Category: IT Infrastructure & Networks

Artiklar om nätverksdesign, infrastruktur och kommunikation i komplexa IT- och OT-miljöer med höga krav på säkerhet och stabilitet.

  • When IT Manages OT

    When IT Manages OT

    TL;DR

    Conclusion

    Successful integration is more about trust and clear processes than just network cables.

    The challenge

    IT and OT have different priorities; IT focuses on data security and confidentiality, while OT prioritises real-time operations and availability.

    The solution

    A clear boundary definition and a shared governance model that respects both disciplines’ needs.

    The effect

    A secure and stable environment where control systems are protected by IT standards without risking the operation of the facility.

    Organisation, Competence and Responsibility in Tomorrow’s OT Environments

    As automation systems become IP-based, it is not only the technical architecture that changes, but also the organisation’s allocation of responsibility. BMS systems increasingly use the same networks, the same security mechanisms and the same infrastructure as enterprise IT. The IT organisation thus becomes a direct prerequisite for building automation to function – regardless of whether this is formally stated or not.

    This is fundamentally a management and governance question, not a technical detail.

    From Enterprise IT to a Shared Platform

    Traditionally, the IT department’s remit has been clearly tied to enterprise IT: users, clients, servers, applications and networks for office and business systems. Building automation and BMS have often been managed by facility management, operations teams or external suppliers, with their own systems and working methods.

    When BMS becomes IP-based, this boundary is erased. The IT infrastructure becomes the shared platform for OT systems as well. This means decisions about networks, addressing, security and changes directly affect the building’s function. In practice, IT is already involved in OT operations – even if the organisation is not always structured for it.

    Different Logics – IT and OT Have Different Prerequisites

    A fundamental challenge is that IT and OT have historically been governed by different logics.

    IT environments are often characterised by: frequent updates, standardised platforms, acceptance of planned outages, and focus on security updates and lifecycle management.

    OT environments, by contrast, are characterised by: long lifespans, high requirements for continuous operation, limited tolerance for change, and systems directly linked to physical function.

    When these perspectives meet without adaptation, friction arises. Operational disruptions, ambiguous decisions and gaps in responsibility are often organisational problems rather than technical ones.

    Patching and Change – An Organisational Key Issue

    One of the clearest areas where IT and OT logic differ is patching and change management. In IT, regular patching is a natural part of security work. In OT, the same update can mean risk of downtime, unforeseen side effects or compatibility problems. An outage in a BMS system affects not only IT functions, but also comfort, energy consumption and sometimes safety functions in the building.

    When OT systems are on the same network and managed through the same processes as IT, adapted procedures are therefore required:

    • Separate change windows for OT
    • Requirements for testing before updates
    • Clear coordination with OT managers before changes to infrastructure

    This is fundamentally a management and governance question, not a technical detail.

    Competence – Mutual Understanding Rather Than Dual Expertise

    A common mistake is trying to create roles that must fully master both deep IT competence and deep OT competence. In practice this is difficult to maintain and often leads to dependencies on individuals. A more sustainable strategy is to build mutual understanding:

    • IT needs to understand OT systems’ requirements for stability, lifespan and consequences of outages
    • OT needs to understand IP networks, addressing, certificates, segmentation and security principles
    • Specialist competence remains within each area, but with clear interfaces for collaboration

    Organisational Models That Work in Practice

    Organisations that succeed with IT/OT convergence often have a clear allocation of responsibility. IT is responsible for the platform: network infrastructure, IP addressing, DNS and DHCP, basic cybersecurity, certificate management and segmentation. OT is responsible for the systems: BMS function and logic, availability and performance requirements, validation of changes from an operations perspective. Shared responsibility covers: change management, incident management, documentation and lifecycle management.

    The decisive factor is not exactly how the organisation is structured, but that responsibilities and decision paths are clear.

    Common Mistakes

    • Moving OT to IT without changing working methods – IT applies existing processes without regard for OT systems’ operational reliability requirements
    • Unclear responsibility between IT and OT – Nobody owns the whole picture, leading to decision gaps and delays
    • Changes implemented without OT alignment – Technically correct changes have unwanted operational consequences
    • Overconfidence in hybrid roles – Individuals are expected to cover the entire competence spectrum without organisational support
    • Treating IT/OT convergence as a technology project – Organisational questions, training and governance are deprioritised

    Who bears responsibility when the building goes digital?

