Services

Security you can actually verify

Every engagement ends with something concrete: a list of vulnerabilities with proof of exploitation, clear priorities and fixes your team can ship.

Scope

How I can help

IoT and embedded penetration testing

Full device analysis: hardware, firmware, communication and update processes. I look for the paths a real attacker would take to own the device or its data.

Who it's forDevice manufacturers, integrators and R&D teams preparing to ship.

  • Hardware analysis: debug interfaces, memory, secure boot protections
  • Firmware extraction and analysis, hunting for secrets and weak mechanisms
  • Wired and wireless communication, including pairing mechanisms
  • Over-the-air update process and image signing
  • Report with CVSS 3.1 ratings and concrete remediation steps

Training and workshops

Sessions built around your team, not an off-the-shelf course. Participants work on real hardware and real vulnerabilities.

Who it's forDevelopment, QA and security teams; universities and industry organisations.

  • IoT and embedded security from the ground up
  • Modern attack techniques - what they actually look like
  • Red Team / Blue Team exercises matched to your stack
  • Secure coding and security across the development lifecycle
  • Conference talks and industry events

Automotive security

Testing of in-vehicle components and systems, built on automotive project experience covering hardware testing and security process automation.

Who it's forComponent suppliers and teams responsible for telematics and in-vehicle systems.

  • Analysis of control and telematics modules
  • Communication buses and zone separation
  • Security of the in-vehicle update process
  • Support in preparing for industry requirements

ICS, OT and infrastructure audits

Testing of industrial control systems and corporate IT infrastructure. Industrial networks were rarely designed on the assumption that someone would get in - and today most of them touch the outside world.

Who it's forManufacturing plants, infrastructure operators, companies bridging office and production networks.

  • Review of network architecture and IT/OT zone separation
  • Testing of controllers, operator panels and supervisory systems
  • Inventory of devices and their exposure to remote access
  • Access control, authentication and remote maintenance configuration
  • Remediation priorities that account for production continuity

Consulting and vulnerability analysis

For when you don't need a full pentest, just answers: is this safe, what should we fix first, and how do we set up a process so it stops coming back.

Who it's forTeams building a security process from scratch or cleaning up an existing one.

  • Security review of the architecture
  • Vulnerability prioritisation by real risk, not the CVSS number alone
  • Support in building security into the development lifecycle
  • Design consulting for new devices

Compliance and audits

Support with regulatory requirements: what actually needs doing, in what order, and how to document it so it survives an audit.

Who it's forCompanies preparing for NIS2, ISO 27001 certification or covered by the Polish KSC.

  • Gap analysis against NIS2 requirements
  • Preparation for ISO 27001 certification
  • Obligations under the National Cybersecurity System
  • Cyber Resilience Act for hardware manufacturers

Not sure which one fits?

Describe the situation in a few sentences. I'll tell you what makes sense in your case - including when the answer is "not yet".