Embedded & Industrial Security

IoT/OT Security Penetration Testing

IoT and OT penetration testing is crucial for securing connected devices and industrial systems. At BlockSecBrain, our researchers provide thorough testing of devices, protocols, and networks while helping preserve operational continuity.

Overview

Where a Security Failure Becomes a Safety Failure

Connected products and industrial systems fail differently from enterprise IT. A compromised controller does not leak records; it moves a physical process. Availability outranks confidentiality, patch windows are measured in years, and the device in the field will outlive the team that built it.

Our methodology reflects that. We work from extracted firmware and bench hardware wherever possible, reserving live-environment testing for what genuinely requires it, and we agree the safety envelope before a single packet is sent.

Coverage runs the full stack: the silicon and its debug interfaces, the firmware and its update chain, the protocols on the wire, the cloud backend, and the companion application that most owners will actually use.

Key activities

In every engagement
  • Firmware extraction, unpacking, and filesystem analysis
  • Hardcoded credential, key, and certificate discovery
  • Secure boot and signed update chain validation
  • Binary hardening and known-CVE component review
  • Hardware interface review: UART, JTAG, SWD, SPI, I2C
  • Debug port exposure and chip-off memory extraction
  • Wireless protocol testing: BLE, Zigbee, LoRaWAN, Wi-Fi
  • Industrial protocol analysis: Modbus, OPC UA, PROFINET
  • PLC, HMI, and SCADA configuration review
  • IT/OT boundary and segmentation validation
  • Cloud backend and device provisioning security testing
  • Companion mobile application and API assessment

Assessment Methodology

IoT/OT Penetration Testing Categories

Comprehensive testing across devices, protocols, networks, remote interfaces, and industrial control systems.

Device & Firmware Testing

Assess device security, firmware vulnerabilities, and update mechanisms to prevent exploits and unauthorised access.

Network & Protocol Analysis

Evaluate communication protocols, network services, and data transmission for weak points and insecure configurations.

Data & Access Control

Test encryption, authentication, and access mechanisms that protect sensitive IoT and OT data.

Industrial OT Security

Review SCADA and industrial control systems for configuration issues and vulnerabilities that could disrupt operations.

Remote & Cloud Interfaces

Assess cloud-connected systems, mobile applications, and remote management surfaces for data exposure risk.

Risk & Compliance Advisory

Provide actionable recommendations to reduce risk and support compliance in connected device ecosystems.

Deliverables

What You Receive

Every engagement closes with a documented, defensible evidence set that serves engineering, leadership, and audit at the same time.

Technical Findings Report

Every finding with reproduction steps, evidence, affected components, risk rating, and specific remediation guidance.

PDF report

Executive Summary

Risk posture, business impact, and thematic root causes written for leadership and board reporting.

PDF / slides

Remediation Tracker

A structured issue list with severity, owner, and status columns that maps directly into your ticketing system.

XLSX / CSV

Retest Certificate

Formal confirmation of which findings were verified as remediated, suitable for customers and auditors.

PDF attestation

Attack Path Narrative

Chained walkthroughs showing how individual weaknesses combine into a realistic compromise scenario.

Report section

Debrief Session

A live walkthrough with your engineering and security teams covering findings, priorities, and fix strategy.

Live session

Reporting Process

Risk Rating Model

Findings are rated on demonstrated exploitability and business impact, not scanner severity. Critical findings are escalated during testing rather than held for the report.

CriticalConfirmed exploitation with direct impact on data, safety, or availability. Reported within 24 hours of validation.
HighExploitable weakness with meaningful business impact or a reliable path to privilege escalation.
MediumRequires specific conditions or chaining, but materially weakens the security posture.
LowLimited impact in isolation. Tracked for hardening and defence-in-depth improvement.
InformationalObservations, hygiene items, and architectural recommendations with no direct exploitability.

Client Benefits

Outcomes You Can Measure

Embedded findings need to be actionable for hardware, firmware, and operations teams at the same time.

Bench

Safe by Default

Testing runs on bench hardware and lab replicas first, so live process risk is contained by design.

SBOM

Component Visibility

Firmware analysis produces a component inventory with known-CVE exposure per package version.

62443

Certification-Ready Evidence

Findings are structured to feed IEC 62443 and product security documentation directly.

Technology Coverage

Technologies We Test

Coverage spans embedded silicon, industrial protocols, and the platforms that connect them.

Silicon & Platforms

  • ARM Cortex-M/A
  • ESP32
  • Nordic nRF
  • STM32
  • RISC-V
  • Yocto / Buildroot
  • FreeRTOS
  • Zephyr

Wireless Protocols

  • BLE
  • Zigbee
  • Z-Wave
  • LoRaWAN
  • Wi-Fi
  • NFC / RFID
  • Sub-GHz
  • Thread / Matter

Industrial Protocols

  • Modbus TCP/RTU
  • OPC UA
  • PROFINET
  • EtherNet/IP
  • DNP3
  • IEC 60870-5-104
  • BACnet
  • CAN / CANopen

Control Systems

  • Siemens S7
  • Rockwell ControlLogix
  • Schneider Modicon
  • Beckhoff TwinCAT
  • WinCC / FactoryTalk
  • Ignition SCADA

Hardware Toolchain

  • Logic analysers
  • Bus Pirate
  • JTAGulator
  • ChipWhisperer
  • SDR / HackRF
  • Flash programmers
  • Ghidra
  • binwalk

Device Cloud

  • AWS IoT Core
  • Azure IoT Hub
  • MQTT brokers
  • OTA update services
  • Device provisioning
  • Digital twins

Standards Alignment

Compliance Mapping

IoT and OT findings map to the product security and industrial standards that increasingly gate market access.