    When the IT department gets responsibility for the building’s OT environment, new challenges arise around security, lifecycles and operational responsibility. We help you define the processes and requirements that make the handover and daily management a success rather than a source of conflict.

  • Tomorrow’s BMS Requires IT-Ready Networks

    Tomorrow’s BMS Requires IT-Ready Networks

    TL;DR

    Conclusion

    The network is not just a cable – it is the backbone of your digital facility strategy.

    The challenge

    Traditional BMS networks are often isolated and lack the security and bandwidth required for modern digitalisation.

    The solution

    By building an IT-ready infrastructure with clear segmentation, a stable platform is created for tomorrow’s control systems.

    The effect

    Enables secure system integration, remote control and real-time analytics without compromising operational security.

    Modern IP Infrastructure for Commercial Properties – The Foundation for Tomorrow’s BMS

    Building automation has long been built on traditional fieldbus protocols such as Modbus, M-Bus and similar technologies. These systems have been robust and relatively easy to maintain, but have been limited in terms of integration, scalability and access to data outside the system itself.

    A modern BMS system is no longer an isolated technical system. It is a network-dependent platform that requires the same structural care as other critical IT infrastructure.

    With the transition to IP-based BMS systems, the conditions change fundamentally. Communication takes place over Ethernet, often with standardised protocols, and systems become part of the organisation’s overall IT environment. This opens up new possibilities in analytics, optimisation and integration – but also places clear demands on network design, security and operating principles.

    A modern BMS system is no longer an isolated technical system. It is a network-dependent platform that requires the same structural care as other critical IT infrastructure.

    IP-Based vs Proprietary Networks

    Traditional automation systems are often built on specialised networks and protocols adapted for a specific purpose. IP-based Ethernet instead means: individual addressing of every device (e.g. with IPv6), better support for integration between different systems and suppliers, and use of standardised protocols with broad market acceptance and long lifespans.

    When BMS communicates over IP, the system ceases to be technically isolated. It becomes part of the shared network infrastructure and is directly affected by how that network is designed, monitored and managed.

    DNS and DHCP – More Than Supporting Functions

    In IP-based automation environments, DNS and DHCP are no longer peripheral support services. They form a central part of the infrastructure: managing large volumes of connected devices, creating a readable, traceable and structured address environment, and enabling automatic updates of names and addresses via dynamic DNS.

    Without a well-thought-out strategy for DNS and DHCP, the environment quickly becomes difficult to oversee. With standardised naming conventions, DNS can also be used as an active tool for documentation and structure, where names reflect function, system membership and location.

    Secure Infrastructure – Encryption, Certificates and Segmentation

    When BMS devices connect to the IP network, the attack surface increases. Systems that were previously physically or logically isolated are now accessible via the network, requiring an entirely different security mindset. Fundamental principles for a secure BMS infrastructure include:

    • Network segmentation, separating automation from other IT traffic
    • Encryption of data in transit, e.g. with TLS
    • Central certificate management, rather than local manual solutions

    Security in OT environments cannot be reduced to individual firewall rules. It must be built into the network architecture from the start and take into account both the threat landscape and operational safety.

    Technical Maturity – Standards, Tools and Processes

    IP-based building automation requires greater technical maturity than traditional solutions. A modern BMS environment needs, among other things: standardised communication protocols such as OPC UA or MQTT, monitoring and visibility of both network and systems, and continuous risk assessment linked to changes and updates.

    Established IT principles such as defence-in-depth and zero trust must be applied with an understanding of the OT environment’s requirements. Security and stability must be balanced, not set against each other.

    Common Mistakes

    • Assuming office IT principles work unchanged in OT environments – Automatic patches and rapid changes can have direct operational consequences in BMS systems
    • Underestimating the need for network segmentation – Inadequate separation increases both security risks and the risk of unintentional impact
    • Lacking a clear strategy for addressing and DNS before implementation – Unstructured solutions lead to increased operating costs and difficult fault-finding
    • Treating OT security as purely a firewall question – Without a holistic view of certificates, encryption and zone division, protection becomes fragmented

    Is your BMS network ready for the next step?

    A modern control system is only as strong as the network it communicates on. We help you bridge the gap between traditional building technology and modern IT architecture – from requirements specification to operational network.

Contact us