Armis Labs Highlights Critical Risks in Building Automation Systems
Building automation has moved from isolated pneumatic controls to data-rich, cloud-connected platforms that fuse HVAC, lighting, access control, energy management, and fire-and-life safety into a single environment. The same connectivity that makes modern Building Automation Systems (BAS) valuable is what makes them dangerous: decades-old protocols designed for air-gapped networks now sit at the intersection of IT and OT, where a compromised controller is both a disruption tool and a pivot point into far more sensitive networks.
Research for this report was conducted in Q3 2026 by Armis Labs, utilizing cutting edge technology that includes deception technologies, incident forensics, reverse engineering, dark web monitoring, and human intelligence to proactively identify and mitigate threats before they manifest. A few key findings include:
- Insecure by Design Is the Installed Base: 91% of Building Automation Systems communicate over insecure protocols, and 73% of organizations have Known Exploited Vulnerabilities in at least one BAS. BACnet, KNX, Modbus, and LonWorks were built for reliability on closed networks, and they assume an air gap that no longer exists.
- Physical Consequence Is the New Leverage: 73% of organizations operate building automation systems of a type already used in ransomware attacks. Attackers no longer need to encrypt data when they can seize badges, unlock doors, and put operating-room climate on the table, as the August 2026 ransomware attack on Manitoba’s largest hospital demonstrated.
- Patch Cycles Have Lost the Race: Around 28% of vulnerabilities are exploited the same day they are published on the CISA KEV catalog, and Armis for Early Warning tracks over 4,200 exploited CVEs that never reach that catalog at all. BAS equipment cannot simply be taken offline, so the remediation backlog grows faster than teams can clear it.
Fragmented visibility and a growing remediation backlog create a false sense of security while real risk accumulates. Protecting building automation starts with treating it as a business continuity system with a named owner, then shortening the exposure window with continuous detection instead of periodic scanning. Our latest report shows how to use early warning intelligence to find and fix would be attacks before they strike.
