IoT PENETRATION TESTING

Audit your connected fleet before someone else does.

A connected product is never one device. It is firmware, a radio link, a mobile app, a cloud backend and an over-the-air update channel, and an attacker needs only the weakest of them. We take the whole chain apart by hand and prove how one unit on a desk becomes a compromise of your entire fleet.

How an IoT pentest works
87%
of our clients renew annually
150+
organisations across multiple European countries
7/10
confirm findings their previous provider did not find
Want to know what your fleet actually opens up? Share your main concern and your email.

Protected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.

Trusted by hardware and product-security teams shipping at scale

Identify exactly how one device becomes a fleet compromise.

CADENA DE ATAQUE 01 / 05
  1. Abrimos el dispositivo en el banco · pinchamos los pads UART · U-Boot cae a una shell de root.
  2. Volcamos la flash · clave de API embebida + contraseña de root compartida · el OTA solo valida SHA256.
  3. Capturamos y reproducimos el emparejamiento BLE Just-Works · el dispositivo se reclama sin permiso de su dueño.
  4. Ingeniería inversa de la app móvil · un IDOR en /v1/devices/claim enumera el parque.
  5. Identidad MQTT compartida · acepta un OTA sin firmar · el firmware del atacante queda preparado para 1,2M de unidades.

We attack the way a real IoT breach starts: with a single unit on a desk, no credentials, no special cloud access, only what a customer or a researcher would have. From there, we move outward.

A flaw in one layer is rarely the whole story. We open the device and read its debug ports (the hidden connectors on the board, UART and JTAG). We pull the software off it and find the keys baked inside (firmware extraction and hardcoded secrets). We record the device’s wireless setup handshake and replay it to take it over (radio pairing replay). We reverse-engineer the companion app, then abuse the cloud service that manages every device you have shipped (the fleet API). Each step is reproducible, with the captures and commands your team can replay to confirm the fix.

WHAT WE TEST
  • The physical board and its debug ports (hardware: UART, JTAG, SWD, fuses)
  • The software inside the device (firmware: extraction, secure boot, code signing)
  • How the device communicates wirelessly (radio: BLE, Wi-Fi, Zigbee, LoRa, sub-GHz)
  • How the app pairs and talks to the device (companion app pairing and API)
  • The cloud that manages the fleet (backend, MQTT, fleet API)
  • How devices are updated (over-the-air pipeline and rollback safety)
  • Whether one customer can reach another’s devices (multi-tenant isolation)
  • Whether abuse is even visible (telemetry, audit logs and detection)

Why a CTO, CISO or hardware lead books an IoT pentest.

A new product line, a firmware drop, a regulator deadline, an enterprise customer’s demand for proof, or a near-miss in the field forces the question.

TAP A SITUATION
Suspected exposure Anomalous OTA or telemetry pattern

Something looked off in the field. You need to know what is still exposed.

The question is not ‘do we have findings’ but ‘are there other paths’. We focus the engagement on the suspected exposure, confirm it is closed, and surface every adjacent path across hardware, firmware, radio, app and cloud.

  • Targeted scope around the suspected exposure
  • Adjacent paths mapped across all five layers
  • Reproducible proofs of concept for the incident-response team
  • Live findings to your responders, not the final report
Compliance & audit ISO 27001 or SOC 2 connected scope

An auditor does not accept a lab certificate scan.

With ISO 27001 or SOC 2 with connected products in scope, or FDA pre-market cybersecurity on the line, the report has to survive scrutiny: traceable scope, a recognised methodology and signed retest evidence.

  • Methodology mapped to recognised IoT and industrial testing standards
  • Evidence formatted for regulator and enterprise customer security review
  • Execution certificate ready for the auditor folder
  • Retest evidence with timestamps, the firmware hash pinned, and signoff
Board & strategic Board asked for IoT assurance

Someone with authority asked, and ‘we’re fine’ isn’t an answer.

When the ask is strategic, you need an external, expert-led IoT pentest and a deliverable that turns one device becoming a fleet problem into business impact, in language a non-technical stakeholder can read.

  • Executive summary that lands without translation
  • Findings ranked by business impact and audit exposure
  • Fleet blast radius stated plainly: what one compromised unit reaches
  • Independence: external and expert-led throughout
By product type Industrial robot or cobot

The product decides the threat model, so the test follows the product.

Every connected product has a different worst day. We scope to yours and test the whole chain: the board and its debug ports, the firmware, the radio link, the companion app and the cloud behind the fleet.

  • Threat model written for your product, not a generic connected-device checklist
  • Hardware, firmware, radio, companion app and cloud backend all in scope
  • Fleet abuse paths chased explicitly: what one unit reaches across the estate
  • Findings tied to product owners, not just an IT ticket queue

Ready to see what your fleet actually opens up?

Book a call
Thirty minutes with an experienced pentester.

A seven-phase method, for your IoT security pentesting.

We work outward through the same five layers you saw above, from the device in your hand to the fleet in the cloud, testing each one before we chain it to the next. The short version is below; the full step-by-step lives on its own page.

What you actually get, and why it is different.

Most IoT reviews stop at a firmware scan or a lab checklist. Here is where we go further.

All five layers, one engagement

Hardware, firmware, radio, app and cloud tested together and chained, because a leaked key on the device only matters when we prove what it unlocks across the fleet.

By hand, on the bench

A senior specialist works on real sample units with real equipment, from opening the board to capturing the radio. No emulator-only scan, no false positives, only what genuinely works.

Mapped to the standards your buyers ask for

Every finding maps to OWASP IoT, ETSI EN 303 645 and IEC 62443, the evidence your auditors and your enterprise customers’ procurement teams actually accept.

