runZero has introduced a new wave of capabilities that directly confront one of the most dangerous myths in industrial cybersecurity: the “segmentation illusion.” While many organizations still believe their operational technology (OT) and industrial control systems (ICS) are safely isolated, runZero’s latest release shows just how thin and fragile those perceived boundaries really are. By combining high-fidelity discovery with attack path mapping, defenders can now see, measure, and validate the real exposure of their IT, OT, and IoT environments.
For owners of smart buildings, factories, and critical infrastructure, this announcement is less about another security feature release and more about a strategic wake‑up call. The convergence of building automation, BACnet-based systems, and enterprise IT has made traditional assumptions about air‑gapping obsolete. The question is no longer whether your OT network is reachable, but how quickly an attacker can get from an exposed device to a PLC, BMS controller, or safety system—and what you’re going to do about it.
From Segmentation Illusion to Verified OT Isolation
The core problem runZero targets is the widespread belief that OT networks are safely segmented or even fully air‑gapped. The World Economic Forum notes that 64% of organizations are worried about critical infrastructure disruption and cyber‑espionage, yet real‑world assessments keep showing OT assets exposed to the internet or one hop away from it. In runZero’s analysis, roughly 30% of OT assets in sample manufacturing environments were only one hop from an internet‑exposed device, and 90% within two hops—numbers that completely undermine confidence in traditional segmentation strategies.
The situation is even more worrisome in highly regulated sectors like financial services, where runZero found that half of OT assets sat just one hop away from the internet edge. These environments often host building management systems, data center infrastructure, or critical facilities automation that organizations assume is isolated. A single misconfigured firewall rule, a forgotten remote access tunnel, or a multi‑homed maintenance laptop can silently bridge networks and create a direct path from IT to OT.
runZero’s new capabilities are built around the principle that segmentation must be verified, not declared. By mapping actual paths from exposed IT assets to PLCs and industrial gateways—including undocumented protocol bridges and legacy devices—security teams can finally validate whether their network design matches the reality on the ground. This is especially critical in smart buildings and campus environments where BACnet, Modbus, and other industrial protocols often cross logical boundaries in ways the original design never fully captured.
Safe, High-Fidelity OT Discovery Across Industrial Protocols
At the heart of this release is runZero’s active scan engine, which has been validated as safe even in fragile OT environments by both customer deployments and an assessment from the U.S. Department of Energy’s National Renewable Energy Laboratory. The evaluation concluded that runZero’s active scanning does not negatively impact system performance, directly challenging the entrenched belief that active scanning is inherently risky for ICS and building automation networks.
Unlike passive‑first tools that only see chatty or frequently communicating devices, runZero combines safe active scanning with passive monitoring to discover both managed and unmanaged assets, including those that cannot host agents or accept credentialed scans. This matters in real OT and smart building scenarios where controllers, field devices, and gateways often run minimal stacks and lack traditional endpoint management. The platform effectively becomes a single source of truth across OT, ICS, BMS, and IoT devices that typically remain dark to IT‑centric tools.
A key advancement in this release is deep visibility into OT sub‑assets behind industrial protocol gateways. runZero can now enumerate and map downstream devices behind Modbus, BACnet, EtherNet/IP, and KNXnet gateways—precisely the areas where building automation and industrial control systems tend to hide their riskiest assets. For security teams, this means field‑level controllers, zone devices, and even safety‑critical equipment that are not directly IP‑addressable become visible and classifiable. In practice, this bridges the gap between traditional ICS security and modern exposure management, giving defenders a complete OT attack surface picture instead of a partial, illusion‑based view.
Mapping the Unmappable: OT Attack Paths, Bridges, and Multi-Homed Devices
Discovery alone is no longer enough in converged IT/OT environments. The real risk lies in how an attacker can move from initial access to physical impact. runZero tackles this by introducing advanced topology mapping and interactive attack path visualization, enabling defenders to see how their networks actually interconnect rather than how diagrams say they should. The platform surfaces multi‑homed devices, misconfigured firewalls, and undocumented network bridges that quietly undermine segmentation policies.
With the new topology maps, security teams can move from a global, multi‑site overview down to individual subnets across hybrid Layer 2 and Layer 3 views. The maps visualize exposures in highly complex environments with hundreds of thousands of assets, supporting 2D and 3D perspectives. Geolocation features leverage public and egress IP data to place assets on the map, allowing teams to search for nearby devices and understand the physical context of each exposure—a critical capability when assessing a risk in a specific plant, campus, or data center.
The interactive attack path mapping allows defenders to set a specific source and target to see exactly how an attacker could traverse the network. Every pivot point, choke point, and bridge is highlighted, making it much easier to identify the handful of assets that, if compromised, would open access to high‑value OT zones. Devices that are connected to multiple networks are automatically surfaced as bridge points, while anomaly detection flags misplaced assets such as a Windows laptop in a production zone or an out‑of‑place IT system in a building automation VLAN. This turns abstract segmentation policies into concrete, testable paths that can be remediated or monitored.
