Executive Overview
This report addresses the unique challenges of cybersecurity in the built environment, particularly for end users in the process, discrete, and hybrid manufacturing industries. Systems in the built environment are diverse and complex, and these systems can no longer be considered as completely isolated from other systems in the manufacturing enterprise as end users increasingly use industrial IoT data platforms and data fabrics that unify data from multiple domains in the enterprise. For many applications, building automation systems are extremely critical either to the production process or to provide a stable environment for large scale IT installations like datacenters.
Built Environment Systems
Built environment systems, like traditional building automation systems, consist of sensors, actuators, I/O, and controllers. These systems are similar to process automation systems and include operator and engineering workstations with embedded functions like EMS and asset management. Because of this, these systems are subject to many of the same vulnerabilities as industrial control systems (ICS) and require the adoption of similar standards such as IEC 62443.
Installation and Threats
Built environment systems are installed in various locations, including commercial office spaces, plant and site-level buildings, and remote instrument enclosures. The new generation of industrial IoT-based buildings expands the threat surface, making cybersecurity even more critical.
The People Problem
One of the significant issues is the lack of responsibility for cybersecurity in building controls. Building and facilities personnel often lack the technological sophistication and understanding of potential cyber risks.
Market and Competitive Landscape
The market for OT cybersecurity solutions for buildings is quite small, and the built environment is far behind other industries in implementing these solutions. Common vulnerabilities include poor asset visibility, unsecured communication ports, and lack of supply chain security.

ARC Discussions with End Users
ARC conducted a survey of process industry end users to understand their approach to cybersecurity for the built environment. Most end users are not evaluating the security of their built environment, and those who are rely heavily on third parties for assessments.
Call to Action
Manufacturing end users must take steps to evaluate the security posture of OT systems and assets in the built environment. Too many of these systems today pose an unacceptable risk that can have associated impacts on critical manufacturing processes and other aspects of the enterprise. Previous cybersecurity incidents such as the Target attack have proven that building automation systems can be used to pivot and move laterally through other networks in the enterprise.
ARC emphasizes the need for an expansion of cybersecurity culture into the OT level of the built environment, involving both people and processes, which can be spearheaded by cybersecurity personnel that already exist in both the ICS/OT and IT domain.
Table of Contents
- Executive Overview
- The Diversity and Complexity of Built Environment Systems
- Primary End User Challenges in Cybersecurity for the Built Environment
- Building Automation Cybersecurity Landscape
- How Other Manufacturing End Users View Building Automation Cybersecurity
- Call to Action and Recommendations
ARC Advisory Group clients can view the complete report at the ARC Client Portal.
Contact Us if you would like to speak with the author.
Obtain more ARC In-depth Research Market Analysis.