CLOSE
  • HVAC
  • Foundation Construction Canada
  • Construction Consulting Europe
  • Mechanical Contractor Canada
  • Mould Remediation and Testing Europe
  • Swimming Pool Construction APAC
  • Building Sealing Solutions Europe
  • Kitchen and Bath
  • Decking Canada
  • MEP APAC
  • Construction Saudi Arabia
  • Construction Law APAC
  • Outdoor Construction
  • Landscaping Canada
  • MEP Canada
  • Apartment and Condominium Contractors Canada
  • Cold Storage Construction APAC
  • Precast Concrete Europe
  • Construction Staffing Europe
  • Pre-Construction Services
  • Flooring System APAC
  • Scaffolding Canada
  • Swimming Pool Construction Canada
  • Residential Construction
  • Systems
  • Structures
  • Professional Services
  • Construction Forensic and Owners Representative Europe
  • Buinding Restoration and Maintenance Europe
  • Modular and Prefab Construction Europe
  • Construction Interiors Europe
  • Outdoor Construction Europe
  • Pre-Construction Services Europe
  • Building Restoration and Maintenance Canada
  • Construction Coating Europe
  • Concrete Canada
  • Construction Cladding APAC
  • Concretes, Aggregates and Construction Materials APAC
  • Concretes, Aggregates and Materials Europe
  • Commercial Contractors Europe
  • Commercial Contractors APAC
  • Dummy
  • Flooring Systems Europe
  • Construction Management APAC
  • Cold Storage Construction Canada
  • Safety and Compliance Europe
  • Architecture and Design Services
  • Construction Bidding and Auctions
  • Mechanical Electrical and Plumbing
  • Roofing and Siding Systems Europe
  • Architectural Glass APAC
  • Startups APAC
  • Forensic and Owners Representative
  • Flooring System
  • Waterproofing APAC
  • Wall Systems
  • Concretes, Aggregates and Materials
  • Construction Engineering Services
  • Modular and Prefab Construction
  • Architectural Glass
  • Construction MENA
  • Construction Demolition and Recycling Europe
  • Construction Interiors
  • Kitchen and Bath Europe
  • Steel Building APAC
  • Doors and windows
  • Roofing and Siding Systems
  • Construction Engineering MENA
  • Specialty Construction Europe
  • Insulation, Coating and Waterproofing
  • Building Information Modeling APAC
  • Architectural Glass Canada
  • Construction Law
  • Sustainable Construction APAC
  • Building Restoration and Maintenance
  • Commercial Contractors
  • Specialty Construction
  • Construction Engineering Canada
  • Construction Management Canada
  • Modular Construction Canada
  • Modular Construction APAC
  • Construction Marketing
  • Construction Latam
  • Workforce Management and Staffing
  • Roofing Systems APAC
  • Construction Consulting
  • Steel Building Europe
  • Construction Demolition and Recycling APAC
  • Safety and Compliance APAC
Skip to: Curated Story Group 1
Construction Business Review
US
EUROPE
APAC
CANADA
MENA
LATAM
AUSTRALIA
About Us Conference Advertise With Us
  • APAC
    • US
    • EUROPE
    • CANADA
    • AUSTRALIA
  • Home
  • Sections
    Architectural Glass
    Building Information Modeling
    Cold Storage Construction
    Commercial Contractors
    Concretes, Aggregates and Construction Materials
    Construction Cladding
    Construction Demolition and Recycling
    Construction Law
    Construction Management
    Flooring System
    MEP
    Modular Construction
    Roofing Systems
    Safety and Compliance
    Startups
    Steel Building
    Sustainable Construction
    Swimming Pool Construction
    Waterproofing
  • Leadership Perspectives
  • Insights
  • News
  • CXO Awards

Thank you for Subscribing to Construction Business Review Weekly Brief

  • Home
  • Leadership Perspectives

CDM Smith

Matthew T. Goss, PE, PMP, CEM, CEA, CDSM, LEED® AP(BD+C), MEP/Energy Practice Leader

Cybersecurity Of Hvac Systems In The Era Of Connected Devices

Matthew T. Goss

Matthew T. Goss

When I work on HVAC-related projects, I often predominantly focus on identifying solutions that best meet client needs and objectives. Over the last several years, much of this work has been driven by implementing energy efficiency, sustainability, or resiliency-related measures. Although it’s always considered, I rarely specifically focus on cybersecurity-related to HVAC systems; however, I have developed a new appreciation for the practice. 


