Volume-09 Issue 11, November-2025 ISSN: 2456-9348 Impact Factor: 8.232 International Journal of Engineering Technology Research & Management (IJETRM) https://ijetrm.com/ IJETRM (http://ijetrm.com/) [176] CYBERSECURITY FOR CONNECTED HVAC AND BMS: MITIGATING VULNERABILITIES AND ACCESS RISKS Nawar Berro Lead Engineer, MEP Department, Bay Air systems, Concord, CA, USA ORCID ID - 0009-0005-2225-8568
[email protected],
[email protected] ABSTRACT This study examines the cybersecurity vulnerabilities of connected Heating, Ventilation, and Air Conditioning (HVAC) systems installed within smart Building Management Systems (BMS). The paper explores how legacy communication protocols such as BACnet, Modbus, and KNX expose network systems cyberattacks due to weak encryption, outdated software, and poor network segmentation. Using a qualitative multi-case design based on twelve professional interviews and eight document analyses, the research investigates technical, organizational, and human factors influencing system security. The findings of the study reveal that cybersecurity performance and effectiveness depend on effective secure network design, organizational culture, cross-departmental cooperation, and staff training. The study recommends a comprehensive cybersecurity framework that combines technical safeguards, policy adherence, and human-centered strategies to enhance resilience against unauthorized access and digital threats. Keywords: Cybersecurity, HVAC systems, Building Management Systems (BMS), IoT security, network protocols, BACnet, Modbus, Zero Trust Architecture, intrusion detection, smart buildings, operational technology (OT), information technology (IT). INTRODUCTION 1.1 Background The rapidly growing rate in the development of the Internet of Things (IoT) has significantly revolutionized building infrastructure by interconnecting different devices through smart Building Management Systems (BMS). One of them is the Heating, Ventilation, and Air Conditioning (HVAC) systems, which are highly significant in the regulation of energy, air quality, and the promotion of comfort among the occupants. The HVAC systems used in the modern intelligent buildings are remotely operated and managed by digital networks and IoT-enabled sensors, and this enables the use of data in decision-making to optimize energy consumption, preventive maintenance, and automation [4]. This connectivity exposes HVAC systems to cybersecurity risks. Recent NIST and IEC guidelines, such as NIST SP 800-82 and IEC 62443, emphasize the need to address such vulnerabilities within critical building infrastructure. HVAC systems, which were once standalone mechanical devices, now add up to a larger cyberphysical network, typically exchanging data with cloud servers, mobile applications, and external vendors. Ocaka et al. [14] argue that the lack of encryption, outdated firmware, and weak access control have increased the susceptibility of connected HVAC systems to cyberattacks in the U.S. When being exploited, these vulnerabilities can lead to unauthorized manipulation of the system and data breaches as well as catastrophic consequences for the occupants of the building and organizations. High-profile cases in the recent past have pointed out this hazard. An example is the case of an attacker who hacked into the Target Corporation in 2014 using the credentials of an HVAC contractor and breached over 40 million credit card records [9]. On the same note, in Europe, cyberattacks in smart building complexes have been reported, where hacked HVAC networks have been employed by the attackers to turn off the cooling systems, resulting in the interruption of operations and exposing people to safety hazards and risks [1]. With the world smart HVAC market projected to reach up to 51.7 billion by 2030 [13], a relevant question that arises as the operational technology (OT) and information technology (IT) become entwined in buildings is how security models can be changed to safeguard the essential building systems against emerging cyber threats. The traditional physical protection cannot be discussed as sufficient, given the fact that cybersecurity represents a new aspect that
Volume-09 Issue 11, November-2025 ISSN: 2456-9348 Impact Factor: 8.232 International Journal of Engineering Technology Research & Management (IJETRM) https://ijetrm.com/ IJETRM (http://ijetrm.com/) [177] becomes a vital factor of the building's reliability and the safety of people. However, few studies have integrated IT cybersecurity models with operational technology (OT) infrastructure in HVAC networks, leaving a practical gap in how these systems can be protected holistically. Year Market Values (USD Billion Annual Growth Rate (%) 2022 28.5 2024 34.2 7.3 2026 41.6 8.1 2028 47.5 6.9 2030 51.7 6.5 Table 1: Global Smart HVAC Market Growth (2022-2030) 1.2 Problem Statement The recent interconnection of the HVAC systems in intelligent buildings has presented a cybersecurity blind spot within the modern infrastructure. Even though IT network protection is a costly enterprise activity, HVAC and other OT systems mainly use outdated communication protocols such as BACnet, Modbus, and LonWorks, and they were not originally developed as secure systems [11]. The systems are not encrypted and may not utilize multi-factor authentication and secure update systems, and this makes them easy targets for cybercriminals. The problem is also compounded by the incorporation of third-party vendors, remote management systems, and cloudbased data analytics that expand the attack area of the system. Cybersecurity of both BMS and HVAC systems is not standardized, and this makes the facilities susceptible to ransomware, unauthorized access, and system hijacking [12]. The gap that is emphasized in the present research is the absence of a detailed, safe network protocol framework that would address the requirements of smart HVAC systems. The issue with this gap should be filled so that system integrity and functional continuity can be guaranteed and the safety of occupants and data privacy of the current buildings can be promoted. 