
CASE STUDY
WarnerMedia pioneers end-to-end smart building cybersecurity at 30 Hudson Yards.
Overview
WarnerMedia’s new headquarters at 30 Hudson Yards was constructed over five years as part of the Hudson Yards development project in New York City. As new construction began, WarnerMedia had oversight over the building design to meet its needs as a global media company. This included making the new headquarters a smart building that delivers tenant comfort, efficient building operation, and remote management.
To provide these smart building capabilities, underlying building technologies and software are networked together throughout the building. Like informational technology (IT) networks, operational technology (OT) networks can be compromised by cyberattacks. With the perspective that its headquarters is a high-profile target for cyberattacks, WarnerMedia evaluated OT cybersecurity risks the same way they would evaluate IT cybersecurity risks. However, WarnerMedia found that the OT systems available on the market did not comply with its existing IT cybersecurity policies. Determined to realize the benefits of a smart building while simultaneously decreasing cybersecurity risk, WarnerMedia engaged the services of Intelligent Buildings, LLC (IB). Leveraging over ten years of experience in smart building cybersecurity, IB helped WarnerMedia achieve complete building technology compliance with its IT cybersecurity policies.
WarnerMedia expands the scope of its enterprise cybersecurity to building infrastructure
Bringing a utility mindset to commercial cybersecurity at WarnerMedia’s new headquarters
WarnerMedia began planning a new headquarters to consolidate seven locations in New York City. In 2014, the company announced that it would purchase a 1.1 million square-foot commercial condo at 30 Hudson Yards for its new headquarters (1). As part of the Hudson Yards Project—one of the largest private real estate projects in the country—the new construction at 30 Hudson Yards presented a rare opportunity in Manhattan for WarnerMedia to tailor the development of its new headquarters to meet its needs as a global media company.
WarnerMedia and its media divisions—CNN, HBO, Turner, and Warner Bros.—relied on servers, applications, IT, and building infrastructure to deliver its media services. However, WarnerMedia assessed building infrastructure decisions more like a utility company than a standard commercial business. Building infrastructure that fails or is compromised by cyberattacks could cause a service outage. Like utility facilities, WarnerMedia considered its headquarters to be a high-profile target for both internal and external cyberattacks, leading the company to pursue sophisticated and secure OT for its headquarters.
WarnerMedia’s bold initiative to completely secure its headquarters’ building technology
WarnerMedia identified several smart building capabilities to meet its business needs, including enabling efficient building operations, delivering a quality tenant experience, providing sophisticated backup sequences to support its mission-critical services if building technologies failed, and centralized remote access to view and manage building performance. While available smart building technologies could meet their performance requirements, they did not meet WarnerMedia’s cybersecurity standards. Unlike IT cybersecurity, there remains limited market availability of OT systems that have strong cybersecurity capabilities (2). With latent demand, market-wide OT security standards have not been established, presenting a monumental task for any existing or new building’s OT cybersecurity to meet its IT policies. WarnerMedia broke with these market trends and engaged IB to create a cybersecure smart building and bring all of their OT—including thousands of sensors—in line with their IT cybersecurity policies.
The underlying security challenges of building technology
OT’s and IT’s contrasting network design pathways
OT and IT have nearly opposing priorities, as their networking structures developed in the 1980s and 1990s. OT required that all building systems interact within milliseconds to provide a quality occupant experience, such as turning the lights on quickly when occupancy is sensed. This led to networks that prioritized information availability over information confidentiality. In contrast, IT developed prioritizing information confidentiality over availability, such as safeguarding credit card data throughout a network. As a result, OT’s incipient architecture left it inherently more vulnerable to security threats as its use cases expanded in the 2000s and 2010s (3).
Converging OT and IT networks reveal formidable security gaps
Traditionally, IT and OT operated independently of each other. However, as IT infrastructure became ubiquitous and demand for more sophisticated OT grew, OT networking systems drew on IT to deliver new features (4). New OT capabilities, like remote access and the proliferation of data from the network-connected Building Internet of Things (BIoT) devices, required IT networks to support building standards and other OT components. The two networks continue to evolve to perform similar tasks, setting OT and IT on a path toward convergence (5).
OT technologies developed these new capabilities in phases, layering new technologies on top of the original network design, which led to an OT architecture without a standard pathway for system-wide software management. For example, a security patch for a company’s servers may take only a few hours to install, but installing a similar security patch throughout an OT system may take several weeks due to bottlenecks that require coordination between the facilities and IT teams, integrators, and vendors.
These cybersecurity gaps between IT and OT are rippling across industries, as demonstrated by the top BIoT security concerns listed in a 2018 survey of organizations representing utility, government, technology, finance, education, and other sectors (6):
- Difficulty or lack of patching BIoT devices and systems, leaving them vulnerable
- Accidental exposures resulting from user or vendor error and system complexity
- Difficulty controlling, locating, tracking, preventing, and managing BIoT connectivity to critical infrastructure and other mission-critical systems
- Failure to incorporate good security practices into the BIoT design, build, and operation and maintenance lifecycle models for systems
- BIoT used as infection vectors to spread in the enterprise
- Management of vendor access and system behavior
Policy initiatives addressing the rising OT security risks
Both government and industry initiatives are working to develop BIoT and overall Internet of Things (IoT) security standards, though there remains no census on BIoT cybersecurity best practices. The National Institute of Standards and Technology (NIST) developed an initial framework in 2014 outlining methodologies to mitigate the risk of IoT cyberattacks and is working toward BIoT and building control systems cybersecurity standards (7).