Industrial Protocol Exposures and the Reality of Insecure-by-Design Systems
One of the most significant elements of runZero’s announcement is its focus on insecure‑by‑design industrial protocols that underpin modern smart buildings and ICS environments. The platform now supports more than 220 protocols, including Modbus, BACnet, EtherNet/IP, KNXnet, Siemens S7comm, and Triconex TriStation—many of which were never designed with encryption, authentication, or modern security in mind. These protocols remain highly attractive to attackers seeking to move from IT into physical operations.
runZero’s new capabilities detect where critical OT and building automation devices are reachable from the IT domain, surfacing protocol exposures that traditional IT security tools may ignore or misclassify. By enumerating OT assets across gateways and non‑IP boundaries, the platform identifies exactly which devices can be accessed through insecure protocols and how those paths are constructed. This is particularly acute in smart buildings, where BACnet and KNXnet are frequently used to control HVAC, lighting, access control, and other components of the building automation system.
Advanced fingerprinting and device classification further refine this picture by analyzing thousands of device attributes to categorize asset type, function, and risk profile. Rather than simply labeling a device as “BACnet controller,” runZero can identify its likely role—such as air‑handling unit controller, chiller interface, or room controller—giving both OT engineers and cyber teams a shared understanding of what is at stake. This level of fidelity helps prioritize which exposures truly matter to uptime, safety, and business continuity.
Risk Prioritization for ICS, Smart Buildings, and Critical Infrastructure
For organizations running complex building automation and ICS environments, the primary challenge is not discovering every device but deciding where to act first. runZero addresses this by integrating exposure visibility, segmentation gaps, and attack path intelligence into a coherent risk prioritization framework. Instead of treating every open port or misconfigured device equally, the platform highlights the specific exposures and connections that materially increase the likelihood of operational impact.
Risk‑based views help teams quickly isolate high‑risk pivot points, end‑of‑life systems, and assets that act as bridges between OT, BMS, and IT networks. In environments with hundreds of thousands of assets, this enables realistic remediation plans that align with maintenance windows, operational constraints, and safety requirements. ICS and facilities engineers can focus on a curated list of changes—such as hardening a protocol gateway, segmenting a BMS subnet, or decommissioning a legacy device—that deliver maximum reduction in attack paths with minimal disruption.
These capabilities also support compliance and governance initiatives, particularly where regulators expect demonstrable oversight of OT and critical infrastructure security. By providing verifiable evidence of segmentation, exposure management, and asset classification, runZero helps organizations show due diligence and continuous improvement, rather than relying on static diagrams and outdated asset inventories. This is critical for sectors like energy, manufacturing, financial services, and commercial real estate where cyber‑physical risk has direct regulatory and reputational implications.
Bridging Exposure Management with Smart Building Platforms Like BAaaS.io
While runZero delivers deep exposure management across IT and OT, many organizations also rely on specialized platforms to manage day‑to‑day operations in smart buildings and campuses. One example is BAaaS.io, a Building Automation as a Service platform that centralizes HVAC, lighting, security, and occupancy data into a single cloud ecosystem. Platforms like BAaaS.io provide real‑time telemetry, automated environmental adjustments, and advanced tenant experience features, but they also represent critical points of convergence between IT, OT, and cloud.
In practice, the combination of runZero and BAaaS.io can help organizations balance efficiency and security in their smart building portfolios. BAaaS.io streamlines operations, supports proactive maintenance, and optimizes energy use, while runZero continuously validates that the underlying networks and control systems are defensible. For example, runZero can identify a BACnet gateway that exposes a building’s chiller plant one hop away from the internet, while BAaaS.io provides the operational context—such as which tenant, zone, or facility is affected—so teams can coordinate remediation without compromising comfort or uptime.
For building owners, operators, and integrators, this pairing enables a more mature cyber‑physical strategy. Exposure management platforms like runZero ensure that segmentation is real and attack paths are minimized, while smart building platforms like BAaaS.io keep the building performant, energy‑efficient, and occupant‑friendly. Together, they address both sides of the equation: operational excellence and verified security.
Conclusion
runZero’s latest release is a significant moment for organizations that depend on OT systems, ICS networks, and smart building automation. By dismantling the segmentation illusion and revealing the true attack paths across IT and OT, the platform shifts defenders from assumption‑based security to validated, evidence‑driven infrastructure insights. High‑fidelity discovery, safe active scanning, protocol‑aware mapping, and interactive attack path visualization combine to give security and operations teams a shared, actionable view of cyber‑physical risk.
In an era where a misconfigured gateway or multi‑homed laptop can bridge the gap between the internet and a PLC, visibility and verification are no longer optional. Organizations that embrace tools like runZero—and complement them with intelligent building platforms such as BAaaS.io—will be better positioned to protect uptime, ensure safety, and sustain energy‑efficient, resilient operations. The segmentation illusion is over; from here on, only defensible architectures and continuously validated networks will keep smart buildings and industrial systems secure.