IoT & hardware security testing in India — your connected devices are the attack surface your IT team cannot see.
Most IoT and OT security assessments miss the hardware layer entirely. SIRI Security conducts specialist embedded security assessments — firmware extraction and analysis, hardware interface testing (JTAG, UART, SPI), RF security testing, and OT/ICS protocol analysis — backed by legal authority and mapped to CERT-In's expanded 2025 audit standard.
Why "we ran a network scan" no longer satisfies the regulator
CERT-In has explicitly said a checklist scan isn't an audit anymore. Hardware-layer testing is the new baseline.
IoT security is fundamentally different from application or network security. Devices often lack security update mechanisms, use hardcoded credentials, transmit data over unencrypted radio protocols, and expose debugging interfaces that were left enabled after manufacturing — vulnerabilities that live entirely below the layer a conventional penetration test examines. What's changed in 2025 is that CERT-In has said so directly, in writing.
CERT-In's Comprehensive Cyber Security Audit Policy Guidelines, issued 25 July 2025, expanded the scope of what counts as a recognised cybersecurity audit to more than 26 categories, explicitly naming OT/ICS and IoT alongside cloud, source code review, red teaming, blockchain, AI system audits, and software/hardware bill-of-materials verification. The guidelines go further than simply listing categories: they state plainly that tool-only, checklist-driven testing is discouraged, and that the OWASP Top 10 by itself does not constitute a comprehensive standard. A VAPT report built from an automated scanner export with a compliance cover page is no longer what a regulator recognises as having been audited for these device classes.
For organisations deploying connected devices in regulated or safety-critical contexts, this changes the practical question from "did we get a pentest" to "was the pentest actually looking at the hardware." STQC's IoT System Certification Scheme, with its graded assurance levels 0 through 4, already requires Level 3 rigour for devices handling sensitive medical data or high-value transactions — and CERT-In's audit standard now reinforces that a device-layer, not just network-layer, examination is what's expected for critical categories.
Real hardware, not just software emulation
Oscilloscopes, logic analysers, and soldering equipment reveal what a network scanner never will.
Where connected-device risk actually builds
The devices you deploy are only as secure as the firmware inside them — which most security assessments never examine
These are the recurring patterns behind the vulnerabilities SIRI's IoT and hardware practice finds most often.
Firmware vulnerabilities persist for years undetected
Hardcoded credentials, insecure bootloaders, unencrypted storage, and backdoor authentication paths in IoT firmware create persistent vulnerabilities that network scanning cannot detect.
OT networks assumed secure, increasingly exposed
Operational technology environments — manufacturing PLCs, SCADA systems, industrial control networks — are increasingly connected to IT networks, exposing legacy systems designed with no cybersecurity to modern threat actors.
Medical and critical device compromise has physical consequences
Vulnerabilities in medical devices, building management systems, and manufacturing control systems have physical safety consequences, with severe legal and insurance implications.
Supply chain attacks originate in hardware
Hardware trojans, modified firmware, and compromised supply chain components are increasingly used in sophisticated attacks. Without hardware-level inspection, organisations have no visibility into device integrity at scale.
What we test
IoT and hardware security testing at every layer of the device stack
From firmware extraction and hardware interface testing through OT/ICS protocol analysis and supply chain security assessment.
Firmware Extraction & Analysis
Firmware extraction using JTAG, UART, and SPI interfaces, binary analysis for hardcoded credentials and backdoors, dependency vulnerability scanning, encryption implementation review, and secure boot assessment.
Hardware Interface Testing
Physical interface analysis (JTAG, UART, SPI, I2C, USB), debug port exposure assessment, chip-off analysis where required, side-channel attack resistance testing, and fault injection assessment.
OT/ICS Security Assessment
SCADA and PLC security assessment, industrial protocol security (Modbus, DNP3, IEC 61850), network segmentation review, OT network penetration testing, and safety instrumented system security evaluation.
RF & Wireless Security
Bluetooth and BLE security assessment, Zigbee and Z-Wave protocol analysis, Wi-Fi and cellular security review, RFID and NFC vulnerability testing, and SDR-based radio frequency analysis.
Medical Device Security
Regulatory-compliant security assessment for medical devices and hospital IoT infrastructure — vulnerability identification, CDSCO SaMD and NHA security control mapping, and CERT-In mandatory reporting advisory.
Supply Chain Security Assessment
Component origin verification, firmware integrity validation, hardware trojan detection methodology, vendor security assessment, and supply chain risk framework design for organisations deploying IoT at scale.
