Skip to content
Zyberum Cyber Security Firm
Menu

IoT & product security

Connected products that stay secure for their whole lifetime.

Smart devices, gateways and controllers, and the apps and clouds behind them, are attacked from day one. We test the complete IoT stack, from hardware and firmware to wireless, apps and cloud APIs, and help manufacturers build security in, as the EU Cyber Resilience Act now requires.

  • EU Cyber Resilience Act
  • ETSI EN 303 645
  • IEC 62443-4-2

In short

IoT security testing is a hands-on assessment of a connected product as a whole: device hardware, firmware, wireless interfaces, companion apps and cloud backends. Zyberum performs IoT penetration tests and firmware analyses, supports secure development and vulnerability handling, and prepares manufacturers for the EU Cyber Resilience Act and standards such as ETSI EN 303 645 and IEC 62443-4-2.

Test scope

The complete IoT attack surface

Attackers take the weakest path. We test all of them, in our lab or at your site.

Hardware & debug interfaces

UART, JTAG/SWD, flash extraction, fault injection and tamper resistance of the device.

Firmware analysis

Reverse engineering, hard-coded secrets, outdated components, secure boot and update integrity.

Wireless & protocols

Bluetooth LE, Wi-Fi, Zigbee, Thread/Matter, LoRaWAN, cellular, MQTT and CoAP.

Apps & cloud

Companion apps (iOS/Android), web interfaces, device-to-cloud APIs and provisioning.

Security by design

Build it in, not bolt it on

Fixing a vulnerability after thousands of devices are in the field is expensive, and sometimes impossible. We work with your engineering team from the concept phase: threat modelling, security architecture and secure update mechanisms.

Our secure development services and secure coding training keep the firmware your team writes robust, and our testing proves it before launch.

  • Threat modelling and security requirements
  • Secure boot, key management and signed updates
  • SBOM and vulnerability monitoring
  • Coordinated vulnerability disclosure (PSIRT)

Approach

From teardown to report

  1. 01

    Scoping & threat model

    We define the scope with you and build a threat model of the device, its interfaces and its backend.

  2. 02

    Hardware & firmware

    Teardown, debug access, firmware extraction and analysis for secrets and vulnerable components.

  3. 03

    Interfaces & cloud

    Attacks on radio protocols, apps and cloud APIs, chained to show real-world impact.

  4. 04

    Report, fix & retest

    CVSS-rated findings, remediation guidance and a retest, ready for your CRA technical documentation.

Case studies

Two IoT products we took apart

FAQ

IoT security FAQ

What is IoT penetration testing?

An IoT penetration test is a security assessment of a connected product across all layers: hardware, firmware, radio interfaces, mobile apps and cloud services. Testers use real attacker techniques to find vulnerabilities before the product ships.

Does the Cyber Resilience Act apply to IoT devices?

Yes. Almost all connected devices sold in the EU are products with digital elements under the CRA. From 11 December 2027 they must meet its essential cybersecurity requirements; reporting of actively exploited vulnerabilities already applies since 11 September 2026.

Which standards are relevant for IoT security?

ETSI EN 303 645 for consumer IoT, IEC 62443-4-1 and 4-2 for industrial components, and the harmonised standards being developed under the CRA. For wireless devices, the cybersecurity requirements of the Radio Equipment Directive (EN 18031) have applied since 1 August 2025.

How long does an IoT pentest take?

Typically two to four weeks for one product, depending on the number of interfaces and whether hardware attacks are in scope. You get a fixed-scope offer after a short scoping call.

Get started

Get your IoT pentest scoped in 15 minutes

Show us your device and its interfaces. We define the test scope together and send you a fixed-price offer.

  • Scope covering hardware, firmware, radio, app and cloud
  • Fixed-price offer after the call
  • Quick check whether your product falls under the CRA
Tom Zaubermann

Your call is withTom ZaubermannFounder & CEO, Zyberum

Call us: +49 176 439 17074info@zyberum.com

Or send us a message

We reply within one business day.

Call usGet your IoT pentest quote

Pick a time that suits you

Open in a new tab