Robot Service Map. Vigla Media OÜ
Guides

When trust in robotics comes down to the Internet connection – The Robot Report

When procurement teams, plant managers, and automation engineers evaluate an industrial robot today, the conversation rarely stops at payload capacity, repeatability, or cycle time. Increasingly, the deciding factor is something far less tangible but arguably more consequential: the quality and security of the robot’s internet connection. The era of the isolated robot—a machine bolted to a production line, communicating with nothing beyond its own controller—is over. According to research highlighted in the source material, industrial robots were originally conceived to be isolated, but they have evolved. They are now routinely exposed to corporate networks and, in many cases, the public internet.

This shift is not a minor operational detail. It is a fundamental change in how trust in robotics is established and maintained. The source material, drawing on an IEEE Spectrum report, describes how researchers scanned the internet and easily found numerous examples of connected industrial robots from top vendors. Some of these machines provided unrestricted access using anonymous credentials—meaning the authentication system was disabled entirely. For any organisation deploying or considering robotic systems, this is the first thing to look for: is the robot reachable from outside your network, and if so, under what conditions?

The source material does not specify which vendors were involved or how many robots were found. It also does not disclose the exact scanning methodology or the timeframe of the scans. What is known is that the researchers were looking for connected robots from leading manufacturers and found several, some with authentication disabled. This should serve as a cautionary data point, not a definitive industry-wide audit. If your organisation is deploying robots, you should assume that a default configuration may not include adequate security measures, and you must verify this yourself.

Another key factor to look for is the broader trend toward connectivity. The source material indicates that the integration of industrial robots into the Industrial Internet of Things (IIoT) is expected to grow by 23% annually until 2030. This is not a niche development. It means that the robots you purchase today will likely be expected to communicate with enterprise resource planning systems, maintenance platforms, and other machinery. The question is not whether your robot will be connected, but how securely and how deliberately that connection is managed.

Trust, according to the source material, is also shaped by perception. A survey of 1,000 technology executives across healthcare, manufacturing, automotive, and heavy machinery—spanning China, France, Germany, Japan, North America, and the UK—found that 77% of global technology leaders trust robotics to carry out essential functions in the workplace. This trust is not blind. The survey identified safety and risk mitigation (42%) and proven reliability and performance (40%) as the top two factors influencing this confidence. Consistency in outcomes and accuracy (33%) and security and data protection (31%) also played significant roles.

What does this mean for someone evaluating a robot? It means that trust is not a single binary decision. It is a composite of several attributes. You should look for evidence of safety features and risk mitigation protocols—not just in the robot’s physical operation but in its network behaviour. You should look for proven reliability, which may come from documented deployments, but the source material does not provide specific performance benchmarks or case studies. You should look for consistency in outcomes, which is often a matter of software quality and sensor calibration. And you should look for security and data protection, which in the context of connected robots means authentication, encryption, and access control.

The source material also touches on a different dimension of trust: how end-users, particularly in care settings, perceive robots. One project mentioned, Caremark Genie, involves small robots with an oval screen at the top. People surveyed for this project expressed desires for voice interaction, a non-threatening appearance, and a "cute design." More practically, many wanted robots that could adapt to changing needs, charge themselves, and clean themselves. One respondent summarised the sentiment: "We don't want to look after the robot – we want the robot to look after us." This is a useful reminder that trust is not only a technical property. It is also a human expectation. For industrial deployments, this translates into a preference for robots that require minimal manual intervention and can operate autonomously within defined parameters.

Finally, the source material references Elon Musk’s Optimus humanoid robot, which served drinks and mingled at a Tesla event. The source does not provide details on the event’s date or the robot’s technical specifications. It is cited as an example of the direction of travel: robots are entering human environments, and the question is whether regulations and standards will be developed proactively or reactively. For an organisation evaluating robots, this suggests that you should look not only at the robot itself but at the regulatory and standards landscape. The source material does not specify which regulations are in development or which standards apply, so this remains an area to monitor rather than a checklist item.

Practical steps

Given the connectivity risks described in the source material, the first practical step is to conduct a network exposure audit. Before a robot is deployed, determine whether it can be reached from the internet. The source material indicates that some robots were found with anonymous credentials and unrestricted access. This is not a hypothetical risk; it has been observed in the field. Your audit should include scanning for open ports, checking default credentials, and verifying whether the robot’s authentication system is enabled. The source material does not provide a specific tool or methodology for this audit, so you should rely on your organisation’s existing network security practices or engage a specialist.

The second step is to enforce authentication. The source material highlights that some robots had authentication disabled entirely. This is an unacceptable configuration for any production environment. Ensure that all robot interfaces—whether web-based, API-based, or vendor-specific—require strong, unique credentials. The source material does not specify what constitutes strong credentials in this context, so you should align with your organisation’s password policy or industry best practices.

The third step is to segment your network. The source material does not provide specific guidance on network architecture, but it is clear from the risks described that robots should not be placed on the same flat network as other critical systems. If a robot is compromised, segmentation limits the blast radius. This is a standard practice in industrial cybersecurity, and while the source material does not explicitly recommend it, the described risks imply the need for isolation or at least strict access controls.

The fourth step is to plan for the IIoT growth trajectory. The source material states that IIoT integration in robotics is expected to grow by 23% annually until 2030. This means that your robot’s connectivity requirements will likely increase over time. Plan for this by ensuring that your network infrastructure can handle additional devices and data flows. The source material does not provide specific bandwidth or latency requirements, so you should consult your robot vendor’s documentation and your IT team.

