BACnet/SC as part of a holistic security approach
There are many layers to a good defense system. Defense-in-depth is a holistic security approach involving people, processes, and technology where defenses are layered to protect what is in the middle - the organization's valuables. While no security mechanism is perfect on its own, when defenses are layered and managed properly, the effort for initiating an attack is increased, and the risk of a successful attack is reduced.
BACnet/SC drastically improves OT network security, but it is not a silver bullet by itself. Even though BACnet/SC provides secure communication even in unsecured environments, BACnet/SC should play a part in a comprehensive defense-in-depth design to close off attack vectors and provide maximum protection of the organization’s attack surface. BACnet/SC fits nicely into holistic defense strategies and provides the value of enhanced OT security as part of an overall organizational cyber defense policyThe use of additional layers of security is strongly encouraged. A carefully designed and properly deployed OT network with BACnet/SC supports a proactive, multi-layered defense-in-depth approach and can become a smart building’s last line of defense in the event of a cyberattack.
Buildings that contain a mix of BACnet networks with BACnet/IP, BACnet MS/TP, and BACnet/SC are not inherently secure. Simply adding BACnet/SC will not secure the entire BACnet Internetwork since the same physical layer – Ethernet, and network layer – Internet Protocol (IP) are likely to be shared with the unsecured BACnet/IP protocol. Initially, OT networks with mixed BACnet devices are designed very much like they are designed today – using external security methods (VLAN, VPN, etc.). In these networks, BACnet/SC communication is only secure between the BACnet/SC hub and node devices. For now, these mixed networks should be treated like an unsecured BACnet/IP network until a full BACnet/SC system is achieved, or until BACnet routing firewalls are introduced. Another option for securing network segments is using advanced routers and firewall configurations, such as deep packet inspection, or other IT practices for managing network access and traffic flow.


BACnet/SC only encrypts communication and authenticates devices within the BACnet/SC secure virtual network of hub and nodes. Any other network segments using the BACnet/IP datalink are not secured and still require external security measures such as VLAN, VPN, etc.