hours, wireless can help offset the install burden.</p>



<h3 class="wp-block-heading"><strong>How do you address concerns around interference with other wireless devices and networks in commercial buildings?</strong></h3>



<p>This a core value at LumenRadio; Wireless Without Worries is our motto. Our 19 patents in Wireless Networking allow us to be interference free and not interfere with other existing and future technologies.</p>



<p>Historically, many technologies are prone to network congestion or interference. For example, a stadium filled with people and smartphones, or an office building with BLE, WiFi, Microwaves, and other technologies contributing to the on-air congestion.</p>



<h3 class="wp-block-heading"><strong>Are there any regulatory or compliance factors to keep in mind when using wireless BAS technology?</strong></h3>



<p>In North America, you want FCC-compliant devices. Each device should have an FCC ID in the unlicensed bands like 2.4 ghz. If using LTE/Cellular technologies, additional certifications may be required.</p>



<p>Another thing to look out for is data storage and data visibility implications. When considering IoT, cloud, and wireless systems is paramount to understand how the data is being used and access control to ensure operational integrity within BAS systems.</p>



<h3 class="wp-block-heading"><strong>Can you give us a high-level overview of LumenRadio’s Wireless BACnet solution?</strong></h3>



<p>It’s rather simple! We replace cable runs between BACnet MS/TP field devices. Think of it as replacing a wired RS-485 trunk with a “wireless trunk”. The Wireless BACNet Mesh solution is a plug-and-play wireless MS/TP cable.</p>



<h3 class="wp-block-heading"><strong>What sets LumenRadio’s technology apart from other wireless solutions in the BAS space?</strong></h3>



<p>Cognitive Coexistence! It’s our core IP innovation that enables interference free transmission without the complexity of network configuration. It enables us to work in any radio and physical environment.</p>



<h3 class="wp-block-heading"><strong>How does LumenRadio’s solution maintain BACnet compliance and interoperability across different vendors?</strong></h3>



<p>Wireless BACnet devices cannot be BTL certified because they are not addressable nor visible in the BAS. However, we maintain interoperability across vendors by mimicking the MAC address of the BACnet field device it connects to and transmitting transparent BACnet. The BAS does not know it is wireless. We are a true wireless cable replacement!</p>



<h3 class="wp-block-heading"><strong>Can you walk us through a typical deployment process using your wireless BACnet solution?</strong></h3>



<p>Let’s take a rooftop retrofit example where running a cable across the roof or underneath the ceiling is prohibitive. Instead of running a cable between each RTU, we will install an individual W-BACnet device at each RTU controller. Then, a W-BACnet Gateway will automatically discover all the RTUs that will be discoverable in the BAS.</p>



<h3 class="wp-block-heading"><strong>How does LumenRadio’s mesh network technology work, and what benefits does it offer for BAS installations?</strong></h3>



<p>Wireless BACnet is a self-configuring and self-healing mesh network. Each W-BACnet node is a repeater that can directly connect to the gateway or indirectly propagate its signal. If a node loses a signal, other nodes in the network will automatically find a path to maintain connectivity. The primary benefit of using our technology is the plug-and-play nature accelerating installation by removing control cable runs from the equation. We built the solution with the installer in mind equipping them with Bluetooth app to quickly verify their installation.</p>



<h3 class="wp-block-heading"><strong>What’s the typical range and scalability of a LumenRadio wireless BACnet network?</strong></h3>



<p>Range! It’s our #1 question. Range will depend on the environment and antennas used. Inside the building, on average, I see 50-700 feet between devices. Outdoors we can reach up to a mile line-of-sight. Our recommendation is to build wireless MS/TP networks in line with wired networks: 25-40 devices per Wireless BACnet network. And yes, you can have multiple W-BACnet networks within the same space.</p>



<h3 class="wp-block-heading"><strong>How do you ensure security — both at the device and network level — with your wireless BACnet system?</strong></h3>



<p>Our networks are stand-alone, not Wifi, with dynamic encryption methods. Thanks to our IP, we can mitigate network jamming attacks and safeguard against replay attacks. Only devices that are commissioned on-site can join W-BACnet networks.</p>



<h3 class="wp-block-heading"><strong>Can LumenRadio’s solution coexist with legacy wired BACnet systems? How does that integration work in practice?</strong></h3>



<p>Yes! A great example is failing Lon VAV devices. It’s common to upgrade 2-3 end-of-life Lon VAVs to BACnet VAVs without affecting existing infrastructure. As Lon VAVs continue to fail, we can add them to the existing Wireless BACnet network without affecting Lon infrastructure.</p>



<h3 class="wp-block-heading"><strong>Do you have examples or case studies where your wireless BACnet solution delivered significant cost or time savings compared to traditional wired approaches?</strong></h3>



