Thank you
Our team of industry domain experts combined with our guaranteed SLAs, our world class technology .
Get Immediate Help
IoT penetration testing spans five layers- hardware, firmware, communications, cloud and API backend- and the companion mobile application- and a quote covering only one or two of them is not a genuine IoT test, regardless of how it's marketed. This guide explains what each layer examines, what testers need from you before starting, and what a complete deliverable includes, grounded in the UAE's growing smart building, smart metering, and connected medical device estate.
Keeping these five layers in view when reading any IoT testing proposal is the single most useful habit a buyer can develop before signing.
The UAE's smart city, smart building, and connected infrastructure programmes make this less abstract here than in most markets, since the connected device estate a UAE enterprise or government entity operates today is considerably larger and more varied than it was even two years ago. Our IoT security assessment service covers this specialised testing area as an ongoing capability; this page focuses specifically on how a single engagement should be scoped and what it should deliver.
| Layer | What gets tested | Typical findings | Access required |
| Hardware and physical interfaces | Debug interfaces (UART, JTAG, SPI, SWD), PCB layout, chip identification | Exposed debug ports, unsecured physical access to memory or credentials | Physical device access, sometimes enclosure opening |
| Firmware | Extraction, reverse engineering, update and cryptographic integrity mechanisms | Hardcoded credentials, weak cryptography, insecure update mechanisms | Firmware image, obtained via extraction or vendor provision |
| Communications and protocols | Wi-Fi, Bluetooth/BLE, Zigbee, MQTT, LoRa, cellular, and IT/OT network segmentation | Unencrypted traffic, weak pairing, poor segmentation between IoT and IT networks | Network access, protocol-specific capture tooling |
| Cloud and API backend | Authentication, authorisation, and injection flaws in APIs and dashboards | Broken access control, privilege escalation, injection vulnerabilities | API documentation, test accounts |
| Companion mobile application | Static and dynamic analysis of the app controlling or monitoring the device | Hardcoded API keys, insecure local storage, exposed backend endpoints | App installation package, test accounts |
Genuine engagements examine all five, since a comprehensive report distinguishes a real IoT test from a repackaged mobile application assessment. Checking a proposal against this table before signing is the fastest way to confirm what you're actually buying.
Buyers should budget for the possibility that hardware-layer testing renders a sample unit unusable afterwards, since physical teardown and debug interface access can affect a unit's condition or warranty status. Discussing this explicitly during scoping, rather than discovering it after testing concludes, avoids an unnecessary dispute later. Our web application penetration testing guide covers the application-layer methodology that feeds directly into both the cloud/API and mobile companion app layers of an IoT engagement.
Findings frequently chain across layers in ways that isolated single-layer testing would never reveal: a hardcoded API key extracted from firmware analysis, for instance, can grant direct access to the cloud backend that no amount of API-layer testing alone would have surfaced without that firmware-derived credential. This is why the five layers cannot be meaningfully tested in isolation.
The remediation guidance split matters more in IoT than in almost any other testing category, since a firmware fix might require a multi-month hardware revision and re-certification cycle, while a backend fix can often deploy within days. A report that lumps all findings together without distinguishing which release cycle each fix belongs to leaves the buyer's engineering teams to work that out themselves, undermining the practical value of an otherwise thorough report.
| Sector | Typical connected estate | Primary risk focus |
| Smart buildings and facilities | HVAC controllers, access control systems, building management platforms | Physical access control bypass, building-wide system compromise |
| Utilities and smart metering | Smart meters, grid sensors, remote monitoring devices | Data integrity, unauthorised meter manipulation |
| Healthcare and connected medical devices | Patient monitors, infusion pumps, diagnostic equipment | Patient safety, data confidentiality, availability of clinical systems |
| Industrial and manufacturing | Sensors, connected PLCs, asset tracking devices | Production integrity, safety consequences of compromise |
| Logistics and asset tracking | GPS trackers, fleet telematics, connected containers | Location data confidentiality, supply chain integrity |
| Retail and hospitality | Point-of-sale devices, connected kiosks, guest-facing IoT | Payment data exposure, guest network segmentation |
Healthcare connected medical devices carry particular regulatory weight in the UAE, since ADHICS explicitly extends its testing obligations to connected medical devices for in-scope Abu Dhabi healthcare entities. Our ADHICS compliance guide covers that specific obligation directly for healthcare organisations weighing IoT testing alongside their broader compliance programme.
This decision can help reduce the risk of under-testing a genuinely significant attack surface, though the appropriate approach depends on the specific device estate and risk profile in question. Our enterprise penetration testing guide covers commercial and procurement details across the broader testing programme this specific engagement type sits within.
Don’t Let Cyber Attacks Ruin Your Business
Call
UK: +44 (0)20 3336 7200
KSA: +966 1351 81844
UAE: +971 454 01252
Contents
To keep up with innovation in IT & OT security, subscribe to our newsletter
Recent Posts
Penetration Testing | 17/09/2026
Penetration Testing | 17/09/2026
Cyber Compliance | 16/09/2026
What is IoT penetration testing?
A manual security assessment spanning five layers: hardware, firmware, communications, cloud backend, and the companion mobile app.How long does an IoT penetration test take?
It varies significantly by device complexity and the number of layers in scope; hardware and firmware analysis typically extend timelines beyond conventional testing.Do testers need physical access to the device?
Yes, for hardware-layer testing specifically. Sample devices and, often, enclosure access are required.Is firmware analysis included in IoT testing?
It should be in any genuine engagement. See the five-layer table above for what a complete scope covers.What is the difference between IoT and OT penetration testing?
IoT spans consumer and enterprise connected devices; OT specifically covers industrial control systems. See our OT and ICS penetration testing guide.Does ADHICS cover connected medical devices?
Yes, explicitly, as part of its annual testing requirement for in-scope healthcare entities. See our ADHICS compliance guide.How much does IoT penetration testing cost in the UAE?
Pricing depends heavily on device count and the scope of layers tested. See our enterprise penetration testing guide for general UAE testing pricing.