IEC 62443

IEC 62443-4-1, 4-2 & 3-3

Secure development lifecycle, component security requirements, and system-level zone and conduit evidence for industrial products and plants.

ISO 21434

ISO/SAE 21434

For automotive components, findings feed TARA validation, cybersecurity assurance levels, and the item-level security case.

OWASP IoT

OWASP IoT Top 10

Device findings carry OWASP IoT categories covering weak credentials, insecure interfaces, and lack of update mechanisms.

MITRE ICS

MITRE ATT&CK for ICS

Attack paths are annotated with ICS techniques so plant detection and response can be validated against real scenarios.

CRA

EU Cyber Resilience Act

Testing evidence supports essential cybersecurity requirements and vulnerability handling obligations for products with digital elements.

RED

RED Delegated Regulation 2022/30

Network protection, personal data, and fraud prevention requirements are assessed for radio equipment in scope.

How an IoT/OT assessment supports each framework.
StandardWhere it appliesHow this engagement supports it
IEC 62443-4-2Component security for devicesRequirement-level gap analysis with security level target assessment.
IEC 62443-3-3System and plant architectureZone and conduit validation across the IT/OT boundary.
ISO/SAE 21434Automotive componentsAttack feasibility input to TARA and validation evidence for the security case.
OWASP IoT Top 10Connected product baselineCategory mapping on every device finding.
MITRE ATT&CK ICSPlant detection coverageTechnique-tagged narratives for OT SOC rule development.
EU CRA / REDEU market accessTest evidence and vulnerability findings that feed the technical documentation file.

Industry Expertise

Industries Served

We work with regulated and safety-critical manufacturers where a security failure carries operational, contractual, and certification consequences.

Automotive OEMs & Tier-1ECUs, telematics, and connected vehicle platforms
Industrial AutomationPLCs, SCADA, and plant-floor networks
IoT ManufacturersConnected products, gateways, and companion apps
Medical DevicesConnected diagnostics, monitoring, and hospital systems
Cloud & SaaSMulti-tenant platforms and customer-facing services
Enterprise Security TeamsInternal validation, assurance, and audit support

Engagement Workflow

How We Work With You

A predictable delivery model with defined checkpoints, so your teams know exactly what happens and when.

Scoping & Rules of Engagement

We agree targets, depth, timing windows, safety constraints, and escalation contacts before any testing begins.

Threat Modelling

Trust boundaries, attacker goals, and abuse cases are mapped so testing effort follows real business risk.

Execution & Validation

Manual, tool-assisted, and AI-accelerated testing with every finding reproduced and evidenced.

Reporting & Risk Rating

Technical detail for engineers, prioritised risk narrative for leadership, delivered in one report set.

Remediation Support

Direct access to the testing engineers while your teams design and implement fixes.

Verification Retest

A free retest of remediated findings confirms the fix holds and closes the engagement.

Questions

Frequently Asked Questions

Practical answers to what procurement, engineering, and security teams ask before an engagement starts.

Will you test our live production line?

Only where it is genuinely necessary and only under agreed constraints. We prefer bench hardware, lab replicas, or maintenance windows. Active testing on live OT is always passive-first, with an agreed abort procedure.

Can you work from firmware alone?

Yes. Firmware analysis alone reveals hardcoded credentials, weak update verification, vulnerable components, and exposed services. Physical hardware extends coverage to debug interfaces and side-channel exposure.

Do you support pre-certification testing?

Yes. We regularly perform gap assessments ahead of IEC 62443 or automotive audits so that issues are found before an assessor finds them. We are consultants, not a certification body.

Do you test production systems?

Yes, where the environment and rules of engagement allow it. We agree timing windows, rate limits, and safety constraints up front, and we maintain a live escalation channel for the duration of the engagement. Where production testing is unacceptable, we test staging and validate configuration parity separately.

How long does a typical engagement take?

Most assessments run between one and three weeks of active testing, depending on scope size and depth. Scoping takes two to three working days, and the report is delivered within five working days of testing completion.

Is the retest really included?

Yes. One verification retest of remediated findings is included in the engagement fee, provided it is requested within 90 days of report delivery.

Who performs the testing?

Senior security engineers only. We do not staff engagements with junior analysts running scanner output, and the engineer who tested your environment is the engineer you speak to during remediation.

Ready to secure your connected products?

From firmware and silicon to plant networks, let us find what an attacker would reach before your product ships or your line runs.