IoT Penetration Testing and Hardware Hacking
Connected devices are the new perimeter. We assess the security of your IoT infrastructure, firmware, communications and industrial hardware before they become the gateway into your network.
Why are IoT devices a critical risk?
A compromised IoT device can serve as a pivot to access the corporate network, exfiltrate production data or bring critical infrastructure to a halt. Manufacturers prioritise functionality over security, and IT teams rarely audit the firmware or communications of these devices. In OT/ICS environments, the impact can be physical.
Scope
- Firmware extraction and analysis (binwalk, static and dynamic analysis)
- Hardware interface assessment: UART, JTAG, SPI, I2C
- Communications analysis: WiFi, Bluetooth/BLE, Zigbee, Z-Wave, LoRa
- Review of the device's backend and cloud APIs
- Analysis of the device's management mobile application
- Assessment of OTA (Over-The-Air) update mechanisms
- Physical security testing: glitching, side-channel, EEPROM dumping
- OT/ICS environments: assessment against IEC 62443, Purdue Model network segmentation
- OWASP IoT Top 10: insecure credentials, unnecessary services, weak encryption
Methodology
- Device reconnaissance: Identification of hardware components, physical interfaces, communication protocols and software architecture.
- Firmware analysis: Firmware extraction, file system analysis, and the search for hardcoded credentials, private keys and vulnerabilities in binaries.
- Communications assessment: Capture and analysis of network traffic, plus testing of encryption, authentication and wireless communication channels.
- Exploitation and pivoting: Demonstration of attack chains from the device into the corporate network or control systems.
- Report and recommendations: Aligned with OWASP IoT Top 10 and IEC 62443, with a mitigation plan for manufacturers and operators.
Deliverables
- Detailed technical report with a PoC for each vulnerability
- Analysis of the device's attack surface
- Classification of findings by OWASP IoT Top 10
- Mapping to IEC 62443 for industrial environments
- Hardening recommendations for firmware, communications and backend
- Manufacturer support throughout the remediation process
Use cases
- IoT device manufacturers that need to certify security before launch
- Industrial companies with SCADA, PLCs or network-connected OT environments
- Critical infrastructure operators: energy, water, transport
- Healthcare companies with connected medical devices
- Installers of home automation and smart building systems (BMS)
Frequently asked questions
Do you need physical access to the device?
For a full test, yes. Some analyses (backend API, mobile app, network communications) can be carried out remotely, but firmware and hardware analysis requires the physical device.
Can you carry out the pentest without affecting industrial production?
We always work with the OT team to define maintenance windows and run the more invasive tests outside production hours. The safety of operations is our priority.
Do you carry out assessments to comply with the RED (Radio Equipment Directive)?
Yes. We help manufacturers prepare the technical security documentation required by the EU's RED directive for IoT devices.