If a light is connected to the network, can it become a security risk?

When a lighting system becomes digital, the way it needs to be protected changes too.

Once, a light did little more than switch on and off. Today, a luminaire can be connected to a control system, communicate with other devices, receive remote commands, interact with sensors and contribute to data collection.

This makes the system much more flexible, but it also raises a question that would have seemed almost absurd a few years ago: can a lighting system become a cybersecurity risk?

The answer is that it can become part of the digital attack surface that an organisation needs to protect.

When a physical system enters the digital world

Digitalisation has progressively changed the nature of infrastructure.

A connected lighting system can include luminaires, control devices, gateways, sensors, software and cloud platforms. These components communicate through networks and protocols, meaning that a physical infrastructure also becomes a digital infrastructure.

However, the physical and digital lifespans of the various elements of this infrastructure do not necessarily coincide. A luminaire installed in a building may remain physically operational for many years, while the software controlling it belongs to a world in which updates, vulnerabilities, operating systems and protocols evolve much more rapidly.

This does not mean “the light can hack the company”

The issue needs to be addressed without alarmism. A connected lighting system does not automatically become a gateway into all of a company's systems.

Risk depends on the architecture, connection methods, access levels, configurations and security measures adopted.

For this reason, cybersecurity should be considered from the very beginning, during the design and technology selection phase.

When evaluating a connected system, the usual criteria include:

  • Functionality;
  • Compatibility;
  • Remote control capabilities;
  • Data collection capabilities;
  • Costs;
  • Scalability.

But other questions should be added:

  • How are credentials managed?
  • How are updates carried out?
  • Where is the data stored?
  • Who can access the system?
  • What happens if a component needs to be replaced?
  • Can the system continue operating if the connection is lost?
  • How is the relationship between the lighting system network and the company network managed?

These may seem like highly technical questions, but they have a very practical consequence: a lighting system can remain installed for 10, 15 or more years. Technology choices therefore also concern how manageable and secure the system will remain in the future.

Categories
Tech
Publication date
24 September 2026
Reading time
2 minutes
Iscriviti alla newsletter

Sign up for the Newsletter