Robot cybersecurity: updates matter as much as motors and sensors
Smart bulb app crashing is a nuisance. Taking control of a mobile robot can have physical consequences. The robot combines cameras, microphones, drives, a building map and often access to the cloud. Therefore, cybersecurity is not an add-on - it is part of the security of the entire device.
What items can be attacked?
- user account and mobile application,
- home or business Wi-Fi network,
- manufacturer's cloud server,
- remote operator panel,
- update mechanism,
- programming interfaces and service ports,
- integrator account with broad permissions.
The result may be image previewing, map theft, work stoppage, setting change or unauthorized motion control.
Updates and support period
Before purchasing, it is worth obtaining a specific update end date. The promise of "regular patches" without a period of support is of little use. In an enterprise, the system should also allow you to control the moment of installation, test a new version and return to the previous configuration if the update causes a problem.
Cyber Resilience Act
The EU Cyber Resilience Act introduces requirements for products with digital elements throughout their lifecycle. Manufacturers must consider security by design, manage vulnerabilities and provide updates. The obligations are being implemented in stages, but a reasonable buyer should demand a similar standard now.
Minimum Safe Robot Configuration
- unique password and multi-factor authentication,
- separate accounts for administrator and operator,
- encrypted connection,
- history of logins and settings changes,
- automatic critical patches or clear update process,
- possibility to limit cloud functions,
- secure erase,
- vulnerability reporting procedure.
Network segmentation in the company
The robot should not unnecessarily have access to the entire enterprise network. A dedicated network, limited permissions and traffic control reduce the risk of a device vulnerability becoming an entry point into business systems.
What happens to the device after support ends?
The robot can mechanically operate for many years, while the manufacturer stops maintaining the application after three. The company should know whether the device will remain in local mode, whether replacement software can be installed, and how to safely retire the hardware.
A digital incident is also an operational incident
The response plan should specify the ability to immediately stop, disconnect the network, retain logs and contact the supplier. In a robot moving next to people, it is not enough to change the password after a few days.
Software Supply Chain
The robot uses libraries, drivers and systems from many suppliers. The vulnerability may appear in a component whose name the customer does not even know. A mature manufacturer maintains an inventory of components, monitors warnings and can assess the impact of the error on specific models.
Secure Service Access
Remote service is convenient, but the technician account should not work constantly. A good solution requires administrator consent, limits session time and records performed activities. A common service password for all robots is an unacceptable risk.
Test after purchase
- change all default data,
- check for available updates,
- disable unused services
- test work after internet loss,
- check if the reset actually removes the maps,
- determine the owner of the administrative account.
Cyber Insurance and Liability
Deploying a robot may impact policy coverage or insurer requirements. The enterprise should determine who is responsible for an incident resulting from an unpatched vulnerability and what evidence needs to be retained.
RoboMorrow assessment
A good robot should have a clear support period, a documented update process, and the ability to restrict access to data. The lack of answers to these questions should affect the evaluation of the product as much as a weak battery.