Cybersecurity commissioning: Why cybersecurity starts at construction
> OT | SITE ASSESSMENT & MORE > Cybersecurity commissioning starts at construction
Where Cybersecurity Gaps Emerge
Critical infrastructure is becoming more digital at every layer. Industrial control systems, building automation, physical security, power management, remote access, cloud platforms, and enterprise networks increasingly intersect within the same operating environment. NIST’s definition of operational technology (OT) reflects this breadth, spanning industrial control systems as well as building automation, transportation systems, physical access control, and other technologies that interact with the physical world.
That convergence is changing how infrastructure must be delivered. Secure-by-design principles are gaining traction, while standards such as IEC 62443 increasingly frame industrial cybersecurity as a lifecycle discipline rather than something added at the end.
But there is still a gap between designing a secure asset and placing a secure asset into service.
That gap is cybersecurity commissioning.
Commissioning is where design intent becomes operational reality. Systems are integrated. Vendors connect. Configurations change. Exceptions are introduced. Project teams are simultaneously working under some of the greatest schedule pressure of the entire project led by construction firms.
It is also the final opportunity to prove that cybersecurity controls are working before the asset enters live operations.
The digital infrastructure paradox
Infrastructure is being designed with more cybersecurity consideration than in the past. CISA’s Secure by Design initiative encourages security to be treated as a core requirement rather than an optional feature, while the IEC 62443 series addresses cybersecurity across the lifecycle of industrial automation and control systems.
Yet secure design does not automatically produce a secure operating environment.
Between design and handover, projects change. Equipment is substituted, vendors require temporary access, network routes are altered, and integration issues appear. Controls that looked clear in a specification have to work across real devices and real operational constraints.
This creates a critical disconnect: organizations can invest heavily in secure-by-design principles while giving comparatively little attention to validating the security of what was actually built and configured.
The result can be a gap between the intended security posture and the actual security posture at go-live. The result is a gap between the security posture envisioned during design and the security posture that actually exists at go-live.
Commissioning: The last window before Go-Live
Commissioning is already one of the most demanding phases of a capital project. Owners want the asset placed into service. Engineering teams are closing punch lists. Contractors are preparing to demobilize. Operators are being trained. Vendors are troubleshooting integration issues. Every delay can affect cost, schedule, and contractual commitments.
Cybersecurity competes with all of those priorities.
That matters because security validation takes time. Access needs to be reviewed. Network paths need to be tested. Configurations need to be checked against the approved design. Monitoring has to be confirmed. Recovery procedures need to be proven. Exceptions need owners and expiration dates.
When these activities are deferred until after handover, the organization is no longer validating a project environment. It is changing a live operational environment.
Cybersecurity commissioning should therefore be understood as a structured assurance process before acceptance: validating that cybersecurity requirements have been implemented, controls work as intended, temporary project access has been removed or formally approved, and the operating team receives a known and documented security baseline.
It is the difference between assuming the asset is secure and demonstrating that it is ready to operate securely.
When temporary measures become permanent risks
Construction and commissioning naturally create temporary conditions. The problem is not that temporary measures exist. The problem is when they survive handover.
A vendor account may be created to resolve an integration issue. A firewall rule may be opened to support testing. Shared credentials may be used because several technicians need access. Logging may be disabled while a system is tuned. A patch may be deferred because nobody wants to destabilize an asset days before go-live. Network segmentation may be bypassed to keep commissioning moving.
Each decision may make sense in isolation. Together, they can create cybersecurity debt.
This is more than a theoretical concern. Current CISA guidance for critical infrastructure continues to emphasize risks including internet-exposed OT, default or weak credentials, insecure remote access, and misconfiguration. In joint guidance published in 2025, CISA and partner agencies also noted that misconfigurations may be introduced by system integrators, managed service providers, or product manufacturers—not only by operators after handover.
Commissioning is therefore a particularly important control point. Many organizations have legitimate access to the environment, configurations are still changing, and project urgency can override the discipline normally expected once an asset is operational.
A strong handover process should be able to answer a simple question:
Which temporary conditions remain, who has accepted the associated risk, and when is each condition scheduled to be removed?
If nobody can answer that confidently, the asset is not fully ready.
Functionality does not equal security
Traditional commissioning asks whether systems perform as designed. Does equipment start and stop correctly? Do control sequences work? Are performance and availability targets met? Do alarms activate? Can systems fail over?
Those questions remain essential. But they do not tell an owner whether the system is secure.
A building management system can control cooling correctly while using shared administrative credentials. A SCADA environment can maintain process availability while remote access is too broadly exposed. A baggage handling system can perform flawlessly while security logging is incomplete. An industrial control network can pass functional testing even though segmentation does not match the approved architecture.
Cybersecurity commissioning therefore has to test a different set of conditions: identity and access control, remote access, network segmentation, logging and monitoring, backup and recovery, system hardening, configuration baselines, vulnerability handling, and ownership of outstanding exceptions.
NIST emphasizes that OT cybersecurity must account for the particular safety, reliability, and performance requirements of operational environments. CISA’s current Cross-Sector Cybersecurity Performance Goals similarly address controls including credentials and privilege, segmentation, backups, logging, vulnerability mitigation, and organizational oversight.
The implication for project delivery is straightforward:
A system should not pass into operations simply because it functions. It should pass because its operational and cybersecurity requirements have both been validated.
Why this matters across critical infrastructure
In data centers, building management systems, electrical power monitoring, cooling controls, physical access systems, and other mission-critical infrastructure operate alongside highly connected digital environments. Data center cybersecurity therefore extends beyond the servers and network equipment housed inside the facility.