1.3 Purpose of the Study and Research Objectives The dissertation will examine the cybersecurity threats of the related HVAC and Building Management Systems (BMS), review the current network protocols and architecture, and propose the secure design strategies to avoid the unauthorized access and cyber intrusions. The study will bridge the knowledge gap between IT cybersecurity frameworks and OT systems operation and will offer a multidisciplinary understanding of how interconnected HVAC networks can be secured without disrupting the performance, interoperability, and energy efficiency The research contributes to the development of a prototype conceptual cybersecurity framework for HVAC networks to guide secure design and implementation. In order to achieve these aims, the following specific objectives have been developed: 1) To identify and explore major cybersecurity vulnerabilities that are inherent in smart HVAC and BMS networks. 2) To assess current communication protocols such as BACnet, KNX, and Modbus in terms of scalability, security, and resilience. 3) To explore existing cybersecurity frameworks and compliance protocols that are pertinent to automation systems of buildings. 4) To come up with a conceptual cybersecurity framework, which promotes network security and reduces unauthorized access risks in connected HVAC systems. 1.4 Research Questions 1) What are the main cybersecurity threats and vulnerability vectors that affect connected HVAC systems and BMS networks? 2) How are the current building automation communication protocols secure against cyberattacks like ransomware, spoofing, and unauthorized access? 3) To what degree do the existing cybersecurity models and regulations address the existing unique challenges linked to HVAC system security?
Volume-09 Issue 11, November-2025 ISSN: 2456-9348 Impact Factor: 8.232 International Journal of Engineering Technology Research & Management (IJETRM) https://ijetrm.com/ IJETRM (http://ijetrm.com/) [178] 4) What network protocol strategies and architectures can be developed to secure strong protection and protect interoperability within smart HVAC systems? 1.5 Significance of the Study The study outcomes will be useful to the academic community and the practical domain, as they will provide practical data regarding the issues of cybersecurity associated with the IoT-based HVAC systems. The research will also identify some of the vulnerabilities of the facility managers among the facility managers and also give a roadmap on how the secure configurations can be implemented. In addition, the implications of the findings will be useful to the policymakers because they would be used to develop cybersecurity measures that are directly applicable to smart building systems. In the field of academia, the dissertation extends interdisciplinary information relating to cybersecurity engineering, mechanical systems, and digital infrastructural management. Further, due to the increasing automation of buildings, the research justifies the global adoption of the smart cities that are cyber-resilient wherein interoperable systems are secured by robust, flexible, and standardized security frameworks. 1.6 Scope and Delimitation The area of research is particularly on HVAC systems included in Building Management Systems (BMS) in smart buildings of institutions and for commercial purposes. It also locks out residential standalone HVAC systems without a network connection. The area of research is the vulnerabilities of cybersecurity and network protocols and access control mechanisms rather than the mechanical performance and the environmental performance of HVAC systems. This is because case studies, security audits, and technical reports of organizations that operate in North America and Europe will be the main sources of empirical data. LITERATURE REVIEW 2.1 Theoretical Underpinnings Several theoretical frameworks are used to study cybersecurity in related HVAC and Building Management Systems (BMS), characterizing both the content of cyber threats and the security mechanisms architecture. The CIA Triad is one of the most basic models, which dwells on confidentiality, integrity, and availability as the three fundamental pillars of information security [19]. When implemented related to the HVAC systems, confidentiality is linked with ensuring that the information on temperature records of the building, access credentials, and other configuration parameters remains confidential and is not shared with third parties. Unigwe states that integrity emphasizes the fact that data and system configuration settings cannot be accessed or altered by unauthorized individuals, and the availability part of the concept deals with the ability to keep the HVAC systems running and available to the authorized operators [19]. The breach of any of these dimensions can lead to both digital and physical elements of data theft and inconvenience or even health hazards to human health. The other theory that can be used in the study is the Cyber-Physical Systems (CPS) Security Model, which takes a collective