All five layers, one engagement
Hardware, firmware, radio, app and cloud tested together and chained, because a leaked key on the device only matters when we prove what it unlocks across the fleet.
A connected product is never one device. It is firmware, a radio link, a mobile app, a cloud backend and an over-the-air update channel, and an attacker needs only the weakest of them. We take the whole chain apart by hand and prove how one unit on a desk becomes a compromise of your entire fleet.
How an IoT pentest worksProtected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.
Request received.
We’ll be in touch within one business day with next steps.
No se ha podido enviar. Inténtalo otra vez o escríbenos.















We attack the way a real IoT breach starts: with a single unit on a desk, no credentials, no special cloud access, only what a customer or a researcher would have. From there, we move outward.
A flaw in one layer is rarely the whole story. We open the device and read its debug ports (the hidden connectors on the board, UART and JTAG). We pull the software off it and find the keys baked inside (firmware extraction and hardcoded secrets). We record the device’s wireless setup handshake and replay it to take it over (radio pairing replay). We reverse-engineer the companion app, then abuse the cloud service that manages every device you have shipped (the fleet API). Each step is reproducible, with the captures and commands your team can replay to confirm the fix.
A new product line, a firmware drop, a regulator deadline, an enterprise customer’s demand for proof, or a near-miss in the field forces the question.
The question is not ‘do we have findings’ but ‘are there other paths’. We focus the engagement on the suspected exposure, confirm it is closed, and surface every adjacent path across hardware, firmware, radio, app and cloud.
With ISO 27001 or SOC 2 with connected products in scope, or FDA pre-market cybersecurity on the line, the report has to survive scrutiny: traceable scope, a recognised methodology and signed retest evidence.
When the ask is strategic, you need an external, expert-led IoT pentest and a deliverable that turns one device becoming a fleet problem into business impact, in language a non-technical stakeholder can read.
Every connected product has a different worst day. We scope to yours and test the whole chain: the board and its debug ports, the firmware, the radio link, the companion app and the cloud behind the fleet.
We work outward through the same five layers you saw above, from the device in your hand to the fleet in the cloud, testing each one before we chain it to the next. The short version is below; the full step-by-step lives on its own page.
Most IoT reviews stop at a firmware scan or a lab checklist. Here is where we go further.
Hardware, firmware, radio, app and cloud tested together and chained, because a leaked key on the device only matters when we prove what it unlocks across the fleet.
A senior specialist works on real sample units with real equipment, from opening the board to capturing the radio. No emulator-only scan, no false positives, only what genuinely works.
Every finding maps to OWASP IoT, ETSI EN 303 645 and IEC 62443, the evidence your auditors and your enterprise customers’ procurement teams actually accept.
Optional multi-revision mode: after a firmware, hardware or cloud change, we re-test the diff against the same product to confirm closure and catch anything the change introduced.
We at Etnia highly value our collaboration with Asperis Security.
Names, roles and companies on the record.
We at Etnia highly value our collaboration with Asperis Security. Their professionalism, approachability, quick response and ability to adapt to our needs have been key in every project. The quality of service and continuous support always give us peace of mind. Without a doubt, it is a pleasure to have them as technology partners.
ASPERIS has worked alongside us to define and implement our cybersecurity roadmap in Microsoft 365 with a structured approach aligned to business objectives. Thanks to their advice, we took the strategic step of completing our Microsoft ecosystem and reinforcing it with CrowdStrike for advanced mobile device protection, significantly raising our security level.
At NPAW we have collaborated with Asperis on various security initiatives and the experience has been very positive. We especially value their ability to adapt to our needs and the depth with which they approach each project. Results are clear, structured and useful for decision-making and continuous security improvement. We like working with Asperis for the judgment and value they bring to every collaboration. Their work has helped us strengthen our security level.
