Case Study • Airport Operations — Building Management Systems
Strengthening Cybersecurity of Airport Building Management Systems
Continuous BMS visibility, vulnerability prioritisation, and protocol-aware threat detection — turning OT telemetry into business-impact decisions without touching a single controller.
The context
OT security should not stop at asset visibility or alert generation. In a cyber-physical environment such as airport BMS, the real value is connecting passive discovery, vulnerability intelligence, abnormal behaviour detection, and business-impact prioritisation into one continuous operating view.
Behind every terminal is a large interconnected BMS — HVAC, chilled-water plants, electrical distribution, lighting, elevators, access control, fire and life-safety monitoring — increasingly linked over the same IP network, connected outward to corporate IT, airport operations, contractors, remote maintenance and cloud services. A single weak link doesn’t just risk an HVAC outage — it can ripple into passenger comfort, equipment availability, operational continuity, and physical security.
The challenge
Familiar building systems, an unfamiliar attack surface
Unclear asset ownership
Controllers and devices added over the years without a complete, current inventory of what existed or how critical each one was.
Flat, under-segmented networks
Building systems shared network space with limited separation, making it easier for an issue in one area to reach another.
Loose credentials & access
Shared or default logins and broad vendor privileges made it hard to know exactly who could reach which systems.
Ageing, unpatched systems
Some servers and workstations ran outdated software with no formal, ongoing process for keeping them current.
Always-on remote access
Vendor and maintenance connections stayed open long after the work was done, with little record of what happened during the session.
No eyes on the network itself
No tool-based way to see what normal BMS traffic looked like, let alone notice the moment something drifted from it.
Why it matters
The building systems don’t need to be attacked directly to be a way in
An intruder doesn’t need to touch any flight-critical system. A realistic path runs from the internet or a compromised IT account, into the general network, across to the BMS, through an engineering workstation, and finally to a controller managing a real physical process.
From there: adjusting HVAC setpoints or stopping equipment, triggering false alarms or silencing real ones, changing schedules, or quietly disabling the very monitoring meant to catch it — using the same protocols and access paths engineers rely on every day.
Assessment
Tool-based assessment, grounded in evidence
Asset discovery: Velos Shield connected via SPAN ports — no agents, no active probing — and built a verified inventory of engineering workstations, BMS servers, controllers, sensors, actuators and their protocols, revealing communication relationships, unmanaged devices, forgotten remote-access endpoints and shadow connections.
Vulnerability management: each asset fingerprinted and correlated against known exposure data, then layered with operational context — what it controls, how exposed it is, what a credible attack path looks like — separating theoretical exposure from risk that could genuinely affect airport operations.
Outcome: a verified BMS asset inventory, a prioritised vulnerability register, and a continuously monitored behavioural baseline — each tied to business impact.
Approach
Establish the baseline, then watch it continuously
Phase 1 — Baseline: a structured Gramax review of assets, network architecture, configurations and working processes — a point-in-time picture against recognized OT security practices.
Phase 2 — Watch continuously: Velos Shield NIDS passively listens via mirrored ports, building a living picture of every asset and conversation: who talks to whom, over which protocol, how often, and why.
A BMS server reading data from an air-handling unit controller is ordinary. An engineering workstation suddenly writing to multiple controllers, or an unfamiliar device querying equipment across the building, looks very different once that baseline exists.
Asset & network awareness
New devices, unexpected addresses, layout changes surfaced as they appear.
Protocol-level detection
Unauthorized commands and unusual frequency stand out against the everyday rhythm.
Cyber-attack indicators
Reconnaissance, lateral movement, repeated logins recognized as patterns.
BMS-specific anomalies
Unexpected setpoint changes, abnormal restarts, unusual access to critical equipment.
Mitigation
Turning telemetry into decisions
Identifying risk: consolidated inventory and findings into a single risk register scored by likelihood and operational consequence; mapped realistic attack paths; reviewed remote-connectivity patterns to find unmanaged vendor exposure.
Mitigating risk: remediation roadmap ordered by business impact; segmentation plan separating BMS from enterprise IT and lower-trust zones; time-bound, reviewed, logged vendor access replacing always-on shared credentials; NIDS policies tuned to the baseline and wired into the airport’s SOC and incident response.
Velos Shield gave the airport the eyes on the network. Gramax gave it the judgment to act on what those eyes saw.
Architecture
Layered around how the building actually operates
Enterprise IT
The corporate network and its users.
Airport SOC
Central monitoring and response.
OT Monitoring
Velos Shield NIDS, watching continuously.
OT DMZ
Jump server and remote-access gateway.
BMS Zone
BMS servers and engineering workstations.
Field Zone
Controllers, sensors, and actuators.
What changed
From scattered visibility to a shared picture
| Area | Before | After |
|---|---|---|
| Asset visibility | Incomplete records of what controllers existed | Critical BMS assets identified and classified by business impact |
| Vulnerability data | No structured, tool-based vulnerability view | Correlated, risk-scored register tied to real assets |
| Network design | Flat segments, little separation | Documented architecture with a segmentation roadmap |
| Access control | Shared credentials, loose vendor access | Vendor access controlled, time-bound, reviewed |
| Monitoring | No protocol-level insight into BMS traffic | Continuous, protocol-aware monitoring in place |
| Detection & response | Limited anomaly detection | Prioritized vulnerabilities with SOC-integrated detection |
Impact
What continuous visibility means beyond the network diagram
- Reduced operational risk — fewer opportunities for unauthorized manipulation of building systems.
- Improved resilience — clearer monitoring and response path for critical facility services during a cyber incident.
- Faster detection — from investigating after something goes wrong to spotting unusual behavior as it happens.
- Stronger vendor governance — full visibility into third-party remote access and contractor activity.
- Clearer executive visibility — findings translated into business-impact language for facilities, engineering, SOC and leadership alike.
Conclusion
Infrastructure now — not just facilities
An airport’s BMS has quietly become a cyber-physical layer of critical infrastructure. Pairing a Gramax-led, tool-based assessment with Velos Shield’s continuous NIDS monitoring gave the airport something more durable than a snapshot: a verified inventory, a prioritized risk register, and an ongoing shared understanding of what’s on the network, how it normally behaves, and what deserves a closer look.
Gramax Cybertech
Specialized cybersecurity for critical infrastructure and cyber-physical environments across aviation, energy, maritime, manufacturing and urban infrastructure.
Velos Shield
OT security and intelligence platform delivering continuous, passive visibility — asset intelligence, risk prioritisation, threat detection and decision-ready insights, built for zero-downtime operations.
Case study by Gramax Cybertech • Technology partner Velos Shield.