Skip to content
Zyberum Cyber Security Firm
Menu

Automotive security

Find the vulnerabilities in your vehicle before attackers do.

Modern vehicles are networks of 100+ ECUs connected to the cloud. We test every layer, from hardware and firmware to CAN, diagnostics, wireless interfaces and backends, and turn the findings into ISO/SAE 21434 evidence.

  • ISO/SAE 21434
  • UN R155 / R156
  • Hands-on lab testing

In short

Automotive penetration testing is a hands-on security assessment of vehicle components, such as ECUs, gateways, infotainment, telematics and backends, to find exploitable vulnerabilities. Zyberum combines manual testing with automated fuzzing (AutoST) and delivers CVSS-rated findings in a TARA-compatible format that feeds directly into ISO/SAE 21434 and UN R155 compliance.

What we do

Four ways we secure your vehicle programme

Penetration testing

Security research on automotive ECUs to find vulnerabilities in hardware and software.

Fuzz testing

Automated fuzzing of UDS, DoIP, SOME/IP and CAN stacks to uncover crashes and memory bugs.

Security by design

Review of security concepts and requirements for newly planned ECUs and architectures.

Risk assessment (TARA)

Threat analysis and risk assessment for ECUs and vehicle concepts according to ISO/SAE 21434.

Test scope

Every layer of the automotive stack

We test real hardware in our lab or at your site, following established methodologies.

Hardware & ECU

JTAG/SWD debug probing, firmware extraction, fault injection, side-channel analysis and PCB reverse engineering.

Firmware reverse engineering

Binary analysis with Ghidra/IDA, secure boot chain, crypto implementation and update mechanism review.

Vehicle networks

CAN/CAN FD bus security, UDS/KWP2000 diagnostics, gateway bypass and inter-ECU communication.

Wireless & RF

Bluetooth/BLE, Wi-Fi, 4G/5G, V2X, TPMS, key fobs (relay, replay, rollback) and NFC.

Backend & APIs

Telematics platforms, OTA update servers, companion app APIs and vehicle-to-cloud channels.

Secure boot & keys

HSM configuration, key storage, certificate management and cryptographic protocol implementations.

Infotainment & apps

IVI systems, Android/iOS companion apps and the boundary between infotainment and safety domains.

EV charging

Charging communication (ISO 15118 / PLC) and backend interfaces of charging infrastructure.

Why now

Cybersecurity is a type-approval requirement

Since July 2024, UN Regulation No. 155 (cybersecurity) and No. 156 (software updates) apply to all new vehicles registered in the EU and other UNECE WP.29 markets. OEMs must operate a certified Cybersecurity Management System (CSMS) and prove that risks in the entire supply chain are managed.

ISO/SAE 21434 defines how to engineer that: from TARA in the concept phase to verification, validation and penetration testing before production. Suppliers are increasingly asked to deliver this evidence with every component.

Approach

How an automotive pentest works

  1. 01

    Scoping & threat modelling

    Define scope, critical assets and a targeted threat model based on your architecture and risk profile.

  2. 02

    Black, grey or white box

    From zero-knowledge attacker simulation to full source-code access with engineering support.

  3. 03

    Active testing & exploitation

    Hands-on testing against real hardware, chaining vulnerabilities to demonstrate real-world impact.

  4. 04

    Reporting & remediation

    Detailed findings, fix guidance and a retest cycle until the issues are closed.

Compliance consulting

ISO/SAE 21434 from CSMS to audit

CSMS implementation

Policies, roles, competence management and continuous improvement that meet ISO/SAE 21434 and UN R155.

ISO/SAE 21434 consulting

TARA

Asset identification, threat scenarios, attack feasibility, risk values and treatment decisions.

Audit preparation

Cybersecurity case, assessment reports and full traceability from requirements to verification evidence.

FAQ

Automotive security FAQ

What is the difference between ISO/SAE 21434 and UN R155?

UN R155 is a legal regulation: vehicle manufacturers need an approved Cybersecurity Management System and must demonstrate it for type approval. ISO/SAE 21434 is the engineering standard that describes how to perform cybersecurity activities across the vehicle lifecycle. It is the most common way to meet the R155 requirements.

How long does an ECU penetration test take?

Typically two to six weeks, depending on the number of interfaces, the level of access (black, grey or white box) and whether hardware attacks are in scope. We give you a fixed scope and offer after the scoping call.

Do you need our hardware?

Ideally yes: two to three samples of the ECU plus a bench setup or wiring harness. We can also test at your site, in a vehicle, or remotely via a test bench you provide.

Can you fuzz our diagnostic stack automatically?

Yes. Our AutoST suite fuzzes UDS, DoIP, SOME/IP and CAN/CAN FD and can run in your CI or HIL environment, so regressions are caught before every release.

Get started

Scope your ECU pentest in 15 minutes

Tell us about your ECU, its interfaces and your SOP date. You talk directly to an automotive pentester.

  • Test depth, samples and timeline clarified
  • Fixed-scope offer after the call
  • TARA-compatible reporting for ISO/SAE 21434
Tom Zaubermann

Your call is withTom ZaubermannFounder & CEO, Zyberum

Call us: +49 176 439 17074automotive@zyberum.com

Or send us a message

We reply within one business day.

Call usScope your ECU pentest

Pick a time that suits you

Open in a new tab