Humanoid Robot Security Checklist
A practical 32-point security checklist for teams buying, deploying or operating humanoid and service robots. It turns the lessons from real robot vulnerabilities, like the Unitree G1 CVEs, into checks you can run before and after a robot joins your network.
Before you buy
- Ask the vendor for a list of known CVEs and the firmware version that fixes each one.
- Request a software bill of materials (SBOM) for the robot's main computer and controllers.
- Ask whether the robot has had an independent security test, and when.
- Confirm how long the vendor commits to security updates for this model.
- Check whether the model or vendor is affected by import rules such as the FCC Covered List.
- Ask what data the robot collects, where it is sent and whether it can run without the vendor cloud.
Network and connectivity
- Put robots on their own network segment, separated from office and production systems.
- Block all inbound connections to robots from the internet.
- Allow outbound traffic only to the vendor endpoints the robot actually needs.
- Disable or restrict remote-control and cloud features you don't use.
- Monitor robot network traffic and alert on unusual destinations or volumes.
Free for subscribers
Get the full checklist and the PDF
Subscribe to The Humanoid Threats Brief (free, one email a week) to unlock the rest of this page and the printable PDF.
Already subscribed? Sign in.