cyber and physical approach to how the occurrence of attacks in digital networks can lead to actual physical effects [3]. The best examples of the CPS are the HVAC systems that combine sensors, actuators, controllers, and software, which are in interaction with the physical environment. Chen et al. [6] note that any form of cyberattack on a CPS digital control interface, e.g., a connected HVAC service, can harm physical functionality, leading to overheating, ventilating, or air quality disruption, thereby posing risks to occupants and disrupting essential infrastructure. Hence, CPS security theory emphasizes the integration between digital and physical layers, and the theory states that the cybersecurity of this kind of system should target the software and hardware weaknesses. The Defense in Depth (DiD) principle is also a critical theoretical approach towards analyzing the problem of cybersecurity in HVAC systems. This model promotes many and multiple layers of security to be implemented in order to secure the key assets [17]. This method may include the securing of endpoint devices such as controllers and sensors, encrypting communication channels between the devices, and applying network segmentation and intrusion detection on a higher architecture level in HVAC networks. Papakonstantinou et al. [15] assert that no single protection suffices to thwart attacks, particularly in the interwoven complex environments. Rather, it encourages a multi-layered approach, where every security mechanism compensates for possible vulnerabilities of the other. The last theoretical model that can be used to supplement the above models is the systems theory that focuses on interdependence and dynamic interaction of components in a complex system [10]. Based on this perspective, an
Volume-09 Issue 11, November-2025 ISSN: 2456-9348 Impact Factor: 8.232 International Journal of Engineering Technology Research & Management (IJETRM) https://ijetrm.com/ IJETRM (http://ijetrm.com/) [179] HVAC subsystem does not function solely but operates in constant interaction with other components in the building, including lighting, security, and energy management systems. According to Haimes [10], system weakness in one subsystem may cascade into other systems through common communication lines or interconnected management systems. The systems theory shows the importance of an integrative and holistic approach to cybersecurity in smart buildings, an approach that considers the whole BMS to be an interconnected ecosystem, but not a set of standalone devices. Combined together, these theoretical models constitute the basis for the conceptual cybersecurity framework put forward later in Section 5, which combines the principles of confidentiality, defense-in-depth, and systemic interdependence to guide secure HVAC network design. Theoretical Model Core Concept Application to HVAC/BMS Security CIA Triad Confidentiality, integrity and availability Protects data and operational reliability in smart HVAC networks Cyber-Physical Systems (CPS) model Integration of physical and cyber elements Connects digital weaknesses to real-world HVAC consequences. Defense in Depth (DiD) Multi-layered protection approach Encourages network, endpoint and user-level defense. System Theory Interlinked subsystems affect one another Encourages integrated and holistic security management. Table 2: Theoretical Frameworks Applied to Smart HVAC Cybersecurity 2.2 Smart HVAC Systems and Network Architecture The literature indicates that smart HVAC systems have changed from isolated mechanical systems to become complex and networked infrastructures integrated within intelligent buildings. These systems form a core component of the existing Building Management System (BMS), which enables centralization of temperature, humidity, and air quality with devices that are Internet of Things (IoT) enabled [8]. The IoT technologies combined with the HVAC allow monitoring in real time, predictive maintenance, and optimization of the energy consumption. The sensors collect data such as temperature, carbon dioxide level, and occupancy, which are sent to the centralized servers where they are processed into data using the algorithms and adjusted automatically to enhance efficiency and comfort. This connectivity has, however, made the system attack surface broader. The common structure of an integrated HVAC system has multiple layers that interact with each other, including a physical layer with sensors and actuators; a communication layer that transmits the data through wired and wireless protocols like BACnet/IP, Modbus TCP/IP, and Zigbee; an application layer that comprises supervisory control and analytics systems; and a cloud layer that allows monitoring and data storage remotely [18]. All these layers present different vulnerabilities. For example, unencrypted communication protocols can expose sensitive operational data to eavesdropping, whereas cloud-based management interfaces can be interfered with in case the authentication controls are not strong enough. According to Bakhshi et al. [2], HVAC systems are among the top five most popular subsystems that are targeted in smart buildings, mainly due to the insecure default settings, obsolete firmware, and weak access controls. They are open ports that the attackers use to access these systems through weak administrative passwords or maladjusted firewalls. After gaining access, an attacker can alter the temperature controls, shut down the ventilation, or utilize the HVAC system as a bridge to the other devices that are connected to the same network.
