Covering robot devices, operating systems, communication, cloud platforms, AI models, Agents, and the motion-control chain, helping robot companies build a full-lifecycle security system that is identifiable, protectable, monitorable, responsive, and auditable.
For humanoid robots, industrial robots, service robots, AGV/AMR, inspection robots, and robot cloud platforms.
Supports security analysis and system building around ROS/ROS2, Linux, Android, cloud platforms, OTA, APIs, and third-party components.
1. Perception & Sensors
2. AI Models & Agents
3. Motion Control & Execution
4. Communication, Cloud & OTA
Callisto Robot Security targets humanoid robots, industrial robots, service robots, AGV/AMR, inspection robots, and robot cloud platforms. Built around five security domains — device and OS, communication and remote operations, AI and Agents, motion control, and cloud platform and security operations — it helps enterprises build identifiable, protectable, monitorable, responsive, and auditable security capabilities across the full R&D, production, delivery, operations, and vulnerability-response lifecycle.
Traditional IT attacks usually affect data and business systems, whereas embodied robots can perceive the environment, make decisions, and perform physical actions. Cyberattacks, model attacks, or loss of privilege control can further translate into device loss of control, production disruption, privacy leaks, and personnel safety risks.
Operating systems, ROS/ROS2, middleware, sensors, controllers, wireless communication, cloud platforms, and third-party components jointly form the attack surface.
Unauthorized control commands, communication hijacking, or policy tampering can affect robot actions and safety boundaries.
Including prompt injection, unauthorized tool calls, model poisoning, perception spoofing, memory poisoning, and task-planning tampering.
After delivery, robots still require ongoing vulnerability monitoring, OTA remediation, incident response, and version governance.
Build security capabilities layer by layer from the robot endpoint to the cloud platform, linked with the AI, Agent, and motion-control chains.
Secure Boot and firmware integrity
Linux / Android / ROS / ROS2 security checks
Process, file, permission, and system-call monitoring
Risk control for USB, debug ports, SSH, ADB, JTAG interfaces
Malicious code and abnormal process detection
Robot internal network and communication protocol analysis
ROS2 DDS communication security
Wi-Fi, Bluetooth, cellular, and private-network risks
API authentication and access control
Remote operations, debugging, and cloud-control channel security
OTA package signing, integrity verification, and rollback protection
Vision, voice, and sensor input risk analysis
Adversarial sample and perception-spoofing detection
LLM prompt-injection protection
Agent tool-call permission control
Integrity of models, prompts, knowledge bases, and policy files
Memory-poisoning and task-planning risk analysis
Safety validation before high-risk action execution
Control-command authorization and anti-replay
Limits on action range, speed, force, and zones
Degradation under anomalies, fail-safe on disconnection, and human takeover
Correlation analysis between cybersecurity and mechanical safety
Robot asset, version, and identity management
SBOM and third-party component vulnerability monitoring
Robot cloud platform and scheduling API security
Log ingestion, correlation analysis, and alert handling
Integration with VSOC / Robot-SOC
PSIRT, vulnerability disclosure, remediation, and audit closed loop
Actionable security modules organized around identify, protect, monitor, respond, and audit.
Identify attack entries across devices, OS, components, interfaces, communication, cloud services, and AI chains, producing asset inventories, data flows, and risk paths.
Perform vulnerability identification, malicious code analysis, and SBOM governance for firmware, OS, ROS packages, container images, and third-party dependencies.
Detect unauthorized access, weak authentication, cleartext transmission, protocol abuse, replay attacks, API privilege escalation, and abnormal data injection.
Review update-package signing, source authentication, version control, rollback protection, and remote debugging privileges to reduce supply-chain and remote-takeover risks.
Monitor abnormal processes, file changes, permission calls, network connections, resource consumption, and policy deviations, supporting alerts and coordinated handling.
Identify and constrain prompt injection, unauthorized tool calls, model input attacks, knowledge-base poisoning, and unintended task execution.
Apply classification, minimized collection, masking, encryption, and access auditing to audio/video, environmental, map, location, personnel, and operational data.
Integrate edge, cloud, and AI events into a unified platform for asset correlation, risk assessment, policy dispatch, remediation tracking, and evidence retention.
Covering six phases: security baseline, threat modeling, testing, remediation design, pre-launch audit, and continuous operations.
