In a Memoori Webinar in March, Laconicly’s Billy Rios spoke extensively on the topic of cyber security in the rapidly evolving smart building sector. Last week the cyber security firm released a white paper highlighting building automation systems (BAS) vulnerability to cyber attacks. On January 14th, 2015, Laconicly discovered a total of 64,003 IP addresses pointing to a device or system that supports a BAS deployment. Of the 64,003 IP addresses discovered, 41,308 IP addresses could be reached and were considered live on the Internet. 19,583 of the 41,308 (47%) devices that were accessible via the Internet offer one or more interfaces (excluding login pages and static content) that are accessible without any authentication. These exposures do not even require a username to be provided. 7,282 devices (25%) provided enough identifying information to associate the device with a specific industry or a specific organisation. Attackers infiltrating such systems could, potentially, gain access to control systems […]