Volume-09 Issue 11, November-2025 ISSN: 2456-9348 Impact Factor: 8.232 International Journal of Engineering Technology Research & Management (IJETRM) https://ijetrm.com/ IJETRM (http://ijetrm.com/) [180] Figure 1: Typical Architecture of a Connected HVAC System 2.3 Cybersecurity Threats and Vulnerabilities in HVAC and BMS Literature and industry reports identify a vast array of cyberattacks that are specific to connected HVAC systems. Stouffer et al. [17] divide them into network-based, application-based, and human-factor vulnerabilities. Networkbased threats include direct attacks on the data transmission routes, like man-in-the-middle (MITM) attacks, where malicious parties intercept and compromise the communication packets between the HVAC controllers and the management servers. Other attacks against networks are denial-of-service (DoS) attacks, which overload system resources with excessive traffic, and spoofing attacks, where attackers pretend to be genuine devices to access the systems in an unauthorized manner. Vulnerability based on application is also a major concern. The research provided by Poyyamozhi et al. [16] indicates that applications and mobile interfaces used to operate HVAC systems by most BMSs are either built on application programming interfaces (APIs), which are not well secured, or on outdated software libraries. Cybercriminals can easily use such weaknesses to steal credentials or hack into the settings of remote systems. To provide an example, the vulnerability of a cloud-based dashboard monitoring HVAC can allow a hacker to alter the temperature setpoints of a building or to shut off the ventilation of a sensitive building such as a hospital or a laboratory. Human error and insider threats are another major problem. Most of the security breaches can be attributed to the lack of adequate training of the operators on best practices in cybersecurity. The unauthorized access or compromise of the system can be caused by phishing emails, use of weak passwords, and misuse of firmware updates [14]. In some cases, installers or maintenance workers have inadvertently installed flawed firmware that has malware, and this gives attackers a backdoor into otherwise secure networks [9]. All these factors together demonstrate that the problem of cybersecurity in the HVAC system is not only a technological but also a human and organizational challenge that needs constant oversight and education. Threat Category Example Attack Consequences Source Network-based Man-in-the-Middle (MITM) Unauthorized command injection [16] Application-based API exploitation System data theft [14] Human-factor Phishing or credential theft Unauthorized remote access [3] Physical access Unauthorized maintenance access Device tampering [17] Table 3: Common Cybersecurity Threats in Connected HVAC Systems
Volume-09 Issue 11, November-2025 ISSN: 2456-9348 Impact Factor: 8.232 International Journal of Engineering Technology Research & Management (IJETRM) https://ijetrm.com/ IJETRM (http://ijetrm.com/) [181] 2.4 Communication Protocols and Security Weaknesses The Building Automation Systems strongly depend on standardized communication protocols to allow interoperability among devices that are manufactured by other manufacturers. Nevertheless, historically, these protocols were structured in a manner that was reliable and easy to integrate, rather than secure. BACnet/IP, Modbus TCP/IP, LonWorks, and KNX, which are the most popularly used protocols, have major vulnerabilities when they are implemented in modern IP-based networks. BACnet/IP, which is among the most frequently used HVAC control protocols, transfers data using broadcast messages that by default lack encryption. This design option provides the attackers the ability to listen to or manipulate network traffic, injecting false commands to alter the temperature or turn off safety features. Similarly, developed in the 1970s for industrial control and operating without encryption or authentication, Modbus TCP/IP transmits all data in plaintext. This vulnerability can be used by the attackers to read or write directly to the control registers, which may potentially lead to mechanical failures or malfunctioning [7]. A newer protocol, KNX/IP, that is used in lighting and HVAC automation, supports the use of the AES-128 encryption, but this is not typically implemented with key management and makes the encryption ineffective. Despite its ability for basic authentication, LonWorks is vulnerable to message interception and manipulation of firmware because of inadequate mechanisms of integrity verification. Protocol Encryption Support Authentication Known Vulnerabilities BACnet/IP Optional Weak Spoofing, sniffing Modbus TCP/IP None None Replay and injection attacks KNX/IP AES-128 (Optional) Medium Key mismanagement LonWorks Basic Weak Message interception Table 4: Security Comparison of Building Automation Protocols These weaknesses indicate the necessity to possess safe protocol extension and robust configuration practices. Researchers indicate that application of these systems in segmented networks, encryption gateways, and installation of intrusion detection systems would go a long way in reducing exposure to computer attacks [14]. Nevertheless, the issue of non-homogeneity of security adoption in construction sectors remains a problem. 