NRGKomm All articles
Communications Strategy

When Your Comms Stack Doesn't Know the Lights Are On: The Compliance Gap Nobody Is Talking About

NRGKomm
When Your Comms Stack Doesn't Know the Lights Are On: The Compliance Gap Nobody Is Talking About

Photo: Kiran891, CC BY-SA 4.0, via Wikimedia Commons

The Infrastructure Nobody Audits Together

Walk into the IT department of almost any mid-sized American enterprise and you will find two parallel worlds running side by side, rarely acknowledging each other's existence. On one side sits the unified communications platform — carefully provisioned, access-controlled, and covered by a detailed data governance policy. On the other side, a constellation of IoT energy sensors, smart HVAC controllers, demand-response terminals, and third-party facility management dashboards hum along under the facilities team's jurisdiction, feeding data outward through their own APIs, their own vendor portals, and sometimes, their own cloud accounts entirely.

This is what practitioners are beginning to call the "shadow energy stack" — and it is quietly becoming one of the most serious compliance blind spots in corporate infrastructure.

What Gets Lost in the Handoff

The problem is not that energy tools are inherently insecure. Many modern building management systems and smart metering platforms are built to reasonable standards. The issue is that they were never designed to operate within the same governance envelope as enterprise communications infrastructure. When a facility manager at a logistics company in Ohio installs a cloud-connected HVAC optimization platform to reduce cooling costs, they are almost certainly not looping in the CISO. The device authenticates, begins transmitting occupancy data, power draw metrics, and environmental readings to a vendor server — and none of that data flow appears in the company's communications audit trail.

Now consider what that data actually contains. Occupancy patterns reveal when buildings are staffed and when they are empty. Power draw spikes can be correlated with server activity. HVAC scheduling data, in aggregate, can expose shift patterns, physical security rhythms, and even the timing of sensitive business operations. For a threat actor who has already mapped a company's external footprint, this kind of operational data is extraordinarily useful context.

Three Real-World Scenarios Where the Gap Becomes a Liability

The Vendor Portal Problem. A regional healthcare network in the Southeast deployed a demand-response energy management platform to qualify for utility incentive programs. The platform was connected to the building's core communications network for bandwidth reasons, but its vendor portal credentials were managed entirely outside of the company's identity governance system. When a phishing campaign compromised a facilities coordinator's email account, attackers gained access to the energy portal — and from there, to floor-level occupancy data for three clinical facilities. The network's unified comms platform flagged nothing because, from its perspective, nothing had happened.

The Regulatory Audit Failure. Under the SEC's updated cybersecurity disclosure rules, publicly traded companies are required to disclose material cybersecurity incidents and, increasingly, to demonstrate that their risk management programs cover all systems that could affect operations. A technology firm in Texas discovered during a pre-audit review that its energy monitoring infrastructure — covering two data centers and a corporate campus — had never been formally mapped as part of its information asset inventory. The systems were transmitting data continuously to three separate vendor clouds. None of those data flows had been reviewed under the company's data processing agreements or privacy policies.

The HVAC-as-Attack-Vector Scenario. This one is not hypothetical. The 2013 Target breach, one of the most studied retail cybersecurity failures in American history, originated through an HVAC contractor's network credentials. A decade later, the lesson has still not been fully internalized. Facility management systems connected to corporate networks without proper segmentation remain one of the most reliable entry points for lateral movement attacks — precisely because they fall outside the scope of standard communications security reviews.

Why Unified Comms Platforms Are Partially to Blame

It would be convenient to blame facilities teams entirely, but the architecture of most unified communications platforms makes integration genuinely difficult. Enterprise platforms like Microsoft Teams, Cisco Webex, and Zoom Phone are built around human communication workflows. Their API ecosystems are rich but oriented toward productivity tools, CRM integrations, and collaboration add-ons. Connecting an energy monitoring platform — which speaks entirely different protocols, operates on different data cadences, and serves entirely different business functions — requires custom middleware, dedicated development resources, and ongoing maintenance that most IT teams are not staffed to support.

The result is a predictable organizational pattern: the communications team governs communications infrastructure, the facilities team governs energy infrastructure, and nobody governs the space between them.

Closing the Gap: A Practical Framework

Addressing this problem does not require replacing either system. It requires building a governance bridge between them. Organizations that have successfully reduced their exposure typically start with three steps.

First, they conduct a cross-functional data flow mapping exercise that explicitly includes all energy monitoring, building management, and facility automation systems alongside traditional IT and communications assets. This exercise should produce a unified inventory of every system transmitting data outside the corporate perimeter — regardless of which department owns it.

Second, they apply identity governance standards consistently across both stacks. Every vendor portal, every cloud-connected device, and every API key associated with energy systems should be subject to the same credential lifecycle management, multi-factor authentication requirements, and access review processes that govern communications platforms.

Third, they establish a shared incident response scope. When the CISO's team runs a tabletop exercise, the scenario should include facility system compromise. When the facilities team evaluates a new energy management vendor, the procurement checklist should include security questionnaire requirements equivalent to those applied to communications software vendors.

The Regulatory Horizon Is Narrowing

Federal regulators are beginning to catch up. The Cybersecurity and Infrastructure Security Agency has expanded its guidance on operational technology security to explicitly include building management systems and smart energy devices. State-level privacy regulators in California, Colorado, and Virginia are increasingly scrutinizing data flows from connected devices that touch commercial facilities. For companies operating in regulated industries — healthcare, finance, energy utilities — the timeline for voluntary compliance is shortening.

The organizations that will navigate this environment most effectively are those that stop treating communications infrastructure and energy infrastructure as separate problems. They are, increasingly, the same problem — and the gap between them is where the real risk lives.

All Articles

Related Articles

Five Platforms, Zero Coherence: The Real Price Your Business Pays for Communication Fragmentation

Five Platforms, Zero Coherence: The Real Price Your Business Pays for Communication Fragmentation

The Millisecond Tax: How Messaging Lag in Data Center Operations Drains Energy and Erodes the Bottom Line

The Millisecond Tax: How Messaging Lag in Data Center Operations Drains Energy and Erodes the Bottom Line

Distributed Workforces Are Quietly Inflating Your Energy Bill — Here's the Audit That Fixes It

Distributed Workforces Are Quietly Inflating Your Energy Bill — Here's the Audit That Fixes It