Phoenix Journal · Ductwork
The controls that run your extraction, gas interlock and ventilation now sit on a network - and that changes what it means to keep a kitchen safe. Here is the cyber side of building management systems, in plain terms.
Field notes
It is half past nine on a Friday, the pass is still full, and the extraction canopy is pulling hard over six burners - until, without warning, the fans drop to a whisper.
Nobody touched a switch. The gas is still flowing, the woks are still roaring, and within minutes the air above the line turns thick and blue. A chef jabs at the wall panel and gets nothing. Somewhere in a plant room upstairs, a small grey box that most people have never noticed has decided the kitchen needs less air, and it will not be argued with.
That box is part of the building management system, or BMS - the quiet network of controllers, sensors and software that runs your ventilation, your heating, your gas interlock and often your lighting and access doors too. When it works, you forget it exists. When it is confused, misconfigured or interfered with, it can throttle the one system a commercial kitchen cannot do without: the extraction that keeps grease, heat and combustion products moving out of the room. The uncomfortable truth is that these systems are now sitting on networks, and networks can be reached. This is the cyber side of a job that has always felt purely mechanical, and it is worth understanding before it understands you.
A modern commercial kitchen is far more connected than the stainless steel suggests. Demand-controlled ventilation adjusts fan speed in real time, reading canopy temperature and carbon dioxide so the system eases off when you are prepping and ramps up when the service kicks in - a genuinely useful feature that can cut ventilation energy by a large margin. Gas interlock panels, working to the principles in BS 6173, will only let gas flow while proven airflow is present. Increasingly, all of this reports back to, and takes instruction from, a central BMS that also runs the rest of the building. That integration is the point. It is also the exposure.
The parts of your extraction system that live on the network are easy to overlook because they are meant to be invisible. But each one is a small computer, and each one makes decisions that affect safety and hygiene in the room below.
None of these were designed to be watched by an operator around the clock. They are designed to be trusted. That trust is exactly what a cyber incident, or even a clumsy misconfiguration during a software update, can turn against you.
Much of the building controls world still speaks languages that predate the modern internet. BACnet, Modbus and LonWorks were written decades ago for reliability, not security - they generally carry no encryption and little or no authentication, so a device that can reach them can often read and change their values. That was tolerable when these systems lived on isolated wiring in a locked plant room. It is a real problem now that BMS networks touch corporate IT, remote-support tools and, in too many cases, the public internet.
The scale is not hypothetical. Claroty's Team82 researchers, in their State of CPS Security 2025 work, looked at more than 467,000 BMS devices across 529 organisations and found that around three quarters of those organisations had devices carrying known, actively exploited vulnerabilities, with a large share of those flaws having been used in ransomware attacks. Building systems have quietly become one of the softest targets in many buildings - unpatched firmware, default or hardcoded passwords, and single-factor logins are still common. For a kitchen, the worst case is not stolen data. It is losing control of the extraction and gas interlock in the middle of service, or having a fault masked so that grease-laden air is being under-extracted for weeks without anyone realising.
The good news is that none of this asks a head chef to become a security engineer. It asks the people who install, maintain and manage your building controls to treat them as the operational technology they are - and it gives you, as an operator, a short list of sensible questions to put to them. Regulation is catching up too. The Cyber Security and Resilience Bill, introduced to Parliament in November 2025 and expected to become law during 2026, is the biggest shake-up of UK cyber rules since the 2018 NIS Regulations, and it pulls far more operational technology into scope. Even if your kitchen is not directly regulated, the buildings and estates you work in increasingly will be, and the expectations will flow down to your systems.
The NCSC's Secure Connectivity Principles for Operational Technology, published with international partners, keep coming back to one idea above all others: keep the controls that matter separated from everything else, and manage every route in and out deliberately. A few practical measures carry most of the weight.
Under the incoming regime, operators of in-scope services will be expected to notice and report a significant incident quickly - an initial notification within around 24 hours and a fuller report within roughly 72. You cannot report what you cannot see, which is why visibility of your own controls is becoming the foundation everything else stands on.
Here is the part that surprises people. A well-run extraction clean is also a moment of truth for your controls. When our engineers are in the ductwork and at the canopy, we are reading the system the way it actually behaves, not the way a dashboard claims it does. If the BMS insists the fans are at full tilt but the airflow at the plate tells a different story, that gap is worth chasing - it can be a failing damper, a drifting sensor, or a control setting that was changed and never changed back. The physical world does not lie, and a clean is one of the few times anyone checks the physical world against the screen.
The same logic runs through the rest of a building's air and water services, where controls and hygiene are tangled together in ways that are easy to miss until something goes wrong. If you manage those risks across a site, it is worth understanding how they connect - our note on legionella risk in building water and air systems covers the same theme from the water side, where sensors, set points and stagnation all shape whether a system stays safe. The message across both is the same. Smart systems are a real gain, but they only stay a gain while someone owns them - checking the readings, hardening the network, and making sure the box in the plant room is serving the kitchen rather than quietly deciding its fate. Keep the ductwork clean, keep the controls honest, and the two together will do far more for your safety and your bills than either one alone.
Questions
Yes. Modern extraction, demand-controlled ventilation and gas interlock systems are increasingly run by networked building controls rather than simple standalone switches. A fault, a bad software change or a genuine intrusion on that network can slow the fans, mask a failing sensor or interfere with the interlock logic. Because these controllers often use older protocols with little built-in security, keeping them separated and monitored matters as much as keeping the ductwork clean.
Start with three questions for whoever maintains your building controls. Are the kitchen and building systems on their own network segment, away from office IT and guest wifi? Have all default passwords been changed, with multi-factor authentication on any remote access? And is there a written firmware update schedule? Those measures, drawn straight from NCSC operational technology guidance, close most of the common gaps without needing any technical expertise from your team.
Phoenix Duct Clean · by the numbers
Phoenix surveys and cleans kitchen and building ductwork to the TR19 standard - measured, cleaned and certificated, UK-wide.