I recently served on the Technical Planning Team for the U.S. Department of Energy’s “Energy Exchange” virtual training event, where I supported a technical training track focused on cybersecurity by developing two technical discussions. One discussion described the importance of implementing cybersecurity for microgrids and distributed energy resources, and the other covered how cybersecurity can be applied to operational technology systems. Operational technology is the hardware and software that detects or causes a change through the direct monitoring and/or control of industrial equipment, assets, processes, and events. HVAC control systems, building management systems, and systems serving similar functions are considered operational technology. Engineers, owners, and operators of these systems need to understand how technologies at their facilities are connected as equipment controls become more advanced to provide additional functionality, more devices become internet-enabled, and everything becomes more “connected” in general. 


I’ve had the opportunity to interact with several thought-leaders in the cybersecurity industry, and there are several suggestions I’d like to pass along to engineers, designers, and owners/operators of connected systems. 


- Don’t connect external devices such as hard drives or USB flash drives to your systems


- Immediately change default usernames/passwords as soon as the equipment is put online


- Don’t use these systems to search and access the internet


- Do not share configuration files


- Continually train all equipment users 



- Disconnect remote access


In retrospect, all of these seem easily achievable, pragmatic, and commonsense. However, the challenge appears to be implementing and enforcing these guidelines. The question is no longer “if” we are hacked but “when.” Therefore, a plan must be in place as a proactive approach to security. I recommend conducting regular check-ins and reviews to ensure that all equipment users are following the rules.


I recommend conducting regular check-ins and reviews to ensure that all equipment users are following the rules.



Individuals need to recognize this is a continuous and ever-changing process – it’s not static. Additionally, owners and operators need to prepare for the worst-case – the “what if” scenario. Again, while it may appear to be common sense, owners and operators should also plan for disaster recovery. They should be prepared with a backup in case of an emergency like data breaches, malware attacks, or data loss. This is especially important as information provided by peers and colleagues indicates that most facilities not only don’t have a disaster recovery plan but don’t even change their systems’ default access information. 


As technology and connectivity advance, and as we use technology to make more informed decisions, we as designers and engineers need to broaden our knowledge and ensure we’re appropriately educating our clients, owners, and operators. It’s our job to give them the knowledge they need to appropriately and securely monitor their environment. 


The articles from these contributors are based on their personal expertise and viewpoints, and do not necessarily reflect the opinions of their employers or affiliated organizations.
EDITOR'S CHOICE
  • Willis Towers Watson

    Cushman & Wakefield [NYSE: CWK]

    Projects Today Come Down to Nerves of Steel and Realistic Expectations

    Jason D’Orlando, Senior Managing Director, and Michael Morehead, Senior Director, Project and Development Services - Industrial

  • Willis Towers Watson

    Walmart [NYSE: WMT]

    Navgating the Challenges and Innovations in Mega Construction Projects: Building Competent Leadership and Embracing Technological Trends

    Seth Roy, Senior Director - Design & Construction, Walmart [NYSE: WMT]

  • Willis Towers Watson

    Meritage Homes

    Act Now to Address Aging Workforce

    Poli Peters, VP of Operations[NYSE: MTH]

  • Willis Towers Watson

    Advanced Drainage Systems [NYSE: WMS]

    Walking the sustainability walk: The case for EPR

    Brian King, EVP Marketing, Product Management and Sustainability, Advanced Drainage Systems, Inc. [NYSE: WMS]

Read Also

Loading...
Copyright © 2026 Construction Business Review All rights reserved. |  Subscribe |  Newsletter |  Sitemap |  About us|  Editorial Policy|  Feedback Policy|  Methodologyfollow on linkedin
This content is copyright protected

However, if you would like to share the information in this article, you may use the link below:

https://hvac.constructionbusinessreviewapac.com/leadership-perspective/cybersecurity-of-hvac-systems-in-the-era-of-connected-devices-nwid-700.html

We use cookies on this website to enhance your user experience. By clicking any link on this page you are giving your consent for us to set cookies. More info

I agree