# Zyberum GmbH > Zyberum GmbH is a German cybersecurity company based in Hannover, specialising in IoT, automotive, OT and IT security. It offers penetration testing and fuzzing of connected products, compliance consulting for the EU Cyber Resilience Act, ISO/SAE 21434, UN R155, IEC 62443 and NIS2, the AutoST automated security testing suite, and Zyberdome, a fixed-price 24/7 managed SOC for small and medium-sized businesses. ## Company facts - Legal name: Zyberum GmbH - Address: Jägerstieg 12, 30657 Hannover, Germany - Market: based in Germany, working for customers worldwide - Founder and managing director: Tom Zaubermann (former lead of the InCar Security Testing Lab at Volkswagen AG) - Certifications: OSCP, Automotive Cybersecurity Level 1 & 2, ISO/IEC 27001 Auditor, CRA Auditor, CCISO - Register: Amtsgericht Hannover, HRB 221584 - Contact: info@zyberum.com, +49 176 439 17074 - Book a free call or consultation: https://zyberum.com/contact - Languages: English, German (website also in French, Italian, Spanish) - Product website for AutoST: https://auto-st.com ## Solutions - [IoT Security & Penetration Testing for Devices](https://zyberum.com/iot-security): IoT security testing is a hands-on assessment of a connected product as a whole: device hardware, firmware, wireless interfaces, companion apps and cloud backends. Zyberum performs IoT penetration tests and firmware analyses, supports secure development and vulnerability handling, and prepares manufacturers for the EU Cyber Resilience Act and standards such as ETSI EN 303 645 and IEC 62443-4-2. - [Automotive Penetration Testing & ISO 21434](https://zyberum.com/automotive-security): Automotive penetration testing is a hands-on security assessment of vehicle components, such as ECUs, gateways, infotainment, telematics and backends, to find exploitable vulnerabilities. Zyberum combines manual testing with automated fuzzing (AutoST) and delivers CVSS-rated findings in a TARA-compatible format that feeds directly into ISO/SAE 21434 and UN R155 compliance. - [OT & Industrial Cybersecurity (IEC 62443)](https://zyberum.com/industrial-security): OT security protects operational technology, such as PLCs, SCADA, DCS and industrial networks, against cyberattacks that could stop production or endanger safety. Zyberum performs OT risk assessments, network segmentation reviews and safety-aware penetration tests and supports manufacturers and operators with IEC 62443 and NIS2. - [IT Security, Web & Cloud Penetration Testing](https://zyberum.com/it-security): IT security protects a company’s networks, endpoints, cloud services and business applications against attacks such as ransomware and phishing. Zyberum performs infrastructure, cloud, web application and API penetration tests, helps organisations prepare for incidents and NIS2, and offers Zyberdome, a fixed-price 24/7 managed SOC for small and medium-sized businesses. ## Products - [AutoST: Automated ECU Security Testing Suite](https://zyberum.com/autost): AutoST is Zyberum’s automated security testing software for automotive ECUs. It runs fuzz tests, security tests and vulnerability scans over UDS, CAN/CAN FD, DoIP, SOME/IP and other interfaces, and documents results for ISO/SAE 21434 verification and UN R155 type approval. - [Zyberdome: Managed SOC for SMBs from €12/Device](https://zyberum.com/zyberdome): Zyberdome is a managed Security Operations Center (SOC) as a service by Zyberum for small and medium-sized businesses. It combines SentinelOne endpoint protection with 24/7 monitoring and incident response by Zyberum analysts, security awareness training and regular reports, starting at €12 per device per month. ## Services & company - [Penetration Testing: IoT, Automotive, OT & IT](https://zyberum.com/penetration-testing): A penetration test (pentest) is an authorised, hands-on attack on a system to find vulnerabilities that a real attacker could exploit. Zyberum performs penetration tests of IoT and embedded devices, automotive ECUs, industrial control systems and IT (web applications, APIs, cloud and networks). Each test delivers CVSS-rated findings with proof-of-concepts, concrete fixes and a retest, at a fixed price agreed after a short scoping call. - [Security Services: Pentest, Secure Coding, CRA](https://zyberum.com/services): Penetration testing, secure development, compliance consulting (CRA, ISO/SAE 21434, IEC 62443, NIS2), managed SOC and training from one German team. - [Secure Coding, Code Review & Secure SDLC](https://zyberum.com/secure-development): Secure development means building security into every phase of software and firmware development: requirements, design, coding, testing and maintenance. Zyberum provides secure coding training for development teams, manual source code review supported by SAST, threat modelling, and secure SDLC and DevSecOps implementation aligned with the Cyber Resilience Act, ISO/SAE 21434 and IEC 