Automotive Security
Modern cars are computers on wheels. We test ECUs and CAN bus interfaces for exploitable weaknesses, under agreed safety constraints on a bench or an authorised vehicle.
Who this is for
Product, firmware and operations teams shipping physical or connected systems, where a security problem has consequences you cannot patch remotely.
Methodology
What We Test
- In-Vehicle Infotainment (IVI) systems and connectivity
- CAN bus messaging and gateway isolation
- ECU firmware and diagnostic services (UDS)
- Keyless entry systems (RF/NFC) and immobilizers
- Telematics Control Units (TCU) and cellular interfaces
- V2X (Vehicle-to-Everything) communication
How We Test
We connect directly to OBD-II and internal buses to fuzz ECU communication. We analyze RF signals for replay or relay attacks. We isolate ECUs to test firmware updates and boot security. We validate separation between safety-critical and infotainment domains.
What You Receive
- Safety-critical vulnerability assessment (ISO 21434 context)
- CAN bus message injection proofs
- Architecture improvements for domain isolation
- Secure boot and update mechanism validation
How an engagement runs
-
Scope, authorisation & safety constraints
We agree the target hardware or environment, the tests permitted on it, and the safety and operational limits before anything is powered on. Nothing starts without written authorisation from someone able to give it.
-
Samples, access & environment
We confirm what you supply — devices or samples, firmware and hardware revisions, bench or lab access, interfaces and credentials — and agree in writing whether work may be invasive or destructive, and how samples are returned or disposed of.
-
Passive analysis first
We start with observation, documentation review and passive analysis so we understand the system before touching anything that could affect it. On operational technology this stage carries the most weight.
-
Controlled active testing
Active testing happens on a bench, a replica or an agreed non-operational window — never against live production or safety-critical operations without explicit written approval and your engineers present.
-
Report & walkthrough
You get an executive summary and technical detail covering what we proved, what held, what could not be tested safely, and why. We walk your team through it.
-
Retest
Fixes are retested against the same samples or environment where that is practical. Retest scope is agreed in your scope document before the engagement begins.
Toolkit
- CANalyzer
- SocketCAN
- HackRF
- Custom ECU tools
