Insights
Device security in practice
Writing on hardware penetration testing, firmware analysis and the requirements the CRA and NIS2 place on manufacturers. Concrete answers to the questions that keep coming up in projects.
Three paths: CRA and compliance for manufacturers with a deadline in the calendar, the basics of commissioning a test for the procurement side, and the workshop, meaning what this work looks like from the inside.
-
Pentest, audit or vulnerability scan: what is the difference
Three different services that offers often blur together. A comparison of scope, time and outcome, plus guidance on which one fits your situation.
-
From a soldering iron to smart TVs. IoT and hardware security in practice
How an interest in electronics and some C turned into testing IoT devices, why an open UART is still the norm, and what I do today keeping televisions secure.
-
Car hacking: how I went from web pentesting to vehicles
Where my interest in automotive security came from, why in-vehicle buses are a different world from web applications, and why this niche is still so lightly explored.
-
From a Rubber Duck to Gandalf: My Road into Prompt Injection and Prompt Engineering
How Harvard's CS50, Lakera's Gandalf and the Web Security Academy materials pulled me into LLM security, and why prompt injection is social engineering wearing a new coat.
-
How to prepare for a penetration test
What to provide before a penetration test of a network, web and mobile app, IoT device or OT system. Common ground rules, per-type checklists and what not to do beforehand.
-
How much does a penetration test cost: networks, apps and devices A rate of PLN 150-250 per hour and effort ranges for testing networks, applications, IoT devices and OT systems. The billing model and how to estimate the cost yourself.
-
Is my product in scope of the CRA? A five question test
Five questions that settle whether a product falls under the Cyber Resilience Act and which category it lands in. The starting point before estimating compliance cost.
-
CRA: what the Cyber Resilience Act requires from manufacturers Product categories, deadlines, Annex I, SBOM and the 24 hour reporting duty. A practical guide to the CRA for manufacturers of products with digital elements.
-
Reporting a vulnerability within 24 hours: who, to whom and what The CRA reporting duty applies from 11 September 2026. The 24 hour, 72 hour and 14 day deadlines, who receives the notification and the readiness the procedure demands.
Need a device, application or network tested, rather than another scanner report?