Skip to content
Source
Robotics & Automation News· Sam Francis·· 3 hours agoEditorial score28

Securing Robotics Infrastructure: Cloud, On-Premises, or Hybrid

Cloud, on-premises or hybrid: Securing robotics infrastructure

Summary

Robotics systems face unique security challenges. Cloud, on-premises, and hybrid setups each offer distinct security models, with responsibilities split differently. Compliance and control remain critical factors in choosing the right approach.

Source: Robotics & Automation News · Read original article ↗

Article text · Original source · English

On this page

A robot arm doesn’t care where the server lives

There is no single safest option. Cloud, on-premises and hybrid setups can all protect robotics systems well. They just split responsibility differently, and most factories end up blending them.

Sounds neat on paper. In practice, it’s messy. A welding cell, a fleet of warehouse robots and a vision-inspection camera all produce data.

Somebody has to decide where that data lives, who touches it and what happens when something breaks at 3am (Production lines rarely fail at convenient hours.)

Industrial automation is also colliding with IT more than ever. Machines that once sat behind a locked door now talk to dashboards, analytics engines and remote engineers. That connectivity is the whole point. It’s also the new attack surface. So where should it all run?

Who holds the keys? Responsibility in the cloud and on-prem

Everything else hangs on this question, so it comes first.

In the cloud, security runs on the shared responsibility model. AWS describes it as security “of” the cloud versus security “in” the cloud. The provider protects the infrastructure underneath: facilities, hardware, the virtualization layer.

The customer secures what is built on top, such as guest operating systems, application software and firewall configuration. (Other major providers follow comparable logic, though the exact split depends on the service chosen.)

On-premises flips the arrangement. The plant owns every layer, from server-room door locks to patch schedules. Total control, total accountability. Nobody else to blame.

For a full side-by-side comparison of both approaches across responsibility, compliance, threats and costs, see https://svitla.com/blog/cloud-vs-on-premises-security/

Where each model usually slips

Neither is bulletproof. The weak spots just look different:

  • Cloud: misconfiguration. An open storage bucket, an over-generous access role, an exposed port. Attackers scan for exactly these.
  • On-premises: ageing systems and thin monitoring. Legacy software that no longer receives security updates is a classic blind spot, and insider activity can go unnoticed without proper logging.

Robotics adds a twist. A misconfigured cloud dashboard might leak data. A compromised control network can halt a line.

Compliance: the standards that matter on the factory floor

Cloud versus on-prem is only half the story. Industrial environments also answer to a rulebook written for machines.

IEC 62443 is a series of standards covering the security of industrial automation and control systems (IACS) across their lifecycle. It is developed jointly by the ISA99 committee and IEC technical committee 65.

ISA describes it as the only consensus-based cybersecurity standard series built specifically for automation and control applications.

One part, IEC 62443-1-6, covers applying the series to the industrial internet of things, which is handy for connected robots. Another, 62443-4-2, sets technical requirements for components such as embedded devices, network components and software applications.

Kevin Staggs of Honeywell, who led the group behind that component standard, said it provides “a common language for product suppliers and all other control system stakeholders.”

Why does this matter for the infrastructure debate? Neither model delivers compliance automatically. Cloud providers hold certifications for their own infrastructure, but data residency, access policies and workload configuration stay with the customer.

On-premises offers direct control over every audit touchpoint, along with the paperwork that comes with it.

What the industry itself is doing

Vendors aren’t picking sides. They’re building for both.

Rockwell Automation built its FactoryTalk Design Studio cloud-first instead of retrofitting cloud features onto legacy desktop software.

Microsoft Azure supplies identity, security and compliance capabilities underneath. The pitch: engineers get modern cloud tools without dropping the security rigor that operational technology demands.

Then there’s Claroty. Its SaaS-powered xDome platform joined Rockwell’s global services portfolio, and Rockwell customers can also access Claroty’s cloud-based and on-premise OT security offerings.

Matt Kennedy of Rockwell called advanced cloud-based OT security something that “isn’t just a value-add; it’s a necessity.”

The warning isn’t new, either. Back in 2016, Martyn Williams of COPA-DATA UK argued that industrial security had stopped being an IT-department matter. It had become a round-the-clock job that reaches the boardroom.

The pattern is clear. Even the biggest names offer both deployment styles, because customers need both.

Hybrid, edge and the questions worth asking first

So why does hybrid cloud security keep coming up? Robotics workloads aren’t uniform. Time-sensitive control loops generally stay close to the machine, while analytics, fleet dashboards and long-term storage fit the cloud neatly.

Edge computing security then becomes its own job, because local gateways need patching and monitoring too.

Hybrid isn’t magic. Two environments mean two sets of controls, and gaps tend to appear at the seams. Ugh.

Before choosing, a plant can run through five questions:

  1. Which data legally or contractually has to stay on-site?
  2. What happens to production if the internet link drops?
  3. Who patches what, and how fast?
  4. Which standards (IEC 62443 included) apply to the system?
  5. Does the team have the skills to run security in-house around the clock?

If the answers differ from system to system, that’s usually a hybrid signal.

Final thoughts

The honest verdict? The safest infrastructure is the one a team can actually manage. Cloud offers speed, scale and built-in tooling, provided configurations get constant attention.

On-premises hands over control, provided budget and expertise keep pace. Hybrid borrows from both and inherits the complexity of both.

For robotics and automation, the practical path often starts with classifying data and systems, writing down who is responsible for what, and aligning with IEC 62443 early rather than bolting it on later. Small steps, revisited often. Threats evolve, so the setup should too.

Here’s to fewer 3am alerts, tidier audits and robots that keep doing exactly what they’re told.

Print Friendly, PDF & Email

Source:Robotics & Automation News · roboticsandautomationnews.com

Timezone · UTC

Article dates follow your selected timezone. Briefing editions use Hong Kong time (UTC+8).