Article
Event Recordings
20
min read
James Dice

How Building Owners Can Prioritize OT Cybersecurity Using Risk- and Consequence-Based Frameworks

December 14, 2025

At NexusCon 2025, Osman Saleem, Managing Director at Actimeta, walked through what OT cybersecurity actually looks like from the building owner’s seat—after the tools are bought, the network is “secured,” and the dashboards light up with thousands of vulnerabilities. Drawing on experience managing OT cyber programs for large portfolios, including critical infrastructure, Osman focused on why traditional vulnerability-driven approaches break down in real buildings.

The presentation zeroed in on the reality of mixed-age devices, forgotten workstations, service contractor access, and thinly staffed FM and OT teams spread across geographies. Rather than another vendor pitch, this was a candid look at what owners are really dealing with once the cyber journey gets messy.

Behind the paywall, Osman unpacks why “enumerating badness” doesn’t work for building portfolios and how owners can shift from panic-inducing dashboards to decisions that actually reduce risk. You’ll hear why probability-based cyber scoring often falls apart, how consequence-based thinking changes prioritization for mission-critical systems, and what governance, contracts, and capital projects have to do with cyber outcomes.

The recording also covers where owners consistently underestimate risk—like OS patching on BMS workstations—and why top-down compliance moves are often the only way to unlock budget for real remediation. This is essential viewing for any FM, EM, or OT leader trying to make progress on cybersecurity without pretending they can fix everything at once.

Watch the full recording inside Nexus Pro →

Sign Up for Access or Log In to Continue Viewing

Sign Up for Access or Log In to Continue Viewing

At NexusCon 2025, Osman Saleem, Managing Director at Actimeta, walked through what OT cybersecurity actually looks like from the building owner’s seat—after the tools are bought, the network is “secured,” and the dashboards light up with thousands of vulnerabilities. Drawing on experience managing OT cyber programs for large portfolios, including critical infrastructure, Osman focused on why traditional vulnerability-driven approaches break down in real buildings.

The presentation zeroed in on the reality of mixed-age devices, forgotten workstations, service contractor access, and thinly staffed FM and OT teams spread across geographies. Rather than another vendor pitch, this was a candid look at what owners are really dealing with once the cyber journey gets messy.

Behind the paywall, Osman unpacks why “enumerating badness” doesn’t work for building portfolios and how owners can shift from panic-inducing dashboards to decisions that actually reduce risk. You’ll hear why probability-based cyber scoring often falls apart, how consequence-based thinking changes prioritization for mission-critical systems, and what governance, contracts, and capital projects have to do with cyber outcomes.

The recording also covers where owners consistently underestimate risk—like OS patching on BMS workstations—and why top-down compliance moves are often the only way to unlock budget for real remediation. This is essential viewing for any FM, EM, or OT leader trying to make progress on cybersecurity without pretending they can fix everything at once.

Watch the full recording inside Nexus Pro →

⭐️ Pro Article

Sign Up for Access or Log In to View

⭐️ Pro Article

Sign Up for Access or Log In to View

Are you interested in joining us at NexusCon 2026? Register now so you don’t miss out!

Join Today

Are you a Nexus Pro member yet? Join now to get access to our community of 600+ members.

Join Today

Have you taken our Smart Building Strategist Course yet? Sign up to get access to our courses platform.

Enroll Now
Conversation
Comments (-)
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Guest
6 hours ago
Delete

This is a great piece!

REPLYCANCEL
or register to comment as a member
POST REPLY
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
Guest
6 hours ago
Delete

I agree.

REPLYCANCEL
or register to comment as a member
POST REPLY
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Get the renowned Nexus Newsletter

Access the Nexus Community

Head over to Nexus Connect and see what’s new in the community. Don’t forget to check out the latest member-only events.

Go to Nexus Connect

Upgrade to Nexus Pro

Join Nexus Pro and get full access including invite-only member gatherings, access to the community chatroom Nexus Connect, networking opportunities, and deep dive essays.

Sign Up