New Research from Claroty's Team82 Reveals Riskiest Building Management System Exposures

Author photo: Larry O'Brien
ByLarry O'Brien
Category:
Company and Product News

Presence of KEVs, KEVs Linked to Ransomware, and Insecure Internet Exposure Found to be Pervasive Among BMS and BAS, According to New Report.

Claroty, the cyber-physical systems (CPS) protection company, recently announced new research on the riskiest exposures among building management systems (BMS) and building automation systems (BAS). The new report from Team82, “State of CPS Security 2025: Building Management System Exposures,” analyzes nearly half a million BMS across more than 500 CPS organizations, finding that 75 percent of organizations have BMS affected by known exploited vulnerabilities (KEVs). Digging deeper into the KEV-affected organizations, 51 percent are affected by KEVs that are also linked to ransomware and are insecurely connected to the internet. Within those organizations, 2 percent of devices contain the same level of risk, meaning that devices essential to business operations are operating at the highest level of risk exposure.

This combination of risk factors raises alarms given the widespread reliance on BMS in commercial real estate, retail, hospitality, and data center facilities to operate systems like HVAC, lighting, energy, elevators, security, and more. The exposure level of these devices provides adversaries with easily accessible entry points, leaving the door open to costly and potentially dangerous disruptions. The findings in the report highlight the need for greater prioritization of these systems' protection, especially as they are brought online for operational and business purposes such as remote management and analytics. By taking an exposure management-based approach and focusing on the unique needs and challenges of CPS environments, organizations can identify, assess, and prioritize the riskiest devices, saving valuable time and resources.

Oftentimes, BMS and BAS are being operationalized on the network without considering the cybersecurity implications,” said Grant Geyer, Chief Strategy Officer at Claroty. “What’s being gained in efficiency and convenience might come at a real risk if not effectively secured—for instance, the cooling of data centers or refrigeration of perishable goods in retail, which are critical systems that could be abruptly taken offline if compromised."

Organizations embracing digital transformation and taking steps to secure BMS when bringing them online have the opportunity to integrate the measurement of business impact and safeguard the operational criticality of those devices. By understanding the full context of these systems, they can reduce risk and avoid the highly consequential disruptions that might result from their failure. As buildings become “smarter,” organizations need to adopt a security framework that provides cybersecurity decision-makers and asset owners with an accurate assessment of their security posture, as well as a remediation plan tailored for risk management teams and understandable by executives.

To access Team82’s complete findings, in-depth analysis, and recommended security measures, download the “State of CPS Security 2025: Building Management System Exposures” report.

Methodology

The "State of CPS Security 2025: Building Management System Exposures" report is a snapshot of the vulnerability and exposure trends in BMS and BAS devices across CPS organizations, as observed and analyzed by Team82, Claroty's threat research team, and its data scientists.

Engage with ARC Advisory Group

Representative End User Clients
Representative Automation Clients
Representative Software Clients