<p>We do! A great example is a Resort FCU retrofit where the installers saved 90% on install cost vs. running wire, and with limited impact on the business – I don’t think resort guest would enjoy the sound of drilling holes and someone being in their room!</p>



<hr class="wp-block-separator has-alpha-channel-opacity"/>



<p>A big thank you to Maciej for sharing his insights on the evolution of wireless in the BAS space and the innovative work LumenRadio is doing with their Wireless BACnet solution. As buildings continue to grow smarter and more connected, it’s clear that wireless will play a key role in driving both flexibility and efficiency in system design. We look forward to seeing how LumenRadio continues to shape the future of wireless BAS technology.</p>



<p></p>
<p>The post <a href="https://www.smartbuildingdesign.com/lumenradio-wireless-bacnet/">Wireless Without Worries: A Conversation with LumenRadio on the Future of BAS Connectivity</a> appeared first on <a href="https://www.smartbuildingdesign.com">Smart Building Design</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.smartbuildingdesign.com/lumenradio-wireless-bacnet/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Part 2: Diving Deeper: The Technical Realities of Zero Trust in OT–A Conversation with Neeve </title>
		<link>https://www.smartbuildingdesign.com/part-2-diving-deeper-the-technical-realities-of-zero-trust-in-ot-a-conversation-with-neeve/</link>
					<comments>https://www.smartbuildingdesign.com/part-2-diving-deeper-the-technical-realities-of-zero-trust-in-ot-a-conversation-with-neeve/#respond</comments>
		
		<dc:creator><![CDATA[Greg Fitzpatrick]]></dc:creator>
		<pubDate>Fri, 16 May 2025 19:31:13 +0000</pubDate>
				<category><![CDATA[Article]]></category>
		<category><![CDATA[News]]></category>
		<guid isPermaLink="false">https://www.smartbuildingdesign.com/?p=3133</guid>

					<description><![CDATA[<p>In Part One of our conversation, we explored the principles of Zero Trust and why it matters for remote access in smart buildings. But understanding the why is only half the equation. For those designing and deploying OT networks, the real challenge is the how—how to implement Zero Trust without breaking legacy systems, interrupting operations, [&#8230;]</p>
<p>The post <a href="https://www.smartbuildingdesign.com/part-2-diving-deeper-the-technical-realities-of-zero-trust-in-ot-a-conversation-with-neeve/">Part 2: Diving Deeper: The Technical Realities of Zero Trust in OT–A Conversation with Neeve </a> appeared first on <a href="https://www.smartbuildingdesign.com">Smart Building Design</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>In Part One of our conversation, we explored the principles of Zero Trust and why it matters for remote access in smart buildings. But understanding the <em>why</em> is only half the equation. For those designing and deploying OT networks, the real challenge is the <em>how</em>—how to implement Zero Trust without breaking legacy systems, interrupting operations, or getting lost in complexity.&nbsp;</p>



<p>I sat back down with <strong>Aaron Brondum</strong>, <strong>Sr. Director of Business Development at</strong> <strong>Neeve</strong>, to talk through the technical side of Zero Trust, and how Neeve is helping real-world organizations deploy it in a way that’s actually usable in the field.&nbsp;</p>



<p class="has-text-color has-link-color wp-elements-fe396db1f3e1107c57ada1ef0fe76137" style="color:#076499"><strong>Greg Fitzpatrick, CxA, Business Development Leader, Cochrane Supply</strong></p>



<p>Aaron, thanks for joining me again. Last time we covered the fundamentals of Zero Trust. Today, I want to dive into the more technical side of things. For those out there trying to figure out how to actually <em>apply</em> Zero Trust to an OT network, where should they be thinking about placing the solution? <br> </p>



<p class="has-text-color has-link-color wp-elements-08faa496b7ff9ea4140118ea1a8d4f8e" style="color:#026f47"><strong>Aaron Brondum, Sr. Director of Business Development, Neeve</strong></p>



<p>Great question, and placement is everything. In OT networks, the best place to start is at the IT/OT boundary. That’s where the biggest risk is, and it’s where Zero Trust can act as a secure gateway. Every connection trying to cross that boundary gets verified—user identity, device health, even where the traffic is coming from and going to. </p>



<p>From there, we look inside the OT network and apply micro-segmentation. Instead of treating the entire OT environment as one big trusted zone, we break it into smaller ones, HVAC, lighting, elevators, each with their own access rules. That way, even if something is compromised, it can’t spread.&nbsp;</p>



<p class="has-text-color has-link-color wp-elements-f7e84a12a69bf2dd9ca71f1759251cbe" style="color:#076499"><strong>Greg:</strong></p>



