
As warehouses become highly connected, digital environments, they are also exposing a rapidly expanding cyber risk surface across operational technology, automation systems and third‑party integrations. Here, experts offer best practices for protecting smart warehouses’ system integrity and operational continuity.
BY SARA PEARSON SPECTER
WAREHOUSES HAVE UNDERGONE a dramatic transformation over the past decade. What were once primarily manual environments are now dense, digitally orchestrated ecosystems powered by connected devices—barcode scanners, radiofrequency identification (RFID) readers, autonomous mobile robots (AMRs), conveyor systems, warehouse execution platforms and environmental sensors—all working together in real time.
This connectivity is unlocking unprecedented gains in speed, accuracy and visibility. But it’s also creating one of the most rapidly expanding—and least understood—cyber risk surfaces in the supply chain. A 2025 study from the Massachusetts Institute of Technology (MIT) Center for Transportation and Logistics, “Identifying the Key Vulnerabilities in the Warehouses of the Future,” found that more than 70% of warehouse operators rely on interconnected operational technology (OT) systems that were not originally designed with cybersecurity in mind, while more than half lack full visibility into all connected assets within their facilities.
The report also highlights how increased integration, remote access and cloud‑based orchestration have made lateral movement between information technology (IT) and OT environments far more achievable. At the same time, expanding vendor ecosystems—spanning automation providers, software platforms and remote support partners—have introduced new exposure points, with third‑party access now among the most common attack vectors. As a result, many organizations are rethinking traditional IT‑centric security approaches and moving toward more integrated, operations‑aware strategies that better align cybersecurity with the realities of warehouse operations.
To better understand how the industry is responding, MHI Solutions spoke with five experts working at the intersection of supply chain operations, automation and cybersecurity:
- Dan Barrera, Head of Warehouse Automation at MHI member Bosch Rexroth
- Jason Hunt, U.S. Cyber & Strategic Risk Principal, Deloitte
- Matt Sterner, Global Customer Marketing Leader at MHI member Honeywell Industrial Automation
- Abdil Tunca, Supply Chain Analyst, Gartner
- Erika Voss, Ph.D., Chief Security Officer at MHI member Blue Yonder
In the following roundtable discussion, these leaders share their perspectives on where vulnerabilities are emerging, how risk is evolving and—most importantly—what best practices are taking hold among organizations working to secure the modern, connected warehouse.
MHI SOLUTIONS: AS WAREHOUSES BECOME MORE DENSELY CONNECTED, WHICH DEVICES OR SYSTEMS ARE EMERGING AS THE MOST VULNERABLE ENTRY POINTS? WHAT STEPS ARE LEADING ORGANIZATIONS TAKING TO SECURE THEM?
Barrera: As warehouses become more densely connected, the most vulnerable entry points are typically devices at the edge of the network. These include mobile and handheld devices such as scanners, tablets and wearables used in goods‑to‑person and person‑to‑goods workflows, as well as Internet of Things (IoT) components like RFID readers, IO‑Link sensors and IoT cameras. At the operational level, industrial control systems managing AMRs, automated storage and retrieval systems (AS/RS), sorters, robotic systems and conveyors also represent critical exposure points, particularly as these systems become more networked and integrated horizontally and vertically (as in edge and IT).
Because all of these devices are connected to the broader infrastructure, any gap in their security can create an entry point for disruption. Risks often stem from inadequate device hardening, lack of proper security controls from vendors or unauthorized access through embedded browsers or unsecured interfaces.
Leading organizations are addressing these vulnerabilities through multi‑layered security. This includes strong access controls such as two‑factor authentication, hardened industrial‑grade devices with long‑term operating system support and kiosk‑mode configurations that restrict user access. Network segmentation is also critical, isolating devices and systems into separate zones or virtual local area networks (VLANs) to limit lateral movement—similar to separating guest and corporate networks. Additional measures, such as physical security policies, USB restrictions and a broader “secure by design” philosophy—where systems are built with security embedded from the ground up and aligned with standards like IEC 62443—are helping reduce risk and strengthen overall resilience.
Hunt: Organizations that are being proactive start with the basics: understanding what their footprint looks like—what they have, what’s out there and what’s actually vulnerable. From there, the focus shifts to the systems and devices that present the greatest risk. It’s less about trying to fix everything and more about taking a risk‑based approach. The idea that you can “patch everything” just turns into whack‑a‑mole. Not everything is created equal, especially in operational environments, so the priority becomes identifying the most critical assets and the points closest to the edge that could enable a broader compromise.
That same mindset carries into modern warehouse environments, where one of the biggest shifts is the move away from hardwired systems to wireless‑connected robotics and automation. A common risk is organizations placing these devices on networks that weren’t purpose‑built for them—like guest networks—without fully considering the implications.
