News Feed

Cybersecurity – Johnson Controls

Data Centers
Our data center infrastructure helps to streamline operations with increased uptime to achieve critical business goals.
Your gateway to your sustainability and business goals
Digital solutions that improve energy efficiency, reduce carbon emission, optimize space use and equipment performance, and ensure health and wellbeing of occupants.
Applying data from both inside buildings and beyond, our customers can now manage operations systemically.
Achieve decarbonization and renewable energy targets and optimize building performance.
Drive productivity, health and wellness.
Indoor air quality is essential for the well-being, health, and productivity of the people inside every building, new and old.
Visionary leaders taking the smart leap in digital transformation.
Visionary leaders taking the smart leap in digital transformation.
Flexible services that scale to your building, operating style, and budget.
Flexible services that scale to your building, operating style, and budget.
Optimize the performance of your building with OpenBlue, a complete ecosystem of connected technologies, expertise and services.
Unlock the performance of your building and provide real-time data visibility across assets, people, and processes with OpenBlue Enterprise Manager.
Funding more than $6B in customer projects worldwide, we partner with you to determine the best way to make your project happen.
Funding more than $6B in customer projects worldwide, we partner with you to determine the best way to make your project happen.

Funding more than $6B in customer projects worldwide, we partner with you to determine the best way to make your project happen. 
Improve patient and staff satisfaction, sustainability, and your bottom line
Johnson Controls offers the world’s largest portfolio of building technology, software and services. Supported by a team of more than 100,000 dedicated employees working across 150 countries, we’re helping customers achieve their sustainability goals and power their mission.
You want to protect your smart building — and Johnson Controls is here to help you.
Facility managers today require their smart building solutions to be cyber-resilient. We have developed a full lifecycle approach and set of security practices that can help you protect your building from a range of potential cyber threats.
How do we do it? Our expert cybersecurity team designs, deploys, and services your building’s connected systems — aligned to your security program, creating a layered defense for information, products, and privacy that’s ready for rapid response as issues arise.
Johnson Controls is setting the industry standard with digital products and services designed for smart buildings. As a leader in this space we continually earn your trust by helping you achieve business outcomes while managing risk.
Johnson Controls takes a holistic, structured approach to help you protect systems and sensitive data from the risk of a cyber-attack. Powering impactful sustainability, safety and security, we deliver an enhanced customer experience. 


Products and Solutions >
As part of OpenBlue Secure, we tailor Cybersecurity to your precise needs — helping you protect your smart building’s systems and data from the threat of cyberattack.


Practices >
Our holistic, structured approach uses cyber-resilient products and services to maintain a robust security posture, information security, product security, and privacy for your smart building.


Response >
A strong offense is just as important as a strong defense. As we proactively monitor the dynamic threat landscape and address risks, we’re ready with rapid response to security incidents.


Resources >
We continuously enhance our products and security guidelines — and partner with you in managing cybersecurity risk by sharing valuable information and best practices.


Product Security Advisories >
We track, identify, and address cybersecurity threats on a daily basis. As part of our commitment to transparency we keep you informed of security concerns and important Johnson Controls product updates.


OpenBlue >
OpenBlue is a complete suite of connected solutions that serves industries from workplaces to schools, hospitals to campuses and more. Our cybersecurity solutions are designed to keep your spaces safe and secure.
Johnson Controls designs cybersecurity into our product and solution offerings and endeavors to protect those solutions (including software, hardware and hosted services) to protect your data and operations across the risk management lifecycle. Our secure product practices include the design, sourcing, development, deployment, servicing, support and retirement of products. All new Johnson Controls commercial products are developed under governance of our cybersecurity policies, standards and guidelines, which includes requirements for product testing and vulnerability management.

Johnson Controls proactively manages cybersecurity and privacy risks. We have dedicated organizations governing product security, information security, and data privacy. These organizations work together to deliver high-quality and consistent cybersecurity and data privacy support in a way that meets the unique mission and technology needs of each customer. Powering our customers’ mission is our top priority, and that means doing our part to protect our customers’ sensitive data and operations. Our rigorous secure product development lifecycle, agile DevSecOps practices, and approach to field operations cybersecurity strengthen our ability to meet that commitment. Additionally, our unified security and privacy controls framework is structured to ensure compliance with laws and regulatory requirements, globally.
It’s more than deep experience protecting smart buildings like yours — it’s continuous innovation as we protect their systems and data from new and evolving threats. That’s why we work in close collaboration with international government agencies, industry peers, and cybersecurity experts to keep our products and services at the leading edge of cyber resilience. We encourage you to learn more about our alliances and partnerships:

Johnson Controls is a founding member of the International Society of Automation’s Global Security Alliance (GCA).




Johnson Controls is a full member of the Forum of Incident Response and Security Teams (FIRST).
For everything from asking a question to raising an alarm, please use this form for a quick response from our Johnson Controls cybersecurity organization.
Report a potential vulnerability or cybersecurity concern | Ask about products and services | Learn about protecting your smart building
Cybersecurity testing may be conducted on Johnson Controls solutions. We recommend that tests are conducted in a non-production test environment to protect against disruption to operations.
A security test may produce field correctable findings if the steps outlined in the associated product Hardening Guide (Resources) are not followed.
Before conducting security tests, fully execute steps in the Hardening Guide (Resources). The following hardening steps, if not conducted, are known to result in addressable security findings:
If a test tool detects potential issues with a Johnson Controls component, you may share the results with Johnson Controls or report other cybersecurity concerns at this link – https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories#ReportAVulnerability, you may also contact us at productsecurity@jci.com.
Please use our downloadable PGP key to secure communications.
Download PGP Key
Please read our Privacy Notice for information on how we protect and manage your personal data. By completing this form and submitting your information, you confirm that you have reviewed, understood and accepted our privacy terms as well as our cookie terms.
Disclaimer: The cybersecurity information presented on this website is intended to be informational only and is provided on an “as is” basis. Johnson Controls makes no representation or warranty (express or implied) that compliance with any of these practices, or the taking of any the actions, identified herein will ensure the security of any product or system, or prevent any unauthorized access or damage caused by a cyber incident. Johnson Controls disclaims all liability for any damages that may occur despite compliance with any of these practices, or the taking of any the actions, identified herein.


This article was autogenerated from a news feed from CDO TIMES selected high quality news and research sources. There was no editorial review conducted beyond that by CDO TIMES staff. Need help with any of the topics in our articles? Schedule your free CDO TIMES Tech Navigator call today to stay ahead of the curve and gain insider advantages to propel your business!

Leave a Reply