2.5 Regulatory and Standards Frameworks Several global frameworks and standards of regulations control the HVAC and BMS cybersecurity. It is important to note the National Institute of Standards and Technology (NIST) SP 800-82 provides an elaborate guideline on how to secure the industrial control systems, and they have provided a defense-in-depth strategy, network segmentation, and continuous monitoring [17]. Similarly, ISO/IEC 27001 (2022) is a model of information security management that is well-developed and can be implemented during smart building infrastructures. The building automation sector has gained the message authentication and encryption functionality of the ASHRAE Standard 135 that manages the BACnet protocol. However, the uniformity of these standards across regions is not achieved. The majority of these facilities are still focusing on operational availability and energy performance rather than cybersecurity and think that security enhancements are either costly or disruptive to the daily operations. In addition, the old HVAC cannot access the computing resource to operate the latest encryption or secure boot protection systems, something that has kept them under constant attack. This lack of connection between standardization and site of implementation is an indicator of a huge challenge to global cybersecurity governance in most smart buildings. METHODOLOGY 3.1 Research Design The qualitative research design is chosen in this study with the assistance of descriptive and exploratory aspects. The objective of the design will be to explore the cybersecurity vulnerabilities of the interconnected HVAC systems and understand how constructs of security, communications protocols, and stakeholder practices
Volume-09 Issue 11, November-2025 ISSN: 2456-9348 Impact Factor: 8.232 International Journal of Engineering Technology Research & Management (IJETRM) https://ijetrm.com/ IJETRM (http://ijetrm.com/) [182] influence system resilience. In order to perform this investigation, the qualitative method should be used because the issue of cybersecurity in the HVAC and Building Management Systems (BMS) currently is a complex of technical, human, and organizational elements that are not possible to adequately describe with the help of quantitative data alone. Thus, the research is oriented at developing the specific knowledge regarding how the vulnerabilities are formed, how the practitioners react to the risks, and what actions can be most constructive in terms of improving cybersecurity. The design is related to a multi-case study design, as the design is concerned with practical cases of smart buildings and facilities with connected HVAC systems. The case study methodology proves handy in the analysis of the phenomena in the natural environment, particularly in situations where the phenomenon and the environment have no apparent boundaries. Each case is treated as an entity of analysis, and a researcher is allowed to make comparisons on cybersecurity practices within different organizations and then discover commonalities or differences that are recurrent. The design also allows incorporating the primary qualitative data (interviews) with a secondary one (technical reports, policy documents, and academic studies), therefore making sure that the results of the research are contextually oriented and theoretically informed. 3.2 Population and Sampling The targeted group will be the professionals directly involved in the design, management, or security of smart HVAC systems and BMS infrastructure. Such players will be engineers in building automation, IT security specialists, facilities managers, and system integrators. The research is dedicated to the field of knowledge, so the participants are recruited on the basis of purposive sampling to find the people with the necessary knowledge and practice. This will be limited to a minimum of three years in the design of either HVAC or cybersecurity management within a building automation setting. The sample size of the study includes twelve respondents, which is appropriate to the requirements of the qualitative research that expects to achieve thematic saturation. Data saturation was confirmed after the twelfth interview when no new codes or themes emerged. The sample will be acquired from among the organizations that are working in North America and Europe because smart building technologies and cybersecurity structures are usually implemented in these areas. The fact that professional background and geographic context are diverse augments the validity and applicability of the study findings. To guarantee that the ethical conduct in the research is taken care of, the participants are voluntarily recruited and provided with elaborate consent forms, which will explain the purpose of the research, procedures, and the confidentiality that will be achieved. 