Hardware / IoT Pentesting
... > Pentesting Services > Hardware / IoT Pentesting
Hardware / IoT Pentesting
IoT devices are a growing target of our test and assessment services. Hardware, firmware and (cloud dwelling) backends are all targets for attackers and often not very well understood.
Bureau Veritas Cybersecurity can test all these aspects, and also apply reverse engineering and firmware hacking techniques to find out which weaknesses exist. Interesting to note in this context is that Bureau Veritas Cybersecurity is also active partner in the INTERSECT research consortium that includes all Dutch Technical Universities and many multinationals, and is focused on developing new technologies for testing and securing (Industrial) IoT devices.
In general it depends largely on the device what exact steps are taken in an IoT assessment. However if hardware is in scope we will identify interfaces such as serial, SPI, I2C, JTAG and others. We will attempt to identify all components and their weaknesses. For certain components Bureau Veritas Cybersecurity can perform ‘chip-off’ techniques by removing the component from the PCB and placing it in a specific test bed. This is usually done to extract memory contents from the component for later analysis.
If an IoT device has a companion app, we can perform a Mobile app assessment on that part, and if the IoT device has a web interface, we can perform a web application assessment on that. Normally, we require several hardware samples to be delivered, that can be destructively tested (i.e.: do not count on getting them back in 1 piece).
Also read: From mattresses to artificial hearts: why IoT security is crucial
I'd like to know more about Hardware / IoT Pentesting

Related Services
CLOUD Pentesting
Wi-Fi Pentesting
Infrastructure Pentesting
Why choose Bureau Veritas Cybersecurity
Bureau Veritas Cybersecurity is your expert partner in cybersecurity. We help organizations identify risks, strengthen defenses and comply with cybersecurity standards and regulations. Our services cover people, processes and technology, ranging from awareness training and social engineering to security advice, compliance and penetration testing.
We operate across IT, OT and IoT environments, supporting both digital systems and connected products. With over 300 cybersecurity professionals worldwide, we combine deep technical expertise with a global presence. Bureau Veritas Cybersecurity is part of the Bureau Veritas Group, a global leader in testing, inspection and certification.