<p>That makes sense, sort of like building a wall, then putting locks on every door inside it. But what about remote access? That’s where a lot of threats get in. How does Neeve handle that differently? <br> </p>



<p class="has-text-color has-link-color wp-elements-4274a25c0462aa51f77b67fbfca92d4a" style="color:#026f47"><strong>Aaron:</strong> </p>



<p>Exactly—and you’re right, remote access is the biggest attack vector in most smart buildings today. That’s why we don’t rely on VPNs. VPNs are a one-and-done deal: you authenticate once, and suddenly you’ve got a tunnel to the entire network. </p>



<p>We use Zero Trust Network Access (ZTNA) instead. It’s more surgical. A technician accessing HVAC controllers only gets access to those, and only for a set time. Every session is authenticated and encrypted, and we can revoke access at any point. It’s dynamic, and it’s role-based.&nbsp;</p>



<p class="has-text-color has-link-color wp-elements-14b768085aead57f37c870a4b9968d23" style="color:#076499"><strong>Greg:</strong></p>



<p>That’s a huge improvement, especially when you’ve got vendors logging in from who knows where. But what about older systems—those legacy devices in OT that weren’t built with any of this in mind? </p>



<p class="has-text-color has-link-color wp-elements-4274a25c0462aa51f77b67fbfca92d4a" style="color:#026f47"><strong>Aaron:</strong> </p>



<p>That’s probably the biggest misconception we hear: “Zero Trust won’t work because my gear is too old.” The truth is, we don’t need the devices themselves to support modern security protocols. </p>



<p>Neeve secures the network layer, not the device layer. We look at the traffic moving between devices, enforce policies at the edge, and isolate anything that shouldn’t be talking. So even if a 20-year-old controller has no encryption, it can still live inside a secure, Zero Trust architecture.&nbsp;</p>



<p class="has-text-color has-link-color wp-elements-9faadd921d0d7d4b1f995f15d4d888ee" style="color:#076499"><strong>Greg:</strong> </p>



<p>So it’s not about upgrading all your gear, it’s about controlling what <em>talks</em> to what? </p>



<p class="has-text-color has-link-color wp-elements-6876c322ecd27424276c7a95268b9199" style="color:#026f47"><strong>Aaron:</strong></p>



<p>Exactly. We like to say: protect the flow, not the box. You don’t need to replace every sensor or controller. You just need to know what normal looks like, then put the guardrails in place to make sure it stays that way. </p>



<p class="has-text-color has-link-color wp-elements-9faadd921d0d7d4b1f995f15d4d888ee" style="color:#076499"><strong>Greg:</strong> </p>



<p>Let’s talk monitoring. Zero Trust is all about verification—but what kind of visibility do you need to really make it work? </p>



<p class="has-text-color has-link-color wp-elements-6876c322ecd27424276c7a95268b9199" style="color:#026f47"><strong>Aaron:</strong></p>



<p>You need full telemetry. That’s part of the power of our platform. We offer real-time monitoring of every connection and session—who connected, when, from where, and what they did. That allows us to: </p>



<ul class="wp-block-list">
<li>Spot anomalies quickly, </li>



<li>Detect lateral movement attempts, </li>



<li>And adjust access policies dynamically. </li>
</ul>



<p>It’s especially useful in OT environments where normal behavior is pretty stable. If a lighting controller suddenly starts trying to talk to an elevator PLC? That’s a red flag.&nbsp;</p>



<p class="has-text-color has-link-color wp-elements-9faadd921d0d7d4b1f995f15d4d888ee" style="color:#076499"><strong>Greg:</strong> </p>



<p>That kind of real-time insight would be huge for incident response too. Have you seen this deployed in the real world? </p>



<p class="has-text-color has-link-color wp-elements-6876c322ecd27424276c7a95268b9199" style="color:#026f47"><strong>Aaron:</strong></p>



<p>Yeah—one great example is Kilroy Realty. They came to us with growing concerns around remote vendor access and a need to strengthen security across multiple buildings. </p>



<p>We started with a risk assessment, then implemented micro-segmentation and ZTNA. Vendors only got access to the exact systems they needed, with MFA and session limits. All traffic was monitored in real time. No more open VPN tunnels.&nbsp;</p>



<p>The result? Tighter control, better compliance, and no disruptions to building operations.&nbsp;</p>



<p class="has-text-color has-link-color wp-elements-9faadd921d0d7d4b1f995f15d4d888ee" style="color:#076499"><strong>Greg:</strong> </p>



<p>That’s the sweet spot—better security, but nothing breaks. So, what are some best practices for firms trying to take this on themselves? </p>



<p class="has-text-color has-link-color wp-elements-4274a25c0462aa51f77b67fbfca92d4a" style="color:#026f47"><strong>Aaron:</strong> </p>



