District technology leaders have spent years building out email security training, endpoint protection, and network monitoring aimed squarely at the threats IT departments know best: phishing, credential theft, ransomware delivered through familiar digital channels. A newer, quieter risk has been building alongside all of it, largely outside IT’s own field of view. CoSN, the Consortium for School Networking, has flagged it directly: cybercriminals can use building automation technology, HVAC controls, access systems, lighting and energy management platforms, as an entry point into a district’s broader network.
This matters because building systems are managed by facilities staff, not IT staff, and facilities has never been asked to think about network security as part of its job. That gap, between a role’s traditional responsibilities and its actual current risk exposure, is exactly where breaches happen.
Why Building Systems Became Real Attack Surface
Modern HVAC, access control, and lighting platforms are increasingly networked, often sharing infrastructure with instructional and administrative systems. Many were procured years ago, by facilities staff working directly with equipment vendors, with little or no IT security review, since nobody involved in that purchase was thinking about the system as a potential network entry point at the time. A remote-access feature that lets a vendor’s technician diagnose an HVAC issue without an on-site visit is a genuinely useful convenience. Left unsegmented and unmonitored, it is also a door into the district’s broader network that has nothing to do with email security training or password policy.
A Role Nobody Built for This
Facility managers report through operations, not IT, and their core responsibilities have never intersected with security planning. CoSN’s warning is really a coordination problem: facilities needs to be part of the security effort, working alongside IT rather than in a separate lane. That is a genuinely new expectation for a role that has never needed this kind of awareness, and districts closing the gap are having to build cross-departmental relationships that didn’t previously need to exist.
“The next serious breach of a school district’s network may not start with a phishing email at all. It may start with a thermostat.”
What Closing the Gap Actually Looks Like
The fix does not require centralizing every facilities purchasing decision under IT. It requires a simple, consistent checkpoint: any facility system connecting to the district network gets a baseline security review before deployment, and a recurring, even quarterly, conversation between IT and facilities about what is currently connected and who manages remote access to it. Districts making real progress here are building this as an ongoing process, not a one-time audit, since the category of network-connected building technology keeps expanding.
A Concrete Scenario Worth Walking Through
Consider a district’s HVAC vendor offering remote monitoring so a technician can diagnose a heating issue without visiting every building in person. This is genuinely useful and increasingly standard. If that remote access point is not segmented from the broader network and monitored the way any other remote access point would be, it becomes an entry point that traditional IT security training, built around email and endpoint behavior, was never designed to catch. A facility manager who knows what to ask a vendor about remote access encryption and monitoring closes a gap no amount of phishing-simulation training would ever touch.
This is precisely the kind of scenario CoSN’s warning points to, and it explains why facility managers specifically, not just IT staff generally, need security awareness built around the systems they actually manage day to day.
The Procurement Gap That Created This
Building automation systems have historically been procured through an entirely different process than instructional technology, generally handled directly by facilities staff working with equipment vendors, with minimal IT involvement in vetting network security implications. This procurement gap is exactly how so much building infrastructure ended up connected to district networks without the scrutiny IT applies to systems it actively manages. Closing it does not require eliminating facilities’ purchasing autonomy. It requires a simple, consistent checkpoint: any system that will connect to the district network gets a baseline security review before deployment, regardless of which department is doing the purchasing.
Why This Is Not a One-Time Fix
Districts that treat this as a single point-in-time security audit, run once and filed away, are likely to find the gap reopens as facility technology continues evolving. New building systems, increasingly AI-enabled monitoring and control platforms among them, keep arriving with new connectivity and new potential exposure. Districts making genuine, durable progress are building a recurring, structured conversation between IT and facilities, even something as simple as a quarterly review of what is currently network-connected and who manages remote access to each system, rather than a single assessment treated as a completed project.
Vendors selling security assessment, training, or facility management platforms into this space should recognize that districts need help building this ongoing coordination process, not just a one-time audit. A vendor offering sustained support for exactly this kind of recurring review, rather than a single engagement that leaves the district to maintain momentum alone, is addressing the durable version of this problem rather than a single symptom of it.
Why Facility Managers Deserve a Real Seat at the Table
This is not simply an IT problem being handed to facilities as extra work. Facility managers bring genuine, relevant expertise to this conversation, since they understand building systems, vendor relationships, and operational continuity requirements better than IT ever will. The districts getting this right are not asking facilities to become security experts overnight. They are building a genuine partnership where IT brings network security expertise and facilities brings deep operational knowledge of the systems actually at risk, each contributing what the other cannot.
Why Smaller Districts Face a Harder Version of This
Larger districts with dedicated security staff can absorb this coordination more easily. Smaller and rural districts, often running facilities with a single operations director wearing several roles, have neither the IT security depth nor the facilities bandwidth to build this out on their own. This is a real gap the vendor and consulting community serving K-12 technology has not yet fully addressed, and it deserves more attention than it currently gets.
A Broader Pattern Across Institutions Facing New Stakeholders
This same dynamic, a previously non-technical role suddenly becoming a genuine risk stakeholder, is showing up elsewhere too. Higher education is navigating its own version of a settled relationship suddenly disrupted, since federal accreditation rules are being rewritten, forcing institutions to evaluate accreditor alternatives for the first time in decades. Healthcare is facing a comparable wave of institutional disruption too, since physician practice bankruptcies just hit their highest level since 2019, and government technology buyers are managing a related coordination challenge, since new AI-specific procurement requirements are pulling legal, compliance, and finance staff into technology purchases that used to sit with a much smaller group.
Facility managers did not ask to become cybersecurity stakeholders. The increasing connectivity of building systems made it their responsibility whether districts have formally recognized it yet or not. The districts closing the coordination gap between facilities and IT now, before an actual incident forces the issue, are the ones most likely to avoid becoming the next unlikely headline about a breach nobody saw coming through a system nobody was watching.