Building Engineering & Technology

Building Controls & BMS

The control layer coordinating HVAC, lighting and other building systems — increasingly the entry point for smart-building and energy-optimisation initiatives, and increasingly a genuine cybersecurity concern.

A — Hard / technicalStrategicTacticalOperational

A BMS that has been running on its original commissioning settings for a decade is not a control system anymore — it is a very expensive way of doing nothing.

Why this service exists

Modern buildings coordinate dozens of interacting systems; without a control layer actively tuned to actual (not design-assumed) occupancy and usage patterns, individual systems run inefficiently even when each is individually well-maintained.

What the service covers

  • BMS configuration and calibration.
  • Control-strategy optimisation against real occupancy data.
  • Fault diagnosis at the controls level (as distinct from the mechanical/electrical asset level).
  • BMS cybersecurity management.
  • Integration of new sensors/systems into the existing control architecture.

Assets and objects

  • BMS head-end and controllers.
  • Sensor networks.
  • Control wiring.
  • Integration points with HVAC/lighting/access systems.

Who takes part

  • BMS specialist/controls engineerRequired

    Mandatory.

  • IT/cybersecurity liaisonRequired

    Increasingly mandatory, not optional.

  • FM operations managerSituational

    Steers the service.

  • Energy managerSituational

    Uses BMS data for optimisation.

What the service needs

  • Current control strategy documentation.
  • Actual occupancy/usage data.
  • Cybersecurity risk assessment for networked building systems.

How delivery runs

  1. 01Review control strategies against actual (not design-assumed) occupancy patterns on a recurring basis, not only at commissioning.
  2. 02Diagnose and resolve control-level faults distinct from underlying mechanical faults.
  3. 03Manage BMS network security in coordination with IT — patching, access control, network segmentation from corporate IT systems.
  4. 04Integrate new sensors or subsystems as they're added, maintaining a coherent control architecture rather than an accumulating patchwork.

What is delivered

  • Calibrated control strategies.
  • Fault diagnosis records.
  • Cybersecurity compliance records.
  • Integration documentation.

From output to outcome

Output

Calibrated, secured controls.

Outcome

Building systems that actually respond to real conditions rather than static design assumptions.

Organisational effect

The outcome that turns individually well-maintained HVAC, lighting and access systems into a genuinely efficient, responsive building rather than a collection of correctly functioning but poorly coordinated parts.

Where it gets tense

  • Control strategies never revisited since original commissioning, even as building occupancy has changed substantially.
  • BMS networks with no meaningful segmentation from corporate IT, creating an under-recognised attack surface.
  • Sensor drift going undetected because nobody is actively monitoring for it, only for outright failure.

Strategic, tactical, operational

Strategic

BMS data is increasingly a strategic asset for sustainability reporting and space-utilisation decisions, not merely an operational control tool.

Tactical

BMS cybersecurity now requires genuine IT/FM collaboration, not FM treating it as purely a building-systems matter or IT treating it as purely an FM matter.

Operational

Control-strategy changes need genuine change management — a well-intentioned optimisation change can create occupant complaints if not communicated and monitored.

Performance indicators

  • Control-strategy review cycle compliance

    Shows whether the BMS is actively managed.

  • Energy performance against BMS-optimisable baseline

    Links controls to energy outcomes.

  • Cybersecurity patch compliance rate

    Core indicator of OT cyber risk.

Risks

  • Cybersecurity risk is now a genuine, not theoretical, FM concern — a compromised BMS is a physical-safety and operational-continuity incident, not merely a data incident.

Statutory context

There is no uniform, FM-specific statutory standard for BMS; national and sectoral cybersecurity frameworks are becoming increasingly relevant and are jurisdiction-specific.

Sourcing options

  • Managing agent

    Often retained under manufacturer service agreement given the specialist, proprietary nature of many BMS platforms.

  • Single service

    Increasingly requires a distinct cybersecurity-specific service line layered on top.

Technology and data

  • BMS platforms.
  • IoT sensor integration.
  • Cybersecurity monitoring tools specific to operational-technology (OT) networks as distinct from standard IT networks.

Competencies required

  • Controls engineering.
  • Increasingly OT cybersecurity awareness.

Common mistakes

  • Treating BMS as "set and forget" once commissioned.
  • Leaving BMS networks unsegmented from corporate IT, an increasingly recognised and increasingly exploited vulnerability.

Connections

Knowledge domains
  • Cybersecurity
  • Smart Buildings
  • IoT
To index
Standards and guidance
  • None FM-specific and internationally uniform; national/sectoral cybersecurity frameworks increasingly relevant (jurisdiction-specific)
To index

Adjacent services

Last reviewed: 2026-08-23

Classified using market terminology (hard / soft / enabling), nuanced against EN 15221-8:2025 and ISO 41011:2024.

Services Atlas