The fifth step is to build trust based on the factors identified in the survey. The source material lists safety and risk mitigation (42%), proven reliability and performance (40%), consistency in outcomes and accuracy (33%), and security and data protection (31%) as the top trust drivers. Use these as evaluation criteria. When comparing robot models, ask vendors for evidence of safety certifications, reliability data, accuracy specifications, and security features. The source material does not provide specific certifications or metrics, so you will need to request this information from vendors directly.

The sixth step is to consider the human dimension. The source material’s care-robot research suggests that users value autonomy and self-maintenance. In an industrial context, this translates into selecting robots that can handle routine tasks without constant human oversight. The source material does not specify which tasks are considered "essential functions," but the survey of executives covered automation, production, support, and research and development roles. Align your robot selection with the specific functions you need to automate, and ensure that the robot can operate reliably in that role.

The seventh step is to engage with the emerging regulatory conversation. The source material quotes a perspective that regulations should be developed before large tech companies deploy robots without public input. While this is a societal-level discussion, it has practical implications for buyers. Stay informed about regulatory developments in your jurisdiction. The source material does not specify which regulations are under consideration or in which countries, so you should monitor relevant government and industry bodies.

The eighth step is to document everything. The source material does not provide a documentation standard, but given the security risks described, it is prudent to maintain a record of your robot’s network configuration, authentication settings, and software versions. This will help with troubleshooting and audits. The source material does not specify how often this documentation should be updated, so a reasonable approach is to review it whenever the robot’s software or network configuration changes.

Common mistakes to avoid

The most obvious mistake, based on the source material, is assuming that a robot is isolated by default. The IEEE Spectrum report explicitly found that industrial robots, originally conceived to be isolated, are now exposed to corporate networks and the internet. If you assume your robot is not connected, you will not look for it, and you will not secure it. The source material does not provide statistics on how many robots are exposed, but the fact that researchers found several from top vendors with anonymous credentials is a clear warning.

A second mistake is ignoring default credentials. The source material notes that some robots provided unrestricted access using anonymous credentials, meaning authentication was disabled. This is not a sophisticated attack; it is a default configuration that should be changed immediately upon deployment. The source material does not specify which vendors had this issue, so you cannot rely on brand reputation alone. Verify authentication settings for every robot you deploy.

A third mistake is treating security as a one-time activity. The source material indicates that IIoT integration is growing at 23% annually until 2030. This means the threat landscape and the connectivity surface will both expand. If you secure a robot at deployment and never revisit it, you will likely miss new vulnerabilities or misconfigurations introduced during updates or maintenance. The source material does not provide a recommended review frequency, so you should align with your organisation’s existing security practices.

A fourth mistake is over-indexing on physical safety while neglecting network safety. The survey in the source material found that safety and risk mitigation was the top trust factor at 42%. This is important, but it should not come at the expense of security and data protection, which was cited by 31% of respondents. A robot that is physically safe but network-vulnerable is not fully trustworthy. The source material does not provide guidance on balancing these factors, but the survey results suggest that both are significant.

A fifth mistake is ignoring the human factors that influence trust. The source material’s care-robot research shows that people want robots to be non-threatening, adaptable, and self-sufficient. In an industrial setting, this translates into selecting robots that are easy to work alongside and do not require excessive hand-holding. The source material does not provide specific usability metrics, but the principle is clear: if workers do not trust the robot, they will not use it effectively.

A sixth mistake is failing to plan for the regulatory future. The source material quotes a perspective that regulations should be developed proactively. If you purchase robots without considering upcoming regulations, you may face compliance costs or operational restrictions later. The source material does not specify which regulations are likely, so this is an area of uncertainty. The prudent approach is to stay informed and design your deployments to be adaptable.

A seventh mistake is neglecting to document your robot’s connectivity. The source material does not explicitly state this, but the described risks—anonymous credentials, unrestricted access—imply that many organisations do not have a clear picture of their robot’s network exposure. Without documentation, you cannot audit, troubleshoot, or demonstrate compliance. The source material does not provide a documentation template, so you should create your own.

An eighth mistake is assuming that trust in robotics is universal. The source material reports that 77% of technology leaders trust robotics for essential functions. This means 23% do not. If you are in the minority, or if your stakeholders are, you need to address their concerns directly. The source material identifies the top trust drivers—safety, reliability, consistency, and security—so use these as talking points. The source material does not provide guidance on how to win over sceptics, but the survey data gives you a starting framework.

A ninth mistake is overlooking the maintenance burden. The source material’s care-robot research found that users want robots to charge and clean themselves. In an industrial context, this translates into a preference for robots with low maintenance requirements. The source material does not provide specific maintenance intervals or spare-part lead times, so you should request this information from vendors. Do not assume that a robot’s maintenance needs are negligible just because it is new.

A tenth mistake is failing to consider the full lifecycle of the robot’s connectivity. The source material states that IIoT integration is growing, which implies that robots will become more connected over time. If you purchase a robot with limited connectivity today, it may become obsolete or require significant upgrades. The source material does not provide a timeline for this evolution beyond the 23% annual growth figure, so you should plan for flexibility.

In summary, the source material paints a clear picture: industrial robots are connected, sometimes dangerously so, and trust in them is built on a combination of safety, reliability, consistency, and security. The practical steps are to audit your network, enforce authentication, segment your systems, plan for IIoT growth, evaluate trust factors, consider human needs, monitor regulations, and document everything. The mistakes to avoid are assuming isolation, ignoring credentials, treating security as one-time, neglecting network safety, ignoring human factors, failing to plan for regulation, skipping documentation, assuming universal trust, overlooking maintenance, and ignoring lifecycle connectivity. The source material does not provide all the answers—it does not specify vendors, exact numbers of exposed robots, or specific regulatory proposals—but it provides enough to guide a responsible approach.

Sources

When trust in robotics comes down to the Internet connection

Published by Vigla Media OÜ (Estonia).