<p>Here’s a simple roadmap we’ve seen work: </p>



<ol start="1" class="wp-block-list">
<li>Start with an asset and communication map. Know what’s connected and how it communicates.</li>
</ol>



<ol start="2" class="wp-block-list">
<li>Segment your network. Start coarse, then work toward micro-segmentation. </li>
</ol>



<ol start="3" class="wp-block-list">
<li>Use role-based access and MFA. Make sure only the right people have access to the right systems. </li>
</ol>



<ol start="4" class="wp-block-list">
<li>Replace VPNs with ZTNA. That alone is a major leap forward. </li>
</ol>



<ol start="5" class="wp-block-list">
<li>Continuously monitor. Know what’s normal so you can spot what’s not. </li>
</ol>



<ol start="6" class="wp-block-list">
<li>Roll out in phases. Don’t try to do the whole network at once. Start where the risk is highest. </li>
</ol>



<p class="has-text-color has-link-color wp-elements-9faadd921d0d7d4b1f995f15d4d888ee" style="color:#076499"><strong>Greg:</strong> </p>



<p>Last question, what do you say to the folks who still think Zero Trust is too expensive or complex? </p>



<p class="has-text-color has-link-color wp-elements-4274a25c0462aa51f77b67fbfca92d4a" style="color:#026f47"><strong>Aaron:</strong> </p>



<p>I’d say they’re not wrong to worry, but they’re probably looking at the wrong solutions. Neeve was built specifically for OT environments, so we focus on using what’s already there. We don’t force forklift upgrades. We integrate gradually, and we secure networks that were never built to be secure. </p>



<p>In most cases, we’re helping organizations improve security <em>without increasing operational cost</em>. That’s the power of doing it right.&nbsp;</p>



<p class="has-text-color has-link-color wp-elements-14b768085aead57f37c870a4b9968d23" style="color:#076499"><strong>Greg:</strong></p>



<p>This has been incredibly helpful, Aaron. For anyone serious about OT cybersecurity, this kind of approach isn’t just smart, it’s necessary. Zero Trust isn’t a buzzword. It’s a technical strategy that works. And with solutions like Neeve, it’s finally accessible to the people who need it. </p>



<p class="has-text-color has-link-color wp-elements-4274a25c0462aa51f77b67fbfca92d4a" style="color:#026f47"><strong>Aaron:</strong> </p>



<p>Appreciate it, Greg. It’s always a pleasure to talk real-world security with someone who gets the OT side. Looking forward to more of these conversations, there’s a lot more ground to cover as this space continues to evolve. </p>



<p>As OT networks become more connected and remote access becomes more common, a Zero Trust architecture, especially one that can be deployed without disrupting legacy systems, is becoming the new standard. With practical tools like Neeve and a phased deployment strategy, cybersecurity is no longer a barrier to smart building innovation. It’s the foundation.&nbsp;</p>
<p>The post <a href="https://www.smartbuildingdesign.com/part-2-diving-deeper-the-technical-realities-of-zero-trust-in-ot-a-conversation-with-neeve/">Part 2: Diving Deeper: The Technical Realities of Zero Trust in OT–A Conversation with Neeve </a> appeared first on <a href="https://www.smartbuildingdesign.com">Smart Building Design</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.smartbuildingdesign.com/part-2-diving-deeper-the-technical-realities-of-zero-trust-in-ot-a-conversation-with-neeve/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>CISA’s challenge to a major stakeholder in the “Cyber Harmony” Model- The Manufacturer</title>
		<link>https://www.smartbuildingdesign.com/cisa-challenge-to-a-major-stakeholder-in-the-cyber-harmony/</link>
		
		<dc:creator><![CDATA[Greg Fitzpatrick]]></dc:creator>
		<pubDate>Sat, 20 Jan 2024 02:47:23 +0000</pubDate>
				<category><![CDATA[Article]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[buildingautomation]]></category>
		<category><![CDATA[contractors]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[HVAC]]></category>
		<category><![CDATA[IOT]]></category>
		<category><![CDATA[operationaltechnology]]></category>
		<guid isPermaLink="false">https://www.smartbuildingdesign.com/?p=2828</guid>

