16
INTELLIGENT BUILDINGS AND CYBERSECURITY Building Control System Cyber Defense Forum November 17-19, 2015 • Washington, D.C. Ronald J. Zimmer CAE President & CEO Continental Automated Buildings Association www.CABA.org LinkedIn: http://www.linkedin.com/groups?gid=2121884

INTELLIGENT BUILDINGS AND CYBERSECURITYsites.nationalacademies.org/cs/groups/depssite/documents/webpage/... · ©2015 Continental Automated Buildings Association (CABA). INTELLIGENT

Embed Size (px)

Citation preview

Page 1: INTELLIGENT BUILDINGS AND CYBERSECURITYsites.nationalacademies.org/cs/groups/depssite/documents/webpage/... · ©2015 Continental Automated Buildings Association (CABA). INTELLIGENT

©2015 Continental Automated Buildings Association (CABA).

INTELLIGENT BUILDINGS

AND CYBERSECURITY

Building Control System Cyber Defense Forum

November 17-19, 2015 • Washington, D.C.

Ronald J. Zimmer CAE

President & CEO

Continental Automated Buildings Association

www.CABA.org

LinkedIn: http://www.linkedin.com/groups?gid=2121884

Page 2: INTELLIGENT BUILDINGS AND CYBERSECURITYsites.nationalacademies.org/cs/groups/depssite/documents/webpage/... · ©2015 Continental Automated Buildings Association (CABA). INTELLIGENT

CABA Board of Directors and Vision

CABA Vision Statement

“CABA accelerates growth in the connected home

and intelligent buildings sectors.”

CABA Board of Directors

2

Page 3: INTELLIGENT BUILDINGS AND CYBERSECURITYsites.nationalacademies.org/cs/groups/depssite/documents/webpage/... · ©2015 Continental Automated Buildings Association (CABA). INTELLIGENT

About CABA

3

• The Continental Automated Buildings Association (CABA) is an

international not-for-profit industry association, founded in 1988,

dedicated to the advancement of connected home and building

technologies.

• The organization is supported by an international membership of

over 325 organizations involved in the design, manufacture,

installation and retailing of products relating to home and building

automation.

• Public organizations, including utilities and government are also

members. CABA's mandate includes providing its members with

research, services and networking opportunities.

• CABA also encourages the development of industry standards and

protocols, and leads cross-industry initiatives.

• CABA maintains the largest “connected home and intelligent

buildings” research library in the world.

Page 4: INTELLIGENT BUILDINGS AND CYBERSECURITYsites.nationalacademies.org/cs/groups/depssite/documents/webpage/... · ©2015 Continental Automated Buildings Association (CABA). INTELLIGENT

CABA Intelligent Buildings and Cybersecurity Study

4

For more information on this research project, go to: http://www.caba.org/CABA/Research/Intelligent-Buildings-Cybersecurity.aspx

Page 5: INTELLIGENT BUILDINGS AND CYBERSECURITYsites.nationalacademies.org/cs/groups/depssite/documents/webpage/... · ©2015 Continental Automated Buildings Association (CABA). INTELLIGENT

What is an Intelligent Building?

Source: Compass Intelligence, 2015 5

Page 6: INTELLIGENT BUILDINGS AND CYBERSECURITYsites.nationalacademies.org/cs/groups/depssite/documents/webpage/... · ©2015 Continental Automated Buildings Association (CABA). INTELLIGENT

6

Intelligent Buildings are the Future

Source: The IET – The Institution of Engineering and Technology

“Intelligent

Buildings are

part of an

increasingly

integrated build

environment.”

Smart

Grid

Smart

Cities

Smart

Homes

Intelligent Transport

Intelligent

Buildings

Page 7: INTELLIGENT BUILDINGS AND CYBERSECURITYsites.nationalacademies.org/cs/groups/depssite/documents/webpage/... · ©2015 Continental Automated Buildings Association (CABA). INTELLIGENT

7

Convergence of IP-Based Infrastructure

Source: The IET – The Institution of Engineering and Technology

• Building Services

• Accommodation

Services

• Business Services

Page 8: INTELLIGENT BUILDINGS AND CYBERSECURITYsites.nationalacademies.org/cs/groups/depssite/documents/webpage/... · ©2015 Continental Automated Buildings Association (CABA). INTELLIGENT

