Show Notes
When Convenience Creates Invisible Risk
Modern commercial buildings depend on connected technology to manage comfort, access, operations, and energy use. But when devices are added quickly and outside a shared process, they can become invisible parts of the building environment. This episode examines how unmanaged thermostats, sensors, and controllers can create operational problems and cybersecurity exposure long after the original installation.
The conversation begins with a routine building audit that uncovered 40 devices on a network that no one had touched in years. The devices included thermostats, sensors, and controllers believed to have been installed by contractors who had since moved on. The issue was not simply that the devices were old. One controller was still trying to manage the same HVAC zone as the building automation system, creating a conflict that made an entire floor consistently warm.
The Hidden Problem: Devices That Nobody Owns
Unmanaged building technology is often not installed with bad intent. It is usually the result of speed. A facilities manager may install a smart thermostat during a short break to solve an immediate problem. A vendor may describe a device as plug-and-play. A contractor may complete an installation, get paid, and leave. In each case, the device goes live without a durable record of what it is, why it is connected, or who will own it years later.
That creates a gap between physical building operations and IT oversight. The building may appear normal on the surface: lights are on, elevators work, and daily activity continues. Underneath, however, disconnected systems can be operating without visibility, documentation, or ongoing maintenance.
- Facilities may not track the device after installation.
- The vendor may assume the building management system covers it.
- The building automation system may not even know the device exists.
- The employee or contractor with the relevant knowledge may no longer be involved.
The result is not necessarily a people problem. It is a process problem. And because it is a process problem, it can be fixed with clear shared practices.
When Building Systems Fight for Control
During the audit described in the episode, the team opened a network cabinet in a mechanical room and found an old gray controller tucked behind unorganized cables. It had dust on top and had apparently gone untouched for years. Tracing the device revealed that it controlled two rooftop units serving the third floor.
The controller was competing with the building automation system for temperature control. On one day, it could call for heat; on another, it could call for cooling. The building automation system attempted to override it, but the older controller retained a higher priority setting and continued to win the control conflict.
This example matters because occupants may only experience the visible symptom: a floor that is always a little too warm. They may not realize that two independent systems are issuing conflicting instructions to the same HVAC zone. Without an inventory and a clear ownership model, the root cause can remain hidden while comfort complaints, maintenance calls, and wasted effort accumulate.
Default Credentials Turn an Operations Issue Into a Security Issue
The audit revealed another serious concern: the controller still used default factory credentials. Anyone on the network could potentially have taken control of that controller. That access could extend beyond temperature settings to fan speeds, dampers, and other HVAC functions connected to the device.
This is why unmanaged building technology cannot be treated only as a maintenance concern. The risk is defined not just by the device itself, but by what the device can reach. An unpatched controller with default credentials can create a path into systems that affect building operations. When the device was installed quickly, never documented, and not maintained, no one may know it is exposed until an audit or a failure brings it to light.
When a rogue device causes a problem, the answers are often unclear:
- Who installed it?
- What is it connected to?
- Who is responsible for maintaining it?
- Who responds if it fails?
- Who is accountable for the security risk?
Without established ownership, facilities teams, vendors, and building-management stakeholders can all assume someone else is handling the device. Meanwhile, the building becomes less comfortable and the operational response slows down.
Three Steps to Regain Visibility
The episode outlines a practical approach for reducing technology sprawl without turning the process into a blame exercise.
1. Build a living inventory
Document every connected device in the building. The inventory should not be a spreadsheet saved on one person’s laptop. It should be a living document that can be maintained, reviewed, and used by the teams responsible for building technology.
Each device needs a named owner. Ownership makes it clear who is responsible for understanding the device, maintaining it, and responding when it stops working or creates risk.
2. Classify devices by risk
Not every device has the same impact. A smart thermostat in a lobby is different from a controller associated with an access control system. One may primarily affect comfort, while the other can introduce a security issue. Risk classification helps teams decide which devices need stronger safeguards, closer review, and more urgent maintenance.
3. Require approval before connection
Before a new device goes on the network, require answers to three questions:
- What is it?
- Why does it need to be connected?
- Who is responsible for it?
If those questions cannot be answered, the device should not be connected. The approval should involve both IT and facilities. When only one side signs off, the same ownership gap can return. Shared approval creates accountability before a device becomes another forgotten component of the building environment.
A More Reliable Building Starts With Discipline
The solution discussed in this episode is not complicated, but it does require discipline. Inventory connected devices. Understand their risks. Assign ownership. Require shared approval before new technology touches the network.
For building owners and operations leaders, this approach supports more than cybersecurity. It helps prevent conflicting controls, improves maintenance response, preserves operational knowledge when people change roles, and gives IT and facilities a shared view of the technology that keeps the building running.
If this sounds familiar, bring IT and facilities together, begin the inventory, and see what is connected today. The devices you find may reveal risks that have been quietly accumulating for years.
The $200 Sensor Problem in Modern Buildings
A small connected device can create a large building problem.
Consider a thermostat, sensor, or controller purchased to solve an immediate facilities issue. It may be inexpensive, easy to install, and described as plug-and-play. A technician connects it, the immediate issue appears resolved, and everyone moves on. Years later, the device is still on the network, still making decisions, and no longer appears in anyone’s records.
That is how shadow IT takes hold in commercial buildings. It is not always a secretive or malicious effort to bypass policy. More often, it is a fast response to a real operational need without a process that connects facilities work, IT oversight, vendor accountability, and long-term maintenance.
The danger is that these devices do not simply disappear when people forget about them. They continue operating. They may retain old configurations, default credentials, unpatched software, and network access. They may also create control conflicts that cause persistent building problems nobody can explain.
