Skip to content
Service 05

IoT Penetration Testing

Connected device testing across firmware, radio interfaces, companion apps, and the cloud services that tie them together.

Where hardware, software, and radio meet

Connected devices sit in homes, offices, factories, and hospitals, and they fail differently from everything else you own. An IoT product is simultaneously a piece of hardware, an embedded operating system, one or more radio protocols, a mobile application, and a cloud service — and the interesting vulnerabilities tend to live in the seams between them rather than in any single component.

Our IoT testing addresses those seams directly.

Multi-layered testing

We work from firmware analysis and radio frequency interface probing through to API and companion application assessment. A device that resists network attack can still be defeated by a UART header on the board or an unauthenticated pairing sequence.

Device-specific assessment

Smart home appliances, wearables, industrial sensors, and connected medical devices each carry their own constraints, protocols, and consequences. Testing is tailored to the category rather than run from a generic template.

Real-world attack simulation

Our testers take the position of an attacker with physical access, an attacker within radio range, and an attacker on the internet, because those are three different threat models with three different answers.

Corporate Wi-Fi — the SSIDs your staff join in the office — is not this engagement. That is wireless penetration testing. Here the radio is the product’s: BLE, Zigbee, a proprietary link, whatever the device actually speaks.

Comprehensive reporting

You receive a categorized set of findings with proof-of-concept evidence and actionable remediation steps, including a clear statement of which issues are fixable in firmware and which are constrained by the hardware design.

Continuous coverage with Pincher

For connected products, exposure changes between releases. Pincher, our attack surface management platform, continuously discovers the hosts, services, and endpoints your devices depend on, and our testers validate what it finds rather than forwarding you raw alerts.

Attack surface management is offered as a full service in its own right — see attack surface management for how it runs alongside scheduled testing.

Common questions

IoT Penetration Testing — what clients ask

What hardware do you need from us?
At least two units of the device, and three is better — testing firmware extraction and fault injection can leave a unit unusable, and having a known-good reference to compare against is genuinely useful. Send them with any documentation, debug interfaces, and the companion app you have.
Do you test the cloud service as well as the device?
Yes, and it is usually where the highest-impact findings are. A vulnerability in one device affects one customer. A vulnerability in the cloud service that device authenticates to can affect every customer at once, which is why we test the device-to-cloud trust boundary explicitly.
Can you test a device that is already shipping?
Yes. Testing a shipped product is more common than testing a prototype, and the results feed directly into your firmware update process. Where a finding cannot be fixed in the field, we say so plainly so you can plan compensating controls rather than discover the constraint later.

Strengthen your defenses.

Tell us what you need tested. We’ll come back with scope, timeline, and a fixed price.

Request a quote