Introduction
Data centre security extends beyond servers, applications, cloud infrastructure, and corporate networks. The operational technology (OT) systems responsible for maintaining the physical environment can be equally important to the availability and resilience of a facility.
Building Management Systems (BMS) are a key component of this operational environment. They can monitor and control cooling, HVAC, temperature, humidity, environmental sensors, alarms, air handling, and other facility functions. Modern BMS environments may also communicate with enterprise networks, remote-access platforms, cloud applications, engineering workstations, vendors, and other critical facility systems.
This connectivity creates an expanded cybersecurity attack surface.
A weakness in a BMS server, controller, engineering workstation, remote-access service, or network connection could potentially allow unauthorised access to systems that influence physical facility operations.
The NIS2 Directive applies to data centre service providers within the digital infrastructure sector. For relevant entities, Commission Implementing Regulation (EU) establishes technical and methodological requirements for cybersecurity risk-management measures.
An OT cybersecurity assessment aligned with NIS2 requirements can help data centre operators understand their BMS and critical facility security posture, identify vulnerabilities, and establish appropriate risk-treatment priorities.
NIS2 and Critical Data Centre Facility Systems
The NIS 2 Directive establishes cybersecurity risk-management requirements for organisations within its scope.
For specified digital infrastructure entities, including data centre service providers, Commission Implementing Regulation (EU) provides more detailed technical and methodological requirements. The regulation requires relevant entities to establish and maintain an appropriate risk-management framework and to document risk assessments and risk-treatment plans.
The requirements address areas including:
- Cybersecurity risk management
- Incident handling
- Business continuity and crisis management
- Supply-chain security
- Vulnerability handling
- Security in network and information-system acquisition and maintenance
- Access control
- Asset management
- Environmental and physical security
- Cryptography
- Security testing
For data centre environments, these requirements provide an important context for assessing not only traditional IT infrastructure but also connected OT and facility-management systems.
Why OT Cybersecurity Assessment Matters for Data Centre BMS
1. BMS Is Part of the Critical Facility Attack Surface
A modern BMS may include:
- BMS servers
- Engineering workstations
- Programmable controllers
- Sensors and actuators
- Network gateways
- HVAC systems
- Cooling controls
- Environmental monitoring platforms
- Web interfaces
- Remote-access systems
- Third-party integrations
Each component can introduce security considerations.
A structured OT assessment helps establish visibility across these technologies and identify weaknesses that may otherwise remain difficult to detect.
2. Protect Environmental and Cooling Systems
Data centre availability depends on maintaining suitable environmental conditions.
Critical facility systems may monitor or control:
- Temperature
- Humidity
- Cooling
- HVAC
- Air handling
- Environmental alarms
- Facility sensors
- Building equipment
Cybersecurity weaknesses affecting these systems could potentially create operational risks.
An assessment can examine whether unauthorised access could allow users to interfere with monitoring or control functions.
3. Assess IT-to-OT Connectivity
BMS environments frequently communicate with corporate IT and other operational systems.
A simplified architecture could be:
Corporate IT → Firewall / DMZ → BMS Network → Controllers → Sensors & Facility Equipment
The security of the connections between these environments is an important assessment area.
Testing and review can examine:
- Network segmentation
- Firewall controls
- Communication pathways
- Trust relationships
- Exposed services
- Administrative connections
- Remote-access routes
This helps determine whether unnecessary connectivity could increase the potential impact of an IT or OT compromise.
4. Evaluate Remote and Vendor Access
Critical facility systems may require remote support from facility teams, system integrators, equipment manufacturers, or other third parties.
Remote connectivity can include:
- VPN
- Remote desktop
- Web portals
- Vendor support connections
- Cloud management platforms
- Engineering applications
Assessment activities can review whether these access mechanisms are appropriately restricted and protected through authentication, authorisation, privileged-access controls, and secure communications.
