📞 Call Now 💬 WhatsApp 📋 Report
⚖️
SIRI Law LLP
● Typically replies within 30 min
👋 Hi! How can SIRI Law LLP help you today?

We offer expert legal and cybersecurity advisory. Tap below for a confidential chat.
SIRI Law · Now
💬  Start Chat on WhatsApp
IoT & Hardware Security Testing in India | Firmware, OT/ICS — SIRI Law LLP
Critical infrastructure incident affecting connected devices? Call: +91 79819 12046 — 24/7
IoT & Hardware Security Testing · Hyderabad, India

IoT & hardware security testing in India — your connected devices are the attack surface your IT team cannot see.

Most IoT and OT security assessments miss the hardware layer entirely. SIRI Security conducts specialist embedded security assessments — firmware extraction and analysis, hardware interface testing (JTAG, UART, SPI), RF security testing, and OT/ICS protocol analysis — backed by legal authority and mapped to CERT-In's expanded 2025 audit standard.

25 Jul 2025CERT-In's audit guidelines declare OWASP Top 10 "not a comprehensive standard"
70%Of vulnerabilities we find are undetectable through standard network scanning
200+Infusion pumps secured in our medical device case study below
26+Audit categories CERT-In now recognises, including OT/ICS and IoT explicitly
The IoT regulatory clock
Live tracking · scroll to see every relevant development
Standing
2021–22
TEC's Code of Practice for Securing Consumer IoT (TEC 31318:2021) published — India's baseline IoT security standard, aligned with ETSI EN 303 645.
Operating
Ongoing
STQC's IoT System Certification Scheme (IoTSCS) offers graded assurance levels 0–4 — Level 3 required for devices handling sensitive medical data or high-value transactions.
Mandatory
2024
MeitY Essential Requirements for CCTV and video surveillance systems make STQC certification mandatory for a specific IoT device category — a template for further sector-specific mandates.
Redefined
25 JUL 2025
CERT-In's Comprehensive Cyber Security Audit Policy Guidelines expand recognised audit scope to 26+ categories including OT/ICS, IoT, SBOM/QBOM/AIBOM verification.
Explicit
2025
Guidelines state directly that tool-only, checklist-driven testing is discouraged and that OWASP Top 10 alone is not a comprehensive standard — hardware-layer testing is now the referenced norm.
Standing
6 hrs
CERT-In Directions under IT Act §70B — cyber incidents on IoT devices in scope must be reported within 6 hours of detection, same clock as any other regulated incident.

Why "we ran a network scan" no longer satisfies the regulator

CERT-In has explicitly said a checklist scan isn't an audit anymore. Hardware-layer testing is the new baseline.

IoT security is fundamentally different from application or network security. Devices often lack security update mechanisms, use hardcoded credentials, transmit data over unencrypted radio protocols, and expose debugging interfaces that were left enabled after manufacturing — vulnerabilities that live entirely below the layer a conventional penetration test examines. What's changed in 2025 is that CERT-In has said so directly, in writing.

CERT-In's Comprehensive Cyber Security Audit Policy Guidelines, issued 25 July 2025, expanded the scope of what counts as a recognised cybersecurity audit to more than 26 categories, explicitly naming OT/ICS and IoT alongside cloud, source code review, red teaming, blockchain, AI system audits, and software/hardware bill-of-materials verification. The guidelines go further than simply listing categories: they state plainly that tool-only, checklist-driven testing is discouraged, and that the OWASP Top 10 by itself does not constitute a comprehensive standard. A VAPT report built from an automated scanner export with a compliance cover page is no longer what a regulator recognises as having been audited for these device classes.

70% of the vulnerabilities we find, network scanning would never see
Across SIRI's IoT assessments, roughly 70% of the vulnerabilities discovered were not detectable through standard network scanning — they required hardware-level testing: physical JTAG or UART interface access, firmware binary analysis, or RF protocol capture. This is precisely the gap CERT-In's 2025 guidelines are responding to, and precisely the layer most security vendors serving India's IoT and OT sector are not equipped to test.

For organisations deploying connected devices in regulated or safety-critical contexts, this changes the practical question from "did we get a pentest" to "was the pentest actually looking at the hardware." STQC's IoT System Certification Scheme, with its graded assurance levels 0 through 4, already requires Level 3 rigour for devices handling sensitive medical data or high-value transactions — and CERT-In's audit standard now reinforces that a device-layer, not just network-layer, examination is what's expected for critical categories.

