
UK offensive security consultancy delivering CREST-accredited penetration testing, adversary simulation and CBEST, TIBER-EU and TBEST threat-led testing, mainly for financial services and other large organisations.
IoT penetration testing evaluates the security of Internet of Things devices, their firmware, communication protocols, cloud backends, and mobile companion apps. This holistic approach examines the entire IoT ecosystem for vulnerabilities that could allow attackers to compromise devices, intercept data, or use IoT devices as entry points into corporate networks.
Testers analyse hardware interfaces (JTAG, UART, SPI), extract and reverse-engineer firmware, examine wireless protocols (Bluetooth, Zigbee, LoRa, Wi-Fi), test cloud APIs and management platforms, and assess the security of update mechanisms.
IoT pen testing is critical for manufacturers of connected devices, organisations deploying IoT at scale, and critical infrastructure operators. Common vulnerabilities found include hardcoded credentials, unencrypted communications, insecure firmware update mechanisms, and weak authentication. As IoT devices proliferate across industries from healthcare to manufacturing, ensuring their security is vital for protecting operational technology environments and preventing large-scale compromises.

UK offensive security consultancy delivering CREST-accredited penetration testing, adversary simulation and CBEST, TIBER-EU and TBEST threat-led testing, mainly for financial services and other large organisations.

Global Big Four professional services firm delivering CREST, CHECK, and CBEST-accredited penetration testing and red teaming services from London, serving the UK's largest enterprises and regulated organisations.

Manchester-based independent cybersecurity consultancy with over 20 years of experience delivering CREST and CHECK-accredited penetration testing, red teaming, and compliance certification services.

Cybersecurity division of the Thales Group, with ANSSI, CREST, FedRAMP 3PAO, and NATO-cleared personnel. Defence, government, and critical infrastructure penetration testing worldwide.
Munich- and Budapest-based embedded cybersecurity experts focused on financial services, automotive and mobility, manufacturing and industrial automation, energy and more. The services and platform go beyond compliance, supporting the requirements of the Cyber Resilience Act, PCI PTS, UN R155, ISO/SAE 21434 and other standards and regulations.

US-headquartered cybersecurity consultancy with 800+ employees, serving ~40% of the Fortune 500. FedRAMP 3PAO, PCI QSA, and HITRUST accreditations.
US penetration testing firm founded in 2011, running 600+ engagements a year with a fully remote, US-based team. Manual, expert-led testing across web, network, cloud, mobile, wireless, OT/ICS, and AI/LLM. Gartner Sample Vendor for PTaaS.

Helsinki-headquartered Finnish cybersecurity firm with roots dating to 1988, offering CREST-accredited penetration testing and deep expertise in EU regulatory compliance including GDPR, NIS 2, and TIBER-EU.

CREST-accredited Canadian pen testing firm with a 95% manual-first approach. All testers hold OSCP minimum certification. Zero false positive guarantee.

Vienna-headquartered Austrian cybersecurity consultancy with a prolific Vulnerability Lab research program and deep expertise in IoT and embedded systems security across the DACH region.

Boutique security consultancy specialising in IoT, SCADA/ICS, embedded systems, and hardware security research with world-renowned researchers.
Swiss cybersecurity firm with major Singapore operation. CREST accredited, CSA-licensed in Singapore. Manual exploitation focus with the proprietary MAD reporting platform.
Any connected device can be tested including industrial sensors, medical devices, smart home products, automotive systems, wearables, and building management systems.
Hardware testing requires physical access for interface analysis. Remote testing can cover cloud backends, APIs, and network communications, but physical access enables the most thorough assessment.
Testers look for hardcoded credentials, insecure firmware updates, unencrypted communications, exposed debug interfaces, weak authentication, and vulnerabilities in wireless protocols.