Services & Solutions

Smart Building & IoT

Cameras, badge readers, HVAC controllers and production equipment all live on your network now. Most of them cannot defend themselves — so the network has to do it for them.

The devices nobody put on the asset register

Building systems arrived on the network one project at a time. The access-control vendor needed a drop. The HVAC contractor wanted remote monitoring. Cameras moved from coax to IP. Each was installed by a specialist who did excellent work in their own domain and had no reason to think about network segmentation — and often no access to anyone who did.

The result is a category of device with three uncomfortable properties: it usually cannot run an endpoint agent, it is often built on firmware that is patched rarely or never, and it frequently ships with credentials that are shared across an entire product line. On many networks these devices sit in the same broadcast domain as staff laptops, which means a compromised camera is a foothold with reach.

This is not an argument against connected buildings — the operational benefits are real. It is an argument for deciding deliberately what those devices can reach, rather than discovering it during an incident.

What this covers

Discovery and visibility

Finding what is actually connected, which is almost always more than the documentation shows. Passive identification matters here: many of these devices respond badly to active scanning, and an aggressive discovery sweep against a controls network is a genuine operational risk rather than a theoretical one.

Segmentation and zoning

Separating building systems, operational technology and IoT from corporate traffic and from each other, with enforcement between zones rather than a shared VLAN and good intentions. Where an industrial environment follows a layered model such as Purdue, we design to it; where it does not, we establish boundaries that reflect how the plant actually runs.

Access control for devices that cannot authenticate

Port-level policy, device profiling and network access control for equipment that cannot present a certificate or run a supplicant. The network decides what a device is and what it may reach, based on how it behaves rather than what it claims.

Vendor and remote access

Controlling how integrators, service contractors and manufacturers reach the equipment they support. This is one of the most common exposures we find: a maintenance path built years ago that still permits broad access, often to a third party whose own security posture is unknown. Scoped, logged, time-bound access instead.

Converged infrastructure design

Designing one network that carries building systems, operational technology and corporate traffic without either compromising the other — including the resilience and quality-of-service considerations that matter when the same infrastructure carries life-safety and production systems.

Monitoring

Watching for the traffic that should not exist: a controller reaching the internet, a camera scanning the subnet, a device suddenly talking to something it has never talked to. In environments where patching is constrained, detection carries more of the weight.

Working alongside the people who own the equipment

These projects have a stakeholder that ordinary network work does not: facilities, plant engineering or clinical engineering owns the equipment, and their priority is uptime and safety rather than security posture. Their caution is usually well-earned — a security control that stops a chiller or halts a line is a worse outcome than the risk it addressed.

We work with those teams rather than around them. Changes are staged and reversible, enforcement is introduced in monitoring mode before anything is blocked, and maintenance windows are respected. The goal is a boundary the controls team is confident in, not one imposed on them.

How we engage

Consult

Discover what is connected, map how it communicates, and identify where building and operational systems currently have reach they should not. You get an inventory, a zoning proposal and a prioritized plan — often the first complete picture anyone has had.

Integrate

Implement segmentation, access control and vendor-access changes in stages, each validated with the teams who operate the equipment before enforcement is turned on.

Manage

Ongoing monitoring and periodic re-discovery, because these estates grow quietly — a new contractor, a replacement controller, a system added during a fit-out that nobody mentioned to IT.

Vendor-neutral by design

Building and operational systems come from a wide range of manufacturers, and you rarely get to choose them — they arrive with the building, the tenant fit-out or the production line. We work with the equipment that is there and design the network around it. See the vendors we work with for the infrastructure side.

Who this is for

  • Organizations that have added building systems over years and no longer have a complete picture of what is connected.
  • Facilities where cameras, access control and HVAC share a network with staff and business systems.
  • Manufacturing and industrial sites where OT and IT have converged in practice without a design that accounts for it.
  • Anyone with standing remote access granted to equipment vendors and integrators.
  • Healthcare and other regulated environments with connected clinical or specialist equipment that cannot be patched on a normal cycle.

The underlying disciplines are the same ones described under network security and Zero Trust — this page is about applying them to equipment that was never designed with either in mind.

Get started

Ready to hand off the tech?

Book a free technology & security assessment. We'll map your gaps and give you a prioritized roadmap — no obligation, no jargon.

Request sent — we'll be in touch