Skip to content
Zyberum Cyber Security Firm
Menu

Penetration testing

We break in. You get the proof and the fix.

A penetration test is only worth something if real attackers could do what the report says. We attack your device, vehicle, plant or IT the way they would, show you what we got, and stay until it is fixed.

  • OSCP-certified testers
  • Fixed price after scoping
  • Retest included

In short

A penetration test (pentest) is an authorised, hands-on attack on a system to find vulnerabilities that a real attacker could exploit. Zyberum performs penetration tests of IoT and embedded devices, automotive ECUs, industrial control systems and IT (web applications, APIs, cloud and networks). Each test delivers CVSS-rated findings with proof-of-concepts, concrete fixes and a retest, at a fixed price agreed after a short scoping call.

What we test

If it runs code, we can test it

IoT & embedded devices

Hardware, debug interfaces, firmware, radio protocols, companion apps and the cloud behind them.

Hardware pentest

Vehicles & ECUs

ECUs, gateways, infotainment and telematics over CAN, UDS, DoIP and SOME/IP, plus backends.

Automotive security

Industrial control systems

PLCs, HMIs, SCADA and remote access, tested safely in the lab or in maintenance windows.

OT security

Web applications & APIs

Manual testing beyond the scanner: business logic, authentication, access control, OWASP Top 10.

Web application pentest

Cloud & infrastructure

External and internal networks, Active Directory attack paths, AWS, Azure and Microsoft 365.

Cloud pentest

Mobile apps

iOS and Android apps, their local storage, their APIs and how they talk to your devices.

Mobile app pentest

How we test

From scoping call to retest

  1. 01

    Scope in 15 minutes

    A short call with a tester. We agree on targets, depth (black, grey or white box) and timing, and you get a fixed-price offer.

  2. 02

    Attack

    Manual testing with our own tooling. We chain weaknesses the way real attackers do, and keep you posted on anything critical right away.

  3. 03

    Report that gets used

    Every finding with CVSS score, proof-of-concept and a concrete fix. Short summary for management, details for engineers.

  4. 04

    Fix and retest

    We walk your team through the findings, answer questions during the fix, and retest to confirm the holes are closed.

Faster with our own AI

More coverage for the same budget

Our testers work with AI models that we host ourselves. They run on our own hardware, inside our lab network. Nothing about your systems, your code or your findings is sent to a cloud AI service.

The models take over the slow, repetitive parts of a test: reading through firmware and code, mapping attack surface, drafting test cases and sorting results. The testers spend their time where a human is needed, on chaining weaknesses and proving impact. In the same number of days we cover more of your system.

  • Self-hosted models, no data leaves our lab
  • More of your system tested in the same time
  • Every finding verified by a human tester
  • Fixed price, agreed before we start

Why it matters

A scan is not a pentest

Automated scanners find known issues. They do not find the forgotten debug port, the API that trusts the wrong ID or the firmware update that accepts unsigned images. People do.

That is the work we enjoy: understanding how your system really behaves and proving what an attacker could do with it. You get evidence, not assumptions, and it doubles as the test evidence that the CRA, ISO/SAE 21434, IEC 62443 and NIS2 ask for.

Who tests

Certified, and still hands-on

Your test is run by engineers who do this every day, not by whoever is free.

Case studies

Findings from real tests

Trusted by engineering teams at

  • Audi
  • Siemens
  • Harman
  • Miele
  • ZKW
  • Delta Electronics
  • Wepa

FAQ

Penetration testing FAQ

What does a penetration test cost?

It depends on the size and depth of the test: a single web application is a few days of work, a complete IoT product with hardware, firmware, app and cloud takes longer. You get a fixed-price offer after a 15-minute scoping call, so there are no surprises.

How long does a penetration test take?

Typically one to four weeks from kick-off to report, depending on scope. If you have a deadline such as a product launch or an audit, tell us in the scoping call and we plan around it.

What is the difference between black box, grey box and white box?

In a black box test we start with no inside knowledge, like an outside attacker. In a grey box test we get accounts or documentation. In a white box test we also get source code and design documents. Grey and white box tests find more issues in the same time.

What is the difference between a vulnerability scan and a penetration test?

A vulnerability scan is automated and lists known weaknesses. A penetration test is done by people who combine and exploit weaknesses to show what an attacker could really achieve, including flaws no scanner knows.

Is a retest included?

Yes. After you have fixed the findings, we retest them and confirm in writing which ones are closed.

Do you sign an NDA?

Yes, on request before you share any details. Everything we learn about your systems stays confidential.

Get started

Get your pentest scoped in 15 minutes

Tell us what needs testing and when. You talk directly to a tester, and you get a fixed-price offer after the call.

  • Scope, test depth and timeline clarified
  • Fixed-price offer after the call
  • NDA on request before you share details
Tom Zaubermann

Your call is withTom ZaubermannFounder & CEO, Zyberum

Call us: +49 176 439 17074info@zyberum.com

Or send us a message

We reply within one business day.

Call usGet your pentest quote

Pick a time that suits you

Open in a new tab