					<description><![CDATA[<p>CISA issues request for information urging software manufacturers to prioritize "Cyber Harmony".</p>
<p>The post <a href="https://www.smartbuildingdesign.com/cisa-challenge-to-a-major-stakeholder-in-the-cyber-harmony/">CISA’s challenge to a major stakeholder in the “Cyber Harmony” Model- The Manufacturer</a> appeared first on <a href="https://www.smartbuildingdesign.com">Smart Building Design</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p>In our pursuit of increased collaboration among construction, facilities, and IT, it becomes crucial for all stakeholders, including software manufacturers deploying products in the built environment, to integrate security features into their offerings.  The <a href="https://www.smartbuildingdesign.com/cybersecurity-awareness-2023-achieve-cyberharmony-with-smartbuildingdesign/" target="_blank" rel="noreferrer noopener">&#8220;Cyber Harmony&#8221;</a> model reveals that manufacturers play a pivotal role among the key stakeholders, contributing significantly to the industry&#8217;s progression toward achieving genuine Cyber Harmony.<br><br>In late December 2023, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) <a href="https://www.cisa.gov/news-events/news/cisa-issues-request-information-secure-design-software-whitepaper" target="_blank" rel="noreferrer noopener">issued a Request for Information (RFI)</a> to gather insights on secure-by-design software practices. This initiative aligns with the agency&#8217;s ongoing global campaign, urging software manufacturers to prioritize secure design and revamp their development programs.  Although there is a push for cybersecurity awareness throughout commercial real estate and all of its stakeholders, I believe that we can all agree that a push for manufacturers to develop more secure devices is a great start.</p>



<div style="height:25px" aria-hidden="true" class="wp-block-spacer"></div>



<h4 class="wp-block-heading">Some The Key Points:</h4>



<ul class="wp-block-list">
<li>CISA&#8217;s RFI, published in the Federal Register, seeks information to enhance its Secure by Design campaign.</li>



<li>Topics include integrating security early into the software development life cycle (SDLC), education, recurring vulnerabilities, AI, operational technology (OT), and addressing the economics of secure design.</li>



<li>CISA emphasizes the need for diverse perspectives and feedback to strengthen its campaign.</li>



<li>The President&#8217;s National Cybersecurity Strategy calls for a shift in security responsibility from customers to software manufacturers.</li>



<li>Co-sealed by 18 U.S. and international agencies, CISA&#8217;s Secure by Design guidance aims to reduce cybersecurity burdens on customers.</li>



<li>The RFI seeks feedback on effective security tactics in the SDLC, with a focus on smaller software manufacturers struggling to implement robust practices.</li>



<li>Input is requested on examples of educational initiatives linking commercial entities, universities, and online programs to enhance security knowledge.</li>



<li>CISA inquires about the costs incurred by manufacturers in developing secure-by-design products and seeks information on how vulnerabilities impact both manufacturers and customers.</li>



<li>The RFI addresses customer perceptions of security and explores ways customers request secure products.</li>



<li>Recurring vulnerabilities are a focal point, with CISA seeking input on barriers to elimination and changes to CVE and CWE programs.</li>



<li>Threat modeling, especially in OT systems, is highlighted, seeking examples of public threat models and best practices for demonstrating robust threat modeling programs.</li>



<li>CISA urges manufacturers and stakeholders to provide written comments by Feb. 20, 2024, to inform future iterations of their whitepaper and collaborative efforts with the global community.</li>
</ul>



<div style="height:25px" aria-hidden="true" class="wp-block-spacer"></div>



<p>In conclusion, the information gathered through CISA&#8217;s Request for Information (RFI) serves as a crucial resource for enhancing the cybersecurity of Operational Technology (OT) deployments. By addressing key areas such as integrating security into the software development life cycle, education, recurring vulnerabilities, and threat modeling in OT systems, the insights obtained can guide the development of more cyber-secure OT solutions. </p>



<p>The emphasis on diverse perspectives, feedback from manufacturers, and understanding the economic aspects of secure design contributes to a comprehensive approach. Ultimately, this initiative facilitates the creation of robust, secure-by-design OT deployments, aligning with CISA&#8217;s global campaign to reduce cybersecurity burdens on customers and foster a safer technological landscape.</p>



<div style="height:25px" aria-hidden="true" class="wp-block-spacer"></div>



<hr class="wp-block-separator has-text-color has-cyan-bluish-gray-color has-alpha-channel-opacity has-cyan-bluish-gray-background-color has-background"/>



<div style="height:33px" aria-hidden="true" class="wp-block-spacer"></div>



<div class="wp-block-media-text is-stacked-on-mobile is-vertically-aligned-center" style="grid-template-columns:25% auto"><figure class="wp-block-media-text__media"><img fetchpriority="high" decoding="async" width="830" height="800" src="https://www.smartbuildingdesign.com/wp-content/uploads/2022/03/Greg-Fitzpatrick-e1705719710545.jpg" alt="" class="wp-image-882 size-full" srcset="https://www.smartbuildingdesign.com/wp-content/uploads/2022/03/Greg-Fitzpatrick-e1705719710545.jpg 830w, https://www.smartbuildingdesign.com/wp-content/uploads/2022/03/Greg-Fitzpatrick-e1705719710545-300x289.jpg 300w, https://www.smartbuildingdesign.com/wp-content/uploads/2022/03/Greg-Fitzpatrick-e1705719710545-768x740.jpg 768w" sizes="(max-width: 830px) 100vw, 830px" /></figure><div class="wp-block-media-text__content">
<p class="has-text-align-left">Greg is currently the Business Development Leader for Building IoT and Integration for Cochrane Supply &amp; Engineering. In 2022, Greg was was appointed to the role of Executive Director for the Real Estate Cyber Consortium (RECC), promoting “cyber harmony” through leadership and insight on best practices, policies, and procedures for real estate owners, operators, and solution providers.</p>
</div></div>