SIRI Law LLP hardware and firmware security testing

Real hardware, not just software emulation

Oscilloscopes, logic analysers, and soldering equipment reveal what a network scanner never will.

Where connected-device risk actually builds

The devices you deploy are only as secure as the firmware inside them — which most security assessments never examine

These are the recurring patterns behind the vulnerabilities SIRI's IoT and hardware practice finds most often.

01 — FIRMWARE

Firmware vulnerabilities persist for years undetected

Hardcoded credentials, insecure bootloaders, unencrypted storage, and backdoor authentication paths in IoT firmware create persistent vulnerabilities that network scanning cannot detect.

02 — OT/IT CONVERGENCE

OT networks assumed secure, increasingly exposed

Operational technology environments — manufacturing PLCs, SCADA systems, industrial control networks — are increasingly connected to IT networks, exposing legacy systems designed with no cybersecurity to modern threat actors.

03 — SAFETY

Medical and critical device compromise has physical consequences

Vulnerabilities in medical devices, building management systems, and manufacturing control systems have physical safety consequences, with severe legal and insurance implications.

04 — SUPPLY CHAIN

Supply chain attacks originate in hardware

Hardware trojans, modified firmware, and compromised supply chain components are increasingly used in sophisticated attacks. Without hardware-level inspection, organisations have no visibility into device integrity at scale.

What we test

IoT and hardware security testing at every layer of the device stack

From firmware extraction and hardware interface testing through OT/ICS protocol analysis and supply chain security assessment.

01 / FIRMWARE

Firmware Extraction & Analysis

Firmware extraction using JTAG, UART, and SPI interfaces, binary analysis for hardcoded credentials and backdoors, dependency vulnerability scanning, encryption implementation review, and secure boot assessment.

02 / HARDWARE

Hardware Interface Testing

Physical interface analysis (JTAG, UART, SPI, I2C, USB), debug port exposure assessment, chip-off analysis where required, side-channel attack resistance testing, and fault injection assessment.

03 / OT/ICS

OT/ICS Security Assessment

SCADA and PLC security assessment, industrial protocol security (Modbus, DNP3, IEC 61850), network segmentation review, OT network penetration testing, and safety instrumented system security evaluation.

04 / RF

RF & Wireless Security

Bluetooth and BLE security assessment, Zigbee and Z-Wave protocol analysis, Wi-Fi and cellular security review, RFID and NFC vulnerability testing, and SDR-based radio frequency analysis.

05 / MEDICAL

Medical Device Security

Regulatory-compliant security assessment for medical devices and hospital IoT infrastructure — vulnerability identification, CDSCO SaMD and NHA security control mapping, and CERT-In mandatory reporting advisory.

06 / SUPPLY CHAIN

Supply Chain Security Assessment

Component origin verification, firmware integrity validation, hardware trojan detection methodology, vendor security assessment, and supply chain risk framework design for organisations deploying IoT at scale.

AI in embedded systems

AI-powered edge device security

AI inference is moving to the edge — devices running on-device ML models, computer vision pipelines, and embedded neural networks face unique attack vectors including model extraction, adversarial input attacks at the hardware level, and side-channel attacks against inference computation. We assess AI edge devices against both traditional IoT attack vectors and emerging AI-specific threats, including physical adversarial attacks on camera-based ML systems and model extraction from edge inference hardware.

Evidence, not guesswork

CERT-In's audit standard, before and after July 2025

Most "CERT-In compliant" IoT assessments on the market still reflect the older, narrower expectation.

Dimension Before 25 July 2025 Under the 2025 Guidelines
Recognised audit categories Narrower, IT-focused scope 26+ categories including OT/ICS, IoT, AI systems, SBOM/QBOM/AIBOM
Automated scanning Commonly accepted as sufficient Explicitly discouraged as a standalone method
OWASP Top 10 as a benchmark Widely treated as adequate coverage Explicitly stated as "not a comprehensive standard"
What a report needs to show Findings list with severity ratings Evidence of methodology depth appropriate to the device/system category

Sources: CERT-In Comprehensive Cyber Security Audit Policy Guidelines, 25 July 2025; TEC 31318:2021 Code of Practice for Securing Consumer IoT; STQC IoT System Certification Scheme. Confirm current guideline text before relying on this summary for a specific compliance submission.

