Use Case

Cyber / OT Exposure Review

You cannot manage connected building risk if nobody knows what is connected.

This owner-side baseline helps IT, security, facilities, and vendors understand what connected building systems exist, where they live, which vendors manage them, and which unknowns require further technical review. It is not a penetration test, vulnerability scan, compliance certification, or security audit.

Connected asset visibility

Map the physical inventory behind cyber and OT questions.

This page helps IT, security, facilities, and vendors understand what connected building systems exist, where they live, which vendors manage them, and which unknowns require further technical review. It is not a penetration test, vulnerability scan, compliance certification, or security audit.

Exposure mapConnected Asset Exposure Map

Network-adjacent systems

  • Cameras / VMS
  • Access control panels
  • BAS / OT controllers and gateways
  • AV endpoints
  • Intercoms / visitor systems
  • Sensors / meters
  • Elevator / lobby interfaces
  • Vendor appliances

Physical context

  • MDF / IDF rooms
  • Racks and panels
  • PoE switches
  • Controllers / gateways
  • Workstations / servers
  • Closets and riser landings

Owner-review flags

  • Unknown vendor ownership
  • Unsupported equipment
  • Cloud / remote-access assumptions
  • Unmanaged or undocumented devices
  • Open segmentation or policy questions

Trust note: Do not submit passwords, alarm codes, credential keys, camera access, network secrets, or sensitive security procedures through public forms. Sensitive transfer methods should be confirmed separately through an owner-approved workflow.

Decision support

How the owner record changes this decision.

The same owner-record discipline is routed differently depending on what the trigger requires.

Before review

IT, security, and facilities can agree on what connected building systems are in scope.

During review

Unknown vendor ownership, unsupported devices, and gateway context become visible.

After handoff

Technical security work can start from a better owner-side asset baseline.

Before / after

A practical, fictionalized scenario.

This illustrates the decision pattern without implying a specific client result or guaranteed savings.

Before the owner record

Teams ask cyber/OT questions without a reliable map of connected building devices, vendor appliances, gateways, panels, and physical locations.

After the owner record

The owner has a connected asset baseline showing systems, vendors, physical context, lifecycle flags, and questions for deeper technical review.

Next step

Ready to scope this OT exposure baseline?

Start with the trigger, systems, floors, source records, access limits, and owner decisions. Globin Engineering can shape the field verification and deliverable package around the actual risk.