IoT & embedded devices
Hardware, debug interfaces, firmware, radio protocols, companion apps and the cloud behind them.
Hardware pentestPenetration testing
A penetration test is only worth something if real attackers could do what the report says. We attack your device, vehicle, plant or IT the way they would, show you what we got, and stay until it is fixed.
In short
A penetration test (pentest) is an authorised, hands-on attack on a system to find vulnerabilities that a real attacker could exploit. Zyberum performs penetration tests of IoT and embedded devices, automotive ECUs, industrial control systems and IT (web applications, APIs, cloud and networks). Each test delivers CVSS-rated findings with proof-of-concepts, concrete fixes and a retest, at a fixed price agreed after a short scoping call.
What we test
Hardware, debug interfaces, firmware, radio protocols, companion apps and the cloud behind them.
Hardware pentestECUs, gateways, infotainment and telematics over CAN, UDS, DoIP and SOME/IP, plus backends.
Automotive securityPLCs, HMIs, SCADA and remote access, tested safely in the lab or in maintenance windows.
OT securityManual testing beyond the scanner: business logic, authentication, access control, OWASP Top 10.
Web application pentestExternal and internal networks, Active Directory attack paths, AWS, Azure and Microsoft 365.
Cloud pentestiOS and Android apps, their local storage, their APIs and how they talk to your devices.
Mobile app pentestHow we test
A short call with a tester. We agree on targets, depth (black, grey or white box) and timing, and you get a fixed-price offer.
Manual testing with our own tooling. We chain weaknesses the way real attackers do, and keep you posted on anything critical right away.
Every finding with CVSS score, proof-of-concept and a concrete fix. Short summary for management, details for engineers.
We walk your team through the findings, answer questions during the fix, and retest to confirm the holes are closed.
Faster with our own AI
Our testers work with AI models that we host ourselves. They run on our own hardware, inside our lab network. Nothing about your systems, your code or your findings is sent to a cloud AI service.
The models take over the slow, repetitive parts of a test: reading through firmware and code, mapping attack surface, drafting test cases and sorting results. The testers spend their time where a human is needed, on chaining weaknesses and proving impact. In the same number of days we cover more of your system.
Why it matters
Automated scanners find known issues. They do not find the forgotten debug port, the API that trusts the wrong ID or the firmware update that accepts unsigned images. People do.
That is the work we enjoy: understanding how your system really behaves and proving what an attacker could do with it. You get evidence, not assumptions, and it doubles as the test evidence that the CRA, ISO/SAE 21434, IEC 62443 and NIS2 ask for.
Who tests
Your test is run by engineers who do this every day, not by whoever is free.
OSCP
Offensive Security Certified Professional
OffSec
Automotive Cybersecurity Level 1 & 2
Automotive Cybersecurity Certification for ISO/SAE 21434
SAE International · TÜV SÜD
ISO/IEC 27001 Auditor
Information security management systems
CRA Auditor
EU Cyber Resilience Act
CCISO
Certified Chief Information Security Officer
Technion
Case studies
Full root access on the device, and access to the live WebRTC camera of other users through the cloud API.
We tested a camera-equipped robot vacuum: root access on the device, and cloud API flaws that opened the live camera of other users. What went wrong and why.
Read the case studyWe could see and activate other customers’ devices through MQTT, and geolocate where they are installed.
We tested a smart irrigation system: a broken MQTT setup let us see and switch the devices of other customers, and locate where they are installed.
Read the case studyTrusted by engineering teams at







FAQ
It depends on the size and depth of the test: a single web application is a few days of work, a complete IoT product with hardware, firmware, app and cloud takes longer. You get a fixed-price offer after a 15-minute scoping call, so there are no surprises.
Typically one to four weeks from kick-off to report, depending on scope. If you have a deadline such as a product launch or an audit, tell us in the scoping call and we plan around it.
In a black box test we start with no inside knowledge, like an outside attacker. In a grey box test we get accounts or documentation. In a white box test we also get source code and design documents. Grey and white box tests find more issues in the same time.
A vulnerability scan is automated and lists known weaknesses. A penetration test is done by people who combine and exploit weaknesses to show what an attacker could really achieve, including flaws no scanner knows.
Yes. After you have fixed the findings, we retest them and confirm in writing which ones are closed.
Yes, on request before you share any details. Everything we learn about your systems stays confidential.
Get started
Tell us what needs testing and when. You talk directly to a tester, and you get a fixed-price offer after the call.

Your call is withTom ZaubermannFounder & CEO, Zyberum
We reply within one business day.
Your privacy
We use cookies and similar technologies to measure our website and the success of our ads. You decide which ones we may use. You can change your choice at any time via "Cookie settings" in the footer. Privacy policy