– Ready today for tomorrow's requirements –

Security as the foundation of modern street lighting

Security is not an add-on for us – it is the foundation of every modern, networked street-lighting system. We protect control, communication and updates across the entire lifecycle, from installation to long-term field operation. That keeps your lighting infrastructure reliable and resilient against current and future cyber threats.

EU CRADSGVO

Risks at a glance

Four risks that don't disappear in live operations.

Networked lighting is often treated like a lighting topic in tenders — in reality it is an IT-security and operational-resilience topic. The most important points at a glance.

Why security is critical for street-lighting systems

Networked street lighting is critical infrastructure today – and therefore a worthwhile target. If it isn't consistently secured, you risk outages, public-space safety issues and loss of trust.

More than just "lights on, lights off"

Modern luminaire controllers are networked digital components and thus part of critical municipal infrastructure. When such systems fail or are tampered with, it doesn't only affect single poles – it affects whole streets, districts or, in the worst case, an entire municipality.

Direct impact on safety and citizens

Good lighting has a direct impact on traffic safety and on how safe people feel in public space. If dimming profiles or schedules are deliberately altered, key arteries, school routes or footpaths can suddenly be insufficiently lit. Consequences range from increased accident risk to a heightened sense of insecurity for citizens.

One vulnerability is enough

Networked lighting systems consist of large numbers of mostly identical field devices. A single vulnerability in hardware or firmware therefore scales – it can affect thousands of controllers at once. Without secure update mechanisms, encrypted communication and proper key management, such risks cannot be controlled.

EU Regulation 2024/2847

What is the EU Cyber Resilience Act

and why does it become required reading for your lighting?

The Cyber Resilience Act is an EU regulation that establishes a uniform minimum level of cybersecurity for all "products with digital elements" – hardware and software directly or indirectly connected to a network. The goal is to substantially reduce vulnerabilities and insecure default configurations and to harmonise the EU single market for connected products.

It obliges manufacturers to consider security across the entire product lifecycle – from development through market launch and field updates. This includes clear vulnerability-management processes, mandatory security updates and transparency towards users and authorities.

The CRA was published in the Official Journal in November 2024 and entered into force on 10 December 2024. Most obligations apply from 11 December 2027, while specific requirements – such as reporting actively exploited vulnerabilities – already kick in from September 2026.

Status quo vs. target picture

What's the situation today, and what is going to change?

Today, without the CRA
  • Ad-hoc updates via site visits
  • Unsigned firmware, no clear vulnerability process
  • Responsibilities between manufacturer, operator and municipality often unclear
  • Data security frequently undocumented
Tomorrow, with the CRA
  • Secure, signed remote updates across the full lifecycle
  • Mandatory vulnerability management with reporting channels from 2026
  • Clear manufacturer duties, transparent operator duties
  • Traceable documentation that holds up to audits

Book a slot directly

Structured intro briefing — 20 minutes

Functional

Enables embedded content like the Calendly booking widget and the map on the contact page.

https://calendly.com/chris-moebus-moebus-engineering/unverbindliches-erstgesprach-mobus-engineering-gmbh