CLOSE

Specials

  • HVAC
  • Cold Storage Construction APAC
  • Decking Canada
  • Architectural Glass Europe
  • MEP APAC
  • Construction Saudi Arabia
  • German Apartment and Condominium Contractors
  • Construction Law APAC
  • Outdoor Construction
  • Foundation Construction Canada
  • MEP Canada
  • Apartment and Condominium Contractors Canada
  • Building Sealing Solutions Europe
  • Precast Concrete Europe
  • Construction Staffing Europe
  • Pre-Construction Services
  • Flooring System APAC
  • Scaffolding Canada
  • Swimming Pool Construction Canada
  • Construction Management Canada
  • Cold Storage Construction Canada
  • Flooring Systems Europe
  • Residential Construction
  • Concrete Canada
  • Construction Cladding Europe
  • Construction Cladding APAC
  • Concretes, Aggregates and Construction Materials APAC
  • Concretes, Aggregates and Construction Materials Europe
  • Commercial Contractors Europe
  • Commercial Contractors APAC
  • Dummy
  • Kitchen and Bath
  • Construction Management APAC
  • Landscaping Canada
  • Construction Coating Europe
  • Construction Tech Startups Europe
  • Insulation Services Europe
  • Mechanical Contractor Canada
  • Mould Remediation and Testing Europe
  • Swimming Pool Construction APAC
  • Construction Insulation, Coating and Waterproofing
  • Safety and Compliance Europe
  • Construction Equipment
  • Mechanical Electrical and Plumbing
  • Roofing Systems Europe
  • Architectural Glass APAC
  • Startups APAC
  • Construction Forensic and Owners Representative
  • Flooring System
  • Waterproofing APAC
  • Wall Systems
  • Construction Cladding
  • Construction Engineering Services
  • Modular and Prefab Construction
  • Architectural Glass
  • Construction MENA
  • Construction Demolition and Recycling Europe
  • Modular Construction Europe
  • Construction Interiors
  • Steel Building APAC
  • Doors and windows
  • Modular Construction APAC
  • Building Information Modeling APAC
  • Sustainable Construction APAC
  • Building Restoration and Maintenance
  • Commercial Contractors
  • Specialty Construction
  • Construction Engineering Canada
  • Construction Engineering MENA
  • Modular Construction Canada
  • Construction Demolition Canada
  • Roofing and Siding Systems
  • Construction Latam
  • Construction Staffing
  • Roofing Systems APAC
  • Construction Consulting
  • Steel Building Europe
  • Construction Demolition and Recycling APAC
  • Safety and Compliance APAC
  • Concretes, Aggregates and Construction Materials
Skip to: Curated Story Group 1
Construction Business Review
US
EUROPE
APAC
CANADA
MENA
LATAM
AUSTRALIA

Advertise

with us

  • APAC
    • US
    • EUROPE
    • APAC
    • CANADA
    • LATAM
    • AUSTRALIA
  • Home
  • Sections
    Architectural Glass
    Building Information Modeling
    Cold Storage Construction
    Commercial Contractors
    Concretes, Aggregates and Construction Materials
    Construction Cladding
    Construction Demolition and Recycling
    Construction Law
    Construction Management
    Flooring System
    MEP
    Modular Construction
    Roofing Systems
    Safety and Compliance
    Startups
    Steel Building
    Sustainable Construction
    Swimming Pool Construction
    Waterproofing
    Architectural Glass
    Building Information Modeling
    Cold Storage Construction
    Commercial Contractors
    Concretes, Aggregates and Construction Materials
    Construction Cladding
    Construction Demolition and Recycling
    Construction Law
    Construction Management
    Flooring System
    MEP
    Modular Construction
    Roofing Systems
    Safety and Compliance
    Startups
    Steel Building
    Sustainable Construction
    Swimming Pool Construction
    Waterproofing
  • Contributors
  • Vendors
  • News
  • Conferences
  • Awards

Thank you for Subscribing to Construction Business Review Weekly Brief

  • Home
  • Contributors

Cybersecurity Of Hvac Systems In The Era Of Connected Devices

Matthew T. Goss, PE, PMP, CEM, CEA, CDSM, LEED® AP(BD+C), MEP/Energy Practice Leader, CDM Smith
Tweet

When I work on HVAC-related projects, I often predominantly focus on identifying solutions that best meet client needs and objectives. Over the last several years, much of this work has been driven by implementing energy efficiency, sustainability, or resiliency-related measures. Although it’s always considered, I rarely specifically focus on cybersecurity-related to HVAC systems; however, I have developed a new appreciation for the practice. 


