The set of technical and organisational measures applied to protect elevator control systems, remote monitoring networks, and IoT-connected components from unauthorised access, manipulation, and cyber-attacks.
Full Definition
As elevators are increasingly connected via IP networks for remote monitoring (EN 81-28), destination dispatch, BMS integration, and IoT diagnostics, they become potential attack surfaces for cyber threats. Elevator cybersecurity threats include: unauthorised access to the controller via open network ports; man-in-the-middle attacks on remote monitoring communications; ransomware targeting building management systems connected to the elevator; and physical tampering with network access points in the hoistway. The IEC 62443 series (Industrial Automation and Control Systems security) is the primary international framework for securing elevator control system networks. Key measures include: network segmentation (elevator controller on an isolated VLAN); encrypted communications (TLS for remote monitoring); strong authentication for remote access; firmware integrity verification and update signing; physical access control to controller cabinets; and regular vulnerability assessment. EN 81-20 does not yet address cybersecurity directly, but the forthcoming EN 81-85 (Remote Elevator Monitoring) and elevator-specific addenda are expected to incorporate cybersecurity requirements. The EU NIS2 Directive (Network and Information Security) may apply to critical infrastructure elevator installations.
Connected elevator installations with remote monitoringIoT diagnosticsdestination dispatch and BMS integration — increasingly relevant to all modern elevators