NIST released new guidance to help organizations secure Building Automation & Control Systems (BACS) as cyber risk grows across operational technology environments in critical infrastructure, commercial properties, and federal buildings. The agency said BACS are increasingly connected to corporate networks and cloud services, expanding the attack surface for systems that manage HVAC, lighting, access control, fire alarms, and energy management. To support owners and operators with limited resources, NIST published a quick-start infographic with immediate defensive steps and pointed readers to broader OT security materials.
The release aligns with NIST’s wider sector-focused cybersecurity work, including the NCCoE’s Transit Cybersecurity Framework Community Profile, which maps cybersecurity practices for transit environments. NIST also said it is revising SP 800-82, the federal guide to operational technology security, and expects to publish a draft update for public comment later in 2026, signaling continued emphasis on practical protections for connected physical systems.

See the actors and campaigns active against you right now.
2 events from the most recent confirmed update back to the earliest known activity.
NIST published a security notice and quick-start infographic with immediate cybersecurity steps for Building Automation & Control Systems owners and operators, developed with the BACS community. The guidance addresses growing OT risk as building systems become more connected to corporate networks and cloud environments.
The National Cybersecurity Center of Excellence published the Transit Cybersecurity Framework Community Profile project page as a sector-specific cybersecurity resource for transportation.
See the adversaries and campaigns active against your sector right now, ranked by what they're exploiting.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.