Systems integration
Retrofitting IoT onto equipment that predates it
Most of the equipment running today was specified before anyone planned to put a sensor on it. Replacing it for the sake of telemetry is rarely the economic answer, but a retrofit fails in ways a software team meets only after the drill has already gone through the enclosure.

Executive summary
3
live sites retrofitted without taking any offline: a campus, a hospital, and an airport
5+ yrs
the battery life the PestBusters sensor retrofit was built around
Core conclusions
- A retrofit fails in the physical layer first — power, certification, and signal integrity on cabling that predates the requirement — not in the data model.
- On a live facility, sign-off from whoever owns the asset comes before any of that; skipping it is the fastest way to lose access to the site.
- Name the recurring human task a retrofit removes, and the one it introduces in its place, with an interval on each — a vendor who can't answer the second half hasn't finished the job.
A retrofit puts a sensor on a machine, a panel, or a building system that was never designed to report anything. That is a different job from specifying a new one, and it fails differently: not in the data model, but in the physical layer underneath it — power, certification, and wiring that predate the requirement by years.
The instinct on a project like this is to start with the platform: what the sensor talks to, what dashboard shows it. On a live facility, that is the second question. The first is whether you can get a sensor onto the asset at all without shutting it down, decertifying it, or creating a new fault it did not have before.
Where a retrofit actually fails
Four points, and they surface in this order on a real site:
- Power. Older equipment rarely has a spare terminal or a 24V rail sized for an add-on load, so the tap-in is its own small electrical project before any data moves.
- Certification. A pressure vessel, a fire system, or a medical enclosure carries a certification that a drilled hole or an added tap can invalidate — the retrofit has to route around the certified boundary, not through it.
- Signal integrity over the existing run. Cable laid decades ago for a different purpose was not specified for the noise floor a new sensor introduces alongside it.
- Sign-off from whoever owns the asset, obtained before any of the above — a retrofit done without it is the fastest way to lose access to the site.
A live-facility example
We ran an IoT and building-management sensor deployment across three sites that could not be taken offline to accommodate it: SUTD, Ng Teng Fong General Hospital, and Changi Airport, feeding real-time environmental data into ENGIE's own systems from 2018. None of the three was built with this in mind. The constraint that shaped the project was not the sensor spec, it was fitting the install around a campus, a working hospital, and an airport that all had to keep operating through it.
The task the retrofit is not allowed to create
The other failure mode is subtler: solving the manual-checking problem by creating a new manual-checking problem. PestBusters' sites used to require someone physically checking every bait box and trap on a fixed schedule, whether or not there was activity to find. The sensors we deployed there run a targeted five-plus years on a single battery, because a retrofit that requires a technician to visit every unit annually to change a battery has not removed the manual round, it has just changed what it is for.
That is the test worth applying to any retrofit proposal before it is signed off: name the recurring human task it removes, and name the recurring human task it introduces in its place, with an interval attached to each. If a vendor cannot answer the second half, the retrofit is not finished, it has just moved the labour from checking the asset to maintaining the sensor.