<div style="height:25px" aria-hidden="true" class="wp-block-spacer"></div>
<p>The post <a href="https://www.smartbuildingdesign.com/cisa-challenge-to-a-major-stakeholder-in-the-cyber-harmony/">CISA’s challenge to a major stakeholder in the “Cyber Harmony” Model- The Manufacturer</a> appeared first on <a href="https://www.smartbuildingdesign.com">Smart Building Design</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>Cybersecurity Awareness 2023: Achieving Cyber Harmony in a Fragmented Industry</title>
		<link>https://www.smartbuildingdesign.com/cybersecurity-awareness-2023-achieve-cyberharmony-with-smartbuildingdesign/</link>
		
		<dc:creator><![CDATA[Greg Fitzpatrick]]></dc:creator>
		<pubDate>Thu, 05 Oct 2023 19:08:16 +0000</pubDate>
				<category><![CDATA[Article]]></category>
		<category><![CDATA[News]]></category>
		<category><![CDATA[buildingautomation]]></category>
		<category><![CDATA[buildingcontrols]]></category>
		<category><![CDATA[commercial realestate]]></category>
		<category><![CDATA[contractors]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[cybersecurityawarenessmonth]]></category>
		<category><![CDATA[HVAC]]></category>
		<category><![CDATA[IOT]]></category>
		<guid isPermaLink="false">https://www.smartbuildingdesign.com/?p=2778</guid>

					<description><![CDATA[<p>Cybersecurity Awareness 2023: Achieving Cyber Harmony in fragmented industry. Ensuring strong cybersecurity for any OT Network.</p>
<p>The post <a href="https://www.smartbuildingdesign.com/cybersecurity-awareness-2023-achieve-cyberharmony-with-smartbuildingdesign/">Cybersecurity Awareness 2023: Achieving Cyber Harmony in a Fragmented Industry</a> appeared first on <a href="https://www.smartbuildingdesign.com">Smart Building Design</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p><strong>By Greg Fitzpatrick, CxA | Business Development | Cochrane Supply &amp; Engineering</strong></p>



<p>For the past five years, I&#8217;ve traveled across the country, engaging in discussions with consulting engineers about the integration of IP technology into their smart building designs. &nbsp;In most cases, I&#8217;ve found that these firms are enthusiastic about incorporating IP Technology into their strategies.</p>



<p>In June 2023, I authored an article for Realcomm&#8217;s Edge Magazine titled &#8220;<a href="https://www.realcomm.com/news/1143/1/real-estate-cyber-consortium-recc-creating-a-path-to-cyber-harmony-challenging-cres-supply-chain" target="_blank" rel="noreferrer noopener">Creating A Path To Cyber Harmony &#8211; Challenging Commercial Real Estate&#8217;s Supply Chain</a>,” where I briefly emphasize the significance of cyber awareness for commercial real estate owners and all project stakeholders, including consulting engineers.</p>



<figure class="wp-block-image size-large"><img decoding="async" width="1024" height="746" src="https://www.smartbuildingdesign.com/wp-content/uploads/2023/10/cyberharmony_graphic-1024x746.jpg" alt="" class="wp-image-2808" style="aspect-ratio:16/9;object-fit:cover" srcset="https://www.smartbuildingdesign.com/wp-content/uploads/2023/10/cyberharmony_graphic-1024x746.jpg 1024w, https://www.smartbuildingdesign.com/wp-content/uploads/2023/10/cyberharmony_graphic-300x218.jpg 300w, https://www.smartbuildingdesign.com/wp-content/uploads/2023/10/cyberharmony_graphic-768x559.jpg 768w, https://www.smartbuildingdesign.com/wp-content/uploads/2023/10/cyberharmony_graphic-1536x1119.jpg 1536w, https://www.smartbuildingdesign.com/wp-content/uploads/2023/10/cyberharmony_graphic-2048x1492.jpg 2048w" sizes="(max-width: 1024px) 100vw, 1024px" /></figure>



<p>While IP technology holds immense potential for smart building design, its implementation introduces new challenges in terms of cybersecurity and potential risks for consulting engineers. The consulting engineering community must recognize that <a href="https://cybersecuritynews.com/key-features-of-a-unified-ot-cyber-security-framework/" target="_blank" rel="noreferrer noopener">cybersecurity is pivotal in deploying Operational Technology (OT)</a> during the construction process.</p>