When a Routine Audit Finds a Building’s Forgotten Technology
In one routine audit, a walkthrough of connected building systems uncovered 40 devices on a network that nobody had touched in years. The list included thermostats, sensors, and controllers apparently installed by contractors who had moved on long ago.
One controller created a particularly revealing problem. It was still trying to control the same HVAC zone as the building automation system. The two systems were effectively fighting over the temperature on the third floor. Occupants did not know the technical cause; they simply believed that floor was always a little warm.
This is what makes unmanaged technology difficult to catch. A building can look functional from the outside. The lights work. The elevators run. Daily operations continue. Yet beneath that normal appearance, disconnected systems may be issuing conflicting instructions, operating with unclear authority, and creating conditions that are expensive to troubleshoot.
When the controller was located, it was in a mechanical-room network cabinet with unorganized, unlabeled cables. The device was tucked behind old cables, covered in dust, and had not been touched in years. After tracing it, the audit team found that it controlled two rooftop units on the third floor.
The controller could call for heat one day and cooling the next. The building automation system attempted to override it, but the old controller had a higher priority setting and kept winning the control conflict.
The lesson is straightforward: a device does not need to be visibly broken to be a problem. A forgotten controller can quietly influence building behavior for years.
Why These Devices End Up Outside the Process
The underlying cause is frequently speed. Someone needs a problem solved quickly, so they install a device. A facilities manager may put in a smart thermostat over a lunch break. A vendor may say the device does not require additional review. The installation feels simple because the immediate need is simple.
The long-term question is harder: who owns this device five years from now?
That question often goes unanswered. Facilities may not have a formal record. The vendor may have completed the work and moved on. IT may not know that the device has been placed on the network. The person who installed it may leave, taking the knowledge of its purpose and configuration with them.
It is tempting to frame this as a failure by one department, but that misses the point. Facilities teams have real operational demands, and vendors are often focused on completing a specific scope of work. The issue is a process gap: no shared mechanism ensures that a connected device is documented, reviewed, secured, and assigned to an accountable owner.
That distinction matters because process problems can be corrected. The goal is not to make every device installation adversarial. The goal is to make sure a quick fix does not become an invisible long-term risk.
From Comfort Complaint to Cybersecurity Exposure
Operational conflicts are only one side of the shadow IT issue. The audit also found that the forgotten controller still used default factory credentials.
That means anyone on the network could potentially take control of it. The potential impact went beyond adjusting a temperature setting. The controller could influence fan speeds, dampers, and other HVAC functions connected to the system.
This is the turning point in the conversation about unmanaged building devices. An old controller is not merely a maintenance concern. It can also be a security concern, especially when it is unpatched, undocumented, and accessible through known default credentials.
The risk of a device is not limited to its purchase price or physical size. It is defined by the systems it can reach and the decisions it can make. A small device installed for convenience can become a point of control inside a larger building environment.
When no one knows the device exists, no one is likely to verify its credentials, assess its network access, document its dependencies, or include it in a maintenance cycle. If it fails or becomes exposed, the first response often becomes a series of unhelpful questions: Who installed it? What is it connected to? Who owns it? Who is responsible for fixing it?
Those questions delay recovery precisely when a building needs a coordinated response.
The Accountability Gap
In unmanaged building environments, responsibility is often assumed rather than assigned. Facilities may believe the vendor handles the device. The vendor may assume the building management system handles it. The building management system may not even know it exists.
That leaves multiple teams pointing at each other while the actual problem continues. In the HVAC example, the building gets more uncomfortable by the hour while the teams try to establish who has authority over the equipment.
Clear accountability prevents that outcome. It gives the organization a known owner who can answer basic questions about each connected asset: what it does, why it is connected, how it is maintained, and who needs to act if it creates an issue.
Ownership is not about assigning blame to a single department. It is about ensuring that no device exists in a gap between IT, facilities, contractors, and vendors.
Three Practical Steps to Control Technology Sprawl
The good news is that restoring visibility does not require an overly complicated program. It begins with three disciplined steps.
1. Inventory every connected device
Create a complete inventory of connected building technology. That includes thermostats, sensors, controllers, and devices that may be outside the core building automation system.
The inventory must be a living document, not a spreadsheet sitting on one person’s laptop. It should remain available to the teams who need it and be updated as devices are added, changed, removed, or transferred between vendors.
Most importantly, every device needs a named owner. Without a named owner, a device is likely to become another forgotten exception.
2. Classify devices by their risk
Different devices carry different consequences. A smart thermostat in a lobby is not the same as a controller associated with an access control system. One may create a comfort concern. The other may create a security concern.
Risk classification helps building and IT teams determine which devices deserve greater scrutiny, stronger controls, and more frequent review. It also helps leadership prioritize attention based on operational and security impact rather than treating every connected asset as identical.
3. Create a shared approval workflow
Before any new device goes on the network, require clear answers to three questions:
- What is it?
- Why does it need to be connected?
- Who is responsible for it?
If no one can answer those questions, the device should not be connected. Both IT and facilities should sign off. Shared approval prevents either team from assuming the other is handling the device and creates accountability before the device becomes part of the operational environment.
Reliability Depends on Disciplined Maintenance
The central message is simple: reliability starts with disciplined maintenance. In commercial buildings, that discipline includes knowing what is connected, understanding the associated risk, and making ownership explicit.
For business owners, property leaders, facilities teams, and IT teams, this is not just a technical exercise. It supports better building comfort, faster troubleshooting, clearer vendor coordination, and a more secure technology environment. It preserves knowledge when personnel change and reduces the chance that a forgotten device will quietly control part of the building without oversight.
Listen to the full episode of Built, Wired & Secured for the complete discussion of how unmanaged devices create hidden risk and how IT and facilities can work together to regain control of the building network.