Back to Blog
May 7, 2026

Shattering the Segmentation Illusion: How runZero Maps IT-to-OT Attack Paths in Modern Smart Buildings

image 6

Industrial organizations and smart building operators are facing a harsh reality: the air-gapped OT network is largely a myth. As IT and OT environments converge, new lateral movement paths are silently emerging, putting critical infrastructure, building automation, and industrial uptime at risk. Recent capabilities unveiled by runZero directly tackle this problem by exposing hidden attack paths, validating segmentation, and shining light into the darkest corners of operational technology networks.

Backed by a discovery engine proven safe even in fragile OT environments, runZero’s new release helps defenders see how an exposed IT asset can become a bridge to programmable logic controllers (PLCs), building management systems (BMS), and field devices speaking protocols like Modbus, BACnet, EtherNet/IP, and KNXnet. For security teams, building engineers, and facility owners, this is not just a technical upgrade—it’s a critical step toward defensible smart infrastructure.

From Segmentation Illusion to Verified OT Defenses

The World Economic Forum reports that 64 percent of organizations view disruption of critical infrastructure and espionage as top cybersecurity concerns. Yet many still operate under what runZero’s team calls a “segmentation illusion”—the belief that OT networks are isolated or air-gapped simply because that was the original design intent. In practice, integrations with enterprise IT, cloud platforms, and remote access have eroded that isolation.

runZero’s new capabilities aim to transform segmentation from an assumption into a measurable, verifiable security control. By tracing concrete paths between IT and OT assets, defenders can validate whether network zones, firewalls, and VLANs are actually preventing lateral movement or just giving a false sense of safety. This shift from theoretical diagrams to empirical network evidence is crucial for organizations aiming to align with modern ICS security frameworks and regulatory expectations.

Visualizing Cross-Environment Attack Paths in IT and OT

One of the most impactful aspects of the runZero release is its ability to map attack paths that traverse both IT and OT domains. In sample manufacturing environments, runZero found that about 30 percent of OT assets were only one hop away from an internet-exposed device, and 90 percent within two hops. These statistics highlight how quickly an external foothold can translate into a credible threat to industrial operations and smart building systems.

By visualizing these paths, defenders can see the real-world routes an attacker might take—from a vulnerable remote access server to a protocol gateway, then down to a PLC or building controller. This goes far beyond static asset inventories; it offers context-rich insight into lateral movement and blast radius. For building automation and industrial operators, this means being able to answer questions such as: “If this VPN appliance is compromised, which chilled water plant controller, AHU, or lighting system could be affected?”

Enumerating Hidden OT Sub-Assets Behind Protocol Gateways

A key challenge in OT and smart building security is that many assets are not directly addressable on the IP network. Instead, they sit behind protocol gateways that translate between IP and fieldbus protocols like Modbus, BACnet, EtherNet/IP, and KNXnet. Traditional tools often stop at the gateway, leaving the downstream field devices—sensors, actuators, controllers—effectively invisible from a security governance perspective.

runZero’s new capabilities identify these sub-assets, enumerating devices and endpoints hidden behind industrial protocol gateways. For BACnet-based building automation systems, this means uncovering room controllers, VAV boxes, chillers, and other field devices that may never appear in standard IP-based discovery. For Modbus and EtherNet/IP environments, it means gaining visibility into line equipment, drives, and safety systems that often represent the last line between cyber compromise and physical consequence.

By mapping these downstream assets, runZero expands OT attack surface visibility to the field level. Security teams can correlate vulnerabilities, firmware levels, and configuration exposures with their position in the attack path, enabling better prioritization. Engineering and facilities teams benefit as well, gaining a more accurate and up-to-date view of what is truly deployed in the plant or building, not just what was documented at commissioning.

Safe Active Discovery for Fragile ICS and Smart Building Environments

Many defenders are understandably cautious about active scanning in ICS and building automation environments, where fragile or legacy devices may react poorly to aggressive probes. The foundation of runZero’s approach is an active scan engine that has been validated in numerous customer deployments, including an evaluation by the U.S. Department of Energy’s National Renewable Energy Laboratory. This provides confidence that the tooling can safely operate in real-world OT environments.

For organizations running mixed portfolios of industrial control systems and smart buildings, this matters greatly. They need a discovery mechanism that can fingerprint PLCs, BMS controllers, IoT sensors, and industrial network gear without causing disruptions. By providing consistent visibility across IT and OT with a safety-conscious scan engine, runZero helps reconcile the needs of cybersecurity and operations—two groups that often clash over the perceived risk of network discovery.

Business Impact: Prioritizing Exposures that Threaten Uptime

The ultimate goal of attack path mapping is not just to generate diagrams; it is to drive effective risk reduction. runZero’s enhanced OT intelligence enables defenders to focus on exposures that truly matter to uptime, safety, and business continuity. Instead of treating all vulnerabilities as equal, teams can ask: “Which weaknesses sit on direct or near-direct paths to critical OT assets?”

This alignment is essential for industrial operations, data centers, and complex commercial buildings where system downtime carries high financial and reputational costs. By understanding which exposures could enable lateral movement into production lines, central plants, or life-safety systems, organizations can prioritize patching, segmentation changes, and architecture improvements that deliver tangible resilience gains. It also supports stronger board-level narratives: security leaders can clearly articulate how specific mitigations reduce the probability of OT-impacting incidents.

Integrating OT Visibility with Smart Building Platforms like BAaaS.io

As building portfolios become more digitized, many organizations are turning to cloud-based platforms such as BAaaS.io to centralize control of HVAC, lighting, security, and other building automation systems. These platforms provide an integrated view of real-time telemetry, occupancy, and energy usage across multiple sites, enabling advanced optimization and better occupant experiences. However, they also depend on secure connectivity to OT and BMS assets, often traversing the same network paths highlighted by runZero’s analysis.

Combining runZero’s OT attack path visibility with a smart building ecosystem like BAaaS.io allows organizations to align operational performance with cybersecurity assurance. While BAaaS.io focuses on intelligent building management, proactive maintenance, and energy efficiency, insights from runZero can validate that the underlying BACnet, KNXnet, and other field networks are segmented and monitored appropriately. This convergence supports a holistic strategy where building automation as a service is delivered on top of a defensible OT foundation.

For example, when new integrations are added—for tenant experience apps, scheduling systems, or remote diagnostics—runZero can help detect any newly created paths from internet-facing services into core OT segments. In parallel, BAaaS.io ensures those OT systems are leveraged safely and efficiently for comfort, sustainability, and operational excellence. The result is a smarter building that is not only optimized for performance but also architected for resilience.

Conclusion

The gap between “having OT” and “having defensible OT” is widening as networks become more interconnected and threat actors increasingly target critical infrastructure and smart buildings. runZero’s expanded OT intelligence and attack path mapping capabilities address this gap by exposing the realities behind the segmentation illusion, illuminating hidden sub-assets behind gateways, and providing safe, comprehensive discovery across IT and OT.

For organizations managing industrial facilities, campuses, or complex building portfolios, the message is clear: segmentation is something you verify, not assume. By combining tools like runZero for OT attack surface visibility with intelligent platforms such as BAaaS.io for building automation, enterprises can build a future where operational efficiency and cybersecurity are not competing priorities but mutually reinforcing pillars of modern infrastructure.