Skip to content
ot security

BACnet

A communication protocol designed for building automation, enabling integration of HVAC, lighting, access control and fire protection systems.

What is BACnet?

BACnet (Building Automation and Control Networks) is an open communication protocol developed by ASHRAE (American Society of Heating, Refrigerating and Air-Conditioning Engineers) and standardised as ISO 16484-5. It was designed specifically for building management systems (BMS).

The protocol enables communication between devices from different manufacturers managing HVAC (heating, ventilation, air conditioning), lighting, physical access control, fire protection systems and lifts. BACnet defines standard objects (e.g. Analog Input, Binary Output, Schedule) and services (ReadProperty, WriteProperty, SubscribeCOV) that ensure interoperability.

BACnet supports several transport layers: BACnet/IP (most commonly used), BACnet MS/TP (RS-485 serial bus) and BACnet/SC (Secure Connect) - a newer version with TLS encryption. The protocol is widely deployed in office buildings, hospitals, data centres and public facilities.

Why does it matter?

BMS systems manage critical building infrastructure - from server room temperatures to hospital ventilation. An attack on a BACnet system could disrupt environmental conditions, open access control doors or disable fire protection systems. Traditional BACnet/IP installations do not use encryption or authentication, so they should be isolated in a dedicated VLAN with traffic monitoring.

Need help in this area?

Our experts will help you assess the risk and plan next steps.

Talk to an expert
+48 22 292 32 23 Talk to an expert