Advisory Banner

ADVISORY

ADVISORY NEWSLETTERS

Towards a Cybersecurity Partnership in Connected Buildings

Vendor Profile

Over the past few months, there has been some well-needed government and media attention paid to the cybersecurity posture of control systems used in smart buildings and Operational Technology (OT) networks. Cyber-threat watchers note that there continues to be a significant number of these control systems that are configured in an insecure manner and exposed on the Internet. This is something that must change.

Decades ago, organizations had to quickly become savvy about protecting their Information Technology (IT) networks from remote attackers. As IT networks grew, so did the cybersecurity threats – viruses, malware, and phishing attacks proliferated, and they continue to do so. Organizations that experienced early, highly publicized cyberattacks and data breaches learned painful and costly lessons. In too many of those cases, proper focus on cybersecurity awareness and best practices only happened after such an attack. Luckily, we can learn from those mistakes and lessons from the past and apply them to OT networks today. It is our goal that smart building owners and operators avoid the harsh realities of cyberattacks now by taking a proactive approach towards cybersecurity.

As many of you know, Tridium’s Niagara Framework is used in OT networks around the world. A universal multi-protocol integration engine that enables applications to connect to, control, and monitor any device, regardless of manufacturer, Niagara enables integrators to build and deploy control solutions and seamlessly aggregate data from a wide variety of systems and equipment. OT experts seeking open-protocol interoperability have converged around the Niagara solutions offered by Tridium’s OEMs and integration service partners in the building automation business. Niagara is now deployed at the controller level, the supervisory level, and at the edge, and Niagara solutions are used in a wide variety of domains.

As businesses use Niagara to connect more equipment, devices and people into workflows that enable data-driven buildings and industrial spaces, they can reap the benefits of comfort, energy savings and better business outcomes. At the same time, any network connectivity also brings challenges related to cybersecurity, and all stakeholders need to be aware of the fact that the target landscape for cyberattacks continues to grow and evolve.

Cybersecurity is a journey that we are on with our Niagara Community. Specifically, we are on this journey with systems integrators who configure our products and facility managers and owners who oversee our products. As an integration platform, it is important that our products are securely configured. Niagara products should always be set up in an organization’s network using security best practices and a defense-in-depth approach. Once deployed, Niagara-based systems need to be kept up-to-date with the most recent security updates and patches. Systems also require continuous monitoring to detect unplanned changes in hardware or software configurations or anomalous activity that could be a sign of cyberattack.

As we look at the lessons learned over the last few decades in protecting our computers and networks, practicing cybersecurity hygiene means more than deploying new technologies. Any serious effort involves the combination of people, processes and technology. Organizations need to adopt best practices and cybersecurity processes, they must deploy defensive technologies and use technology properly to defend against the threats. This type of change requires a focus on people. Behaviors related to the use of technology must change, and people in the organization need to be made aware of the threats and be trained in new cybersecurity processes.

In order to help our community defend against cyber threats, Tridium is offering the following guidance:

    (1) Follow the cybersecurity best practices that we provide. Tridium has released a Cybersecurity White Paper focused on best practices for cybersecurity for any organization, including specific guidance for Niagara systems. This paper provides an overview of the threats and resources for defending against those threats, as well as organizational and technical best practices.
    (2) Do not expose your systems on the Internet. When any system is exposed on the Internet, it is discoverable by potential attackers and can be open to a wide range of potential attacks. We urge our customers to make certain that their systems are on networks that are configured with network security best practices, using a defense-in-depth approach. Customers should also perform periodic assessments on their systems, verifying and ensuring that those systems are not exposed on the Internet or other untrusted networks.
    (3) Continue to update your systems with the most recent security updates. At Tridium, we continually release patches and security updates so that our customers’ systems can be updated with the most recent versions. To be protected, it is critical that those updates be applied as soon as is practical. Conduct periodic assessments of your systems to ensure they are up-to-date with the latest patches and cybersecurity updates.
    (4) Use our Niagara Hardening Guides to securely configure Niagara systems. Tridium has released security hardening guides for our AX products and our Niagara 4 family of products that include step-by-step instructions on best practices aimed at securing our products (available on our website HEREand HERE.
    (5) Use our other available online resources. In addition to the Cybersecurity White Paper, there is a TridiumTalk webinar focused on cybersecurity available on our website and a keynote presentation available on Tridium’s YouTube channel.