Additionally, the Industrial Control Systems Computer Emergency Response Teams (ICS-CERT) centralizes known OT vulnerabilities identified by governments, system owners, operators, and vendors, and then releases multiple control system security advisories per year (8). These ICS-CERT advisories and the corresponding vendor patches can address known vulnerabilities in a system, but only if facility managers have visibility into all of the OT elements in a building and their current configurations. However, like BIoT cybersecurity as a whole, there is also no industry-wide standard to achieve network visibility.
WarnerMedia implements end-to-end OT cybersecurity to achieve a secure smart building
Bringing the OT cybersecurity at 30 Hudson Yards in line with IT standards
IB began its work by defining WarnerMedia’s OT cybersecurity objectives through collaboration with WarnerMedia’s Enterprise Infrastructure Services (EIS), which maintains the company’s Cybersecurity Policies. EIS provided fifty cybersecurity policy documents that IB reviewed to determine application strategies for building technologies that did not impact the functionality of the system and culminated a defined OT Cybersecurity Policy for WarnerMedia.
IB then reviewed the security capabilities of every BIoT device and identified any required security functions that a device could not perform. If a device was unable to meet a component of the Cybersecurity Policy when installed, the IB team worked with vendors to create compensating controls to meet the requirement. A compensating control is an alternative method to reduce the risk that a BIoT device poses to the network (e.g., by implementing physical isolation, network segregation, or continuous monitoring). Because most BIoT devices have different security controls, every compensating control needs to be designed for a specific device. The IB cybersecurity team leveraged their experience with BIoT devices and implementing building integrations to create compensating controls for every cybersecurity gap in thousands of BIoT devices at 30 Hudson Yards.
Securing the OT networks through segmentation and segregation was the next step of the process. This isolates the OT networks from other networks—such as the Internet—by creating restrictive gateways to OT domains that minimize the methods and level of access to OT networks. Securely implementing OT networks becomes complex at the enterprise level, because every implementation is unique to the building. For example, at 30 Hudson Yards, the OT and IT networks needed to share the infrastructure. After the IB cybersecurity team determined the OT network architecture required to meet WarnerMedia’s cybersecurity goals, EIS isolated the OT networks on the shared infrastructure by developing a series of virtual local area networks (VLANs) for each OT system.
Maintaining building technology cybersecurity compliance
Lastly, WarnerMedia needed a process for maintaining OT cybersecurity compliance as regular software updates are released or patches for newly identified vulnerabilities became available. This began with providing facility managers the existing security features of every BIoT device. As they reviewed BIoT devices and implemented any compensating controls, the IB cybersecurity team created and refined control profiles for every device. The control profiles include rules for how the device could securely interact with IT networks by security function, such as whether the device is capable of strong passwords. If the device is capable of the security function, the control profile lists the associated process for the device. If it is not capable, the compensating control is listed. The control profile also includes guidance for manufacturer default credentials, settings for auto lockout, and known vulnerabilities at the time of installation.
In addition to the control profiles, IB ensured complete visibility throughout the building control systems and BIoT devices with standard naming and tagging to enable facility managers to query devices easily.
Maintaining OT security requires the facilities management (FM) and IT teams to work together to align cybersecurity needs across the systems. Both teams’ BIoT cybersecurity work will be coordinated by updating the device control profiles with any changes. The EIS team will continue to work with BIoT vendors to update devices and systems to meet the cybersecurity requirements The FM team will monitor and evaluate ICS-CERT security advisories, as well as manufacturer security advisories and updates, for any impact on WarnerMedia’s OT using the device control profiles. If a security vulnerability is identified, WarnerMedia worked with IB to establish patch management protocols with device vendors to test and perform the security patches. The FM team will manage the end-of-life plans for OT devices by monitoring when a vendor announces the end of their support for a specific device, or if a device has no capable pathway to meet WarnerMedia’s cybersecurity policies.
Meeting OT cybersecurity concerns head on to demonstrate the potential of large-scale, cybersecure smart buildings
By taking OT cybersecurity risks seriously, WarnerMedia committed to bringing their BIoT devices in line with their IT cybersecurity policies. While the industry struggles with its concerns about BIoT cybersecurity risks, WarnerMedia worked with IB to overcome these concerns by implementing patch management protocols, creating control profiles detailing how to securely use devices, providing complete visibility into their building control systems and BIoT devices, and delivering end-to-end OT cybersecurity in line with their IT policies. This allowed WarnerMedia to confidently implement sophisticated smart building capabilities that provide business value, which may not have been viable otherwise.