SysTools
VAPT Service

IoT Device VAPT

Security testing of connected devices — the hardware itself, the software inside it, its wireless connections, and the phone app or online service behind it. We test the way a real attacker would: with the device in our hands, or from within radio range of it.

Progress 0% 0 of 0 answered 0 mandatory pending

Before you start

  • We test the physical device, the software inside it, how it talks to the outside world, and anything that comes with it — a phone app or an online service.
  • Most of this can be answered in a sentence. If you are not sure about something, write what you know and we will pick it up on the scoping call.
  • Please do not type passwords or keys into this form.
  • Fields marked * are needed before we can begin.

1 Assessment Details

Mandatory

Plain English is fine. Tell us what it is, who uses it, and what would be worst if someone tampered with it.

2 The Devices

Decides the timeline

The number of different device models is what decides the estimate. Ten identical units count as one model.

Scope

Different device models to testnot the number of units

Units

Test units you can give us, per model

Guide

Two units per model is idealone is opened up, one stays working2 each

Model names or numbers if you have them. We only test what is listed here.

Anything that carries data in or out — Wi-Fi, Bluetooth, a mobile network, a cable, or a radio link to another device.

For example a medical device, a vehicle part, or something controlling machinery, heating or power.

Anything with a safety consequence is tested more carefully, and never in a way that could cause it.

Our lab is normally quicker, as the equipment is already set up. If the devices cannot leave your premises, we bring the equipment to you.

3 What Comes With the Device

Mandatory

Most serious problems with connected devices are not in the device itself — they are in the app or the online service behind it.

Testing the app alongside the device is normally worth it — the two are usually only as strong as the weaker one.

Often called the firmware, and usually an update file your engineering team can provide. It saves a lot of time — without it we have to extract it from the device ourselves, which is slower and sometimes damages the unit.

4 Data and Standards

Affects how serious a finding is

If you do not know, leave this blank — we will suggest what fits your device and your market.

5 How We Test

Nothing here needs an answer — it is what you are buying.

How the assessment runs

We use the device as a customer would, then open it up and examine the electronics inside. We get the software out of it — from you if you can supply it, otherwise by reading it off the hardware — and search it for passwords and known weaknesses. We capture everything the device sends and receives, test its wireless connections from where an attacker would stand, and where a phone app or online service is in scope we test those too. Each finding is reproduced, evidenced and rated, and retested once a fixed version exists.

What we look for

Service connections left on the circuit board. Passwords and keys built into the software. Whether the device would accept an update that did not come from you. Whether the data it sends can be read, changed or replayed. Default or shared passwords across the fleet. What is left on a device that is returned, resold or thrown away. And whether one customer can reach another customer's device through the app or the service behind it.

What we will not do

This is a controlled assessment, not a red-team exercise. We work only on the units you provide, never on devices live in customers' hands, and never in a way that could cause physical harm.

Please note: reading software off a chip or connecting to the electronics inside can leave a unit unusable, and devices may not survive the assessment. That is normal for this kind of testing, so we will ask you for spare units we are allowed to damage when the scope is confirmed. If nothing may be damaged, tell us on the call and we will keep to methods that leave the device working — some findings will then be recorded as unproven rather than confirmed.

6 How We Rate Findings

SeverityWhat it means
CriticalCould let someone take control of devices remotely, reach every customer's data, or install their own software across your whole fleet.
HighCould let someone take over a device, reach another customer's data, or get past a login — with physical access or from nearby.
MediumA real problem, but it needs something specific first — the device in their hands, being within radio range, or a valid login.
LowLimited impact on its own. Worth fixing in the next hardware or software revision.
InformationalAn observation or hardening suggestion with no direct security impact.

A weakness that needs the device in someone's hands is rated lower than the same weakness reachable over the internet — unless your devices sit in public places, where physical access is easy to get. Anything with a safety consequence is rated on that basis rather than on the data involved. After a retest each finding is marked Closed, Open, Partially Fixed, Risk Accepted or Not Retested.

7 Timeline Estimate

The device count carries over from section 2 automatically.

Timeline inputs

Different device models
People working on it at once
Number of retests

Ten identical units count as one model. One retest is included as standard. If a phone app or an online service is also in scope, that is added when the scope is confirmed.

Estimated duration 0 working days
Testing0
Retest0

Subject to final scope review, device availability and resource confirmation. The final timeline is confirmed after the complete scope has been reviewed and understood.

Save and Export Response

Responses are stored in this browser until exported or cleared.