Supply-chain security is also an explicit consideration within the NIS2 implementing requirements.
5. Identify Legacy OT Risks
Some BMS and facility-control systems can have long operational lifecycles.
This may create challenges such as:
- Unsupported operating systems
- Older firmware
- Legacy communication protocols
- Limited authentication capabilities
- Difficult patching processes
- Vendor dependencies
- Hardware replacement constraints
An assessment can identify these conditions and help security and facility teams develop risk-based mitigation strategies.
Our OT Cybersecurity Assessment Methodology
The methodology for a BMS and critical facility assessment should account for the operational sensitivity of OT systems.
Unlike conventional IT environments, BMS components may directly interact with physical equipment. Assessment activities should therefore be based on the approved scope, operational requirements, architecture, and rules of engagement.
1. Scope Definition and Asset Discovery
The assessment begins by establishing the systems and components within scope.
Potential assessment areas include:
- BMS servers
- Controllers
- Engineering workstations
- Sensors and gateways
- Network infrastructure
- Remote-access platforms
- Management interfaces
- Connected facility systems
- Supporting IT infrastructure
- Third-party systems
An accurate asset inventory helps establish the OT attack surface.
2. OT Architecture and Dependency Review
The architecture is examined to understand how BMS and facility systems interact.
The review can consider:
- IT-to-OT connections
- BMS network zones
- Controller communications
- Engineering workstation access
- Vendor connections
- Internet-facing services
- Cloud connectivity
- Third-party integrations
This provides visibility into system dependencies and potential attack pathways.
3. Vulnerability Assessment
A structured vulnerability assessment can identify known security weaknesses within the approved environment.
Activities may include:
- Asset discovery
- Service identification
- Vulnerability identification
- Firmware and software review
- Configuration assessment
- Authentication review
- Exposure analysis
Findings can be prioritised according to technical severity, exploitability, asset criticality, and potential operational impact.
4. Controlled Penetration Testing
Where authorised and technically appropriate, penetration testing can validate selected vulnerabilities.
Testing may examine:
- Authentication
- Authorisation
- Privilege escalation
- Network exposure
- Remote-access mechanisms
- Web interfaces
- Segmentation
- Potential lateral movement
Testing should be carefully controlled when conducted against live BMS or facility systems to minimise the possibility of operational disruption.
The NIS2 Implementing Regulation expressly recognises security testing as part of verifying whether cybersecurity risk-management measures are implemented and functioning effectively. It identifies activities such as penetration testing, vulnerability scanning, configuration testing, and security audits as possible forms of security testing.
5. BMS Security Review
The BMS application and management layer can be assessed for weaknesses involving:
- User accounts
- Administrative privileges
- Authentication
- Authorisation
- Management interfaces
- Engineering access
- Logging
- Monitoring
- Communication security
The objective is to determine whether access to sensitive BMS functions is appropriately restricted.
6. Network Segmentation Assessment
Segmentation is particularly important where IT, BMS, and OT systems share interconnected infrastructure.
The assessment can examine whether:
- BMS networks are appropriately isolated
- Firewall rules restrict unnecessary traffic
- Administrative access is controlled
- Vendor connections are limited
- OT systems are unnecessarily exposed
- Communication between security zones is appropriately restricted.
7. Configuration and Access-Control Review
Configuration reviews can identify weaknesses that may not be detected through vulnerability scanning alone.
Areas may include:
- Privileged accounts
- Password policies
- User permissions
- Firewall rules
- Remote access
- System hardening
- Logging
- Monitoring
- Backup controls
- Security configurations
8. Risk-Based Reporting
Assessment findings should translate technical weaknesses into actionable security information.
Reports can document:
- Affected asset
- Identified vulnerability
- Technical evidence
- Severity
- Potential impact
- Risk context
- Recommended remediation
Findings can then contribute to the organisation’s broader risk-treatment process.
The NIS2 Implementing Regulation requires relevant entities to document risk assessments and establish, implement, and monitor risk-treatment plans.