I recently served on the Technical Planning Team for the U.S. Department of Energy’s “Energy Exchange” virtual training event, where I supported a technical training track focused on cybersecurity by developing two technical discussions. One discussion described the importance of implementing cybersecurity for microgrids and distributed energy resources, and the other covered how cybersecurity can be applied to operational technology systems. Operational technology is the hardware and software that detects or causes a change through the direct monitoring and/or control of industrial equipment, assets, processes, and events. HVAC control systems, building management systems, and systems serving similar functions are considered operational technology. Engineers, owners, and operators of these systems need to understand how technologies at their facilities are connected as equipment controls become more advanced to provide additional functionality, more devices become internet-enabled, and everything becomes more “connected” in general. 


I’ve had the opportunity to interact with several thought-leaders in the cybersecurity industry, and there are several suggestions I’d like to pass along to engineers, designers, and owners/operators of connected systems. 


- Don’t connect external devices such as hard drives or USB flash drives to your systems


- Immediately change default usernames/passwords as soon as the equipment is put online


- Don’t use these systems to search and access the internet


- Do not share configuration files


- Continually train all equipment users 



- Disconnect remote access


In retrospect, all of these seem easily achievable, pragmatic, and commonsense. However, the challenge appears to be implementing and enforcing these guidelines. The question is no longer “if” we are hacked but “when.” Therefore, a plan must be in place as a proactive approach to security. I recommend conducting regular check-ins and reviews to ensure that all equipment users are following the rules.


I recommend conducting regular check-ins and reviews to ensure that all equipment users are following the rules.



Individuals need to recognize this is a continuous and ever-changing process – it’s not static. Additionally, owners and operators need to prepare for the worst-case – the “what if” scenario. Again, while it may appear to be common sense, owners and operators should also plan for disaster recovery. They should be prepared with a backup in case of an emergency like data breaches, malware attacks, or data loss. This is especially important as information provided by peers and colleagues indicates that most facilities not only don’t have a disaster recovery plan but don’t even change their systems’ default access information. 


As technology and connectivity advance, and as we use technology to make more informed decisions, we as designers and engineers need to broaden our knowledge and ensure we’re appropriately educating our clients, owners, and operators. It’s our job to give them the knowledge they need to appropriately and securely monitor their environment. 


  • CUSHMAN & WAKEFIELD [NYSE: CWK]

    Projects Today Come Down to Nerves of Steel and Realistic Expectations

    Jason D’Orlando, Senior Managing Director, Cushman & Wakefield, Michael Morehead, Senior Director, Project and Development Services - Industrial, Cushman & Wakefield

  • WALMART [NYSE: WMT]

    Navgating the Challenges and Innovations in Mega Construction Projects: Building Competent Leadership and Embracing Technological Trends

    Seth Roy, Senior Director - Design & Construction, Walmart

  • MERITAGE HOMES

    Act Now to Address Aging Workforce

    Poli Peters, VP of Operations, Meritage Homes

  • ADVANCED DRAINAGE SYSTEMS [NYSE: WMS]

    Walking the sustainability walk: The case for EPR

    Brian King, EVP Marketing, Product Management and Sustainability, Advanced Drainage Systems

  • TOLL BROTHERS [NYSE: TOL]

    Transforming Construction: Overcoming Challenges And Embracing Technological Trends

    Korey Herndon, Safety Director, Toll Brothers

  • PORTLAND GENERAL ELECTRIC

    The Future of Construction Management

    Ken Pitta, Senior Construction Manager at Portland General Electric [NYSE: POR]

  • BRIXMOR PROPERTY GROUP

    Navigating the Landscape of Retail Project Management: Strategies for Success

    T.J. McKeever, Senior Project Manager, Brixmor Property Group

Copyright © 2025 Construction Business Review All rights reserved. |  Subscribe |  Newsletter |  Sitemap |  About us|  Editorial Policy|  Feedback Policyfollow on linkedin
This content is copyright protected

However, if you would like to share the information in this article, you may use the link below:

https://hvac.constructionbusinessreviewapac.com/cxoinsight/cybersecurity-of-hvac-systems-in-the-era-of-connected-devices-nwid-700.html

We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info

I agree