8

Case Study – IP Based Systems – Sports Stadium

Source: The IET – The Institution of Engineering and Technology

Page 9: INTELLIGENT BUILDINGS AND CYBERSECURITYsites.nationalacademies.org/cs/groups/depssite/documents/webpage/... · ©2015 Continental Automated Buildings Association (CABA). INTELLIGENT

9

Risks Arising from Compromised Systems

Source: The IET – The Institution of Engineering and Technology

Corporate IT

systems

Loss of

view

Loss of

Information

Denial of

Service

Financial

Integrity

Building

Systems (ICS)

Safety and operational risk

Financial and reputational risk

Loss of

control

Impact on systems

Page 10: INTELLIGENT BUILDINGS AND CYBERSECURITYsites.nationalacademies.org/cs/groups/depssite/documents/webpage/... · ©2015 Continental Automated Buildings Association (CABA). INTELLIGENT

North America Threat Profile for Intelligent Building and Market (2015)

Source: 2015 Verizon Data Breach Investigation Report 10

Page 11: INTELLIGENT BUILDINGS AND CYBERSECURITYsites.nationalacademies.org/cs/groups/depssite/documents/webpage/... · ©2015 Continental Automated Buildings Association (CABA). INTELLIGENT

11

CABA Member Funders

Four Options:

1. Avoidance

2. Reduction

3. Sharing the Risks

4. Retention and Manage

Consequences

Source: The IET – The Institution of Engineering and Technology

Page 12: INTELLIGENT BUILDINGS AND CYBERSECURITYsites.nationalacademies.org/cs/groups/depssite/documents/webpage/... · ©2015 Continental Automated Buildings Association (CABA). INTELLIGENT

12

Security Zones and Conduits

• Solutions developed

during the design phase.

• Proposed design should

be assessed for new

ideas.

• BMS application needs

networked segregation

(firewall).

• Secure gateway protection

(data diode secures BMS).

Source: The IET – The Institution of Engineering and Technology

Page 13: INTELLIGENT BUILDINGS AND CYBERSECURITYsites.nationalacademies.org/cs/groups/depssite/documents/webpage/... · ©2015 Continental Automated Buildings Association (CABA). INTELLIGENT

13

Cybersecurity Responsibility Paradigm

• Manage interaction between

infrastructure and business

systems.

• Need clear operating

procedures and agreed “best

practices”.

• Need to be based on

recognized standards (eg.,

ISO 27001).

• Legal issues – lease/tenancy

agreements covering data

protection, human rights, etc.

• Insurance policies need to be

revised and possibly updated.

Source: The IET – The Institution of Engineering and Technology

Page 14: INTELLIGENT BUILDINGS AND CYBERSECURITYsites.nationalacademies.org/cs/groups/depssite/documents/webpage/... · ©2015 Continental Automated Buildings Association (CABA). INTELLIGENT

Global Cybersecurity Revenues Market, 2015-2022

Source: Compass Intelligence, 2015 14

Global Cybersecurity Expenditures, 2015-2022

$75.8B - $160.6B

Page 15: INTELLIGENT BUILDINGS AND CYBERSECURITYsites.nationalacademies.org/cs/groups/depssite/documents/webpage/... · ©2015 Continental Automated Buildings Association (CABA). INTELLIGENT

Percent of Revenues by Region for the Global Cybersecurity Market, 2015

NA

$33.4

Europe

$17.4

APAC

$15.9

MEA

$5.3

LATAM

$3.8 Region Revenues (B)

NA $33.4

Europe $17.4

APAC $15.9

MEA $5.3

LATAM $3.8

Source: Compass Intelligence, 2015 15

Page 16: INTELLIGENT BUILDINGS AND CYBERSECURITYsites.nationalacademies.org/cs/groups/depssite/documents/webpage/... · ©2015 Continental Automated Buildings Association (CABA). INTELLIGENT

Contact Us

Continental Automated Buildings Association (CABA) 1173 Cyrville Road, Suite 210

Ottawa, ON K1J 7S6 613.686.1814

Toll free: 888.798.CABA (2222) Fax: 613.744.7833

[email protected] www.CABA.org

www.twitter.com/caba_news www.linkedin.com/groups?gid=2121884

16