In energy and utilities, increasingly connected generation, transmission, distribution, and distributed energy systems create more digital dependencies to understand before go-live. Water and wastewater operators depend on SCADA and control systems managing physical processes with direct service and safety consequences.
Manufacturers are connecting industrial automation, robotics, remote support, and production data platforms. Airports integrate baggage, lighting, access control, building systems, and ground operations. Ports combine cargo management with automated handling and vessel traffic technologies.
The same principle applies across oil and gas, mining, and telecommunications. The technologies and consequences differ, but every sector faces a version of the same question at handover:
Do we know exactly what has been connected, how it is configured, who can access it, how it is monitored, and how it can be recovered?
NIST’s broad treatment of OT—from industrial control to building automation and transportation systems—reinforces why this is a cross-sector challenge rather than an issue confined to traditional industrial facilities.
Cybersecurity commissioning creates a formal point at which those questions must be answered before the project becomes an operating asset.
The cost of finding problems after Go-Live
The most expensive security issue is not always the most technically complex one. Often, it is the issue discovered at the wrong time.
Before go-live, a firewall rule can be corrected as part of project closeout. After go-live, that same change may require a maintenance window, operational approvals, vendor coordination, regression testing, and contingency planning.
A weak account structure that could have been redesigned during commissioning may become embedded within operating procedures. A segmentation issue can become substantially harder to correct once production, safety, customer, or availability commitments depend on the existing architecture.
Live changes can introduce downtime, production risk, safety considerations, contractual issues, and reputational exposure. In critical infrastructure, even a relatively simple configuration change can become a business decision once the asset is operational.
The economic argument for cybersecurity commissioning is therefore largely an argument about timing.
The closer a problem is identified to the point at which it was introduced, the more options the project team has to address it before operational constraints take over. This mirrors a familiar principle in construction and quality assurance: issues that are manageable during project delivery become considerably more disruptive once they interfere with commissioning or operational startup.
A shift in industry thinking
Cybersecurity is increasingly moving from a specialist activity performed around the project to an assurance discipline embedded within it.
The shift is visible in current guidance. CISA’s Cross-Sector Cybersecurity Performance Goals 2.0 place greater emphasis on governance, oversight, third-party risk, least privilege, configuration-related controls, logging, and resilience. IEC 62443 addresses industrial cybersecurity across organizational, system, service-provider, and product lifecycles rather than as a single technical test.
For project delivery, that means establishing clear cybersecurity acceptance criteria, assigning accountability, involving qualified OT cybersecurity professionals at the right project gates, and treating unresolved security findings with the same discipline applied to other commissioning deficiencies.
A cybersecurity commissioning gate might ask:
- Have temporary and default accounts been removed, disabled, or formally accepted?
- Is remote access limited, secured, documented, and owned?
- Does implemented network segmentation match the approved architecture?
- Are logging and monitoring functioning before handover?
- Have backup and recovery procedures been tested in an operationally safe way?
- Is there an approved configuration baseline for the operations team?
- Are outstanding cyber risks visible in the final punch list, with owners and due dates?
The value comes from asking these questions before the project team disperses and the asset becomes difficult to change.
Cybersecurity starts at construction
Cybersecurity cannot begin when operations inherits the asset. By then, many of the decisions shaping long-term exposure have already been made.
It starts when cybersecurity requirements enter planning and design. It continues through procurement and construction. And commissioning is where those requirements must finally be proven against the asset that was actually built.
For Bureau Veritas, this thinking fits naturally within a broader lifecycle assurance model. Bureau Veritas already operates across design review, Owner’s Engineering, construction supervision, QA/QC, commissioning, and asset handover in buildings, infrastructure, power, and mission-critical environments. Our data center activities, for example, already include commissioning, QA/QC, and operational risk management.
Bringing cybersecurity assurance into the same project milestones creates an opportunity to connect digital risk with the engineering and operational realities of the asset.
The objective is not more testing for its own sake. It is a more complete definition of readiness.
Operational readiness means the asset performs as intended.
Cybersecurity readiness means the controls, access, configurations, monitoring, recovery arrangements, and governance needed to operate securely have been validated.
Together, they create infrastructure resilience.
As critical infrastructure becomes more connected, commissioning that ignores cybersecurity leaves a critical question unanswered at the moment it matters most:
Is this asset truly ready to operate?
The industry standard should evolve so that the answer is no longer assumed.
Planning a new build, expansion, or major modernization? Talk with Bureau Veritas about what cybersecurity readiness should look like at handover, and how security assurance can be integrated into existing construction and commissioning milestones.
More information
Discover how cyber experts like Jagannathan Raghunathan, director of Cyber Physical Security Services and author of this blog can help you get started with your cybersecurity commissioning journey. Fill out the form and we'll aim to get back to you within 1 working day.
Why choose Bureau Veritas Cybersecurity
Bureau Veritas Cybersecurity is your expert partner in cybersecurity. We help organizations identify risks, strengthen defenses and comply with cybersecurity standards and regulations. Our services cover people, processes and technology, ranging from awareness training and social engineering to security advice, compliance and penetration testing.
We operate across IT, OT and IoT environments, supporting both digital systems and connected products. With over 300 cybersecurity professionals worldwide, we combine deep technical expertise with a global presence. Bureau Veritas Cybersecurity is part of the Bureau Veritas Group, a global leader in testing, inspection and certification.