AI in embedded systems
AI-powered edge device security
AI inference is moving to the edge — devices running on-device ML models, computer vision pipelines, and embedded neural networks face unique attack vectors including model extraction, adversarial input attacks at the hardware level, and side-channel attacks against inference computation. We assess AI edge devices against both traditional IoT attack vectors and emerging AI-specific threats, including physical adversarial attacks on camera-based ML systems and model extraction from edge inference hardware.
Evidence, not guesswork
CERT-In's audit standard, before and after July 2025
Most "CERT-In compliant" IoT assessments on the market still reflect the older, narrower expectation.
| Dimension | Before 25 July 2025 | Under the 2025 Guidelines |
|---|---|---|
| Recognised audit categories | Narrower, IT-focused scope | 26+ categories including OT/ICS, IoT, AI systems, SBOM/QBOM/AIBOM |
| Automated scanning | Commonly accepted as sufficient | Explicitly discouraged as a standalone method |
| OWASP Top 10 as a benchmark | Widely treated as adequate coverage | Explicitly stated as "not a comprehensive standard" |
| What a report needs to show | Findings list with severity ratings | Evidence of methodology depth appropriate to the device/system category |
Sources: CERT-In Comprehensive Cyber Security Audit Policy Guidelines, 25 July 2025; TEC 31318:2021 Code of Practice for Securing Consumer IoT; STQC IoT System Certification Scheme. Confirm current guideline text before relying on this summary for a specific compliance submission.
Client outcomes
Measurable results
Of vulnerabilities SIRI has found required hardware-level testing to surface at all.
Infusion pumps secured before active exploitation — see the case study below.
Well inside the mandatory 6-hour window, with full legal and technical coordination.
Methodology calibrated to the graded IoTSCS assurance level your device category requires.
How we assess
Four stages from scoping to remediation
A structured assessment methodology covering every layer of the IoT device attack surface.
Scoping & threat modelling
Device architecture review, interface identification, attack surface mapping, and threat model construction, defining the testing scope and establishing the highest-priority assessment targets.
Week 1Hardware & firmware testing
Physical interface extraction, firmware analysis, RF testing, protocol assessment, and network communication review, with all findings documented under privilege.
Weeks 2–3Legal risk mapping
Each vulnerability mapped to CERT-In reporting obligations, product liability exposure, customer contractual obligations, regulatory disclosure requirements, and insurance notification obligations.
Week 4Remediation & retesting
Vendor remediation guidance, patch validation retesting, supply chain risk programme design, and ongoing monitoring for new firmware vulnerabilities.
OngoingCase study · Medical device security
Hospital network discovers critical firmware vulnerability in 200+ connected infusion pumps
A Hyderabad hospital network engaged SIRI Security to assess connected medical devices. Our assessment identified a critical authentication bypass vulnerability in the firmware of 200+ infusion pumps, allowing remote dosage modification — a finding with direct patient safety consequences, not just a data-security one.
SIRI simultaneously managed the CERT-In mandatory notification, coordinated with the vendor on emergency firmware patching, and produced the regulatory disclosure documentation — all findings protected under legal privilege from the moment the vulnerability was confirmed.
Representative matters
Typical engagements
All matters described generically to protect client confidentiality.
Unauthenticated BLE communication found
Identified unauthenticated Bluetooth Low Energy communication in a medical monitoring device, allowing an attacker within BLE range to send arbitrary commands. Reported to manufacturer with responsible disclosure coordination.
Global hardcoded credentials discovered
Extracted and reverse-engineered firmware from an industrial PLC, discovering hardcoded administrator credentials used across all device deployments globally. Critical finding with supply chain implications.
Cleartext Modbus, direct IT pathway
Assessed a building management system, identifying cleartext Modbus communication between controllers and a direct path from the building network to corporate IT infrastructure.
7 vulnerabilities in a smart home hub
Conducted a comprehensive security assessment of a consumer smart home hub, identifying 7 vulnerabilities including UART root shell access, hardcoded API keys, and unencrypted cloud communications.
Why SIRI
IoT security backed by legal authority and CERT-In compliance
SIRI Security assessments are conducted under attorney-client privilege — meaning vulnerability findings in your IoT infrastructure cannot be subpoenaed in regulatory investigations or civil litigation. No other IoT security firm in India offers this protection.
Hardware-level technical capability
Our IoT team uses specialist hardware — programmers, oscilloscopes, logic analysers, and SDR equipment — to conduct the firmware extraction, interface testing, and RF analysis that standard penetration testers cannot perform.
Assessment under legal privilege
All IoT vulnerability findings documented under attorney-client privilege — findings cannot be subpoenaed in CERT-In investigations, regulatory proceedings, or civil litigation, a protection no consultancy can offer.