62443-4-1. - [Cyber Resilience Act (CRA) Compliance Services](https://zyberum.com/cyber-resilience-act): The EU Cyber Resilience Act (Regulation (EU) 2024/2847) requires manufacturers of products with digital elements to design them securely, handle vulnerabilities for the product’s support period and report actively exploited vulnerabilities. Reporting obligations apply from 11 September 2026; all other requirements apply from 11 December 2027. Zyberum provides CRA gap analyses, secure development lifecycle implementation, vulnerability handling processes and penetration testing. - [NIS2 Compliance: Check, Measures & Pentest](https://zyberum.com/nis2): NIS2 is the EU directive on cybersecurity for essential and important entities. Germany implemented it with the NIS2 Implementation Act, in force since 6 December 2025. It applies to companies in 18 sectors with at least 50 employees or more than €10 million in turnover and balance sheet total, requires risk-management measures, registration with the BSI and incident reporting within 24 hours, and makes management liable. Zyberum offers NIS2 applicability checks, gap analyses, implementation of the required measures, penetration tests and 24/7 monitoring. - [Automotive Security & Secure Coding Training](https://zyberum.com/training): Hands-on security training: automotive hacking with real ECUs and 30+ CTFs, secure coding for developers and ISO/SAE 21434 compliance courses. - [About Zyberum: Hands-on Security Team from Hannover](https://zyberum.com/about): Zyberum GmbH is a cybersecurity company from Hannover, Germany, founded in 2019 by Tom Zaubermann, who previously led the InCar Security Testing Lab at Volkswagen AG. The team performs hands-on penetration tests of IoT devices, vehicles, industrial systems and IT, develops the AutoST automotive security testing suite and runs the Zyberdome managed SOC. Certifications include OSCP, the SAE and TÜV SÜD Automotive Cybersecurity Certification for ISO/SAE 21434, and ISO/IEC 27001 and CRA auditor qualifications. - [Cybersecurity Jobs in Hannover](https://zyberum.com/careers): Join Zyberum GmbH: open positions for embedded security specialists, SOC analysts and sales in Hannover, Germany. Help us secure the world. - [Contact Zyberum](https://zyberum.com/contact): Contact Zyberum GmbH in Hannover for penetration testing, CRA and ISO 21434 compliance, AutoST demos or Zyberdome. Free initial consultation. ## Insights - [Case Study: Root on a Robot Vacuum, and Other People’s Cameras](https://zyberum.com/insights/case-robot-vacuum): We tested a camera-equipped robot vacuum: root access on the device, and cloud API flaws that opened the live camera of other users. What went wrong and why. - [Case Study: A Smart Irrigation System Anyone Could Control](https://zyberum.com/insights/case-smart-irrigation): We tested a smart irrigation system: a broken MQTT setup let us see and switch the devices of other customers, and locate where they are installed. - [Cyber Resilience Act: What Manufacturers Must Do by 2027](https://zyberum.com/insights/cyber-resilience-act-guide): A practical guide to the EU Cyber Resilience Act: scope, product classes, deadlines, reporting duties and the concrete steps manufacturers should take now. - [ECU Fuzzing Explained: Finding Bugs in UDS, DoIP and SOME/IP](https://zyberum.com/insights/ecu-fuzzing-explained): How fuzz testing works for automotive ECUs, which protocols to target, how to detect crashes on real hardware and how fuzzing supports ISO/SAE 21434. - [IoT Penetration Testing: What We Attack and What We Find](https://zyberum.com/insights/iot-penetration-testing-explained): What an IoT pentest covers, from debug ports and firmware to radio, apps and cloud, which findings come up most often, and how to prepare your device for testing. - [ISO/SAE 21434 vs UN R155: How They Fit Together](https://zyberum.com/insights/iso-21434-vs-un-r155): UN R155 is the law, ISO/SAE 21434 is the engineering standard. Learn how CSMS, TARA and testing connect, and what suppliers need to deliver to OEMs. - [NIS2 in Germany: Who Is Affected and What to Do Now](https://zyberum.com/insights/nis2-what-to-do-now): The German NIS2 law has applied since 6 December 2025. A practical checklist: scope, registration, the ten risk measures, reporting deadlines and first steps. - [RED Cybersecurity and EN 18031: What Wireless Devices Need](https://zyberum.com/insights/red-en-18031-cybersecurity): Since 1 August 2025 radio equipment sold in the EU must meet the RED cybersecurity requirements. What EN 18031 demands and how it relates to the CRA. - [Secure Coding in Embedded C: Five Bugs We Keep Finding](https://zyberum.com/insights/secure-coding-embedded-c): Unchecked lengths, integer overflows, format strings, weak randomness and debug leftovers: the five bug classes we find most in firmware, and how to avoid them. ## German version - https://zyberum.com/de