<p>OT systems, such as building automation and control systems, are increasingly interconnected and susceptible to <a href="https://www.cybersecuritydive.com/" target="_blank" rel="noreferrer noopener">cyber threats</a>. The recent cyberattacks to <a href="https://www.cybersecuritydive.com/news/mgm-resorts-investigates-cyberattack/693351/" target="_blank" rel="noreferrer noopener">MGM &amp; Caesars properties in Las Vegas</a>, and to <a href="https://www.cybersecuritydive.com/news/johnson-controls-ransomware-attack/695130/" target="_blank" rel="noreferrer noopener">building controls manufacturers,</a> underscore the urgency of addressing cyber risks in the construction industry.</p>



<p>Robust cybersecurity measures safeguard not only sensitive construction data but also the physical infrastructure. This protection prevents potential disruptions, unauthorized access, or sabotage, ensuring the safety, efficiency, and integrity of construction projects. But, as we are experiencing, these devices are limited for shielding against the growing sophistication of the costly ransomware of today’s hackers.</p>



<p>Concentrated threats to properties and controls manufacturers are alarming, and with SEC’s approval of new cybersecurity disclosure rules, consulting engineers must elevate their cyber awareness and comprehend how to incorporate the necessary hardware and software to address cybersecurity concerns in their designs and specifications.</p>



<h2 class="wp-block-heading">Cybersecurity Expertise to Achieve &#8220;Cyber Harmony&#8221;</h2>



<p>With over 30 years in the consulting industry my aim has always been to simplify the process of designing and specifying OT and integration, making it as clear and concise as possible. Cybersecurity is no exception. </p>



<div class="wp-block-columns are-vertically-aligned-center is-layout-flex wp-container-core-columns-is-layout-28f84493 wp-block-columns-is-layout-flex">
<div class="wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow">
<p>Earlier this year I accepted the role as the Executive Director of the <a href="https://reccinc.org/" target="_blank" rel="noreferrer noopener">Real Estate Cyber Consortium (RECC)</a>, where I&#8217;m striving to foster a movement towards <a href="https://www.smartbuildingdesign.com/real-estate-cyber-consortium-recc-creating-a-path-to-cyber-harmony/" target="_blank" rel="noreferrer noopener">&#8216;Cyber Harmony&#8217;</a> across the industry.</p>



<p>It is important to bridge the gap between facilities and IT departments, and implementing internal OT teams. My goal is to achieve “Cyber Harmony” through increased collaboration among diverse stakeholders, promoting activities such as knowledge sharing, best practice documentation, podcasts, and other communication channels to ultimately develop best practices and standards for the industry.</p>
</div>



<div class="wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow">
<figure class="wp-block-image alignright size-large is-resized"><img decoding="async" src="https://www.smartbuildingdesign.com/wp-content/uploads/2023/10/Greg_Quote_Realcomm_Edge-1024x1024.jpg" alt="" class="wp-image-2797" style="width:303px;height:303px" width="303" height="303" srcset="https://www.smartbuildingdesign.com/wp-content/uploads/2023/10/Greg_Quote_Realcomm_Edge-1024x1024.jpg 1024w, https://www.smartbuildingdesign.com/wp-content/uploads/2023/10/Greg_Quote_Realcomm_Edge-300x300.jpg 300w, https://www.smartbuildingdesign.com/wp-content/uploads/2023/10/Greg_Quote_Realcomm_Edge-150x150.jpg 150w, https://www.smartbuildingdesign.com/wp-content/uploads/2023/10/Greg_Quote_Realcomm_Edge-768x768.jpg 768w, https://www.smartbuildingdesign.com/wp-content/uploads/2023/10/Greg_Quote_Realcomm_Edge-1536x1536.jpg 1536w, https://www.smartbuildingdesign.com/wp-content/uploads/2023/10/Greg_Quote_Realcomm_Edge-2048x2048.jpg 2048w" sizes="(max-width: 303px) 100vw, 303px" /></figure>
</div>
</div>



<p>My objective is to streamline the fundamental cybersecurity requirements for consulting engineers, making these principles an integral part of the designer&#8217;s drawings and specifications when creating construction documents for building systems.</p>



<p>In any given project, there is typically a discovery phase where the designer must ask essential questions before proceeding. Incorporating cybersecurity into your design follows a similar pattern. Here are some key points to clarify during the discovery phase to determine your cybersecurity strategy:</p>



<p>1. Determine whether you are deploying IP devices on the owner&#8217;s network or designing a separate OT network that supports various building technologies. If the owner manages all OT, the designer&#8217;s responsibility is to ensure data encryption, while firewalls and VPN strategy fall under the owner&#8217;s IT department.</p>



