Eight Tips for Lighting Cybersecurity

Cyber Security

Apr 14, 2019

By Craig DiLouie

Connectivity enables LED lighting to go far beyond illumination and energy savings to offer revolutionary new capabilities and value for occupants, cost reductions, quality lighting, and business process improvement. By networking luminaires and lighting control points in a centralized architecture, the lighting system becomes programmable and able to generate data. While connecting devices for various business purposes can produce extraordinary value, it can also impose data privacy and security risks. Part 1 of this article explored the nature of the risks, and what manufacturers are doing. Here in Part 2: eight tips on how you can help your clients manage the risks.

1. Become conversant in cybersecurity “hygiene.” While lighting professionals need not become cybersecurity experts, they can benefit from education about basic concepts and practices.

2. Engage with the client about cybersecurity. It can be beneficial to engage the client about security needs during the project programming phase. This may require talking to client IT departments, which vary in how they’re composed. The IT department may have questions and requirements that will affect how the project is designed.

After product selection, it can be beneficial to include security documentation as part of the project documents. For challenging questions, the manufacturer should be able to provide support.

3. Ensure good encryption. Encryption is encoding data between devices to prevent them from being intercepted and manipulated. In a May 2018 bulletin, Cyber Security for Lighting Systems, the U.S. Department of Energy’s Federal Energy Management Program (FEMP), recommends AES 128-bit encryption.

AES 256-bit encryption is available, but there is a trade-off between power draw (and latency) and encryption in wireless lighting devices, resulting in a majority of devices using 128 instead of 256.

4. Choose an appropriate method of authentication. Authentication is about ensuring only devices that trust each other can share data. The FEMP recommends good authentication, with possibly the most secure authentication method being use of both a public and private key. The device initiating communication does so using a public key, and the responding device answers with a private key.

5. Safeguard the lighting network. If security is a concern, the network should be protected by a firewall. If the lighting network will touch the corporate network, as an added security measure, FEMP recommends segmenting it using a virtual local area network (VLAN). With a VLAN, a portion of a network is partitioned and run separately as a subnet with its own functionality and security.

6. Advise client on their responsibilities. The client should be advised about delineating administrator permissions (who will have access to the network and what powers they will have inside), the importance of installing vendor software updates (which may include important security enhancements) and changing passwords, and so on.

7. Secure after commissioning. FEMP recommends that any radios used to commission the control system be turned off after use. Or, if the radios are needed for ongoing system operation, they should be secured.

8. Scrutinize products. Look for suppliers that use a strong security methodology, are able to explain it, and can support you when needed. Here, education can go a long way in evaluating products with comparable security features but where the manufacturer implements them very differently.

One resource for evaluating products is the DesignLights Consortium (DLC), which lists networked control systems in a Qualified Products List that utilities in turn use to qualify products for their rebate programs. The Qualified Products List allows manufacturers to report compliance with certain security standards, and will require standards compliance in 2020.

Networked lighting and the IoT are a new world, presenting exciting opportunities for end-users but requiring new skillsets and creating new potential risks. Savvy building professionals will become educated on the basic issues, demand good security methodology from manufacturers, and engage with the right people at the customer to ensure all requirements are satisfied.

Read Part 1 here.

Craig DiLouie, LC, is Education Director for the Lighting Controls Association. Reprinted with permission of the Lighting Controls Association.

Photo by jaydeep_ on Pixabay

Related Articles


Latest Articles

  • CAF-FCA Provides Recomendations on Apprenticeship Investment

    CAF-FCA Provides Recomendations on Apprenticeship Investment

    April 13, 2025 CAF-FCA have provided an outline of actionable recommendations—developed through national consultation—to enhance accessibility, reduce financial barriers, and better align apprenticeship training with industry needs. Source Read More…

  • New Report: Preparing Alberta’s Buildings for Severe Weather

    New Report: Preparing Alberta’s Buildings for Severe Weather

    April 13, 2025 Alberta is facing more severe weather events, with rising temperatures, wildfires, and more frequent extreme storms threatening homes and businesses. Our report, Preparing Alberta’s Buildings for Severe Weather−written in partnership with the Alberta Ecotrust Retrofit Accelerator program−highlights the need for deep retrofits to ensure the province’s buildings can withstand these changing conditions. Four… Read More…

  • CCA Bulletin: Managing Tariff Risks in Construction Projects

    CCA Bulletin: Managing Tariff Risks in Construction Projects

    April 13, 2025 This bulletin was prepared by select members of the Canadian Construction Association’s (CCA) General Contractors National Advisory Council. Its purpose is to assess the potential impacts of tariffs and counter-tariffs on general contractors in Canada focusing specifically on: In both areas, the bulletin explores both upstream and downstream impacts – examining how… Read More…

  • Video: ABB Installation Products Proudly Powering Canada

    Video: ABB Installation Products Proudly Powering Canada

    April 7, 2024 From coast to coast, ABB Installation Products is built by Canadians, for Canadians—delivering high-quality solutions that power industries and support communities across the country. Read More…


Changing Scene

  • PEI’s First Net Zero Ready School Officially Opens

    PEI’s First Net Zero Ready School Officially Opens

    April 13, 2025 Island students, their families and the Sherwood school community came together today to celebrate the opening of PEI’s first net zero ready school. The new Sherwood Elementary School, built next to the former school, offers over 82,000 square feet of space with many innovative features to promote enhanced learning experiences for up… Read More…

  • Nova Scotia Invests to Connect Nova Scotians to Skilled Trades

    Nova Scotia Invests to Connect Nova Scotians to Skilled Trades

    April 13, 2025 The Province is helping more Nova Scotians explore and connect to careers in skilled trades through a $10-million investment in the construction industry. The investment will support more skilled trades training through three key initiatives: “Nova Scotia needs more skilled trades professionals to support our growing economy and to build the homes,… Read More…

  • PEI Tables Bill Aimed to Eliminate Trade and Labour Barriers

    PEI Tables Bill Aimed to Eliminate Trade and Labour Barriers

    April 13, 2025 Hon. Rob Lantz, Premier of Prince Edward Island, introduced the Interprovincial Trade & Mobility Act in the provincial legislature. This bill will allow Prince Edward Island to eliminate unnecessary barriers to trade and labour mobility with reciprocating jurisdictions.   The Bill will accept provincial inspections and standards on goods coming from a… Read More…

  • PEI Minimum Wage Set to Increase

    PEI Minimum Wage Set to Increase

    April 13, 2025 Minimum wage in Prince Edward Island will increase incrementally to $17 per hour by April 1, 2026.  The Employment Standards Board reviews minimum wage annually and provides their recommendation to government.  Go HERE for more information Source Read More…