02/02/2026
Quick story from today:
A vendor tried to connect a robot at a client site. It was blocked by our firewall geofencing (we restrict traffic to China).
We asked for the robot’s destination IPs/FQDNs so we could allowlist only what was necessary.
Vendor said: “We don’t know them… and they change.”
That’s not a reason to open the network wider. That’s a reason to stop and reassess.
We advised the owner not to “open up to all of China” to make a device work. He agreed and supported the secure decision.
Lesson: If a vendor can’t define or control a device’s network dependencies, you can’t properly manage the risk.