3.3 Data Collection Methods The data collection is carried out using semi-structured interviews supported by a document analysis. Semistructured interviews have been chosen because they allow the researcher to guide the interview through a set of predetermined questions as well as give the participants an opportunity to elaborate on their experiences and views. This is essential flexibility in the provision of finer information on system vulnerabilities, security management, and organizational challenges. The interviews will last between 45 and 60 minutes, and they will be conducted either physically or via secure online conferencing systems based on the availability and location of participants. The interview protocol will include open-ended questions, which will be structured in a way that will motivate the participants to give detailed information about some aspects of HVAC cybersecurity. The participants will be asked to specify the network protocols that they use in their systems, what measures they take to prevent unauthorized access to the systems, and what problems or incidents they have had. The other questions are based on the organizational culture, the training of employees, and the compliance with the international standards of cybersecurity, such as NIST SP 800-82 and ISO/IEC 27001. All the interviews will be tape recorded with the permission of the interviewees and transcribed word-for-word to be analyzed. In addition to interviews, such secondary data sources as manufacturer technical documentation, cybersecurity audit reports, and regulatory guidelines are also analyzed in detail and supplement primary data. The different combinations of data sources foster the methodological triangulation, thereby increasing the validity and the richness of the results of the research. Data collection was carried out within a period of six weeks, between February and March 2025 in order to secure adequate time to schedule interviews, transcribe and review the documents.
Volume-09 Issue 11, November-2025 ISSN: 2456-9348 Impact Factor: 8.232 International Journal of Engineering Technology Research & Management (IJETRM) https://ijetrm.com/ IJETRM (http://ijetrm.com/) [183] Research Phase Key Activities Output/Outcome Research Design Defined research objectives and qualitative multi-case approach Conceptual framework established Participant Selection Purpose sampling of 12 professionals (HVAC engineers, and IT security specialists) Representative expert participants identified. Data Collection Semi-structured interviews and 8 document analyses (technical reports, policies) Raw qualitative data compiled Data Preparation Transcription, coding, and organization of data using NVivo 14 software Thematic database development Data Analysis Applied Bruan & Clarke’s sixphase thematic analysis model Key themes and patterns identified Discussion and Findings Compared emergent themes with theoretical frameworks (CIA Triad, CPS, DiD) Validated insights and literature connections. Recommendations Developed conceptual cybersecurity framework for connected HVAC systems. Formulation of practical framework and policy implications. Table 5: Table 8: Research Framework and Data Collection Process 3.4 Data Analysis The study employs the thematic analysis as the primary technique of data interpretation. The thematic analysis permits the systematic identification, organization, and interpretation of trends in qualitative data [5]. According to the six-phase model of research conducted by Braun and Clarke [5], the researcher begins with familiarization, i.e., by repeating the transcripts, and subsequently the process of coding, i.e., the recognition of meaningful parts of the text. These codes are then grouped together into themes that represent key concepts such as network protocol vulnerabilities, organizational security practices, and human factors in system breaches. All the themes undergo the process of polishing by comparing them across responses made by the participants and secondary information. The thematic analysis approach provides the deductive and inductive information. Inductively, it documents the lived experiences of the participants and arisen concerns related to HVAC cybersecurity. Deductively, it examines theoretical propositions derived from models such as the CIA Triad, Defense in Depth, and Cyber-Physical Systems models, which were discussed in Chapter Two. Data analysis This software is applicable in qualitative data analysis (NVivo 14): it facilitates data coding and effective retrieval of thematic contents. The researcher maintains analytic memos in order to record reflections, insights, and evolving conceptual relationships. 