Field perspective
Where this usually goes wrong
A network-connected fire alarm system can be functionally healthy while its remote-access configuration, shared credentials, or service laptop creates an avoidable cybersecurity risk. But a requirement in the 2025 edition does not automatically mean that edition governs a current project.
Start with the adopted edition and project requirements
NFPA 72 has included a cybersecurity chapter since the 2022 edition, largely with informative guidance. The 2025 edition expanded Chapter 11 with additional normative provisions. That does not make Chapter 11 universally enforceable on every existing fire alarm system. First establish which edition has been adopted for the project, the governing building/fire code, project specifications, and the AHJ's direction. The application of individual cybersecurity provisions depends on the actual code text and scope.
Do not turn a good cybersecurity practice into an invented citation. Conversely, do not ignore a real network exposure simply because an older code edition applies.
Map the system before changing any settings
Identify the fire alarm control panels, network interfaces, workstations, gateways, remote monitoring or diagnostic connections, management servers, vendor service links, and any shared customer IT or building-management infrastructure. Determine which interfaces can only report status and which could change programming, acknowledge or control functions, or affect operation.
Ask the system owner or IT representative who administers each connection and whether a current, approved network diagram exists. Be especially careful where a life-safety network shares switches, routers, fiber, or wide-area connectivity with other systems.
Protect programming and service tools
Use an authorized and updated programming laptop, approved software, individual credentials where supported, and the manufacturer's supported connection method. Avoid leaving default credentials, shared passwords, unapproved remote-control utilities, or persistent open vendor access paths in place.
Coordinate operating-system updates, antivirus tools, access controls, removable media, and service accounts with the organization's security policy and the manufacturer. Do not install unapproved security software on a listed fire alarm control unit or alter its network architecture without engineering and manufacturer review.
Document and verify after any network or security change
Save the as-found state: software/firmware versions, network path, authorized access method, current trouble or event history, and approved backup. When settings change, record who approved the change and what was modified. Reconfirm supervision, annunciation, monitoring transmission, remote interfaces, and all functions affected by the change as required by the approved test plan.
Changes to firewalls, VLANs, switches, IP addresses, gateways, remote-access tools, or certificates can disrupt communication even if no fire alarm device was touched. Restore any impaired function and document the outcome using the site's required procedure.
Know when to involve the owner, IT, or manufacturer
A fire alarm technician should confirm that the system operates as listed and approved, but does not need to make unilateral enterprise cybersecurity decisions. Escalate internet exposure, unsupported firmware, credential ownership problems, firewall requests, and shared-network architecture to the manufacturer, designer, owner, and IT/security personnel as appropriate.
For compliance questions, check the actual adopted text of NFPA 72 Chapter 11 and any AHJ conditions rather than relying on a generic statement that all IP-connected systems require the same protections.
Common mistakes to avoid
- Assuming a new code edition automatically applies to every existing installed system
- Leaving remote-access paths or shared passwords in place without owner authorization
- Reconfiguring fire alarm network infrastructure without the manufacturer or IT team
- Performing a security update without checking the fire alarm and monitoring functions it affects
Quick network-security service checklist
- Verify the governing code edition and project scope
- Identify FACP, workstation, communicator, gateway, and remote interfaces
- Record authorized access method and current firmware/software versions
- Coordinate firewalls, VLANs, passwords, and remote access with IT/owner
- Apply only manufacturer-supported changes and preserve a backup
- Verify affected life-safety functions and supervising-station communication
- Document changes, results, ownership, and follow-up risks
Frequently asked field questions
Does every fire alarm panel need a firewall?
No universal blanket conclusion can be made. The correct protection depends on the connection, the actual governing requirements, manufacturer instructions, and the project security design. Unrestricted internet access is a concern even where a specific code provision is not triggered.
Does the 2025 NFPA 72 edition apply automatically in Connecticut?
No. Verify the current Connecticut code adoption and the edition governing your project. A published national standard does not by itself change the legally adopted state baseline.
What to verify before you act
Use this article to organize the field problem, then verify the requirement or permitted method in the documents that govern the job:
- NFPA 72 Chapter 11 in the edition legally adopted for the project
- Manufacturer cybersecurity bulletins, firmware guidance, and network installation instructions
- Approved drawings, cybersecurity specifications, site IT policy, and written AHJ requirements
Primary references to check
These are the source documents I would verify for this topic before making a field, design, or compliance decision:
- NFPA 72, National Fire Alarm and Signaling Code, 2025 edition — Chapter 11 (official text through NFPA LiNK or licensed copy)
- NFPA 72, 2022 edition — Chapter 11 and related informative annex for historical comparison
- Electrical Contractor Magazine — Cybersecurity and Fire Alarms: New requirements in the 2025 edition of NFPA 72 (2025)
Important limitation
This guide is a field-oriented starting point, not a substitute for the adopted code, approved drawings, project specifications, manufacturer instructions, site safety procedures, or the authority having jurisdiction. Do not bypass a listed protection feature or leave a required system impaired without following the approved impairment process.