Eight Tips for Lighting Cybersecurity

Cyber Security

Apr 14, 2019

By Craig DiLouie

Connectivity enables LED lighting to go far beyond illumination and energy savings to offer revolutionary new capabilities and value for occupants, cost reductions, quality lighting, and business process improvement. By networking luminaires and lighting control points in a centralized architecture, the lighting system becomes programmable and able to generate data. While connecting devices for various business purposes can produce extraordinary value, it can also impose data privacy and security risks. Part 1 of this article explored the nature of the risks, and what manufacturers are doing. Here in Part 2: eight tips on how you can help your clients manage the risks.

1. Become conversant in cybersecurity “hygiene.” While lighting professionals need not become cybersecurity experts, they can benefit from education about basic concepts and practices.

2. Engage with the client about cybersecurity. It can be beneficial to engage the client about security needs during the project programming phase. This may require talking to client IT departments, which vary in how they’re composed. The IT department may have questions and requirements that will affect how the project is designed.

After product selection, it can be beneficial to include security documentation as part of the project documents. For challenging questions, the manufacturer should be able to provide support.

3. Ensure good encryption. Encryption is encoding data between devices to prevent them from being intercepted and manipulated. In a May 2018 bulletin, Cyber Security for Lighting Systems, the U.S. Department of Energy’s Federal Energy Management Program (FEMP), recommends AES 128-bit encryption.

AES 256-bit encryption is available, but there is a trade-off between power draw (and latency) and encryption in wireless lighting devices, resulting in a majority of devices using 128 instead of 256.

4. Choose an appropriate method of authentication. Authentication is about ensuring only devices that trust each other can share data. The FEMP recommends good authentication, with possibly the most secure authentication method being use of both a public and private key. The device initiating communication does so using a public key, and the responding device answers with a private key.

5. Safeguard the lighting network. If security is a concern, the network should be protected by a firewall. If the lighting network will touch the corporate network, as an added security measure, FEMP recommends segmenting it using a virtual local area network (VLAN). With a VLAN, a portion of a network is partitioned and run separately as a subnet with its own functionality and security.

6. Advise client on their responsibilities. The client should be advised about delineating administrator permissions (who will have access to the network and what powers they will have inside), the importance of installing vendor software updates (which may include important security enhancements) and changing passwords, and so on.

7. Secure after commissioning. FEMP recommends that any radios used to commission the control system be turned off after use. Or, if the radios are needed for ongoing system operation, they should be secured.

8. Scrutinize products. Look for suppliers that use a strong security methodology, are able to explain it, and can support you when needed. Here, education can go a long way in evaluating products with comparable security features but where the manufacturer implements them very differently.

One resource for evaluating products is the DesignLights Consortium (DLC), which lists networked control systems in a Qualified Products List that utilities in turn use to qualify products for their rebate programs. The Qualified Products List allows manufacturers to report compliance with certain security standards, and will require standards compliance in 2020.

Networked lighting and the IoT are a new world, presenting exciting opportunities for end-users but requiring new skillsets and creating new potential risks. Savvy building professionals will become educated on the basic issues, demand good security methodology from manufacturers, and engage with the right people at the customer to ensure all requirements are satisfied.

Read Part 1 here.

Craig DiLouie, LC, is Education Director for the Lighting Controls Association. Reprinted with permission of the Lighting Controls Association.

Photo by jaydeep_ on Pixabay

Related Articles


Latest Articles

  • Take the Lesson

    Take the Lesson

    September 2, 2024 By Keith Sones, seasoned utility industry executive “I really don’t want to do this.” “You have to Keith. You have no choice. You can’t leave him hanging” replied my wife. I stared at the phone like a child looks at liver on their plate. They know you have to eat it but also… Read More…

  • Quebec Drives the Growth in Residential Building Construction in June, 2024

    Quebec Drives the Growth in Residential Building Construction in June, 2024

    Investment in building construction grew 2.8% to $21.4 billion in June, after a slight increase of 0.8% in May. These increases partly reflect April’s record high of $13.4 billion in total building permits value, since investment levels for a given period are driven by permits issued in prior months. The June increase in investment in building construction was primarily… Read More…

  • Western Memorial Regional Hospital Sets New Infrastructure Precedent and Receives LEED Silver Certification 

    Western Memorial Regional Hospital Sets New Infrastructure Precedent and Receives LEED Silver Certification 

    August 16, 2024 The new Western Memorial Regional Hospital in Corner Brook is home to Canada’s largest geothermal system, which has set a precedent for modern infrastructure for both Newfoundland and Labrador and North America. The geothermal field is approximately 600 feet below the hospital’s parking lot, and provides 100 per cent of the ground… Read More…

  • Brightening Communities: LED Technology in Action

    Brightening Communities: LED Technology in Action

    August 15, 2024 By Alex Price, Brand & Planning Manager, Current LightingTechnical Contributor: Gary Steinberg, Senior System Manager (Outdoor LED Fixtures), Current Lighting As the landscape of Canadian cities continues to evolve, the importance of outdoor lighting cannot be overstated. From enhancing public safety to promoting economic activity and fostering a sense of community, well-planned… Read More…


Changing Scene

  • Schneider Electric Launches SMART Buildings Division to Drive Sustainable Building Innovation in Canada

    Schneider Electric Launches SMART Buildings Division to Drive Sustainable Building Innovation in Canada

    Schneider Electric is transforming its Digital Buildings business in Canada with the launch of the SMART Buildings Division. This evolution marks a strategic move to deliver comprehensive solutions and services that support building owners and operators in achieving their decarbonization and sustainability goals. The demand for smart buildings is surging, driven by a global shift… Read More…

  • Introducing Alan Bearden as Interim President of Southwire Canada

    Introducing Alan Bearden as Interim President of Southwire Canada

    September 4, 2024 Southwire Canada is pleased to announce that Alan Bearden has been appointed Interim President. In this role, Alan will provide leadership and guidance for Southwire’s Canada-based organization, ensuring continuity and driving growth during this transitional period. Alan Bearden brings a wealth of experience to the position, having joined Southwire in 2008. Over… Read More…

  • A Partnership Between Electromag Graybar Canada and Phoenix Contact

    A Partnership Between Electromag Graybar Canada and Phoenix Contact

    September 3, 2024 Electromag Graybar Canada, a pioneer in industrial automation solutions and pneumatic products, is excited to announce a partnership with Phoenix Contact, a global leader in electrification, networking, and industrial automation. This collaboration, which initially began in the Langley and Ontario branches, is now expanding to Quebec. The alliance aims to provide cutting-edge… Read More…

  • Sonepar Announces the Retirement of William (Bill) C. Smith, Electrozad Director of Transitional Business

    Sonepar Announces the Retirement of William (Bill) C. Smith, Electrozad Director of Transitional Business

    September 2, 2024 William (Bill) C. Smith, Director, Transitional Business of Electrozad Supply Company Limited announced his retirement as of August 30th, 2024 after 49 years of leadership. Bill began his electrical career working part-time at Electrozad Supply while completing a Sales & Marketing Program at St. Clair College.  After his first full-time position in… Read More…