We see a lot as Commissioning Agents (CxA) that most of the folks in the industry don’t get exposed to if they are just working on the design side or just on the construction side. Every other month, one of our Commissioning Agents will dive into the inner world of systems commissioning through this series. We will shed light on some of the issues that occur between design and construction, and how CxA’s like us go about solving those issues to help the client get their systems operational.

Cybersecurity Commissioning as a Blind Spot

When clients plan large-scale capital projects, traditional systems like HVAC, lighting, electrical, and physical access controls tend to dominate the commissioning conversation. However, as building management systems (BMS) and operational technology (OT) networks become increasingly interconnected, a critical gap has emerged: Cybersecurity Commissioning.

Currently, our commissioning team is working alongside our internal cybersecurity practice on a major aviation project. In this environment, Faith Group’s ability to offer integrated cybersecurity commissioning, has  proven to be very beneficial for our client.

By bringing cybersecurity into our traditional commissioning scope, we have been able to round out our full-service capabilities. We are also able to provide an essential layer of checks and balances that protect our clients from day one.

How Our Commissioning and Cybersecurity Disciplines Work Hand-in-Hand

Many of you may wonder how both of our specialized teams are able to work cross-functionally within this project ecosystem. Part of what has made this seamless for us so far is having clearly defined roles internally from the get-go. Instead of overlapping or stepping on each other’s toes, our cybersecurity and commissioning teams operate with clear boundaries and constant communication.

The Cybersecurity Team: Our cyber specialists handle the more technical execution within this project, such as configuring security controls, hardening network architecture, and maintaining a focus on building a robust digital defense for our client.

The Commissioning Team: Our Commissioning Authority (CxA) steps in at designated milestones to test, verify, and validate that these security controls perform under real-world conditions. We keep our sights set on the client’s “big picture,” ensuring cybersecurity infrastructure integrates seamlessly into overall building operations. As CxA’s, we cannot just ask, “Is the software installed correctly?” We need to ask, “Does the system respond correctly when stressed?” and “Does it align with the owner’s operational requirements?” Uncovering every potential vulnerability early on is how we deliver maximum value and peace of mind to our clients.

To keep everyone on the same page, our teams host standing check-ins multiple times per week with our external cybersecurity implementation partner and the overall project team. We have also held live approval workshops directly with the client to come to agreeance on the process for validating systems. This close coordination allows our commissioning team to leverage the breadth of knowledge from our cyber subject-matter experts (SMEs) to develop an unbiased, objective supervision that clients rely on us to deliver.

What Does the Cybersecurity Testing Process Look Like in Practice?

Traditional commissioning tests physical valves, air flow, electrical breakers and physical systems. Cybersecurity commissioning tests networking perimeters, account vulnerabilities, and data flows.

Before a system can go live, our teams run it through extensive, real-world simulations:

  1. “Test Lab” Demonstrations Sandbox: Before deploying changes to live infrastructure, we build isolated “sandbox” environments. For example, we can generate a dummy profile (an account for “Bob Jones”) to simulate user access. Within this secure environment, we attempt different types of simulated breach scenarios (credential exploitation, unauthorized network access, two-factor authentication) to identify any vulnerabilities without risking actual airport operations.
  2. Connecting the Physical and Digital Dots: Securing a network requires knowing every endpoint. Our teams work collaboratively to verify device inventories, IP and MAC addresses, data imports, and even physical cabling infrastructure connecting hardware from source to destination.
  3. Phishing & Access Controls: We evaluate how resilient systems and personnel accounts are against social engineering, unverified links, and corrupt permissions attempts.
  4. Operational Readiness Review: Ensuring that the people are ready is one of the most critical real world validations necessary for success. Commissioning teams are used to seeing and attending training exercises as part of a wholistic commissioning process. In the cyber security environment, this takes on a whole new level of involvement from the project stakeholders. To be deemed operationally ready, end users must not only be trained, but should themselves go through extensive simulation and activation exercises designed to make them ready to not only operate these systems, but be readily aware of the threats they face on a regular basis. Simulation and activation scenarios prepare them to witness and identify these threats as well as gain a base level experience for dealing with them as they arise. The commissioning team works with the project stakeholders to identify and develop workshops, training scenarios, and trials for the end users to participate in that are designed to make the operationally ready to operate and man these systems.

Key Takeaways for Clients and Owners

Navigating complex systems, intricate testing schedules, and multi-vendor integrations can easily overwhelm project teams. Having a unified front handles both domain-specific cybersecurity and the overarching commissioning process needed to streamline delivery and guarantee nothing falls through the cracks.

While aviation facilities demand some of the highest security standards in the world, the need for cybersecurity commissioning spans far beyond airports. Any environment featuring specialized networks or mission critical operations, such as hospitals, healthcare clinics, data centers, operations centers, and smart buildings, can benefit from these services.

By acting as a technical bridge between network security and physical building operations, our commissioning team can certify facilities are both operational and secure on day one.


For more insights like this, check out our other “Cx As I See It” articles from Chris Fasano, Curtis Monette, and Anthony Grgas.

About the Author:

Christopher.Fasano@faithgroupllc.com

Christopher Fasano is a registered CxA with the ACG and Commissioning Manager at Faith Group LLC. He has more than 15 years of experience commissioning MEP/FP, Low Voltage, Safety and Security, Telecommunication, Audiovisual, and IT Network systems in Healthcare, Aviation and Transit, Commercial, Higher Education, Federal and Local Government, and Utility Infrastructure markets.