> ## Content Index
> Fetch the complete content index at: https://www.industrialbriefs.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# Legacy BACnet Poses Security Threat to Building Systems
- URL: https://www.industrialbriefs.com/legacy-bacnet-security-threats/
- Published: 2026-10-04T07:00:28.000Z
- Updated: 2026-10-04T07:00:46.000Z
- Description: Legacy BACnet protocols leave building systems vulnerable to cyber threats, urging AECM sectors to modernize for security compliance.
- Author: IndustrialBriefs
- Tags: construction, architecture, policy, #enriched

![IB_KEY_FACTS:[{"stat":"73%","label":"**73% of facilities** have vulnerable building automation systems.","sublabel":"These systems are susceptible to ransomware attacks due to outdated protocols."},{"stat":"91%","label":"**91% of systems** communicate over insecure protocols.","sublabel":"This includes legacy standards like BACnet and others, increasing cyber risk."}]](https://industrial-briefs.ghost.io/favicon.ico)

Legacy building automation protocols, particularly BACnet, are exposing HVAC and other systems to increasing cyber threats, according to a recent analysis by cybersecurity firm Armis Labs. This growing concern is critical for construction and architecture executives as it affects the operational integrity and security of facilities.

**What Happened**  
Armis Labs has highlighted that nearly 73% of facilities still employ [building automation systems](https://www.industrialbriefs.com/kiewit-track-laying-california-rail/) that are susceptible to ransomware attacks, largely due to the legacy BACnet standard. Introduced in the 1990s, BACnet was designed without security protocols, as the systems were not originally networked. However, these systems are now vulnerable as they have become connected and integrated into organizational networks. A notable incident occurred in August with Shared Health in Manitoba, Canada, where hackers seized control of the hospital's elevators, HVAC monitoring, and security systems, severely disrupting operations.

The use of AI is further compounding the issue, as it accelerates hackers' ability to identify and exploit vulnerabilities. Armis Labs, now a part of ServiceNow, notes that AI-driven vulnerability research is decreasing the time between discovering a flaw and weaponizing it. Despite the growing threat, patching these vulnerabilities remains a slow process due to the critical nature of building operations, which cannot simply be taken offline for updates.

**What This Means for Your Business**  
For AECM industry professionals, the implications are significant. The reliance on outdated protocols like BACnet exposes facilities to potential [operational disruptions](https://www.industrialbriefs.com/walbridge-stargate-data-center-groundbreaking/) and financial losses. This vulnerability necessitates a reassessment of current security measures and the integration of more robust cybersecurity protocols. Organizations must consider investing in modernizing their infrastructure to meet current security standards, which could involve substantial upfront costs but offer long-term protection and operational continuity.

Moreover, with 91% of systems communicating over insecure protocols, there is an urgent need for compliance with [cybersecurity frameworks](https://www.industrialbriefs.com/bechtel-sabine-pass-lng-contract/) such as the Cybersecurity Maturity Model Certification (CMMC) and adherence to NIST guidelines. These measures are crucial for maintaining business continuity and safeguarding against the increasing threat landscape.

**What US Operators Should Watch**  
Facility managers and decision-makers should track developments in cybersecurity regulations and standards closely. As threats evolve, there may be impending federal mandates requiring the upgrade of legacy systems. Keeping abreast of these changes will be essential to ensure compliance and avoid potential penalties. Additionally, with the acquisition of Armis Labs by ServiceNow, there may be new solutions emerging in the market for securing building automation systems. Monitoring these advancements could provide opportunities for strategic investments in cybersecurity enhancements.

*Source:* [*Facilities Dive*](https://www.facilitiesdive.com/news/legacy-bacnet-leaves-hvac-other-building-systems-vulnerable-to-hacks/831950/?ref=industrialbriefs.com)

> **Partner Insight** · [VisioneerIT](https://www.visioneerit.com/?ref=industrialbriefs.com)  
>  
> The increasing reliance on legacy building automation systems highlights the critical need for robust cybersecurity measures in the AECM sector. Organizations must prioritize compliance with frameworks like CMMC to safeguard their operations against evolving threats.  
>  
> [Explore VisioneerIT Cybersecurity →](https://www.visioneerit.com/?ref=industrialbriefs.com)