Building Controls & BMS
The control layer coordinating HVAC, lighting and other building systems — increasingly the entry point for smart-building and energy-optimisation initiatives, and increasingly a genuine cybersecurity concern.
A BMS that has been running on its original commissioning settings for a decade is not a control system anymore — it is a very expensive way of doing nothing.
Why this service exists
Modern buildings coordinate dozens of interacting systems; without a control layer actively tuned to actual (not design-assumed) occupancy and usage patterns, individual systems run inefficiently even when each is individually well-maintained.
What the service covers
- BMS configuration and calibration.
- Control-strategy optimisation against real occupancy data.
- Fault diagnosis at the controls level (as distinct from the mechanical/electrical asset level).
- BMS cybersecurity management.
- Integration of new sensors/systems into the existing control architecture.
Assets and objects
- BMS head-end and controllers.
- Sensor networks.
- Control wiring.
- Integration points with HVAC/lighting/access systems.
Who takes part
- BMS specialist/controls engineerRequired
Mandatory.
- IT/cybersecurity liaisonRequired
Increasingly mandatory, not optional.
- FM operations managerSituational
Steers the service.
- Energy managerSituational
Uses BMS data for optimisation.
What the service needs
- Current control strategy documentation.
- Actual occupancy/usage data.
- Cybersecurity risk assessment for networked building systems.
How delivery runs
- 01Review control strategies against actual (not design-assumed) occupancy patterns on a recurring basis, not only at commissioning.
- 02Diagnose and resolve control-level faults distinct from underlying mechanical faults.
- 03Manage BMS network security in coordination with IT — patching, access control, network segmentation from corporate IT systems.
- 04Integrate new sensors or subsystems as they're added, maintaining a coherent control architecture rather than an accumulating patchwork.
What is delivered
- Calibrated control strategies.
- Fault diagnosis records.
- Cybersecurity compliance records.
- Integration documentation.
From output to outcome
Calibrated, secured controls.
Building systems that actually respond to real conditions rather than static design assumptions.
The outcome that turns individually well-maintained HVAC, lighting and access systems into a genuinely efficient, responsive building rather than a collection of correctly functioning but poorly coordinated parts.
Where it gets tense
- Control strategies never revisited since original commissioning, even as building occupancy has changed substantially.
- BMS networks with no meaningful segmentation from corporate IT, creating an under-recognised attack surface.
- Sensor drift going undetected because nobody is actively monitoring for it, only for outright failure.
Strategic, tactical, operational
BMS data is increasingly a strategic asset for sustainability reporting and space-utilisation decisions, not merely an operational control tool.
BMS cybersecurity now requires genuine IT/FM collaboration, not FM treating it as purely a building-systems matter or IT treating it as purely an FM matter.
Control-strategy changes need genuine change management — a well-intentioned optimisation change can create occupant complaints if not communicated and monitored.
Performance indicators
- Control-strategy review cycle compliance
Shows whether the BMS is actively managed.
- Energy performance against BMS-optimisable baseline
Links controls to energy outcomes.
- Cybersecurity patch compliance rate
Core indicator of OT cyber risk.
Risks
- Cybersecurity risk is now a genuine, not theoretical, FM concern — a compromised BMS is a physical-safety and operational-continuity incident, not merely a data incident.
Statutory context
There is no uniform, FM-specific statutory standard for BMS; national and sectoral cybersecurity frameworks are becoming increasingly relevant and are jurisdiction-specific.
Sourcing options
- Managing agent
Often retained under manufacturer service agreement given the specialist, proprietary nature of many BMS platforms.
- Single service
Increasingly requires a distinct cybersecurity-specific service line layered on top.
Technology and data
- BMS platforms.
- IoT sensor integration.
- Cybersecurity monitoring tools specific to operational-technology (OT) networks as distinct from standard IT networks.
Competencies required
- Controls engineering.
- Increasingly OT cybersecurity awareness.
Common mistakes
- Treating BMS as "set and forget" once commissioned.
- Leaving BMS networks unsegmented from corporate IT, an increasingly recognised and increasingly exploited vulnerability.