Sep 29, 2026

Your Building is Now an Endpoint: Closing the BAS Exposure Window in 2026

Armis Labs BAS report blog thumbnail

 
On 10 August 2026, Shared Health disclosed a ransomware attack on the facility-maintenance systems at Winnipeg Health Sciences Centre, Manitoba’s largest hospital. The clinical record never went down. The building did. Door and access control, central HVAC monitoring, badge issuance and elevator service all failed. The security office closed, and the hospital posted physical guards at entrances to do the job its card readers no longer could. A week later, recovery was still in progress.

Attackers have worked out that they do not need to encrypt data when they can seize badges, stop elevators and put operating-room climate on the table. Building automation has become the bargaining chip, and it sits almost entirely outside the scope most security programs were built to cover.

Armis Labs data shows how wide that gap runs:

  • 73% of organizations operate building automation systems of a type already used in ransomware attacks.
  • 73% carry Known Exploited Vulnerabilities in at least one building automation system.
  • 91% of building automation systems communicate over insecure protocols.

In our latest Armis Labs report, Catch Attackers Before They Strike: Early Warning Insights for Building Automation Systems, we examine how the systems that keep hospitals, data centers and commercial real estate running became a primary target, and what it takes to shrink the exposure window without taking critical equipment offline.

Top 3 Cyber Threats Facing Building Automation

  • Physical consequence as the new leverage. BAS attacks disable HVAC, lighting, access control and fire safety.
  • An insecure-by-design installed base, now internet-facing. BACnet, KNX, Modbus and LonWorks were built for reliability on air-gapped networks, frequently without authentication or encryption.
  • Inherited vendor stacks carrying inherited risk. Research uncovered controller code dating to 2008 that passed through three owners without meaningful security review, along with roughly a thousand bugs, undocumented backdoors and hard-coded credentials.

Why “Early Warning” is the New Standard

Waiting for public alerts is no longer a viable strategy. Around 28% of vulnerabilities are exploited the same day they appear on the CISA KEV catalog, and BAS teams cannot patch at that tempo because the equipment they protect cannot be taken offline.

Armis for Early Warning is currently tracking over 4,200 CVEs that have not reached the official catalogs at all. For the building automation CVEs in this report, customers were notified of active exploitation years before any public listing, several of them still absent from KEV today. That is time back on the clock for teams whose only other option is an outage.

The Strategic Pivot: Autonomous Security

Faster scanning will not close this gap. Closing it takes a shift toward autonomous security, built on four principles:

  • Strive to zero exposure. Measure the exposure window itself, not ticket counts or scan coverage.
  • Shift completely left. Move remediation into design and build.
  • Secure by design. Treat posture as a property of how assets and workflows get created.
  • Continuous vulnerability detection. Replace periodic scanning with always-on detection.

What’s Inside the Full Report?

Download the full report to access:

  • Top targets at risk: the eight areas Armis Labs sees under most pressure.
  • Widely exploited CVEs: the building automation vulnerabilities actively exploited in Q3 2026 across LOYTEC, Optergy, Automated Logic, ECOA and Schneider Electric, with first-intel dates.
  • Early warning spotlights: in-depth breakdowns and step-by-step remediation for high-risk flaws, including compensating controls where no patch exists yet.
  • Tactical intelligence: a working Indicators of Compromise library spanning network and protocol, identity and remote access, head-end hosts, physical process anomalies, and platform-specific breadcrumbs.

Insecure by design
Most building automation protocols were written for closed, air-gapped networks where anyone on the wire was assumed to be trusted. Connecting those same systems to corporate IT and cloud platforms for remote management removed the air gap, but the protocols never changed, which is why 91% of building automation systems still communicate insecurely today.

Your building is already an endpoint. Download the latest Armis Labs Insights Report to find out who else knows.

Get Updates

Sign up to receive the latest from Armis.