System architecture, software versions, communication interfaces, cloud platform materials
Asset inventory, SBOM, attack surface list
Asset inventory, attack surface, business and deployment scenarios
Threat model, attack paths, risk grading, remediation priorities
Firmware and software packages, communication protocols, APIs and remote channels
Vulnerability list, test evidence, reproduction steps, impact analysis
Risk grading, test conclusions, product and R&D constraints
Security architecture, control policies, remediation advice, interface requirements
Remediation results, release versions, deployment configuration
Validation report, residual risks, release recommendations, audit evidence
Runtime logs, threat intelligence, live incidents
Vulnerability alerts, impact analysis, remediation tracking, incident reports
There is currently no single global cybersecurity regulation for embodied robots. Robot companies typically need to consider digital product cybersecurity, machinery safety, AI governance, data protection, and operational security requirements at the same time. The applicability of the regulations below should be assessed based on product, use case, market, and deployment model.
| Regulation / Standard | Type | Primary Focus | Meaning for Robot Companies |
|---|---|---|---|
| EU Cyber Resilience Act (CRA) | EU Law | Product cybersecurity, vulnerability handling, security updates, technical documentation, SBOM, and incident reporting | Applies to "products with digital elements" within scope (not all robots unconditionally). Main obligations apply from 2027-12-11; known exploited vulnerability and serious incident reporting obligations apply from 2026-09-11. |
| EU Machinery Regulation 2023/1230 | EU Law | Preventing tampering of safety-related software and control systems; linking cyber risk with machinery safety | First determine whether the product falls within its scope. As machinery products, robots must incorporate cyber risk into machinery safety assessment. |
| EU AI Act | EU Law | Risk management, logging, human oversight, robustness, and cybersecurity for high-risk AI systems | Requires assessment based on use case, product regulations, and high-risk classification — not all AI-enabled robots are high-risk AI. Refer to the official timeline as of 2026-07. |
| NIS2 | EU Law | Enterprise risk management, supply chain, incident response, and business continuity | Applicability depends on entity sector, size, and member state transposition — not all critical-sector robot operators are automatically subject to NIS2. |
| IEC 62443 | Recommended Standard | Cybersecurity for industrial automation and control systems | An important reference framework for industrial robot and production-line security design and assessment (not EU law). |
| ISO 10218 / ISO/TS 15066 | Recommended Standard | Safety of industrial robots and collaborative robots | A foundational reference standard for mechanical and collaborative safety design. |
| ISO 13482 | Recommended Standard | Safety of personal care robots | A reference standard for service and care robot safety design. |
| ETSI EN 303 645 | Recommended Standard | Cybersecurity baseline for consumer IoT devices | A baseline security reference for connected robot devices (not EU law). |
| ISO/IEC 42001 | Recommended Standard | AI management system | A reference standard for building AI governance and management systems. |
Note: In the table above, the EU CRA, EU Machinery Regulation 2023/1230, EU AI Act, and NIS2 are EU laws; the IEC, ISO, ETSI, and ISO/IEC series are recommended standards or industry reference frameworks, not laws. Specific applicability must be assessed based on product, use case, market, and deployment model. Callisto supports requirement mapping, gap analysis, technical remediation, and compliance evidence building, and does not guarantee certification outcomes.
For each robot form factor, we outline the primary assets, typical risks, and key security capabilities.
Perception sensors, AI models and Agents, controllers, operational data
Perception spoofing, model/Agent privilege escalation, remote takeover, control-command tampering, and privacy data leaks
AI runtime protection, action safety validation, system integrity monitoring, and behavior auditing
Control programs, ICS network, PLC/controllers, production data
ICS network intrusion, ransomware, control-program tampering, supply-chain vulnerabilities, and line downtime
IEC 62443 risk analysis, network segmentation, protocol monitoring, runtime detection, and security operations
Scheduling systems, positioning and navigation, wireless communication, task data
Communication hijacking, positioning spoofing, scheduling privilege abuse, and fleet loss of control
Communication encryption and authentication, scheduling API security, anomaly monitoring, and coordinated handling
Physiological and imaging data, interaction systems, cloud records
Privacy data leaks, unauthorized access, command tampering, and compliance risks
Data classification, access auditing, privacy protection, and runtime monitoring
User data, maps and locations, payment and business interfaces
Privacy leaks, malicious manipulation, API privilege escalation, and business fraud
Authentication, permission governance, data masking, and anomaly detection
Imaging and inspection data, communication links, critical infrastructure information
Communication hijacking, footage tampering, data leaks, and unauthorized control
Transport encryption, integrity verification, access control, and security operations
Control channels, mission payloads, location and status data
Remote takeover, command tampering, communication interference, and privilege escalation
Strong authentication, anti-replay commands, action safety boundaries, and fail-safe handling
Device identities, scheduling APIs, versions and configuration, massive operational data
API privilege escalation, bulk data leaks, supply-chain risk, and lateral movement
Asset and identity management, API security, SBOM monitoring, and VSOC / Robot-SOC integration
Depending on project scope, Callisto can deliver the following robot security outputs.
