Security Testing for Manufacturers and Users of IoT Devices
The Institute for Innovative Security conducts security tests on IoT products to identify vulnerabilities. This enables organizations to address them. These organizations include manufacturers of IoT products as well as their users, such as companies and government agencies. In particular, the institute also offers security testing for small organizations that are often too small to work with for-profit service providers.

Security Scans for Organizations of All Sizes
As digitization advances, companies and government agencies are connecting their devices to one another and to the Internet. This Internet of Things (IoT) gives organizations access to smart features. However, this necessary connectivity also increases the attack surface for cybercriminals. To minimize the risk of IT security incidents as much as possible, manufacturers and users of IoT products should conduct tests to identify and address vulnerabilities as early as possible.
The Institute for Innovative Security conducts these security tests for manufacturers and users of IoT products to identify vulnerabilities and enable the organization to address them.
Security Tests: A Challenge in Everyday IT Operations
In large organizations, such tests are often planned and carried out by the in-house IT department. In everyday practice, however, small and medium-sized businesses and government agencies rarely have the capacity to conduct security tests. For this reason, external service providers are often hired. However, testing small systems is not economically viable. In addition to larger projects for manufacturers and users of IoT products, the Institute for Innovative Security at THA therefore also explicitly offers compact security scans for small organizations such as SMEs and government agencies.
As a manufacturer of IoT products, security must be integrated into the development process from the very beginning. This is because the first vulnerabilities can arise at this early stage. If the product is already on the market, vulnerabilities must be addressed retroactively—and until then, they pose a risk to users and the manufacturer’s reputation. To identify problems as early as possible, manufacturers of IoT products can work with THA to test various configurations and operating modes for vulnerabilities during the development phase—in detail, both in the source code and in the firmware.
In addition to larger projects, the Institute for Innovative Security at THA also offers compact security scans for small organizations. These consist of standardized security tests that are specifically tailored to the needs of SMEs and small government agencies.
How is a security test conducted?
Phase 1: Initial Consultation
A confidential preliminary consultation always takes place before your security test begins. During this consultation, the researchers will work with you to assess your current situation and agree on measures tailored to your individual needs.
Phase 2: Implementation
Here, researchers from the Institute for Innovative Security examine your IoT products. In doing so, they address the various requirements of your organization as a manufacturer or user of IoT products.
Phase 3: Preparation of Results
You will receive the results of the security test and recommendations for action in a report presented as clearly and simply as possible. This will enable you to efficiently implement effective measures to address the identified vulnerabilities and secure your IoT products.
