Industrial Product Security

We test the product. Not just the perimeter.

Deep security testing across hardware, firmware, software, protocols, cloud backends and cryptography. For teams building security-critical B2B products and platforms.

Hardware → CloudCross-layer assessment
Product systemsDevice, software and backend
Engineering scopeArchitecture and threat model
MCU / SoC
live lab note online
$ probe uart /dev/ttyUSB0
interface detected
boot_log exposed
recovery_mode reachable
UART
The serial interface responds and exposes boot output. We use it to understand startup behavior, recovery paths and what the device reveals before the application is running.
What we work on

Industrial products are systems, not single interfaces.

Industrial and security-critical B2B products rarely stop at one technical boundary. A device may extend into applications and cloud services; a digital product may depend on APIs, Kubernetes, identity and secrets. We test the layers that define the real attack surface.

PRODUCT ENVIRONMENT DEVICE → PROTOCOL → API → BACKEND
DIGITAL PRODUCT / CLOUD PLATFORM
APIK8sIAMSECRETS
INDUSTRIALcontroller / gateway
NETWORKsecurity appliance
INFRASTRUCTUREenergy / charging
EMBEDDEDplatform / module
Why it matters

A security defect can scale with the product.

Once deployed, a shared weakness can affect devices, customer environments and the infrastructure behind the product.

Customer & fleet impact A shared weakness can affect deployed devices, customer environments or an entire product platform.
Cost of remediation After release, fixes can require field updates, customer coordination, emergency releases or hardware replacement.
Release & commercial risk Late findings can delay releases, block customer acceptance or turn into field incidents.
Product assessments

Follow the attack path
across product layers.

Start with the physical or embedded product itself, or with the software platform around it. We scope the test around the product architecture and the attack paths that matter.

01 / Device & Firmware

Industrial Device & Firmware Security Assessment

Physical / embedded product in scope

For products where the device itself is part of the target. We test the system from physical interfaces, hardware security controls and boot chains through firmware, protocols, applications and backend components.

HardwareHardware ControlsFirmwareBoot UpdatesProtocolsBackendCrypto
Device & Firmware Assessment
attack path selected
Cloud / Backend
Backend control paths reshape how a product is attacked, updated and trusted.
02 / Penetration Testing

Product Penetration Testing

Product software / platform in scope

For products where hardware analysis is not required. We test web and mobile applications, APIs, cloud-native backends, Kubernetes, management interfaces and network services as the product attack surface.

WebMobileAPIsCloud BackendsKubernetesNetwork Services
Product Penetration Testing
product test scope architecture
APPLICATIONweb · mobile
APIauth · access control
BACKENDservices · management plane
KUBERNETESRBAC · workload identity
SECRETS / IAMcredentials · trust
NETWORKmanagement · exposed services
Focused reviews

Cryptography, protocols
and security-critical code.

Review scope can be limited to a specific trust model, protocol implementation or security-critical code path.

root oftrust
trust note active
Boot Trust
We trace which key or immutable state anchors the boot chain, and whether recovery, debug or verification behavior can bypass it.
03 / Cryptography

Cryptography Review

We review where trust is established, how it propagates through the product and where implementation or lifecycle decisions can break it.

PKIKey ManagementSecure BootSigningProtocol Crypto
Cryptography Review
04 / Protocols & Wireless

Protocol & Wireless Security

Proprietary protocols, RF, pairing, authentication and protocol reverse engineering.

Protocol & Wireless Security
05 / Source Code Review

Firmware & Source Code Review

Embedded code, bootloaders, protocol parsers, update agents and security-critical components.

Firmware & Source Code Review
06 / Vulnerability Response

Product Vulnerability Response

Technical response for reported product vulnerabilities, reproduction, exploitability analysis, remediation support, coordinated disclosure and retesting.

On-demand response · Response retainer
Product Vulnerability Response
TRIAGEreport · context
REPRODUCEvalidate · scope
REMEDIATEfix · coordinate
VERIFYretest · close
Dr. Ewan Fleischmann
Founder / Technical Direction
Founder & Technical Direction

Dr. Ewan Fleischmann

Founder · Product Security & Cryptography

Redlings is technically led by Dr. Ewan Fleischmann, a PhD cryptographer with a background in offensive security, security research and complex product-security assessments.

22+ years IT security 25+ scientific publications PhD cryptography OSCP · OSCE · CISSP
Research

We investigate products
to understand how they fail.

Original technical work across devices, firmware, protocols and cryptography.

research method selected
EXTRACT
Get below the product surface: firmware images, interfaces, binaries, update packages and device state.
Redlings Research

Reverse engineering, analysis and tooling.

Original technical work across devices, firmware, protocols, cryptography and product infrastructure.

Devices & firmware Protocols & RF Cryptography & trust Tools & technical writeups
Research →
How we work

Scope. Attack & Review. Verify.

We scope with the engineers who build the product, test the relevant attack paths, and return findings in a form they can reproduce and fix.

01

Scope with engineering

Map architecture, trust boundaries, attacker assumptions and the access needed for the assessment.

02

Attack & review

Use the methods the target requires: penetration testing, reverse engineering, protocol analysis, cryptographic review, source code review or hardware analysis.

03

Findings and retest

Document reproducible findings, technical impact and remediation context. Retest fixes against the original attack path.

Product security requirements

Need the testing to support a regulatory requirement?

Where required, assessment work and findings can be mapped to relevant technical requirements from the CRA, EN 18031 and IEC 62443.

Product Security Regulation
CRA EN 18031 IEC 62443
Technical testing and evidence. Certification is outside the scope.
Start with the product

Building a product that needs serious security testing?

Tell us what you're building, the current development stage and what you want tested. We’ll define the scope with your engineering team.

Discuss your product ↗ NDA first if required.