IoT & product security
Penetration testing of connected devices, firmware and apps, plus CRA-ready secure development for manufacturers of products with digital elements.
IoT securityHands-on security from Hannover
Zyberum is a team of security engineers who take real devices apart, break real systems and show you exactly how to fix them. Less paperwork, more proof. Compliance with the CRA, ISO/SAE 21434 and NIS2 follows from the work, not the other way round.
In short
Zyberum GmbH is a German cybersecurity company based in Hannover, specialising in IoT, automotive, OT and IT security. It offers penetration testing and fuzzing of connected products, compliance consulting for the EU Cyber Resilience Act, ISO/SAE 21434, UN R155, IEC 62443 and NIS2, the AutoST automated security testing suite, and Zyberdome, a fixed-price 24/7 managed SOC for small and medium-sized businesses.
Trusted by engineering teams at







What we secure
Devices, vehicles, machines and corporate networks are converging, and so are their attack surfaces. We secure all of them, from the chip to the cloud.
Penetration testing of connected devices, firmware and apps, plus CRA-ready secure development for manufacturers of products with digital elements.
IoT securityPentesting and fuzzing of ECUs, gateways, infotainment and backends. TARA and compliance for ISO/SAE 21434 and UN R155.
Automotive securityAssessments and hardening of PLC, SCADA and DCS environments to IEC 62443 and NIS2, without disrupting production.
OT securityInfrastructure, web and cloud pentests, plus Zyberdome, our fixed-price 24/7 managed SOC for small and medium-sized businesses.
IT securityHow we work
Security that only exists in a document protects nobody. This is how we work instead.
We solder, dump firmware, sniff buses and write exploits. If we say something is vulnerable, you get the proof-of-concept.
Every finding comes with a severity, the steps to reproduce it and a fix. Your engineers can start the same day.
The evidence for the CRA, ISO/SAE 21434, IEC 62443 and NIS2 comes out of real testing, not out of templates.
What we learn in the lab, we automate. AutoST, our ECU security testing suite, is the result.
No account managers in between. You talk to the people who test your system.
Our testers work with self-hosted AI models. Nothing about your systems goes to a cloud service, and you get more coverage for the same budget.
Credentials
Certificates do not find vulnerabilities, people do. These are the ones our customers ask for.
OSCP
Offensive Security Certified Professional
OffSec
Automotive Cybersecurity Level 1 & 2
Automotive Cybersecurity Certification for ISO/SAE 21434
SAE International · TÜV SÜD
ISO/IEC 27001 Auditor
Information security management systems
CRA Auditor
EU Cyber Resilience Act
CCISO
Certified Chief Information Security Officer
Technion
Case studies
Two IoT products, two tests, and findings nobody wants to read about their own device.
Full root access on the device, and access to the live WebRTC camera of other users through the cloud API.
We tested a camera-equipped robot vacuum: root access on the device, and cloud API flaws that opened the live camera of other users. What went wrong and why.
Read the case studyWe could see and activate other customers’ devices through MQTT, and geolocate where they are installed.
We tested a smart irrigation system: a broken MQTT setup let us see and switch the devices of other customers, and locate where they are installed.
Read the case studyProducts & services
Our services follow the lifecycle of your product and your business, backed by our own tools.
Hands-on security research on devices, vehicles, industrial systems, applications and infrastructure, with proof-of-concepts and retests.
Penetration testingSecure coding training, source code review, threat modelling and DevSecOps, so fewer vulnerabilities are written in the first place.
Secure developmentGap analysis, secure development lifecycle, vulnerability handling and testing to get products with digital elements CRA-ready.
CRA complianceFuzzing, security tests and vulnerability scanning over UDS, CAN FD, DoIP and SOME/IP, with evidence for UN R155 and ISO/SAE 21434.
Discover AutoSTEndpoint protection, 24/7 monitoring and incident response for Windows, macOS and Linux, from €12 per device per month.
See plansAutomotive hacking with real ECUs and 30+ CTF challenges, secure coding for developers and ISO/SAE 21434 compliance courses.
Training catalogueHow we work
We agree on goals, assets and constraints, and build a threat model around your architecture.
Black, grey or white box. Hands-on testing on real hardware, networks and code, backed by automation.
CVSS-scored findings, proof-of-concepts and a remediation roadmap, in a TARA-compatible format.
We support your engineers through remediation and verify the fixes, producing audit-ready evidence.
FAQ
Zyberum is a cybersecurity company from Hannover, Germany, focused on IoT, automotive, OT and IT security. We perform penetration tests and fuzzing, support compliance with the CRA, ISO/SAE 21434, UN R155, IEC 62443 and NIS2, build the AutoST security testing suite and run Zyberdome, a managed SOC for SMBs.
IoT and electronics manufacturers, automotive OEMs and suppliers, industrial companies and critical-infrastructure operators, and small and medium-sized businesses, as well as healthcare and software companies. Teams at ZKW, Delta, Wepa, Audi, Harman, Miele and Siemens have trusted our work.
Yes. We are based in Hannover, Germany, and work for customers worldwide, on site or remotely, in English and German.
Get started
Tell us what you are building or running. In 15 minutes you will know whether and how we can help.

Your call is withTom ZaubermannFounder & CEO, Zyberum
We reply within one business day.
Your privacy
We use cookies and similar technologies to measure our website and the success of our ads. You decide which ones we may use. You can change your choice at any time via "Cookie settings" in the footer. Privacy policy