With Asperis you don’t hire a service. You hire a partner. They don’t look to bill a project. They look to establish a relationship of trust, caring about the key points that affect your organisation’s security. Professionalism, know-how and diligence.
Tell us your product, its firmware version and where you want us to start. An experienced consultant replies with a tailored scope, a fixed quote and a timeline.
IoT penetration testing is a manual security assessment of a connected product across all of its layers: the hardware, the firmware, the radio it uses to communicate, the mobile app that controls it, and the cloud backend that manages the fleet. Because a weakness in one layer can be chained into the others, the test proves how far an attacker reaches from a single device, and whether that reaches your entire fleet. The deliverable is a set of proven attack chains, ranked by business impact, each with a reproducible proof of concept.
No. A lab certification checks a product against a checklist, such as ETSI EN 303 645, and confirms whether the required controls are present. An IoT pentest proves what an attacker can actually do: whether one device on a bench yields a cloud key, a fleet-wide update, or another customer’s data. A product can hold a clean certificate and still be exploitable end to end. Most companies shipping connected products at scale do both, the certification tied to the product release, the pentest tied to firmware drops, hardware revisions and fleet milestones.
Through the parts every device shares. A single unit on a bench often reveals a hardcoded key, a cloud endpoint or an update mechanism that is identical across the fleet. From there, an attacker uses the shared cloud API, the over-the-air update channel, or weak separation between customers to move from one device to many. That is why we always test the path from a single device to the fleet, not just the device in isolation.
Usually yes, at least a small number. Genuine IoT testing means hardware on the bench: opening a unit, reading its debug ports and extracting firmware needs the physical device. We typically ask for two or three sample units, ideally with debug access enabled, plus access to the companion app and the cloud backend. Where physical access is impossible, we scope around what can be tested (firmware images, the app and the cloud) and say so plainly in the proposal.
No. We work on sample units and staging environments, not your customers’ live devices, and every engagement runs under documented Rules of Engagement with a critical-finding protocol. Fleet-wide and cloud tests are performed against a controlled test tenant or with explicit approval, never as destructive actions on production. You get the attacker’s view of your product without putting shipped devices at risk.
A single connected product with a documented cloud backend typically takes two to three weeks of active testing, given the hardware, firmware, radio and cloud work involved; multi-product families or complex radio stacks run longer. Scoping happens beforehand and the retest follows your fixes. We confirm the timeline in the proposal, delivered within 48 hours of the first call.
Price follows scope: the number of devices and layers, the radio protocols involved, and whether the fleet backend is included. We quote a fixed price with no hidden fees and no obligation to renew. A focused single-product engagement sits at the bottom of the range; multi-product families or engagements needing specialist radio hardware scale from there. The retest, against the same firmware and hardware revision, is always included.
The senior specialist you meet on the first call runs it end to end. Our team holds OSCP, OSCE³, OSWE and OSEP credentials, and our IoT practice adds hardware, firmware and radio expertise (tools such as Ghidra, HackRF, Ubertooth and JTAGulator). We are NASA Bug Bounty verified contributors with published findings against connected products. The same person scopes, executes and retests. They stay your point of contact throughout.
Start with a no-obligation introductory meeting. We will review your connected-product estate, hardware, firmware, radio, app and cloud, and define the right IoT pentest before the project begins.
Protected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.
Request received.
Request received. A senior specialist will reply within one business day with scope, a fixed quote and a timeline.
No se ha podido enviar. Inténtalo otra vez o escríbenos.
Or email [email protected] directly.
OUR CLIENTS HAVE ALREADY DONE IT
We at Etnia highly value our collaboration with Asperis Security.
ASPERIS has worked alongside us to define and implement our cybersecurity roadmap in Microsoft 365 with a structured approach aligned to business objectives.
At NPAW we have collaborated with Asperis on various security initiatives and the experience has been very positive.
With Asperis you don’t hire a service. You hire a partner.
Pick a time that suits you. You tell us what you need and where you are, and we explain how we work and how we can help.