{domain:"www.qualitydigest.com",server:"169.47.211.87"} Skip to main content

        
User account menu
Main navigation
  • Topics
    • Customer Care
    • Regulated Industries
    • Research & Tech
    • Quality Improvement Tools
    • People Management
    • Metrology
    • Manufacturing
    • Roadshow
    • QMS & Standards
    • Statistical Methods
    • Resource Management
  • Videos/Webinars
    • All videos
    • Product Demos
    • Webinars
  • Advertise
    • Advertise
    • Submit B2B Press Release
    • Write for us
  • Metrology Hub
  • Training
  • Subscribe
  • Log in
Mobile Menu
  • Home
  • Topics
    • Customer Care
    • Regulated Industries
    • Research & Tech
    • Quality Improvement Tools
    • People Management
    • Metrology
    • Manufacturing
    • Roadshow
    • QMS & Standards
    • Statistical Methods
    • Supply Chain
    • Resource Management
  • Login / Subscribe
  • More...
    • All Features
    • All News
    • All Videos
    • Training

Building Automation and Control System Cybersecurity

NIST releases tips and tactics

TECNIC Bioprocess Solutions / Unsplash

Keith Stouffer
Bio
Michael Galler
Bio
Wed, 09/09/2026 - 12:02
  • Comment
  • RSS

Social Sharing block

  • Print
Body

Recent cyberattacks highlight the growing threat to operational technology (OT) used in critical infrastructure. Whether you work for an infrastructure owner/operator or are a consumer of an infrastructure service, recent events have made it clear that cybersecurity is an important factor in ensuring the safe and reliable delivery of critical goods and services. For OT owners/operators, it can be challenging to address the range of cybersecurity threats, vulnerabilities, and risks that can negatively affect their operations, especially with limited resources.

ADVERTISEMENT

Modern commercial and federal buildings rely heavily on building automation and control systems (BACS) to manage heating, ventilation, air conditioning (HVAC), lighting, access control, fire alarms, energy management, and other critical operations. These OT systems improve occupant comfort and safety, reduce energy consumption, and streamline facility management. But as BACS networks are integrated with corporate networks and the cloud, their risk of cyberattack increases significantly.

To help resource-constrained BACS owners/operators manage these risks, NIST developed a quick-start infographic outlining immediate, actionable security steps. Although the infographic was developed in collaboration with the BACS community, the recommendations also offer valuable protection for critical infrastructure sectors including water/wastewater, transportation, energy, manufacturing, healthcare, and food/agriculture.

In addition to the infographic, there are many OT cybersecurity resources available from NIST for clarification, including:

Cybersecurity for Building Systems Project: Developing building-services cybersecurity application profiles and guidance needed by building owners, designers, manufacturers, and others involved in the life cycle of the building, to understand threats, risks, countermeasures, and governance approach, and to ensure cybersecure facilities.

National Cybersecurity Center of Excellence (NCCoE): Security guidelines for water/wastewater, transportation, energy, and manufacturing sectors.

Guide to Operational Technology (OT) Security: Guidance on how to secure OT while addressing unique performance, reliability, and safety requirements. NIST is currently revising NIST SP 800-82 Guide to Operational Technology (OT) Security to reflect the state of practice in cybersecurity risk management approaches for OT.  We look forward to sharing a draft of the next revision for public comment later in 2026.

Cybersecurity Framework (CFS): Voluntary guidance, based on existing standards, guidelines, and practices for organizations to better manage and reduce cybersecurity risk.

CSF Manufacturing Profile: Provides CSF version 1.1 implementation details developed for the manufacturing environment. The “manufacturing profile” of the CSF can be used as a road map for reducing cybersecurity risk for manufacturers that’s aligned with manufacturing sector goals and industry best practices.

CSF Manufacturing Profile Implementation Guide: Implementation guidance to help manufacturers select and deploy cybersecurity tools and techniques that best fit their needs while minimizing operational effects. The guide provides general implementation guidance (Volume 1) and two complete example proof-of-concept solutions (volumes 2 and 3) demonstrating how available open-source and commercial off-the-shelf products can be implemented in manufacturing environments to satisfy the manufacturing profile requirements.

Risk Management Framework (RMF): A comprehensive, flexible, repeatable, and measurable seven-step process that any organization can use to manage information security and privacy risk for organizations and systems. It links to a suite of NIST standards and guidelines to support the implementation of risk management programs that meet the requirements of the Federal Information Security Modernization Act (FISMA).

The collection of NIST OT cybersecurity resources is available on the Operational Technology Security website.

Published Aug. 19, 2026, in the NIST Cybersecurity Insights blog.

Add new comment

The content of this field is kept private and will not be shown publicly.
About text formats
Image CAPTCHA
Enter the characters shown in the image.

© 2026 Quality Digest. Copyright on content held by Quality Digest or by individual authors. Contact Quality Digest for reprint information.
“Quality Digest" is a trademark owned by Quality Circle Institute Inc.

footer
  • Home
  • Print QD: 1995-2008
  • Print QD: 2008-2009
  • Videos
  • Privacy Policy
  • Write for us
footer second menu
  • Subscribe to Quality Digest
  • About Us