Robot asset and attack surface inventory
System architecture and data-flow analysis
SBOM and third-party component risk report
Firmware and software vulnerability report
ROS / ROS2 and communication protocol test report
OTA and remote operations security assessment report
AI / Agent risk analysis report
Threat model and attack paths
Remediation recommendations and priorities
Security architecture and control policies
Runtime monitoring and alert rules
PSIRT and vulnerability response process
Regulation/standard mapping and compliance evidence package
The specific delivery scope is determined by product architecture, deployment scenario, and project phase.
Rather than focusing on single-device vulnerabilities, we cover robot endpoints, communication links, cloud platforms, AI models, and security operations.
We correlate attack paths with control privileges, action impact, and business consequences, helping customers identify the high-risk issues that truly affect product safety.
We support security assessment, product remediation, pre-launch validation, vulnerability monitoring, incident response, and operational closed loops.
We extend engineering experience in edge-cloud security, OTA, supply chain, vulnerability management, and security operations from intelligent vehicles to robots.
Robot cybersecurity protects robot devices, operating systems, communication, cloud platforms, AI models, and Agents from unauthorized access, command tampering, and data leaks. It spans the full R&D-to-operations lifecycle, aiming to prevent cyber risks from becoming physical safety risks.
Traditional robot security focuses on devices and networks, while embodied AI security must also cover AI models, perception inputs, and Agent decisions. Because embodied robots perceive the environment and perform physical actions, model attacks and privilege escalation can directly affect action safety.
The main risks include perception spoofing, model or Agent privilege escalation, remote takeover, control-command tampering, and privacy data leaks. Since humanoid robots interact directly with people and the physical environment, these risks can carry physical safety implications.
ROS2 is built on DDS and offers security mechanisms such as SROS2 that support authentication, encryption, and access control, but they may not be enabled by default. Effective risk reduction requires engineering configuration of node permissions, communication policies, and system hardening.
An SBOM (Software Bill of Materials) records the operating systems, open-source components, and third-party dependencies a robot uses. With an SBOM, companies can quickly locate affected components, assess vulnerability impact, and support vulnerability-handling and disclosure requirements under regulations such as the CRA.
Main risks include tampered update packages, untrusted sources, and lack of signature validation and rollback protection. If the OTA channel is abused, attackers may push malicious firmware or affect device availability, so signing, integrity verification, and version control are required.
We recommend enabling strong authentication, least privilege, channel encryption, and access auditing for remote debugging and cloud-control channels, and restricting high-risk entries such as SSH, ADB, and debug ports. All remote actions should be traceable and linked with operational monitoring.
Agents can call tools and drive actions, so prompt injection or unauthorized tool calls may trigger unintended actions. Tool calls need permission control, high-risk actions need pre-execution validation, and behavior logs should be retained for auditing.
IEC 62443 is a recommended standard for industrial automation and control systems, not a mandatory law. It is an important reference for industrial robot and production-line security design and assessment, and many customers and industries adopt it as a security requirement in procurement and audits.
Typically the EU CRA (product cybersecurity), EU Machinery Regulation 2023/1230 (machinery safety), EU AI Act (AI governance), and NIS2 (operational security). Callisto supports requirement mapping, gap analysis, and compliance evidence building, but does not guarantee certification outcomes.
It usually includes monitoring of abnormal processes, file changes, permission calls, network connections, resource consumption, and policy deviations, combined with alerting and coordinated handling. The goal is to promptly identify behavior deviating from normal logic and respond per policy.
Callisto provides attack surface analysis, firmware and SBOM analysis, communication and interface testing, OTA and remote operations security, runtime monitoring, AI/Agent security, data protection, and security operations, covering assessment, remediation, and continuous operations.
It usually requires system architecture, software versions, communication interfaces, cloud platform and OTA materials, plus deployment scenario and target market descriptions. More complete materials help define the priority assessment scope and attack surface list.
On top of a traditional SOC’s asset, log, and response capabilities, a Robot-SOC adds focus on robot endpoints, AI/Agents, and motion control, correlating edge, cloud, and AI events to support security monitoring and handling for large-scale robot operations.
If your product is entering mass production, customer audits, overseas certification, or large-scale operations, Callisto can conduct security assessment and system building around robot endpoints, ROS/ROS2, cloud platforms, OTA, AI Agents, and the supply chain.
Share your product type, system architecture, target market, and current phase, and we will help determine the priority assessment scope.
Last updated: July 2026 · Content by the Callisto Robot Security Team