Research Library / Case Studies /

IoT / Facility Management (M&A Technical Due Diligence)

Cyber Risk Analysis of New IoT Ventures

A German company evaluating the acquisition of a smart-facility IoT startup asked Payatu for a technical risk analysis from an investment standpoint. Findings, including a hardcoded private key, publicly accessible cloud instances and a hardware debug port that gave full device control, became one of the deciding factors in the acquisition deal.
Hardware Security Assessment, Secure Code Review, Cloud Security Assessment

At a glance

INDUSTRY

IoT / Facility Management (M&A Technical Due Diligence)

CLIENT PROFILE

A German company evaluating the acquisition of a smart-facility IoT startup

SERVICES

Hardware Security Assessment, Secure Code Review, Cloud Security Assessment

ENGAGEMENT

Six-week technical due diligence assessment

Key Takeaways

  • Client – A German company evaluating the acquisition of a facility management startup that designs IoT solutions for smart facilities.

  • Problem – The client needed a technical risk analysis of the target company's ecosystem, hardware, software and cloud, from an investment due diligence perspective before completing the deal.

  • What Payatu did – Ran a comprehensive security assessment of the startup's hardware, source code and cloud infrastructure over six weeks.

  • Outcome – Found a hardware debug port giving full device control, hardcoded credentials and injection vulnerabilities in the code, and publicly accessible cloud instances, results that became a major factor in the acquisition decision.

the challenge

Why the client called us in

Before completing an acquisition, the client wanted more than a financial and legal picture of the facility management startup it was evaluating, it wanted a technical risk analysis of the startup's IoT ecosystem from an investment perspective. That meant testing the whole stack: hardware, software and cloud. The client brought in Payatu to run that assessment ahead of the deal.

  • Assess the security of the target company's device hardware
  • Review source code for vulnerabilities and hardcoded secrets
  • Evaluate cloud infrastructure exposure

‍

scope of engagement

What was in scope

  1. Hardware security assessment
  2. Source code review
  3. Cloud security assessment

Our Approach

How Payatu ran the engagement

01

Hardware Assessment
Gained control of the device via its hardware debug port, extracted the firmware, and compromised the device by injecting malicious firmware after changing the boot priority to the SD card.

02

Source Code Review
Reviewed the codebase and found a hardcoded private key, SSH password, MQTT client ID and username and passwords, along with access key injection, SQL injection, access control and IDOR vulnerabilities.

03

Cloud Assessment
Found that some cloud instances were publicly accessible, a gap that could have compromised data security.

Key findings

What we found

Hardware Debug Port Exposure
The hardware debug port allowed full control of the device, and firmware could be extracted and replaced by changing the device's boot priority to an SD card.
Hardcoded Credentials and Injection Flaws
The source code contained a hardcoded private key, SSH password, MQTT client ID and username and passwords, alongside access key injection, SQL injection, access control and IDOR vulnerabilities.
Publicly Accessible Cloud Instances
Some cloud instances were accessible publicly, a gap that could have compromised the security of the data they held.

the outcome

Results and Impact

Payatu's comprehensive, six-week assessment identified issues that could have cost the German company millions post-acquisition, and the findings became one of the major factors in the final deal between the two companies.

‍

  • Hardware debug port exposure and firmware extraction risk surfaced before the deal closed

  • Hardcoded credentials and injection vulnerabilities identified in the target's codebase

  • Publicly accessible cloud instances flagged for remediation

  • Findings became a key input into the acquisition decision

Dark background with a flowing, curved red wave pattern across the center.

Get the full case study

Download the complete PDF - full methodology, findings and remediation detail.

Download Case Study (PDF)
White arrow pointing downward on a dark background.White arrow pointing downward on a dark background.

More Case Studies

No items found.
OT/ICS

Building a Security Program from Ground Up for a Security-Critical Government Agency in Asia

Read Case Study
No items found.
OT/ICS
No items found.
IoT & hardware

Payatu IoT Security Assessment Success Stories

Read Case Study
No items found.
IoT & hardware
Fintech
Infrastructure Security Assessment

National Bank Infrastructure Security Assessment

Read Case Study
Fintech
Infrastructure Security Assessment
Physical Security Assessment
Social Engineering Assessment
Security Awareness Training
Regulatory Compliance Assessment