Case Study • Airport Operations — Building Management Systems

Strengthening Cybersecurity of Airport Building Management Systems

Continuous BMS visibility, vulnerability prioritisation, and protocol-aware threat detection — turning OT telemetry into business-impact decisions without touching a single controller.

SectorAirport Operations — BMS
ServicesOT Security Assessment • Discovery & Vuln Mgmt • Risk Mitigation Advisory
Technology partnerVelos Shield

The context

OT security should not stop at asset visibility or alert generation. In a cyber-physical environment such as airport BMS, the real value is connecting passive discovery, vulnerability intelligence, abnormal behaviour detection, and business-impact prioritisation into one continuous operating view.

Behind every terminal is a large interconnected BMS — HVAC, chilled-water plants, electrical distribution, lighting, elevators, access control, fire and life-safety monitoring — increasingly linked over the same IP network, connected outward to corporate IT, airport operations, contractors, remote maintenance and cloud services. A single weak link doesn’t just risk an HVAC outage — it can ripple into passenger comfort, equipment availability, operational continuity, and physical security.

The challenge

Familiar building systems, an unfamiliar attack surface

Unclear asset ownership

Controllers and devices added over the years without a complete, current inventory of what existed or how critical each one was.

Flat, under-segmented networks

Building systems shared network space with limited separation, making it easier for an issue in one area to reach another.

Loose credentials & access

Shared or default logins and broad vendor privileges made it hard to know exactly who could reach which systems.

Ageing, unpatched systems

Some servers and workstations ran outdated software with no formal, ongoing process for keeping them current.

Always-on remote access

Vendor and maintenance connections stayed open long after the work was done, with little record of what happened during the session.

No eyes on the network itself

No tool-based way to see what normal BMS traffic looked like, let alone notice the moment something drifted from it.

Why it matters

The building systems don’t need to be attacked directly to be a way in

An intruder doesn’t need to touch any flight-critical system. A realistic path runs from the internet or a compromised IT account, into the general network, across to the BMS, through an engineering workstation, and finally to a controller managing a real physical process.

From there: adjusting HVAC setpoints or stopping equipment, triggering false alarms or silencing real ones, changing schedules, or quietly disabling the very monitoring meant to catch it — using the same protocols and access paths engineers rely on every day.

Assessment

Tool-based assessment, grounded in evidence

Asset discovery: Velos Shield connected via SPAN ports — no agents, no active probing — and built a verified inventory of engineering workstations, BMS servers, controllers, sensors, actuators and their protocols, revealing communication relationships, unmanaged devices, forgotten remote-access endpoints and shadow connections.

Vulnerability management: each asset fingerprinted and correlated against known exposure data, then layered with operational context — what it controls, how exposed it is, what a credible attack path looks like — separating theoretical exposure from risk that could genuinely affect airport operations.

Outcome: a verified BMS asset inventory, a prioritised vulnerability register, and a continuously monitored behavioural baseline — each tied to business impact.

Approach

Establish the baseline, then watch it continuously

Phase 1 — Baseline: a structured Gramax review of assets, network architecture, configurations and working processes — a point-in-time picture against recognized OT security practices.

Phase 2 — Watch continuously: Velos Shield NIDS passively listens via mirrored ports, building a living picture of every asset and conversation: who talks to whom, over which protocol, how often, and why.

A BMS server reading data from an air-handling unit controller is ordinary. An engineering workstation suddenly writing to multiple controllers, or an unfamiliar device querying equipment across the building, looks very different once that baseline exists.

Asset & network awareness

New devices, unexpected addresses, layout changes surfaced as they appear.

Protocol-level detection

Unauthorized commands and unusual frequency stand out against the everyday rhythm.

Cyber-attack indicators

Reconnaissance, lateral movement, repeated logins recognized as patterns.

BMS-specific anomalies

Unexpected setpoint changes, abnormal restarts, unusual access to critical equipment.

Mitigation

Turning telemetry into decisions

Identifying risk: consolidated inventory and findings into a single risk register scored by likelihood and operational consequence; mapped realistic attack paths; reviewed remote-connectivity patterns to find unmanaged vendor exposure.

Mitigating risk: remediation roadmap ordered by business impact; segmentation plan separating BMS from enterprise IT and lower-trust zones; time-bound, reviewed, logged vendor access replacing always-on shared credentials; NIDS policies tuned to the baseline and wired into the airport’s SOC and incident response.

Velos Shield gave the airport the eyes on the network. Gramax gave it the judgment to act on what those eyes saw.

Architecture

Layered around how the building actually operates

Enterprise IT

The corporate network and its users.

Airport SOC

Central monitoring and response.

OT Monitoring

Velos Shield NIDS, watching continuously.

OT DMZ

Jump server and remote-access gateway.

BMS Zone

BMS servers and engineering workstations.

Field Zone

Controllers, sensors, and actuators.

What changed

From scattered visibility to a shared picture

AreaBeforeAfter
Asset visibilityIncomplete records of what controllers existedCritical BMS assets identified and classified by business impact
Vulnerability dataNo structured, tool-based vulnerability viewCorrelated, risk-scored register tied to real assets
Network designFlat segments, little separationDocumented architecture with a segmentation roadmap
Access controlShared credentials, loose vendor accessVendor access controlled, time-bound, reviewed
MonitoringNo protocol-level insight into BMS trafficContinuous, protocol-aware monitoring in place
Detection & responseLimited anomaly detectionPrioritized vulnerabilities with SOC-integrated detection

Impact

What continuous visibility means beyond the network diagram

  • Reduced operational risk — fewer opportunities for unauthorized manipulation of building systems.
  • Improved resilience — clearer monitoring and response path for critical facility services during a cyber incident.
  • Faster detection — from investigating after something goes wrong to spotting unusual behavior as it happens.
  • Stronger vendor governance — full visibility into third-party remote access and contractor activity.
  • Clearer executive visibility — findings translated into business-impact language for facilities, engineering, SOC and leadership alike.

Conclusion

Infrastructure now — not just facilities

An airport’s BMS has quietly become a cyber-physical layer of critical infrastructure. Pairing a Gramax-led, tool-based assessment with Velos Shield’s continuous NIDS monitoring gave the airport something more durable than a snapshot: a verified inventory, a prioritized risk register, and an ongoing shared understanding of what’s on the network, how it normally behaves, and what deserves a closer look.

Gramax Cybertech

Specialized cybersecurity for critical infrastructure and cyber-physical environments across aviation, energy, maritime, manufacturing and urban infrastructure.

Velos Shield

OT security and intelligence platform delivering continuous, passive visibility — asset intelligence, risk prioritisation, threat detection and decision-ready insights, built for zero-downtime operations.

Case study by Gramax Cybertech • Technology partner Velos Shield.