Multi-revision retest

Optional multi-revision mode: after a firmware, hardware or cloud change, we re-test the diff against the same product to confirm closure and catch anything the change introduced.

Want to see what your next IoT pentest with us would look like?

We at Etnia highly value our collaboration with Asperis Security.
Sergi Leno, Systems Manager · ETNIA Barcelona

Loved by engineering and security teams.

Names, roles and companies on the record.

We at Etnia highly value our collaboration with Asperis Security. Their professionalism, approachability, quick response and ability to adapt to our needs have been key in every project. The quality of service and continuous support always give us peace of mind. Without a doubt, it is a pleasure to have them as technology partners.
Sergi Leno, Systems Manager
ETNIA Barcelona
ASPERIS has worked alongside us to define and implement our cybersecurity roadmap in Microsoft 365 with a structured approach aligned to business objectives. Thanks to their advice, we took the strategic step of completing our Microsoft ecosystem and reinforcing it with CrowdStrike for advanced mobile device protection, significantly raising our security level.
Jordi Bondia, IT Director
SALVI
At NPAW we have collaborated with Asperis on various security initiatives and the experience has been very positive. We especially value their ability to adapt to our needs and the depth with which they approach each project. Results are clear, structured and useful for decision-making and continuous security improvement. We like working with Asperis for the judgment and value they bring to every collaboration. Their work has helped us strengthen our security level.
Sergi Laencina Verdaguer, CISO
NPAW
With Asperis you don’t hire a service. You hire a partner. They don’t look to bill a project. They look to establish a relationship of trust, caring about the key points that affect your organisation’s security. Professionalism, know-how and diligence.
Juan Valer Tecedor, Software Engineer
GNOSS
READY WHEN YOU ARE

Want a real IoT Pentesting scope for your perimeter?

Tell us your product, its firmware version and where you want us to start. An experienced consultant replies with a tailored scope, a fixed quote and a timeline.

Questions that come up before signing.

IoT penetration testing is a manual security assessment of a connected product across all of its layers: the hardware, the firmware, the radio it uses to communicate, the mobile app that controls it, and the cloud backend that manages the fleet. Because a weakness in one layer can be chained into the others, the test proves how far an attacker reaches from a single device, and whether that reaches your entire fleet. The deliverable is a set of proven attack chains, ranked by business impact, each with a reproducible proof of concept.

No. A lab certification checks a product against a checklist, such as ETSI EN 303 645, and confirms whether the required controls are present. An IoT pentest proves what an attacker can actually do: whether one device on a bench yields a cloud key, a fleet-wide update, or another customer’s data. A product can hold a clean certificate and still be exploitable end to end. Most companies shipping connected products at scale do both, the certification tied to the product release, the pentest tied to firmware drops, hardware revisions and fleet milestones.

Through the parts every device shares. A single unit on a bench often reveals a hardcoded key, a cloud endpoint or an update mechanism that is identical across the fleet. From there, an attacker uses the shared cloud API, the over-the-air update channel, or weak separation between customers to move from one device to many. That is why we always test the path from a single device to the fleet, not just the device in isolation.

Usually yes, at least a small number. Genuine IoT testing means hardware on the bench: opening a unit, reading its debug ports and extracting firmware needs the physical device. We typically ask for two or three sample units, ideally with debug access enabled, plus access to the companion app and the cloud backend. Where physical access is impossible, we scope around what can be tested (firmware images, the app and the cloud) and say so plainly in the proposal.

No. We work on sample units and staging environments, not your customers’ live devices, and every engagement runs under documented Rules of Engagement with a critical-finding protocol. Fleet-wide and cloud tests are performed against a controlled test tenant or with explicit approval, never as destructive actions on production. You get the attacker’s view of your product without putting shipped devices at risk.

A single connected product with a documented cloud backend typically takes two to three weeks of active testing, given the hardware, firmware, radio and cloud work involved; multi-product families or complex radio stacks run longer. Scoping happens beforehand and the retest follows your fixes. We confirm the timeline in the proposal, delivered within 48 hours of the first call.

Price follows scope: the number of devices and layers, the radio protocols involved, and whether the fleet backend is included. We quote a fixed price with no hidden fees and no obligation to renew. A focused single-product engagement sits at the bottom of the range; multi-product families or engagements needing specialist radio hardware scale from there. The retest, against the same firmware and hardware revision, is always included.

The senior specialist you meet on the first call runs it end to end. Our team holds OSCP, OSCE³, OSWE and OSEP credentials, and our IoT practice adds hardware, firmware and radio expertise (tools such as Ghidra, HackRF, Ubertooth and JTAGulator). We are NASA Bug Bounty verified contributors with published findings against connected products. The same person scopes, executes and retests. They stay your point of contact throughout.

Ready to close your fleet’s entry points?

Start with a no-obligation introductory meeting. We will review your connected-product estate, hardware, firmware, radio, app and cloud, and define the right IoT pentest before the project begins.

Request an IoT pentest proposal.
An experienced IoT pentester replies within one business day. You talk to the person who runs the test.

Protected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.

Or email [email protected] directly.

OUR CLIENTS HAVE ALREADY DONE IT

We at Etnia highly value our collaboration with Asperis Security.

Sergi Leno, Systems Manager
ETNIA Barcelona

ASPERIS has worked alongside us to define and implement our cybersecurity roadmap in Microsoft 365 with a structured approach aligned to business objectives.

Jordi Bondia, IT Director
SALVI

At NPAW we have collaborated with Asperis on various security initiatives and the experience has been very positive.

Sergi Laencina Verdaguer, CISO
NPAW

With Asperis you don’t hire a service. You hire a partner.