3.5 Reliability and Validity Qualitative research provides reliability and validity by using transparency, rigor, and triangulation as compared to numerical measurements. To make the research credible, the researcher employs triangulation through crossverification of the findings of interviews with individuals in the sources of secondary information, such as cybersecurity reports and policy documents. The member checking is also undertaken, which enables the participants to check and make sure that their transcribed statements and interpretations are correct. Rich and contextual descriptions of the transferability are made possible by enabling the reader to assess the transferability of the findings to other contexts. Additional reliability is achieved by maintaining an audit trail, which entails the process of data collection and analysis, but confirmability is achieved by means of reflexive journaling because the researchers continuously cogitate about the potential bias and assumptions throughout the whole study. 3.6 Ethical Considerations The research adheres to the ethical conduct of carrying out research that requires the participation of a human being. The institutional review board that is concerned issues the ethical approval before data are collected. The participants are made aware of the objective of the research, the voluntary nature of participation, and their right to leave willingly without any penalty. The information regarding the interviews was given to each participant in
Volume-09 Issue 11, November-2025 ISSN: 2456-9348 Impact Factor: 8.232 International Journal of Engineering Technology Research & Management (IJETRM) https://ijetrm.com/ IJETRM (http://ijetrm.com/) [184] written form before the interviews. To maintain confidentiality, it is ensured that the pseudonyms are employed rather than actual names and any organizational information is removed or generalized. All digital data, e.g., interview recordings and transcripts, are stored safely in the encrypted folders that can be accessed only by the researcher. Besides, the research tackles ethical aspects of the cybersecurity research, such that no confidential systems and sensitive security settings are disclosed or published. The study results have been offered in a manner that is informative of best practice without disrupting the privacy or working integrity of the participating organizations. Ethical devotion of the researcher determines the integrity of the research process. DISCUSSION AND FINDINGS The chapter outlines and explains the results of the qualitative data collected using the semi-structured interviews and document analysis. These results are contrasted with the theoretical and empirical literature analyzed in Chapter Two, which displays the similarities and dissimilarities between the observations of the participants and the available literature. The chapter narrows down on the big themes that were identified in the process of the thematic analysis, including (1) vulnerabilities of HVAC network protocols, (2) organizational cybersecurity, (3) human and institutional factors, and (4) mechanisms and technologies used to strengthen HVAC cybersecurity. All these conclusions lead to the overall comprehension of how integrated HVAC systems can be effective and safe in smart building systems. 4.1 Vulnerability in HVAC Network Protocol Among the main themes that come out in the interviews is the susceptibility of the communication protocols through which the smart HVAC systems operate at all times. The majority of the participants noted that BACnet/IP and Modbus TCP/IP are still prevalent in the building management industry, as they are easy to use and interoperable. Nevertheless, they also acknowledged that the same attributes make them insecure. Many engineers noted that, in most installations, BACnet traffic is not encrypted, and this makes it possible for hackers to intercept and compromise network commands in case they get access to the internal network of a building. Participants reported that although new implementations of BACnet Secure Connect (BACnet/SC) provide encryption, adoption still remains slow because of issues related to incompatibility with older devices and the high cost of upgrading the system. The other problem commonly reported is associated with poor network segmentation. To support remote monitoring, many organizations have their HVAC systems directly connected to the corporate IT network, inadvertently making the operational technology (OT) assets at risk because of the exposure to the internet [9]. Such configurations provide routes for cyberattacks to cross over from less secured HVAC networks into vital IT infrastructure. According to the participants, although a few organizations have started using virtual LANs (VLANs) and firewalls between the IT and OT domains, most smaller facilities do not have the technical knowledge to properly configure them. This non-segmentation contradicts with the principle of the defense in depth discussed earlier, leaving systems at increased risk of lateral movement after an attacker gets access. Vulnerability Type Description Observed Consequences Frequency (From Interviews) Unencrypted BACnet traffic Communication between devices not secured Command interception spoofing High Poor network segmentation HVAC directly connected to corporate network Potential crossnetwork attack High Weak or default passwords Factory credentials unchanged Unauthorized remote access Moderate Insecure remote access tools Weak VPN configuration or open ports External intrusion risk Moderate Table 5: Common Vulnerabilities Identified in HVAC Systems