MHI SOLUTIONS: HOW HAS THE RISE OF MOBILE AND AUTOMATED EQUIPMENT CHANGED SECURITY EXPECTATIONS FOR BOTH OPERATORS AND EQUIPMENT VENDORS?
Sterner: The rise of mobile and automated equipment has created a structural change in risk, as all of these connected devices introduce new entry points that can be used to access networks and cause operational disruptions—expanding both cyber risk and the physical safety risk of workers at the same time. In response, expectations for operators and vendors have shifted toward secure‑by‑design equipment built to defend against cyberattacks, protected communication protocols and lifecycle accountability that includes ongoing security patches. Just as important is the need for clearly defined responsibilities across all parties, including OEMs, integrators and end users.
Voss: As warehouses become more mobile and automated, security becomes more of an operational issue, not just an IT concern. Systems that were never designed with security in mind—like HVAC or supervisory control and data acquisition (SCADA)‑based controls—are now connected, and they can be some of the easiest entry points into a network. The same is true for mobile devices. We rely on them for everything, but they’re essentially carrying internet connectivity into every corner of the operation. Yet, the more functionality you push into mobile and automated systems, the more you have to assume they can be compromised—and design your defenses accordingly.
As automation becomes more sophisticated, the role of software becomes even more critical. That introduces new considerations around software integrity, update management and data security. Organizations need to ensure that every update is validated, every configuration is controlled and every data input is trusted.
Tunca: Today’s equipment vendors are increasingly expected to support encrypted communications and secure software updates. If you have risk management programs, documenting those cybersecurity processes becomes important. On the customer side, operators are asking tougher questions when they’re adopting technology. Instead of focusing solely on throughput, accuracy, cost or return on investment, they’re asking how software updates are managed, how those weak spots are disclosed after implementation. Security is becoming part of a buying decision rather than an afterthought after deployment.
MHI SOLUTIONS: WHAT BEST PRACTICES ARE YOU SEEING AROUND NETWORK SEGMENTATION AND ARCHITECTURE DESIGN THAT ALLOW COMPANIES TO ISOLATE RISK WITHOUT DISRUPTING WAREHOUSE PERFORMANCE?
Hunt: A lot of best practices around network segmentation start with keeping it simple. Where organizations tend to struggle is trying to do too much in one fell swoop. The focus should first be on better controlling how data moves between a site and the corporate network or other locations. Get that right, then expand into deeper segmentation based on the criticality of specific sites. Today, there are also more flexible options than in the past. Instead of relying solely on physical firewalls, organizations can use more logical segmentation approaches, with tools that can evaluate traffic and even make recommendations based on observed behavior.
At the same time, segmentation isn’t just about the physical network. It also requires a fresh look at identity and access management, particularly within systems like Active Directory. Many attacks ultimately rely on elevated privileges, so the question becomes whether organizations are giving enough attention to how access is structured and managed. It’s not necessarily about completely overhauling environments, but about ensuring the right level of control and oversight is in place to limit risk without disrupting operations.
Segmentation is becoming a foundational practice. The idea is to create clear boundaries between different parts of the environment—IT systems, operational systems and external connections—and strictly control how they interact. This limits the potential impact of an incident and makes it easier to monitor and manage activity across the network.
Voss: Best practices are really converging around segmentation—whether that’s traditional network segmentation or more granular micro‑segmentation. The goal is to ensure the right controls are in place: closing unnecessary ports, restricting access points and clearly defining where traffic is allowed to flow.
What organizations are doing is really stepping back and looking at their entire attack surface. If someone wanted to cause disruption, how could they do it? In supply chain environments, that becomes especially complex because we’re often dealing with legacy systems—transportation management systems and warehouse management systems—that have been in place for decades and continue to function reliably.
So when you start talking about ransomware or segmentation, you sometimes see a bit of a deer‑in‑the‑headlights reaction. The way through that is to prioritize: what is most critical versus least critical? From there, you can design segmentation logically.
That includes asking very practical questions: Are robotics systems segmented? Are OT environments properly isolated? How are those OT systems secured and managed? And where do warehouse applications, corporate IT and third‑party vendors intersect? Those boundaries—and how clearly they’re defined—are what ultimately determine how resilient the operation is.
Barrera: One principle we emphasize is ‘deny by default.’ Systems shouldn’t automatically trust each other just because they’re on the same network. We’re seeing organizations implement segmentation through VLANs, firewalls and isolated environments. In some cases, vendors are placed in sandboxed areas, so their access is controlled and contained. That way, if something goes wrong, it doesn’t affect the rest of the operation.
Click here to read the full article.
MHI Solutions Improving Supply Chain Performance