# We hack your IoT, vehicles, plants and IT. Before someone else does.

> Zyberum GmbH is a German cybersecurity company based in Hannover, specialising in IoT, automotive, OT and IT security. It offers penetration testing and fuzzing of connected products, compliance consulting for the EU Cyber Resilience Act, ISO/SAE 21434, UN R155, IEC 62443 and NIS2, the AutoST automated security testing suite, and Zyberdome, a fixed-price 24/7 managed SOC for small and medium-sized businesses.

Zyberum secures IoT devices, vehicles, industrial systems and business IT: penetration testing, CRA, ISO/SAE 21434 & IEC 62443 compliance and a 24/7 SOC.

Source: https://zyberum.com/

Zyberum is a team of security engineers who take real devices apart, break real systems and show you exactly how to fix them. Less paperwork, more proof. Compliance with the CRA, ISO/SAE 21434 and NIS2 follows from the work, not the other way round.

## Four domains. One team of hands-on security engineers.

Devices, vehicles, machines and corporate networks are converging, and so are their attack surfaces. We secure all of them, from the chip to the cloud.

### IoT & product security

Penetration testing of connected devices, firmware and apps, plus CRA-ready secure development for manufacturers of products with digital elements.

### Automotive security

Pentesting and fuzzing of ECUs, gateways, infotainment and backends. TARA and compliance for ISO/SAE 21434 and UN R155.

### OT & industrial security

Assessments and hardening of PLC, SCADA and DCS environments to IEC 62443 and NIS2, without disrupting production.

### IT security for SMBs

Infrastructure, web and cloud pentests, plus Zyberdome, our fixed-price 24/7 managed SOC for small and medium-sized businesses.

## Less paper. More proof.

Security that only exists in a document protects nobody. This is how we work instead.

### Hands on the hardware

We solder, dump firmware, sniff buses and write exploits. If we say something is vulnerable, you get the proof-of-concept.

### Results you can act on

Every finding comes with a severity, the steps to reproduce it and a fix. Your engineers can start the same day.

### Compliance as a by-product

The evidence for the CRA, ISO/SAE 21434, IEC 62443 and NIS2 comes out of real testing, not out of templates.

### We build our own tools

What we learn in the lab, we automate. AutoST, our ECU security testing suite, is the result.

### Engineers talk to engineers

No account managers in between. You talk to the people who test your system.

### AI that stays in our lab

Our testers work with self-hosted AI models. Nothing about your systems goes to a cloud service, and you get more coverage for the same budget.

## Certified where it counts

Certificates do not find vulnerabilities, people do. These are the ones our customers ask for.

## What it looks like when we test

Two IoT products, two tests, and findings nobody wants to read about their own device.

## From secure design to 24/7 operations

Our services follow the lifecycle of your product and your business, backed by our own tools.

### Penetration testing

Hands-on security research on devices, vehicles, industrial systems, applications and infrastructure, with proof-of-concepts and retests.

### Secure development

Secure coding training, source code review, threat modelling and DevSecOps, so fewer vulnerabilities are written in the first place.

### Cyber Resilience Act readiness

Gap analysis, secure development lifecycle, vulnerability handling and testing to get products with digital elements CRA-ready.

### AutoST: automated ECU testing

Fuzzing, security tests and vulnerability scanning over UDS, CAN FD, DoIP and SOME/IP, with evidence for UN R155 and ISO/SAE 21434.

### Zyberdome: managed SOC

Endpoint protection, 24/7 monitoring and incident response for Windows, macOS and Linux, from €12 per device per month.

### Hands-on training

Automotive hacking with real ECUs and 30+ CTF challenges, secure coding for developers and ISO/SAE 21434 compliance courses.

- 15+: years in IT and product security
- 4: security domains: IoT, automotive, OT, IT
- 24/7: SOC monitoring with Zyberdome
- 360°: coverage from device firmware to the cloud

## From first call to fixed findings

1. **Scope & threat model** We agree on goals, assets and constraints, and build a threat model around your architecture.
2. **Test & analyse** Black, grey or white box. Hands-on testing on real hardware, networks and code, backed by automation.
3. **Report & prioritise** CVSS-scored findings, proof-of-concepts and a remediation roadmap, in a TARA-compatible format.
4. **Fix & retest** We support your engineers through remediation and verify the fixes, producing audit-ready evidence.

## FAQ

**What does Zyberum do?**

Zyberum is a cybersecurity company from Hannover, Germany, focused on IoT, automotive, OT and IT security. We perform penetration tests and fuzzing, support compliance with the CRA, ISO/SAE 21434, UN R155, IEC 62443 and NIS2, build the AutoST security testing suite and run Zyberdome, a managed SOC for SMBs.

**Which industries does Zyberum work with?**

IoT and electronics manufacturers, automotive OEMs and suppliers, industrial companies and critical-infrastructure operators, and small and medium-sized businesses, as well as healthcare and software companies.

**Do you work outside Germany?**

Yes. We are based in Hannover, Germany, and work for customers worldwide, on site or remotely, in English and German.

---
Zyberum GmbH. Canonical page: https://zyberum.com/
