Skip to content
Zyberum Cyber Security Firm
Menu

Hands-on security from Hannover

We hack your IoT, vehicles, plants and IT. Before someone else does.

Zyberum is a team of security engineers who take real devices apart, break real systems and show you exactly how to fix them. Less paperwork, more proof. Compliance with the CRA, ISO/SAE 21434 and NIS2 follows from the work, not the other way round.

  • Real exploits, not checklists
  • OSCP-certified testing
  • 24/7 managed SOC

In short

Zyberum GmbH is a German cybersecurity company based in Hannover, specialising in IoT, automotive, OT and IT security. It offers penetration testing and fuzzing of connected products, compliance consulting for the EU Cyber Resilience Act, ISO/SAE 21434, UN R155, IEC 62443 and NIS2, the AutoST automated security testing suite, and Zyberdome, a fixed-price 24/7 managed SOC for small and medium-sized businesses.

Trusted by engineering teams at

  • Audi
  • Siemens
  • Harman
  • Miele
  • ZKW
  • Delta Electronics
  • Wepa

What we secure

Four domains. One team of hands-on security engineers.

Devices, vehicles, machines and corporate networks are converging, and so are their attack surfaces. We secure all of them, from the chip to the cloud.

IoT

IoT & product security

Penetration testing of connected devices, firmware and apps, plus CRA-ready secure development for manufacturers of products with digital elements.

IoT security
Automotive

Automotive security

Pentesting and fuzzing of ECUs, gateways, infotainment and backends. TARA and compliance for ISO/SAE 21434 and UN R155.

Automotive security
OT

OT & industrial security

Assessments and hardening of PLC, SCADA and DCS environments to IEC 62443 and NIS2, without disrupting production.

OT security
IT

IT security for SMBs

Infrastructure, web and cloud pentests, plus Zyberdome, our fixed-price 24/7 managed SOC for small and medium-sized businesses.

IT security

How we work

Less paper. More proof.

Security that only exists in a document protects nobody. This is how we work instead.

Hands on the hardware

We solder, dump firmware, sniff buses and write exploits. If we say something is vulnerable, you get the proof-of-concept.

Results you can act on

Every finding comes with a severity, the steps to reproduce it and a fix. Your engineers can start the same day.

Compliance as a by-product

The evidence for the CRA, ISO/SAE 21434, IEC 62443 and NIS2 comes out of real testing, not out of templates.

We build our own tools

What we learn in the lab, we automate. AutoST, our ECU security testing suite, is the result.

Engineers talk to engineers

No account managers in between. You talk to the people who test your system.

AI that stays in our lab

Our testers work with self-hosted AI models. Nothing about your systems goes to a cloud service, and you get more coverage for the same budget.

Credentials

Certified where it counts

Certificates do not find vulnerabilities, people do. These are the ones our customers ask for.

Case studies

What it looks like when we test

Two IoT products, two tests, and findings nobody wants to read about their own device.

Products & services

From secure design to 24/7 operations

Our services follow the lifecycle of your product and your business, backed by our own tools.

Test

Penetration testing

Hands-on security research on devices, vehicles, industrial systems, applications and infrastructure, with proof-of-concepts and retests.

Penetration testing
Build

Secure development

Secure coding training, source code review, threat modelling and DevSecOps, so fewer vulnerabilities are written in the first place.

Secure development
Comply

Cyber Resilience Act readiness

Gap analysis, secure development lifecycle, vulnerability handling and testing to get products with digital elements CRA-ready.

CRA compliance
Product

AutoST: automated ECU testing

Fuzzing, security tests and vulnerability scanning over UDS, CAN FD, DoIP and SOME/IP, with evidence for UN R155 and ISO/SAE 21434.

Discover AutoST
Operate

Zyberdome: managed SOC

Endpoint protection, 24/7 monitoring and incident response for Windows, macOS and Linux, from €12 per device per month.

See plans
Learn

Hands-on training

Automotive hacking with real ECUs and 30+ CTF challenges, secure coding for developers and ISO/SAE 21434 compliance courses.

Training catalogue
years in IT and product security
15+
years in IT and product security
security domains: IoT, automotive, OT, IT
4
security domains: IoT, automotive, OT, IT
SOC monitoring with Zyberdome
24/7
SOC monitoring with Zyberdome
coverage from device firmware to the cloud
360°
coverage from device firmware to the cloud

How we work

From first call to fixed findings

  1. 01

    Scope & threat model

    We agree on goals, assets and constraints, and build a threat model around your architecture.

  2. 02

    Test & analyse

    Black, grey or white box. Hands-on testing on real hardware, networks and code, backed by automation.

  3. 03

    Report & prioritise

    CVSS-scored findings, proof-of-concepts and a remediation roadmap, in a TARA-compatible format.

  4. 04

    Fix & retest

    We support your engineers through remediation and verify the fixes, producing audit-ready evidence.

FAQ

Frequently asked questions

What does Zyberum do?

Zyberum is a cybersecurity company from Hannover, Germany, focused on IoT, automotive, OT and IT security. We perform penetration tests and fuzzing, support compliance with the CRA, ISO/SAE 21434, UN R155, IEC 62443 and NIS2, build the AutoST security testing suite and run Zyberdome, a managed SOC for SMBs.

Which industries does Zyberum work with?

IoT and electronics manufacturers, automotive OEMs and suppliers, industrial companies and critical-infrastructure operators, and small and medium-sized businesses, as well as healthcare and software companies. Teams at ZKW, Delta, Wepa, Audi, Harman, Miele and Siemens have trusted our work.

Do you work outside Germany?

Yes. We are based in Hannover, Germany, and work for customers worldwide, on site or remotely, in English and German.

Get started

Talk to a security expert this week

Tell us what you are building or running. In 15 minutes you will know whether and how we can help.

  • You speak with a security engineer, not a sales rep
  • A concrete next step after the first call
  • Free and without obligation, NDA on request
Tom Zaubermann

Your call is withTom ZaubermannFounder & CEO, Zyberum

Call us: +49 176 439 17074info@zyberum.com

Or send us a message

We reply within one business day.

Call usBook a 15-min call

Pick a time that suits you

Open in a new tab