Skip to main content

Secur-IT Data Solutions – Toronto – Canada

featured building management system security

Building Management System Security: When Ransomware Reaches Doors and HVAC

Building management system security is the discipline that keeps ransomware away from the doors, heating, and ventilation that people depend on every day. On August 10, 2026, Shared Health confirmed a ransomware incident affecting facility maintenance systems at Winnipeg’s Health Sciences Centre, including door access, heating, ventilation and air conditioning, according to CBC News. Shared Health said patient care and clinical operations were not affected, and extra security staff were placed at entrances while doors were affected. For any building owner or operator in Ontario, Toronto, or anywhere in Canada, that event is a warning about systems most people never think about.

Why Building Management System Security Is Really an OT Problem

The doors, elevators, chillers, and thermostats in your building are not office computers. They are operational technology (OT), and building management system security has to treat them that way. These systems were designed to run for decades, often with default passwords, flat networks, and vendor remote access that nobody documented.

Most building operators assume their IT team covers everything with a network cable. That assumption is exactly where trouble starts. A building automation controller sitting on the same network as accounting can become the pathway an attacker uses to reach either side.

The Winnipeg incident showed what happens when maintenance systems, not clinical ones, take the hit. Doors and HVAC are physical safety functions. When they fail, you do not get a spinning cursor, you get people who cannot get in or out, and rooms that stop being climate controlled.

Good building management system security starts with a simple question: who can reach these controllers, and from where? Consider the following weak points that show up in nearly every building:

  • Legacy controllers that cannot be patched but sit on the internet
  • Vendor remote access tools left permanently connected
  • No separation between building networks and business networks
  • No monitoring, so an intrusion runs for weeks unseen

If you cannot answer who is on your OT network right now, you have a gap. That gap is the whole point of this article.

The Technical Gap Between IT Security and Building Controls

Traditional IT tools do not understand building protocols like BACnet, Modbus, or LonWorks. This is why building management system security needs specialists who read OT traffic, not just firewall logs. An intrusion detection rule built for email will miss a command that tells a chiller to shut down.

Take a real pattern that security firms see often. An attacker phishes an office user, lands on the corporate network, then moves laterally into a flat building network because nothing separates the two. From there, ransomware encrypts the servers that run door access and HVAC scheduling, exactly the category of facility maintenance systems reported in the Winnipeg case by CBC News.

The fix is architectural. Network segmentation places OT behind its own boundary so that a compromise on the office side cannot cross into the controllers that open doors. A managed FortiGate firewall paired with 24/7 SOC-as-a-Service monitoring can enforce that boundary and watch for the odd commands that signal trouble.

Understanding the difference between these two worlds matters, and our guide on IT vs OT cybersecurity breaks it down further. Data flow controls and one-way gateways from vendors like Advenica exist precisely because building systems should send telemetry out without accepting commands back from untrusted zones. Strong building management system security uses these boundaries deliberately, not by accident.

How to Assess and Harden Your Building Systems

You do not need to boil the ocean. Start with a focused sequence that any operator can follow. Building management system security improves fastest when you know what you have and where it connects.

  1. Inventory every controller, gateway, and vendor connection touching doors, HVAC, elevators, fire, and access control.
  2. Map which of those devices can reach the internet or the business network, and cut anything that does not need it.
  3. Segment the OT network so building controls sit behind their own firewall boundary.
  4. Disable or gate all vendor remote access, and require it to run through logged, approved channels only.
  5. Add continuous monitoring so someone sees an intrusion in hours, not weeks.

An OT security assessment gives you that inventory and map without guesswork. It also tells you which legacy devices cannot be patched, so you can wrap compensating controls around them instead of pretending they are fine.

Do not skip the physical fallback plan. Winnipeg placed extra security staff at entrances while doors were affected, per CBC News, and that manual backup kept people moving safely. Every building needs a written answer to “what do we do if the doors stop obeying us?”

Building Management System Security and Canadian Compliance

Regulators are catching up to the risk. Building management system security now sits inside broader obligations under PIPEDA when a facility system touches personal data, and under PHIPA for health facilities in Ontario. If door logs or access records identify individuals, those records fall under privacy law like any other dataset.

The Canadian Centre for Cyber Security lays out ransomware and OT guidance in its National Cyber Threat Assessment 2025-2026, and it treats critical infrastructure, including building systems, as a growing target. Aligning your program to the NIST Cybersecurity Framework gives you a recognized structure: identify, protect, detect, respond, recover. That last function, recover, is what a facility with a manual door plan is exercising when its systems go down.

CISA publishes practical cybersecurity best practices that map cleanly onto building environments, from segmentation to access control. Building management system security done well borrows from all of these sources rather than inventing something new. The goal is a defensible position you can show an auditor, an insurer, or your own board.

For health facilities, the stakes under PHIPA are higher because a building failure can ripple into care delivery. Treat every building controller as if a regulator will eventually ask how you protected it.

Common Mistakes to Avoid

  • Assuming the IT team already covers building controls when nobody actually owns OT.
  • Leaving vendor remote access connected permanently instead of gating and logging it.
  • Running building systems on the same flat network as email and finance.
  • Buying monitoring tools that speak IT protocols but ignore BACnet and Modbus.
  • Having no manual fallback for doors, so a system outage becomes a physical safety crisis.

Frequently Asked Questions

Q: What is building management system security and why does it matter?

Building management system security is the practice of protecting the operational technology that runs doors, HVAC, elevators, and access control from cyberattack. It matters because these systems control physical safety, so an outage affects people, not just data. The Winnipeg incident reported by CBC News shows how ransomware can reach facility maintenance systems directly.

Q: How long does an OT security assessment for a building take?

Timelines vary with building size and how many controllers you run, but a focused assessment usually maps your systems and connections within a few weeks. The output is an inventory, a network map, and a prioritized list of fixes so you spend budget where risk is highest.

Q: How is building security different from regular IT security?

IT security protects data and office computers, while building controls are operational technology that must run continuously and often cannot be patched. Building systems use protocols like BACnet and Modbus that standard IT tools do not read, so they need OT-aware monitoring and segmentation.

Q: Does Canadian privacy law apply to building systems?

Yes, when a building system handles personal data such as access logs, PIPEDA applies, and PHIPA applies to health facilities in Ontario. The Canadian Centre for Cyber Security also treats building and critical infrastructure systems as priority targets in its threat guidance.

Q: What is the first step to improve building management system security?

Start with an OT security assessment to inventory every controller and connection, then segment the building network behind a managed firewall. From there, add continuous detection so an intrusion is caught in hours. Our SOC as a service in Canada page explains that monitoring layer.


If your building’s doors and HVAC run on networks nobody watches, Secur-IT Data can help you segment and monitor them. Reach out through securitdata.ca to talk through an OT security assessment.

References

  1. BankInfoSecurity: Ransomware Attack Disables Canadian Hospital’s Doors, HVAC
  2. Canadian Centre for Cyber Security: National Cyber Threat Assessment 2025-2026
  3. CISA, Cybersecurity Best Practices
  4. NIST Cybersecurity Framework

For securing AI systems as part of a modern security program, SecuritAI is built for exactly that.


Ready to Strengthen Your Cybersecurity?

Secur-IT Data Solutions is a Toronto-based MSSP providing enterprise-grade cybersecurity for Canadian businesses. Whether you need OT security, AI threat protection, penetration testing, or full managed security services, our team is ready to help.

Get a free consultation:

Share article

Let’s Connect

Need advice or you have an inquiry to discuss? We would love to hear from you.

Related Cybersecurity Articles