Client outcomes

Measurable results

70%
Undetectable by network scan

Of vulnerabilities SIRI has found required hardware-level testing to surface at all.

200+
Devices protected, one engagement

Infusion pumps secured before active exploitation — see the case study below.

48 hrs
CERT-In notification filed

Well inside the mandatory 6-hour window, with full legal and technical coordination.

Level 4
STQC assurance tiers we test to

Methodology calibrated to the graded IoTSCS assurance level your device category requires.

How we assess

Four stages from scoping to remediation

A structured assessment methodology covering every layer of the IoT device attack surface.

01

Scoping & threat modelling

Device architecture review, interface identification, attack surface mapping, and threat model construction, defining the testing scope and establishing the highest-priority assessment targets.

Week 1
02

Hardware & firmware testing

Physical interface extraction, firmware analysis, RF testing, protocol assessment, and network communication review, with all findings documented under privilege.

Weeks 2–3
03

Legal risk mapping

Each vulnerability mapped to CERT-In reporting obligations, product liability exposure, customer contractual obligations, regulatory disclosure requirements, and insurance notification obligations.

Week 4
04

Remediation & retesting

Vendor remediation guidance, patch validation retesting, supply chain risk programme design, and ongoing monitoring for new firmware vulnerabilities.

Ongoing

Case study · Medical device security

Hospital network discovers critical firmware vulnerability in 200+ connected infusion pumps

A Hyderabad hospital network engaged SIRI Security to assess connected medical devices. Our assessment identified a critical authentication bypass vulnerability in the firmware of 200+ infusion pumps, allowing remote dosage modification — a finding with direct patient safety consequences, not just a data-security one.

SIRI simultaneously managed the CERT-In mandatory notification, coordinated with the vendor on emergency firmware patching, and produced the regulatory disclosure documentation — all findings protected under legal privilege from the moment the vulnerability was confirmed.

200+Devices protected from active exploit
CriticalAuthentication bypass confirmed
48 hrsCERT-In notification filed
Medical IoT Firmware security CERT-In Regulatory disclosure
Medical device firmware vulnerability found by SIRI Law LLP

Representative matters

Typical engagements

All matters described generically to protect client confidentiality.

Medical Device Assessment

Unauthenticated BLE communication found

Identified unauthenticated Bluetooth Low Energy communication in a medical monitoring device, allowing an attacker within BLE range to send arbitrary commands. Reported to manufacturer with responsible disclosure coordination.

Industrial Controller Security

Global hardcoded credentials discovered

Extracted and reverse-engineered firmware from an industrial PLC, discovering hardcoded administrator credentials used across all device deployments globally. Critical finding with supply chain implications.

Smart Building System

Cleartext Modbus, direct IT pathway

Assessed a building management system, identifying cleartext Modbus communication between controllers and a direct path from the building network to corporate IT infrastructure.

Consumer IoT Security

7 vulnerabilities in a smart home hub

Conducted a comprehensive security assessment of a consumer smart home hub, identifying 7 vulnerabilities including UART root shell access, hardcoded API keys, and unencrypted cloud communications.

Why SIRI

IoT security backed by legal authority and CERT-In compliance

SIRI Security assessments are conducted under attorney-client privilege — meaning vulnerability findings in your IoT infrastructure cannot be subpoenaed in regulatory investigations or civil litigation. No other IoT security firm in India offers this protection.

01 — Hardware

Hardware-level technical capability

Our IoT team uses specialist hardware — programmers, oscilloscopes, logic analysers, and SDR equipment — to conduct the firmware extraction, interface testing, and RF analysis that standard penetration testers cannot perform.

02 — Privilege

Assessment under legal privilege

All IoT vulnerability findings documented under attorney-client privilege — findings cannot be subpoenaed in CERT-In investigations, regulatory proceedings, or civil litigation, a protection no consultancy can offer.

03 — Legal mapping

Legal advisory integration

Every significant vulnerability identified includes legal risk mapping — CERT-In reporting obligations, product liability exposure, regulatory disclosure requirements, and legal implications of known unpatched vulnerabilities.

04 — CERT-In

CERT-In compliance support

CERT-In mandatory reporting obligations apply to critical infrastructure IoT incidents. SIRI manages the notification, investigative response, and regulatory follow-up simultaneously with technical containment.

