October 11, 2026

Human Factor in OT Cybersecurity: Why People Matter Most

Human Factor in OT Cybersecurity: Why People Matter Most

The Human Factor in OT Cybersecurity: The Role of People in OT Cyber Attacks

Imagine one password that opens the building automation system of every building a contractor services across a city. Not for a day. For months. It happened, and nobody involved meant any harm. It is one of the reasons we tell building owners the same thing in almost every assessment: the most important part of OT cybersecurity is not a product. It is people. This post looks at the human factor in OT cybersecurity: how attackers use people to reach OT systems, and what to do about it.

People, processes and technology, known as the PPT triad, is the lens most experts use when dealing with cybersecurity. When it comes to operational technology (OT), building owners and property managers need a security framework or policy for their OT systems. It can stand alone or extend the organization's wider security framework, as long as it covers topics specific to OT. Securing the technology is a task shared by the manufacturer and the integrator. The owner starts the process by specifying security controls in the contract and verifying them before the building transitions to steady state operation. Processes then define the standards and baselines everyone must follow. But the most important element of the triad is people.

Why the human factor is bigger in OT

The 2025 Verizon Data Breach Investigations Report found that the human element, meaning errors, social engineering and misuse, played a role in 60% of breaches. That data comes mostly from IT environments, but the pattern carries over to OT. Attackers use social engineering to exploit behavioural tendencies through phishing, baiting and credential theft. In OT the problem is worse. The systems were never designed with basic security controls, and the facility managers, operators and contractors who run them often lack IT training. That combination gives attackers easy pickings.

Think about what that means in a building. In an office, a careless click usually reaches email or files. In a building, the same careless moment can reach the controls for cooling, power or access.

Three cases of the human factor in OT cyber attacks

These come from our own assessments. We have removed the details that would identify anyone, because the lesson matters more than the name.

One password for a whole city

During a review of a group of buildings for a major property management firm, a facility manager told us how the technicians of a major BAS integrator used the same password for every BAS they serviced across an entire city, for months. Their reasoning was practical. The technicians moved between sites and did not want to remember a different password for each one. That is not laziness. It is a sensible answer to a badly designed process. The integrator has since fixed the practice, but for those months dozens of buildings with high-profile tenants sat one leaked password away from compromise.

A public IP address and a default password

Another firm suffered multiple attacks from foreign actors. In one case, the attackers logged in to the BAS and changed the parameters of the chiller plant. The system was reachable through a public IP address and protected by a simple default password. In a second case the entry point was the same but the outcome was worse. The attackers reached the main backup server and erased every backup of the BAS and security systems. Notice what was missing: no advanced exploit. Two ordinary decisions did most of the work. A changed parameter can be put back. A system with no backups has no way back.

Skills that did not move with the technology

Assessments also expose a mismatch between roles and skills. On one site, the lead building operator told us he preferred pneumatic controls and disliked modern OT interfaces. He admitted he had not owned a personal computer until the previous year. His building ran on IP-based direct digital controls (DDC). This is not a criticism of him. The building moved to IP-based controls, and nobody planned how the person running it would move too. We wrote about this gap in BAS personnel need IT expertise.

Why you cannot blame the individual

There are too many similar cases to list. The common thread is that people's behaviour and practices can be exploited. But you cannot hold these individuals fully responsible. In most cases they have never received cybersecurity awareness training, and their employer has no OT cybersecurity policy to guide them. Attackers will target your systems through your staff. Senior management owns the responsibility for developing the OT cybersecurity policy and training staff, and both management and staff own adherence to it.

The pattern is not new. In 2013, attackers broke into a large retailer's network using credentials stolen from one of its refrigeration and HVAC contractors, according to reporting by Krebs on Security. The people with the keys include the people who service your equipment.

The same applies to OT vendors and service providers. They need to build security into their products, train their technicians and educate customers on the security features of their systems and the practices that reduce risk.

What you can do now

  1. Train for the job. Deliver short, role-based OT cybersecurity awareness training for operators, technicians and facility managers, focused on passwords, remote access, phishing and reporting. A technician who services chillers needs different examples than a property manager. Make reporting easy, so people know who to tell and do not fear blame.
  2. Design for mistakes. Training will not stop every error. Set up the environment so one shared password or one careless click cannot reach the controls: individual accounts enforced by the system, remote access through a single controlled gateway, and no OT system reachable from the internet.
  3. Write it down. Develop an OT cybersecurity policy for staff and vendors, and a process that checks adherence. A policy nobody checks is just a document, so put the requirements in vendor contracts and verify them before handover.
  4. Match roles to skills. Where operators lack digital skills, invest in them or pair them with someone who has them.

Three questions to ask in your own building

You do not need a full assessment to start. Ask:

  • Does every technician who touches our systems have an individual account, or does anyone share a login?
  • Is any OT system reachable from the internet, even for "temporary" vendor access?
  • If an operator saw something strange tonight, would they know who to call?

If you cannot answer any of these with confidence, that is where to begin.

The technicians who shared one password across a city were not careless people. They were solving a real problem, too many sites and too many credentials, with the only tool they had. Give your people a secure way to do their job that is also the easy way, and most of them will take it.

Frequently asked questions

How do people cause OT cyber attacks?

Mostly through everyday habits, not advanced hacking: shared or default passwords, systems left reachable from the internet and phishing messages that get clicked. Attackers look for these because they are easy.

Why is the human factor harder in OT than in IT?

OT systems were never designed with basic security controls, and the people who run them, such as facility managers, operators and contractors, often have no IT training. One shared password or careless click can reach further.

What should OT cybersecurity awareness training cover?

Passwords, remote access, phishing and how to report something unusual, in short sessions built for each role.

Related reading

Actimeta is an OT cybersecurity company focused on smart buildings and critical infrastructure.

References

‍

Author:
Team Actimeta