IoT / Smart Building Automation
Infrastructure Assessment of an IoT Ecosystem
At a glance
INDUSTRY
IoT / Smart Building Automation
CLIENT PROFILE
A German company offering IoT-based smart building automation solutions
SERVICES
Hardware Security Assessment, Web Application Security Testing, Secure Code Review
ENGAGEMENT

Key Takeaways
Client – A German company offering IoT-based solutions that turn commercial facilities into smart buildings, with a broader automation range for the smart building space.
Problem – The client wanted its entire IoT ecosystem, hardware, cloud, web interface and source code, tested for security gaps before relying on it further.
What Payatu did – Ran a comprehensive assessment covering device hardware, the IEEE 802.15.4-based radio protocol, the web interface and a source code review.
Outcome – Found that devices could be booted from an SD card, that a single shared encryption key exposed the entire device fleet, and that access control gaps in the web interface exposed user data, all within a four-week engagement.
the challenge
Why the client called us in
The client builds IoT-based automation solutions that turn commercial facilities into smart buildings, with a portfolio spanning multiple automation use cases. To make its offerings robust and foolproof against intrusion, it wanted the whole ecosystem, hardware, cloud, web interface and code, tested for security gaps. The client brought in Payatu to run that assessment.
- Test device hardware for physical and firmware-level weaknesses
- Assess the radio protocol securing device-to-device communication
- Review the web interface and source code for access control and credential handling gaps
scope of engagement
What was in scope
- Hardware security assessment
- Web interface security assessment
- Source code review
Our Approach
How Payatu ran the engagement
01
02
03
04
Key findings
What we found
the outcome
Results and Impact
Payatu's four-week assessment let the client protect user-sensitive information before a leak could cause fraud or financial loss to end users, and close the loopholes that put its IoT system's intellectual property at risk.
Shared encryption key across the device fleet identified before it could be exploited at scale
Web interface access control gaps exposing user data closed
Hardcoded MQTT credentials and license keys removed from source code
Full ecosystem, hardware, radio, web and code, assessed within four weeks
Get the full case study
Download the complete PDF - full methodology, findings and remediation detail.

.png)







