Penetration testing
Security research on automotive ECUs to find vulnerabilities in hardware and software.
Automotive security
Modern vehicles are networks of 100+ ECUs connected to the cloud. We test every layer, from hardware and firmware to CAN, diagnostics, wireless interfaces and backends, and turn the findings into ISO/SAE 21434 evidence.
In short
Automotive penetration testing is a hands-on security assessment of vehicle components, such as ECUs, gateways, infotainment, telematics and backends, to find exploitable vulnerabilities. Zyberum combines manual testing with automated fuzzing (AutoST) and delivers CVSS-rated findings in a TARA-compatible format that feeds directly into ISO/SAE 21434 and UN R155 compliance.
What we do
Security research on automotive ECUs to find vulnerabilities in hardware and software.
Automated fuzzing of UDS, DoIP, SOME/IP and CAN stacks to uncover crashes and memory bugs.
Review of security concepts and requirements for newly planned ECUs and architectures.
Threat analysis and risk assessment for ECUs and vehicle concepts according to ISO/SAE 21434.
Test scope
We test real hardware in our lab or at your site, following established methodologies.
JTAG/SWD debug probing, firmware extraction, fault injection, side-channel analysis and PCB reverse engineering.
Binary analysis with Ghidra/IDA, secure boot chain, crypto implementation and update mechanism review.
CAN/CAN FD bus security, UDS/KWP2000 diagnostics, gateway bypass and inter-ECU communication.
Bluetooth/BLE, Wi-Fi, 4G/5G, V2X, TPMS, key fobs (relay, replay, rollback) and NFC.
Telematics platforms, OTA update servers, companion app APIs and vehicle-to-cloud channels.
HSM configuration, key storage, certificate management and cryptographic protocol implementations.
IVI systems, Android/iOS companion apps and the boundary between infotainment and safety domains.
Charging communication (ISO 15118 / PLC) and backend interfaces of charging infrastructure.
Why now
Since July 2024, UN Regulation No. 155 (cybersecurity) and No. 156 (software updates) apply to all new vehicles registered in the EU and other UNECE WP.29 markets. OEMs must operate a certified Cybersecurity Management System (CSMS) and prove that risks in the entire supply chain are managed.
ISO/SAE 21434 defines how to engineer that: from TARA in the concept phase to verification, validation and penetration testing before production. Suppliers are increasingly asked to deliver this evidence with every component.
Approach
Define scope, critical assets and a targeted threat model based on your architecture and risk profile.
From zero-knowledge attacker simulation to full source-code access with engineering support.
Hands-on testing against real hardware, chaining vulnerabilities to demonstrate real-world impact.
Detailed findings, fix guidance and a retest cycle until the issues are closed.
Compliance consulting
Policies, roles, competence management and continuous improvement that meet ISO/SAE 21434 and UN R155.
ISO/SAE 21434 consultingAsset identification, threat scenarios, attack feasibility, risk values and treatment decisions.
Cybersecurity case, assessment reports and full traceability from requirements to verification evidence.
FAQ
UN R155 is a legal regulation: vehicle manufacturers need an approved Cybersecurity Management System and must demonstrate it for type approval. ISO/SAE 21434 is the engineering standard that describes how to perform cybersecurity activities across the vehicle lifecycle. It is the most common way to meet the R155 requirements.
Typically two to six weeks, depending on the number of interfaces, the level of access (black, grey or white box) and whether hardware attacks are in scope. We give you a fixed scope and offer after the scoping call.
Ideally yes: two to three samples of the ECU plus a bench setup or wiring harness. We can also test at your site, in a vehicle, or remotely via a test bench you provide.
Yes. Our AutoST suite fuzzes UDS, DoIP, SOME/IP and CAN/CAN FD and can run in your CI or HIL environment, so regressions are caught before every release.
Get started
Tell us about your ECU, its interfaces and your SOP date. You talk directly to an automotive pentester.

Your call is withTom ZaubermannFounder & CEO, Zyberum
We reply within one business day.
Your privacy
We use cookies and similar technologies to measure our website and the success of our ads. You decide which ones we may use. You can change your choice at any time via "Cookie settings" in the footer. Privacy policy