Tomorrow’s BMS Requires IT-Ready Networks

Nätverksarkitektur för ett modernt BMS-system med fokus på IT-säkerhet, segmentering och skalbarhet.

TL;DR

Conclusion

The network is not just a cable – it is the backbone of your digital facility strategy.

The challenge

Traditional BMS networks are often isolated and lack the security and bandwidth required for modern digitalisation.

The solution

By building an IT-ready infrastructure with clear segmentation, a stable platform is created for tomorrow’s control systems.

The effect

Enables secure system integration, remote control and real-time analytics without compromising operational security.

Modern IP Infrastructure for Commercial Properties – The Foundation for Tomorrow’s BMS

Building automation has long been built on traditional fieldbus protocols such as Modbus, M-Bus and similar technologies. These systems have been robust and relatively easy to maintain, but have been limited in terms of integration, scalability and access to data outside the system itself.

A modern BMS system is no longer an isolated technical system. It is a network-dependent platform that requires the same structural care as other critical IT infrastructure.

With the transition to IP-based BMS systems, the conditions change fundamentally. Communication takes place over Ethernet, often with standardised protocols, and systems become part of the organisation’s overall IT environment. This opens up new possibilities in analytics, optimisation and integration – but also places clear demands on network design, security and operating principles.

A modern BMS system is no longer an isolated technical system. It is a network-dependent platform that requires the same structural care as other critical IT infrastructure.

IP-Based vs Proprietary Networks

Traditional automation systems are often built on specialised networks and protocols adapted for a specific purpose. IP-based Ethernet instead means: individual addressing of every device (e.g. with IPv6), better support for integration between different systems and suppliers, and use of standardised protocols with broad market acceptance and long lifespans.

When BMS communicates over IP, the system ceases to be technically isolated. It becomes part of the shared network infrastructure and is directly affected by how that network is designed, monitored and managed.

DNS and DHCP – More Than Supporting Functions

In IP-based automation environments, DNS and DHCP are no longer peripheral support services. They form a central part of the infrastructure: managing large volumes of connected devices, creating a readable, traceable and structured address environment, and enabling automatic updates of names and addresses via dynamic DNS.

Without a well-thought-out strategy for DNS and DHCP, the environment quickly becomes difficult to oversee. With standardised naming conventions, DNS can also be used as an active tool for documentation and structure, where names reflect function, system membership and location.

Secure Infrastructure – Encryption, Certificates and Segmentation

When BMS devices connect to the IP network, the attack surface increases. Systems that were previously physically or logically isolated are now accessible via the network, requiring an entirely different security mindset. Fundamental principles for a secure BMS infrastructure include:

  • Network segmentation, separating automation from other IT traffic
  • Encryption of data in transit, e.g. with TLS
  • Central certificate management, rather than local manual solutions

Security in OT environments cannot be reduced to individual firewall rules. It must be built into the network architecture from the start and take into account both the threat landscape and operational safety.

Technical Maturity – Standards, Tools and Processes

IP-based building automation requires greater technical maturity than traditional solutions. A modern BMS environment needs, among other things: standardised communication protocols such as OPC UA or MQTT, monitoring and visibility of both network and systems, and continuous risk assessment linked to changes and updates.

Established IT principles such as defence-in-depth and zero trust must be applied with an understanding of the OT environment’s requirements. Security and stability must be balanced, not set against each other.

Common Mistakes

  • Assuming office IT principles work unchanged in OT environments – Automatic patches and rapid changes can have direct operational consequences in BMS systems
  • Underestimating the need for network segmentation – Inadequate separation increases both security risks and the risk of unintentional impact
  • Lacking a clear strategy for addressing and DNS before implementation – Unstructured solutions lead to increased operating costs and difficult fault-finding
  • Treating OT security as purely a firewall question – Without a holistic view of certificates, encryption and zone division, protection becomes fragmented

Is your BMS network ready for the next step?

A modern control system is only as strong as the network it communicates on. We help you bridge the gap between traditional building technology and modern IT architecture – from requirements specification to operational network.

author avatar
David Nordin

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *

Contact us