Legal advisory integration
Every significant vulnerability identified includes legal risk mapping — CERT-In reporting obligations, product liability exposure, regulatory disclosure requirements, and legal implications of known unpatched vulnerabilities.
CERT-In compliance support
CERT-In mandatory reporting obligations apply to critical infrastructure IoT incidents. SIRI manages the notification, investigative response, and regulatory follow-up simultaneously with technical containment.
The comparison
Without SIRI versus with SIRI
| Capability | Standard penetration testing firm | SIRI Security — IoT + legal + compliance |
|---|---|---|
| Testing depth | Network scanning only — firmware, hardware interfaces, and RF protocols not assessed | Hardware-layer testing capability with specialist equipment across the full device stack |
| Firmware and interface testing | Requires specialist equipment and training most testers do not have | JTAG/UART interface testing, firmware binary analysis, and chip-level analysis included |
| Finding protection | Reports discoverable in regulatory investigations and civil litigation | Every finding documented under attorney-client privilege |
| CERT-In support | Not equipped to manage regulatory notification and investigation process | Mandatory CERT-In notification and investigative follow-up managed alongside remediation |
Frequently asked
IoT and hardware security, answered directly
What is the difference between IT security testing and OT/ICS security assessment?
IT security testing targets enterprise networks, applications, and servers using standard penetration testing methodologies. OT/ICS security assessment addresses operational technology — PLCs, SCADA systems, DCS, RTUs, and industrial control networks — which have different protocols (Modbus, DNP3, IEC 61850), different uptime requirements, and different consequences of compromise.
Does CERT-In's 2025 audit standard change what counts as a proper IoT security assessment?
Yes, substantively. CERT-In's Comprehensive Cyber Security Audit Policy Guidelines, issued 25 July 2025, expanded the scope of a recognised cybersecurity audit to more than 26 categories, explicitly including OT/ICS and IoT alongside cloud, source code review, and AI system audits. The guidelines also state directly that tool-only, checklist-driven testing is not sufficient and that the OWASP Top 10 alone does not constitute a comprehensive standard. In practical terms, a network scan with a compliance cover page no longer satisfies what CERT-In considers an audit for these device categories — hardware-layer testing of the kind we conduct is now the standard being referenced, not an optional upgrade.
How do you extract firmware from a device?
Firmware can be extracted through direct JTAG or UART interface access (hardware debugging interfaces left exposed in production devices), SPI or I2C flash memory chip reading, network-based firmware update interception, or physical chip desoldering and reading (chip-off). Our team determines the most appropriate method through initial interface analysis.
Do you test medical devices and hospital infrastructure?
Yes. We assess medical device security under a methodology calibrated to regulatory requirements, including CDSCO's Software as a Medical Device framework, NHA Digital Health guidelines, and international standards such as IEC 80001. All assessments are conducted under strict confidentiality and attorney-client privilege.
What CERT-In obligations apply to IoT vulnerabilities in critical infrastructure?
CERT-In's mandatory reporting directions apply to cybersecurity incidents in critical information infrastructure, including energy, power, banking, telecommunications, and healthcare. Significant IoT vulnerabilities in these sectors may require CERT-In notification within 6 hours of detection. SIRI's integrated legal and technical team maps your specific reporting obligations and manages the notification process.
How do you handle assessment of OT systems that cannot be taken offline?
OT assessments use passive analysis methodologies for systems that cannot tolerate testing-induced disruption — passive network monitoring, configuration review, and protocol analysis on OT networks without active scanning. For specific devices, we may assess identical devices in a test environment rather than on live production systems.
Ready when you are
Your connected devices have attack surfaces your current security programme cannot see.
Book a confidential IoT security assessment with SIRI Security. We will identify the firmware vulnerabilities, hardware exposures, and OT security gaps that standard security testing misses.
Related services
Other ways SIRI Law LLP secures connected-device organisations
Cybersecurity testing services
Full portfolio — application, cloud, network, and AI/LLM security testing.
Healthcare technology law
CDSCO SaMD classification and regulatory advisory for connected medical devices.
Manufacturing & logistics legal counsel
OT/ICS legal advisory for connected plant-floor environments.
Visit or contact us
SIRI Law LLP — Hyderabad, India
| Registered office | HITEC City, Madhapur, Hyderabad, Telangana 500081, India |
| Telephone | +91 79819 12046 |
| info@sirilawllp.com | |
| Other offices | New Delhi, India · Austin, Texas, USA · Online worldwide |
| Hours | Mon–Sat, 9:30 AM – 7:00 PM IST · Emergency line 24/7 |