<p>2. If the designer is responsible for a separate OT network, they must understand how to incorporate cybersecurity into the design.</p>



<h2 class="wp-block-heading">Strategy First: Planning for Cybersecurity is Paramount</h2>



<p>When considering essential design prerequisites for cybersecurity in your OT Network, assuming the owner prefers complete separation of the OT from their IT network (air gapped), I recommend these four tips:</p>



<p>1. Ensure that the specified OT Network solution offers robust port security capabilities, both in software and through the ability to bind device MAC addresses. This is critical to safeguard against unauthorized access. Optigo provides an OT network solution with the necessary port security and unified management through a user-friendly interface.</p>



<p>2. Implement robust data encryption mechanisms for network traffic, which can be achieved through various methods, including BAS system web supervisors, dedicated gateway devices, or BACnet Secure Connect (BACnet SC) using Tridium&#8217;s Niagara. This ensures data confidentiality and protection against threats.</p>



<p>3. Prioritize security when facilitating remote access to the network via the internet. Specify a firewall solution and establish a secure Virtual Private Network (VPN) appliance and strategy for remote access. This multi-layered approach enhances network security.</p>



<p>4. Collaborate with the end user on a VPN strategy for remote access and select a secure VPN appliance. TosiBox offers a product known for its ease of deployment and security features, popular among systems integrators.</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">
<iframe title="Realcomm IBcon 2023: CRE Cybersecurity Forum - Hosted by Greg Fitzpatrick" width="800" height="450" src="https://www.youtube.com/embed/dHbUGuuxbv0?feature=oembed" frameborder="0" allow="accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share" allowfullscreen></iframe>
</div><figcaption class="wp-element-caption">Watch this recap of the CRE Cybersecurity Forum from Realcomm IBcon 2023 hosted by Greg Fitzpatrick.</figcaption></figure>



<h2 class="wp-block-heading">Incorporating Your Cybersecurity Strategy into Your Construction Documents</h2>



<p>Once a cybersecurity strategy is determined for our design, the question often arises: &#8220;How do I incorporate cybersecurity into my construction documents?</p>



<p>As a general practice, it&#8217;s wise to include as much detail as possible on your drawings and provide further clarification in the specifications. I advocate for the use of a detailed &#8220;<a href="https://www.smartbuildingdesign.com/system-architecture/" target="_blank" rel="noreferrer noopener">Systems Integration Drawing</a>&#8221; as the foundation for conveying intent to the master systems integrator (MSI). This drawing should display the OT network layout and the hardware used in your cybersecurity strategy.</p>



<p><strong>The use of this drawing allows the designer show:</strong></p>



<ul class="wp-block-list">
<li>Deployment location of the supervisory software</li>



<li>VPN hardware/software</li>



<li>Cell Modem</li>



<li>Firewall</li>



<li>OT Network router</li>



<li>OT Network management switch(s)</li>



<li>OT Network media</li>



<li>IP switch types and locations</li>



<li>Gateway devices</li>



<li>Server (where applicable)</li>



<li>Subnetwork media</li>



<li>Technology being integrated</li>



<li>OT Network MDF location and installed hardware</li>
</ul>



<h2 class="wp-block-heading">SmartBuildingDesign.com has the resources to help you need for ensuring strong cybersecurity for any OT Network</h2>



<p>At SmartBuildingDesing.com we have detailed Systems Integration Drawings available here: <a href="https://www.smartbuildingdesign.com/system-architecture/" target="_blank" rel="noreferrer noopener">https://www.smartbuildingdesign.com/system-architecture/</a></p>



<p>Regarding specifications, I recommend using Division 25 &#8211; Integrated Automation as the section for hardware and software related to your cybersecurity strategy. Examples of Division 25 specifications are available on our <a href="https://www.smartbuildingdesign.com/guide-specifications/">Guide Specifications</a> page.</p>



<p>Incorporating these measures into your OT Network design not only reduces your risk as a designer but significantly enhances your client&#8217;s cybersecurity posture, reducing vulnerabilities and ensuring the safety and integrity of their critical operations.</p>



<p><strong>Greg Fitzpatrick, CxA<br></strong>Business Development Leader- IoT and Integration, Cochrane Supply and Engineering<br>Executive Director, Real Estate Cyber Consortium</p>
<p>The post <a href="https://www.smartbuildingdesign.com/cybersecurity-awareness-2023-achieve-cyberharmony-with-smartbuildingdesign/">Cybersecurity Awareness 2023: Achieving Cyber Harmony in a Fragmented Industry</a> appeared first on <a href="https://www.smartbuildingdesign.com">Smart Building Design</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
