Cybersecurity and Warehouse Robotics: Exotec's Supply Chain Strategy
When a robotic system manages restocking for several hundred stores or the distribution of automotive spare parts, its availability becomes a top-tier strategic issue. At the Tech For Industry Show, Pascal Férard, Head of Cybersecurityand Jérémie Rozenblum, Sales Executive (Exotec), a French provider of robotic logistics technology, detailed the company's cybersecurity strategy.
Exotec: 100% French Design and Manufacturing
Exotec designs and manufactures all of its robots — around 14,000 units currently in operation — at its French plant, which also serves as its headquarters, in Wasquehal. The company employs around 1,000 people, including 800 engineers, with integration teams present in North America, Europe and Asia-Pacific (South Korea, Japan). It now equips around twenty client sites across numerous countries, with notable references such as Decathlon — whose entire European store network is now restocked using Exotec technology — and Renault, for distributing spare parts to garages across France.
A System Touching Every Link in the Logistics Chain
Exotec's technology can operate at different levels of a client's supply chain: storing components ahead of assembly, storing semi-finished or finished products, or direct distribution to e-commerce customers. In every case, the strategic stakes are the same: downtime can translate into an assembly line stopping, unfulfilled customer orders, or customers unable to collect their order in-store.
A Connected Technical Architecture, Designed to Limit Exposure
The system includes a dedicated WiFi network, robot fleet orchestration servers, the robots themselves, conveyors, robotic arms and various ancillary machines (box forming, RFID tunnels). The whole thing is delivered turnkey and connected to the client's network, with an exposed API allowing the client's WMS (Warehouse Management System) to send picking orders — with the system then automatically identifying the fastest robot to fulfill the order. Exotec commits contractually to this performance, with associated penalties — a point presented as a strong differentiator for the company.
By design, this system isn't directly exposed to the internet, which limits the attack surface. It remains, however, exposed to the client's internal network (through strictly authorized application flows) and to the WiFi network, whose physical range inevitably extends beyond the warehouse walls.
Two Main Risks, Two Structured Responses
Total or Partial Downtime
A failure, a bug, or an attack deliberately targeting a company's logistics chain can slow down or completely stop the system. To address this, Exotec built a resilient architecture based on a master-slave system: if the master system fails, the slave system automatically takes over, with no visible impact on operations. This resilience is complemented by continuous monitoring from three control centers spread around the world (France, United States, Japan), covering every time zone, making it possible to detect a problem before it causes a production incident — and to intervene remotely if needed (for example, to free a stuck robot). According to the speaker, in 90% of cases, the client isn't even aware that an incident occurred and was resolved. Real-time — rather than daily — backup of inventory status also makes it possible to precisely restore the warehouse's state just before a major incident.
Regulatory Non-Compliance
Exotec made the strategic choice to embed cybersecurity as a commercial differentiator from the design stage of its solutions, obtaining ISO 27001 certification (a European standard, more process-oriented) alongside an annual SOC 2 Type II report (an American framework, more operationally oriented) — a dual certification now seen as nearly essential for engaging with large international accounts.
This compliance effort also addresses two European regulations: the NIS2 directive, which applies to nearly all European companies (Exotec being classified as an "important entity"), and for which the company estimates it has already covered around 80% of requirements thanks to its existing certifications; and the Cyber Resilience Act (CRA), specifically applicable to industrial products starting in 2027, a necessary condition for maintaining CE marking — itself essential for selling products in Europe.
Cybersecurity, a Sales Argument in Its Own Right
According to the speakers, cybersecurity has become, for many large industrial groups, a topic addressed even before commercial and logistics discussions — a kind of "entry ticket" conditioning whether talks continue at all. Exotec claims support that doesn't stop at the sale: the company remains engaged with its clients throughout the solution's entire lifecycle, with a results-based commitment (not just a best-efforts one) on system availability — cybersecurity being presented as an essential component of that commitment. According to the company, this approach is tied to a high repeat-purchase rate among existing clients.
A Sovereignty Dimension, with Nuance
Exotec highlights its French design and manufacturing as a factor of proximity and trust, particularly for French and European clients, and as a differentiator against competitors, notably Chinese ones. The speaker, however, transparently qualifies this positioning: the company also uses American cloud resources (hosted in a European region), which limits the scope of this sovereignty in the strict sense.
AI, Between Opportunity and New Risk
In closing, the session addresses the role of artificial intelligence: both as an accelerator, notably for identifying and fixing vulnerabilities in code, and as a growing source of risk as AI models become more powerful — the speaker referencing so-called "frontier" models and the need to prepare AI-based defenses against an expected surge in exploitable vulnerabilities.
Key Takeaways
Exotec's session illustrates how cybersecurity, far from being a peripheral constraint, can become a genuine commercial differentiator in a sector — robotic logistics — where system availability directly determines the client's business. By embedding security from the design stage and maintaining commitment throughout the solution's lifecycle, Exotec illustrates an approach to industrial cybersecurity conceived as a long-term investment rather than a mere regulatory obligation.
Watch the full session, along with the other Tech For Industry Show replays, on our dedicated page.