Lock down your BAS — TLS configuration, certificate management, and access control.
18 articles
Address concerns about published Niagara vulnerabilities with this hardening checklist
Users cannot log in or station appears offline after applying security hardening
Address owner and IT questions about BAS security with these quick wins
TLS handshake failed due to certificate issues - wildcard certificates may cause problems.
Cybersecurity resource tracking Common Vulnerabilities and Exposures (CVEs) specific to Building Automation Systems and Operational Technology.
Instructions on using the integrated Metasys system to detect, track, and respond to security breaches.
Guide on utilizing the dashboard to monitor system security, identify risks, and view health status.
Best practices for managing passwords and credentials in building automation systems per CISA ICS advisories and NIST guidelines.
Guide to common BAS cybersecurity vulnerabilities including default credentials, unencrypted protocols, and lack of authentication, with practical mitigations referencing ICS-CERT advisories and NIST guidelines.
Guide to connecting on-premise BAS to cloud platforms for analytics, remote monitoring, and enterprise integration using edge controllers and secure cloud services.
Step-by-step guide to integrating Niagara 4 stations with Active Directory for centralized user management via LDAP, including TLS requirements and troubleshooting.
Practical walkthrough of deploying BACnet Secure Connect including hub/node configuration, certificate management, and migration from traditional BACnet/IP.
Comprehensive security hardening checklist for building automation networks covering segmentation, credentials, firmware management, and compliance frameworks.
Practical BACnet/SC guidance covering architecture, certificates, migration planning, and security-focused deployment practices.
Security-focused guide to Metasys account administration, role assignment, password policy, and least-privilege access management.
Minimal port and flow documentation for BAS networks, aligned with vendor guidance and a least-privilege posture.
Decision-tree troubleshooting for Niagara TLS failures, covering trust stores, certificate lifecycle, and fox/foxs/foxwss port mismatches.