Cybersecurity is a partnership: we all have a role to play. At Tridium, we see cybersecurity as a top priority, and we are dedicated to continuously improving the security posture of our products and providing guidance to Niagara systems integrators, business partners, and facility managers. We want to work together with you in this cybersecurity partnership, and we will continue to update you as we release new security features, enhancements and updates.

Kevin Smith, CTO, Tridium
Kevin Smith is the CTO of Tridium, providing technology strategy and direction. The author of seven technology books on the subjects of cybersecurity, semantic interoperability, and software engineering, he is a frequent speaker at industry conferences on various topics, including a focus on cybersecurity and building control systems. For more than 25 years, Kevin has led technology organizations and endeavored to develop highly secure, data-focused software solutions for a wide variety of customers, including both US government and commercial industry.

This Week’s Sponsor

Tridium is a world leader in business application frameworks, advancing open data environments and easy interoperability. Our Niagara Framework® universal multi-protocol integration engine has fundamentally changed the way people connect and control devices and systems. Tridium delivers Niagara software and the JACE® controller and server platform through an open distribution business model with open protocol support. With almost one million instances worldwide, Niagara is helping a significant number of businesses, manufacturing enterprises and government entities improve performance and reduce energy, operating and other costs, and be more strategic and competitive. The Niagara Community is a large and active community of innovative developers, integrators, consultants, manufacturers, resellers and end users who use Niagara daily. Tridium is an independent business entity of Honeywell International.

Realcomm News


Be a part of one of the most interactive and exciting sessions of the conference, the Smart Building Best Practice Showcase, which will be held on June 14 from 8:30am to 10:30am. The Showcase presents the world’s most successful implementations of smart buildings, campuses, and portfolios. These projects represent the future of real estate with their state-of-the art design, connectivity, systems integration and enhanced occupant experience. For the past six years, this event has featured over 200 smart projects by Google, Microsoft, LinkedIn, Ford Land Energy, Stanford University, Aruba and many more!

If you are involved with a smart building, campus, portfolio or city project you feel would add significant value to the Showcase, please contact Tina Danielsen.

UPCOMING REALCOMM WEBINARS

Top GLOBAL INNOVATIONS of 2019 Impacting Commercial and Corporate Real Estate - 12/12/2019

2019 will likely be another year of great innovations for the Commercial and Corporate Real Estate industry. With a multitude of new companies and ideas being funded by an insatiable appetite of investors, the traditional workflows and processes of Real Estate are challenged daily. Add to this a desire by the established marketplace to also innovate and the pressure of change increases. This webinar will bring together some of the industry’s most prolific prognosticators who will discuss and debate the state of innovation in our industry for 2019. For those firms that are leaning into the change brought about by technology this is a perfect opportunity to hear about the leading solutions, case studies and best practices.

headshot for Jim Young
Jim Young Realcomm
Jim Young Co-Founder & CEO Founder of Realcomm Conference Group, an education organization that produces Realcomm, IBcon and CoRE Tech, the world's leading conferences on techno
headshot for Jim Young
Jim Young
Co-Founder & CEO
Realcomm
LinkedIn

Founder of Realcomm Conference Group, an education organization that produces Realcomm, IBcon and CoRE Tech, the world's leading conferences on technology, automated business solutions, intelligent buildings and energy efficiency for the commercial and corporate real estate industry. As CEO, Jim interacts with some of the largest companies globally pertaining to some of the most advanced and progressive next generation real estate projects under development.

headshot for Jeffrey Chulick
Jeffrey Chulick EY
Jeffrey Chulick Global RE Technology & Innovation Leader Jeff Chulick is the Technology and Innovation Leader for EY Real Estate Services. He leads a global team of professionals focused on the identificatio
headshot for Jeffrey Chulick
Jeffrey Chulick
Global RE Technology & Innovation Leader
EY
LinkedIn

Jeff Chulick is the Technology and Innovation Leader for EY Real Estate Services. He leads a global team of professionals focused on the identification, innovation, design and realization of technology solutions that greatly enhance the workplace experience. His areas of focus include digital strategy, smart workplace, IoT, visual communications, workplace management, physical access and audio/visual technology. Jeff has over 20 years of enabling workplace strategies and delivering innovative solutions for EY and external clients across many different industries.