Plan before a strange event becomes an emergency

Before connecting a KOKO trial unit, request the security contact and incident instructions for that program. Homebot One's overview does not include a household incident playbook. The response steps should explain how to stop safely, preserve relevant records, limit access, restore service, or return hardware.

This guide adapts public NIST and CISA practices into questions for a home or small pilot team; it does not claim that a KOKO security incident has occurred. Treat the vendor contact path, supported containment steps, evidence handling, and return-to-service criteria as part of the deployment decision.

Review the KOKO software-update policy questions

Plan KOKO service and support contacts

Define triggers and decision owners in advance

Write examples that should start a response: an unrecognized account, unexpected remote session, configuration change, unexplained movement, repeated authentication alerts, missing device, suspected data disclosure, unusual network traffic, or a vendor security notice. These are general planning examples, not reported KOKO behaviors. Ask which signs the current build can display, log, or alert on and which may only be visible through a router, app, or support channel.

Assign one person to protect people and the physical space, one to contact Homebot One, and, for an organizational pilot, one to coordinate security, privacy, legal, and communications duties. In a household, the same person may fill several roles. Record an alternate if the owner is unavailable. Decide who can pause routines, isolate the device, revoke accounts, approve reactivation, and notify affected people.

  • Safety lead for movement, people, pets, and the room
  • Technical lead for accounts, network, logs, and vendor instructions
  • Privacy lead for affected people and potentially exposed information
  • Decision owner for containment, return to service, and final closure
  • Primary and backup contacts at Homebot One or the program sponsor

Contain safely and preserve useful evidence

Human safety comes first. If behavior could create physical risk, use the documented stop or safe-state procedure and keep people clear. Do not improvise a power, network, or mechanical action that conflicts with manufacturer instructions. For a suspicious digital event without immediate physical danger, ask the designated technical lead or Homebot One whether to revoke a session, isolate a network path, pause an integration, or take another supported action.

Record what was observed, the local time, affected account or device, recent changes, and every response action. Preserve screenshots, alert text, relevant router or application events, and case numbers without copying unnecessary household content. CISA emphasizes protected logging and named response contacts, while the NIST Cybersecurity Framework organizes outcomes across Govern, Identify, Protect, Detect, Respond, and Recover. The goal is a reliable timeline, not amateur forensic analysis.

  • Do not erase, factory-reset, or update the unit before receiving appropriate guidance
  • Do not post suspected private data or credentials in public forums
  • Do not reconnect the device merely to see whether the issue repeats
  • Do document each change so the team can understand what evidence may have changed

Review household Wi-Fi and offline behavior questions

Coordinate notification and recovery from confirmed facts

A suspected event is not automatically a confirmed breach. Ask Homebot One what it can determine, which components were affected, the time window, what containment has occurred, and what users should do. An organization may have contractual, regulatory, insurance, or internal reporting duties that a household does not. Route those decisions to the responsible professionals rather than promising a universal notification timeline in a generic playbook.

Recovery should have explicit criteria. Confirm the software and configuration state, reset or replace credentials as directed, review integrations, verify that monitoring is working, and run a low-risk routine in a controlled space. Record who approved service restoration and which capabilities remain disabled. If the root cause is uncertain, a restricted mode or continued pause may be the correct result.

Review privacy and data-value tradeoffs

Check warranty and repair responsibilities

Run a short tabletop and improve the plan

A tabletop is a discussion, not an attempt to trigger a real incident. Give the team a simple scenario: the owner receives an unexpected login alert while KOKO is scheduled to run a routine. Ask what happens in the first five minutes, who is called, which safe action is permitted, what evidence is saved, how residents are informed, and who decides the device can operate again. Use no real credentials and do not disrupt an active care or research activity.

After the exercise, correct missing contacts, ambiguous authority, inaccessible instructions, and unrealistic assumptions. Date the plan and repeat the discussion when the build, network, household, integration, or program terms change. NIST SP 800-61 Rev. 3 places incident response within ongoing cybersecurity risk management. Use that approach to keep preparation, detection, response, recovery, and lessons learned connected.

  • Current contacts and support hours
  • Approved stop, isolation, and account-revocation actions
  • Minimum incident record and secure storage location
  • Recovery tests and person authorized to resume use
  • Lessons learned, owner, and due date for each correction

Include service interruption in the response plan

Review the KOKO price and value buyer hub

Frequently asked questions

Has a cybersecurity incident involving KOKO been reported here?

No. This is a preparedness guide and does not allege that KOKO has experienced a cybersecurity incident. Current security information should come from Homebot One and applicable official notices.

Should I immediately factory-reset KOKO after suspicious activity?

Protect people first, then follow the documented product and incident instructions. A reset can alter useful evidence or configuration, so do not treat it as a universal first step.

What information should an initial incident note contain?

Record what was observed, date and time, affected device or account, recent changes, people present, actions taken, alerts or screenshots, and the support case number while avoiding unnecessary sensitive content.

When can KOKO return to service after a suspected incident?

Use written recovery criteria for the specific case: containment, verified software and configuration, credential actions, integration review, monitoring, a controlled low-risk test, and approval by the named owner.

Sources & further reading

  1. Homebot One: Official KOKO overview and development status (opens in a new tab)
  2. NIST: Cybersecurity Framework 2.0 (opens in a new tab)
  3. NIST SP 800-61 Rev. 3: Incident Response Recommendations and Considerations (opens in a new tab)
  4. CISA: Use Logging on Business Systems (opens in a new tab)

From Homebot One, the team building KOKO in Fremont, California.