The challenge behind the engagement.
Connected and embedded devices ship with security gaps that a normal application test never sees. IoT and device security testing examines the whole product, layer by layer. We test the physical and hardware interfaces on the device, the software inside it, the wireless and network connections it relies on, and the mobile and cloud services behind it. We look for exposed access points on the circuit board, secrets and keys left in the software, weak or unsigned update mechanisms, and connections an attacker nearby or on the same network could abuse. You get a clear picture of what an attacker with the device in hand, or within range of it, could actually do, findings written for your engineering and manufacturing teams, and a retest once fixes ship.
For device manufacturers and product security teams shipping connected hardware. Common before a product launch, ahead of a device security baseline or labeling review, or when a customer asks how the device holds up against physical and wireless attacks.
What we do.
What you can use.
Gather units and firmware
We ask for several device units, some set aside for destructive hardware work, the device software or update packages, datasheets and design documents, companion app builds with test accounts, and the backend service details. We agree that opening up the hardware and extracting its software are expected on the sacrificial units.
Test every layer
We probe the exposed access points on the circuit board and extract the device software, analyze it for embedded secrets and weak or unsigned updates, and test the wireless and network connections the device uses. The companion mobile app is tested against the recognized mobile security standard, along with the backend services behind it.
Report by layer and retest
You receive findings across hardware, software, wireless, app, and cloud with severity ratings and evidence, and a mapping to the consumer device security baseline. Remediation is written for your manufacturing and engineering teams, and we retest fixes on updated device software.
Who it’s for.
When you need it.
- Device manufacturers and product security teams shipping connected hardware to the field
- Organizations whose products face physical, radio, and firmware attacks after they ship
- Teams preparing for a device security baseline or product labeling review
- Businesses whose devices depend on companion apps and backend cloud services
- A connected product is approaching launch or a hardware revision
- A retailer or enterprise buyer asks how the device resists physical tampering
- A labeling scheme or baseline review requires evidence of device testing
- New firmware, radios, or a companion app were added to the product
What the scope can include.
- 01
Probe the exposed access points on the device hardware and extract its software
- 02
Analyze the device software for embedded secrets and weak update mechanisms
- 03
Test the wireless and network connections the device relies on
- 04
Test the companion mobile app against the recognized mobile security standard
- 05
Assess the backend cloud APIs and services behind the device
What it typically costs.
One rate: $150/hour.
Every engagement is priced by the hours it takes at one flat rate, with scoping, the work, and reporting, plus a retest of your fixes, included. Find the size closest to yours.
One simple device, software review only, no companion app
About 40–56 hoursOne device with hardware teardown, wireless, a companion app, and its cloud service
About 80–120 hoursA product family or multi-radio device with apps, cloud services, and update system
About 140–200 hours- Number of device models and hardware revisions
- Hardware teardown and software extraction depth
- Wireless connections in use
- Companion apps and cloud services in scope
Ranges are planning estimates at $150/hour, not a quote. Your price is confirmed in writing after a scoping call, before any work begins.
What you take forward.
- Findings across hardware, software, wireless, app, and cloud with evidence
- Mapping of results to the consumer device security baseline with severity ratings
- Remediation written for your manufacturing and engineering teams
- Retest of remediated findings on updated device software
Final coverage, deliverables, timing, and any retesting or implementation work are confirmed before the engagement begins.
Before we get started.
How many units do you need, and will they survive?
Plan on several units, and expect some not to survive. Hardware work like opening the device, extracting its software, and probing the access points on the board is destructive by nature, so we ask for sacrificial units alongside intact ones for wireless, app, and cloud testing. We confirm exactly how many during scoping, based on the device and how deep the teardown goes.
Can you map results to a recognized device security baseline or labeling scheme?
We map findings to the widely used consumer device security baselines that cover the ground buyers ask about. We test and map; we do not certify. A government labeling mark is granted through an official program, not by a penetration tester, so treat our mapping as preparation for that process. The mapping shows where the device meets each expectation and where it falls short.
- NIST SP 800-115: Technical Guide to Information Security Testing and Assessment
- OWASP Web Security Testing Guide
- OWASP Top 10 API Security Risks – 2023
- Common Vulnerability Scoring System version 4.0: Specification Document
- NIST SP 800-82 Rev. 3: Guide to Operational Technology (OT) Security
- Penetration Testing - Amazon Web Services (AWS)