Cyberintelsys OT and BMS Security Services
Cyberintelsys supports organisations with security assessments covering OT, BMS, networks, infrastructure, applications, and connected systems.
1. OT Security Testing
OT Security Testing helps identify cybersecurity weaknesses within operational technology environments.
For data centre BMS environments, testing can cover:
- OT network architecture
- BMS infrastructure
- Controllers and gateways
- Remote-access pathways
- Security configurations
- Network segmentation
- Connected facility systems
2. ICS / SCADA Security Assessment
Where critical facility infrastructure includes industrial control or SCADA technologies, ICS / SCADA Security Assessment can provide specialised assessment coverage.
3. Network Penetration Testing
Network Penetration Testing can assess network infrastructure supporting BMS and OT environments.
The assessment can help identify:
- Exposed services
- Weak network controls
- Segmentation weaknesses
- Insecure communication
- Unnecessary connectivity
4. Infrastructure VAPT
Infrastructure VAPT can assess servers, operating systems, network devices, and supporting infrastructure connected to critical facility systems.
5. Building Automation System Compliance Services
BMS forms part of the broader building automation environment.
Building Automation System (BAS) Compliance Services can support organisations addressing security and compliance considerations associated with building automation systems.
6. IEC 62443 Compliance Services
For applicable OT and industrial automation environments, IEC 62443 can provide an additional cybersecurity framework.
Cyberintelsys offers IEC 62443 Compliance Services for organisations with relevant OT security and compliance requirements.
7. NIS2, OT Security and Security Testing
A NIS2-aligned assessment should not be viewed as a single vulnerability scan or penetration test.
The Implementing Regulation calls for relevant entities to regularly carry out security tests under dedicated policies and procedures to verify that cybersecurity risk-management measures are implemented and functioning properly. It identifies multiple testing approaches, including vulnerability scanning, penetration testing, configuration testing, and security audits.
Why Choose Cyberintelsys?
Data centre OT security requires an understanding of both cybersecurity and the operational processes supported by the technology.
An assessment should help organisations understand:
- Which BMS and facility assets are exposed
- Where vulnerabilities exist
- How IT and OT systems interact
- Whether network segmentation is effective
- How remote access is protected
- Which third parties have system access
- Which risks require remediation priority
Cyberintelsys supports security testing across OT environments, building automation systems, networks, infrastructure, applications, cloud environments, and connected technologies.
Cyberintelsys is a CREST-accredited cybersecurity company for Vulnerability Assessment (VA) and Penetration Testing (PT), delivering industry-recognized security testing services for organizations across multiple sectors.
Strengthen Data Centre BMS and Critical Facility Security
Building Management Systems and critical facility systems are increasingly connected to the digital infrastructure of modern data centres. Their cybersecurity therefore forms an important part of protecting operational resilience.
A structured OT cybersecurity assessment can help identify vulnerabilities across BMS servers, controllers, engineering workstations, network architecture, remote-access systems, and connected facility technologies.
For data centre service providers covered by the applicable NIS2 provisions, establishes technical and methodological cybersecurity risk-management requirements, while ENISA’s technical guidance provides practical implementation support.
NIS2 applicability and specific obligations depend on the organisation, its activities, entity classification, and applicable national implementation. OT cybersecurity assessment should therefore form part of a broader cybersecurity risk-management and resilience programme rather than being treated as a standalone compliance exercise.
Contact Cyberintelsys
Strengthen the security of your Data Centre BMS and critical facility systems with an OT cybersecurity assessment aligned with applicable NIS2 requirements.
From BMS architecture and network segmentation to vulnerability management, remote access, critical facility systems, and OT security testing, a structured assessment can help identify weaknesses and support stronger cyber resilience.
Contact Cyberintelsys to discuss your Data Centre BMS OT cybersecurity assessment, NIS2 requirements, and security testing scope.