Hardware & debug interfaces
UART, JTAG/SWD, flash extraction, fault injection and tamper resistance of the device.
IoT & product security
Smart devices, gateways and controllers, and the apps and clouds behind them, are attacked from day one. We test the complete IoT stack, from hardware and firmware to wireless, apps and cloud APIs, and help manufacturers build security in, as the EU Cyber Resilience Act now requires.
In short
IoT security testing is a hands-on assessment of a connected product as a whole: device hardware, firmware, wireless interfaces, companion apps and cloud backends. Zyberum performs IoT penetration tests and firmware analyses, supports secure development and vulnerability handling, and prepares manufacturers for the EU Cyber Resilience Act and standards such as ETSI EN 303 645 and IEC 62443-4-2.
Test scope
Attackers take the weakest path. We test all of them, in our lab or at your site.
UART, JTAG/SWD, flash extraction, fault injection and tamper resistance of the device.
Reverse engineering, hard-coded secrets, outdated components, secure boot and update integrity.
Bluetooth LE, Wi-Fi, Zigbee, Thread/Matter, LoRaWAN, cellular, MQTT and CoAP.
Companion apps (iOS/Android), web interfaces, device-to-cloud APIs and provisioning.
Security by design
Fixing a vulnerability after thousands of devices are in the field is expensive, and sometimes impossible. We work with your engineering team from the concept phase: threat modelling, security architecture and secure update mechanisms.
Our secure development services and secure coding training keep the firmware your team writes robust, and our testing proves it before launch.
Approach
We define the scope with you and build a threat model of the device, its interfaces and its backend.
Teardown, debug access, firmware extraction and analysis for secrets and vulnerable components.
Attacks on radio protocols, apps and cloud APIs, chained to show real-world impact.
CVSS-rated findings, remediation guidance and a retest, ready for your CRA technical documentation.
Case studies
Full root access on the device, and access to the live WebRTC camera of other users through the cloud API.
We tested a camera-equipped robot vacuum: root access on the device, and cloud API flaws that opened the live camera of other users. What went wrong and why.
Read the case studyWe could see and activate other customers’ devices through MQTT, and geolocate where they are installed.
We tested a smart irrigation system: a broken MQTT setup let us see and switch the devices of other customers, and locate where they are installed.
Read the case studyFAQ
An IoT penetration test is a security assessment of a connected product across all layers: hardware, firmware, radio interfaces, mobile apps and cloud services. Testers use real attacker techniques to find vulnerabilities before the product ships.
Yes. Almost all connected devices sold in the EU are products with digital elements under the CRA. From 11 December 2027 they must meet its essential cybersecurity requirements; reporting of actively exploited vulnerabilities already applies since 11 September 2026.
ETSI EN 303 645 for consumer IoT, IEC 62443-4-1 and 4-2 for industrial components, and the harmonised standards being developed under the CRA. For wireless devices, the cybersecurity requirements of the Radio Equipment Directive (EN 18031) have applied since 1 August 2025.
Typically two to four weeks for one product, depending on the number of interfaces and whether hardware attacks are in scope. You get a fixed-scope offer after a short scoping call.
Get started
Show us your device and its interfaces. We define the test scope together and send you a fixed-price offer.

Your call is withTom ZaubermannFounder & CEO, Zyberum
We reply within one business day.
Your privacy
We use cookies and similar technologies to measure our website and the success of our ads. You decide which ones we may use. You can change your choice at any time via "Cookie settings" in the footer. Privacy policy