The comparison

Without SIRI versus with SIRI

Capability Standard penetration testing firm SIRI Security — IoT + legal + compliance
Testing depth Network scanning only — firmware, hardware interfaces, and RF protocols not assessed Hardware-layer testing capability with specialist equipment across the full device stack
Firmware and interface testing Requires specialist equipment and training most testers do not have JTAG/UART interface testing, firmware binary analysis, and chip-level analysis included
Finding protection Reports discoverable in regulatory investigations and civil litigation Every finding documented under attorney-client privilege
CERT-In support Not equipped to manage regulatory notification and investigation process Mandatory CERT-In notification and investigative follow-up managed alongside remediation

Frequently asked

IoT and hardware security, answered directly

What is the difference between IT security testing and OT/ICS security assessment?

IT security testing targets enterprise networks, applications, and servers using standard penetration testing methodologies. OT/ICS security assessment addresses operational technology — PLCs, SCADA systems, DCS, RTUs, and industrial control networks — which have different protocols (Modbus, DNP3, IEC 61850), different uptime requirements, and different consequences of compromise.

Does CERT-In's 2025 audit standard change what counts as a proper IoT security assessment?

Yes, substantively. CERT-In's Comprehensive Cyber Security Audit Policy Guidelines, issued 25 July 2025, expanded the scope of a recognised cybersecurity audit to more than 26 categories, explicitly including OT/ICS and IoT alongside cloud, source code review, and AI system audits. The guidelines also state directly that tool-only, checklist-driven testing is not sufficient and that the OWASP Top 10 alone does not constitute a comprehensive standard. In practical terms, a network scan with a compliance cover page no longer satisfies what CERT-In considers an audit for these device categories — hardware-layer testing of the kind we conduct is now the standard being referenced, not an optional upgrade.

How do you extract firmware from a device?

Firmware can be extracted through direct JTAG or UART interface access (hardware debugging interfaces left exposed in production devices), SPI or I2C flash memory chip reading, network-based firmware update interception, or physical chip desoldering and reading (chip-off). Our team determines the most appropriate method through initial interface analysis.

Do you test medical devices and hospital infrastructure?

Yes. We assess medical device security under a methodology calibrated to regulatory requirements, including CDSCO's Software as a Medical Device framework, NHA Digital Health guidelines, and international standards such as IEC 80001. All assessments are conducted under strict confidentiality and attorney-client privilege.

What CERT-In obligations apply to IoT vulnerabilities in critical infrastructure?

CERT-In's mandatory reporting directions apply to cybersecurity incidents in critical information infrastructure, including energy, power, banking, telecommunications, and healthcare. Significant IoT vulnerabilities in these sectors may require CERT-In notification within 6 hours of detection. SIRI's integrated legal and technical team maps your specific reporting obligations and manages the notification process.

How do you handle assessment of OT systems that cannot be taken offline?

OT assessments use passive analysis methodologies for systems that cannot tolerate testing-induced disruption — passive network monitoring, configuration review, and protocol analysis on OT networks without active scanning. For specific devices, we may assess identical devices in a test environment rather than on live production systems.

Ready when you are

Your connected devices have attack surfaces your current security programme cannot see.

Book a confidential IoT security assessment with SIRI Security. We will identify the firmware vulnerabilities, hardware exposures, and OT security gaps that standard security testing misses.

or call +91 79819 12046 — Mon–Sat, 9 AM – 7 PM IST · Critical infrastructure line 24/7

Visit or contact us

SIRI Law LLP — Hyderabad, India

Registered officeHITEC City, Madhapur, Hyderabad, Telangana 500081, India
Telephone+91 79819 12046
Emailinfo@sirilawllp.com
Other officesNew Delhi, India · Austin, Texas, USA · Online worldwide
HoursMon–Sat, 9:30 AM – 7:00 PM IST · Emergency line 24/7
© SIRI Law LLP · Hyderabad, Telangana

All security testing is conducted under a signed rules-of-engagement agreement with explicit written authorisation from the asset owner. Findings are confidential and delivered only to authorised client representatives. References to CERT-In's 2025 audit guidelines, STQC certification levels, and related deadlines reflect publicly available information as of publication and remain subject to further regulatory clarification; confirm current guideline text before relying on any provision here. Case study and representative matter details are described generically to protect client confidentiality. This page does not constitute legal advice. SIRI Law LLP is a registered law firm under the Limited Liability Partnership Act 2008, practising under the Advocates Act 1961; complaints regarding professional conduct may be directed to the Bar Council of Telangana.

Scroll to Top