What We Do

Fill 4

ERNW Insinuator

Our company blog is the main source for research and insights created at ERNW, reflections on the information security world, and practical security advice resulting from assessment and consulting projects.

ERNW Research

Our first spin-off focuses on research work of all kinds, which can comprise publicly funded projects, cooperation with universities or fellow researchers, and the supervision and support of ERNW-internal research or methodology-focused projects.

>

Troopers

Our IT Security conference offers a high-quality selection of trainings and talks given by IT security practitioners from all over the world. We strive to make TROOPERS an amazing and unforgettable event and to set a new standard in “how to make the world a safer place”.


Services

  • service-assessment

    Assessment

    We provide assessment services such as penetration testing, audits, red teaming, and (closed-source) product evaluations. While we have developed many defined testing methodologies for different technologies, we mainly focus on highly technical and individual assessments. Examples for specialized assessment expertise comprise IoT/embedded/industrial/medical devices, cloud/virtualization/hosting platforms, Microsoft & Active Directory environments, or network/security appliances.

  • service-consulting

    Consulting

    Using the insight from (offensive) assessment projects, we also support our customers during design, implementation, and approval of their IT landscapes by offering design/concept/process reviews, security concept development, risk assessments, product evaluation, or network (security) design.

  • Active Directory-, Azure- & Windows OS Platform Security Services

    In the space of Active Directory, Azure and Windows OS platform security, we provide a wide range of security services from Active Directory assessments to highly individual analysis projects based on specific customer questions and requirements for selected Microsoft products. Typical services we provide can be found here.

  • Red Teaming

    We understand Red Teaming as a holistic assessment of established security measures and its effectiveness. In contrast to classical penetration testing, red teaming includes methods of assessing physical security and specifically considers the human element. As red teaming potentially includes methods of social engineering, appropriate projects are always processed in close cooperation with ERNW’s internal ethics committee.

  • Artificial Intelligence Security

    Developing and implementing new products based on artificial intelligence, particularly generative AI, requires a comprehensive understanding of the associated risks. We assist our customers in recognizing these risks and offer services to evaluate the security of AI technologies from the design phase through to implementation and usage.

  • Mobile Penetration Testing

    Our service of mobile penetration testing and security code analysis covers the full spectrum of modern apps: native Android and iOS, as well as cross-platform apps. Our methodology is based on the OWASP Mobile Top 10, covering critical attack vectors such as insecure data storage and unprotected communications. The app is tested against a range of attack scenarios, including local attackers with escalated privileges, to validate its security even under the most adverse conditions. Moreover, our testing extends to the app’s backend infrastructure, such as APIs and server-side logic, providing a complete coverage of the app’s attack surface.

  • service-bluetooth-line

    Bluetooth Security

    Bluetooth is present in various environments, from consumer wearables and medical devices to industrial sensors and smart infrastructure. We offer baseline security checks as well as in-depth security assessments of Bluetooth implementations across the full protocol stack, from the Bluetooth controller to the host and the applications on top. Our experience in Bluetooth assessments and dedicated security research enables us to dig deep into finer details of the Bluetooth specification and tailor our assessments precisely to the technical challenges of given use cases and design constraints. In addition to our assessments, we also offer consulting during the design and implementation phases of Bluetooth-based products.

  • service-iot

    IoT and Embedded Device Security

    The Internet of Things and the broader landscape of embedded devices present complex security challenges. Heterogeneous hardware, constrained operating environments, proprietary protocols, and long deployment lifetimes combine to create large and complex attack surfaces. Our assessments cover the full scope of IoT and embedded ecosystems, from individual device hardware and firmware to communication protocols, cloud backends, and mobile applications. In addition to decades of experience in classical software stacks, we bring hands-on expertise in embedded systems, constrained and real-time operating systems, and low-level hardware interfaces into every project that requires it.

  • Medical Device Security

    We offer security assessments and research for medical devices, with a focus on the unique technical challenges these devices and their operational environments present. We are familiar with the challenges of these devices in both modern and legacy stacks and are able to identify threats and viable solutions in medical systems and their surrounding infrastructure. Our work covers firmware analysis, hardware interface testing, proprietary communication protocols, and the specific attack surfaces arising from clinical network environments and device interoperability. Typical evaluation targets include diagnostic and imaging equipment, infusion and therapeutic devices, and wearable systems.

  • service-research

    Research

    Following our knowledge-driven company culture, we offer research services to work on both scientific and pragmatic problems in the IT security space. Past funded research activities focused on Security Awareness, Digital Forensics, Reverse Engineering & Vulnerability Analysis, and telecommunications security. Future activities are coordinated by ERNW Research.

  • service-forensic

    Digital Forensics & Incident Analysis/Response

    We support our customers in implementing incident response processes/preparation as well as in analyzing occurred or suspected incidents. Following common incident response process models, we offer the development of incident preparation plans, immediate and on-site incident response and malware analysis, as well as the compilation of technical forensic reports.

  • service-training

    Training & Knowledge Transfer

    We offer training and knowledge transfer for most areas of IT security. The types of trainings range from video content over on-site trainings to gamified IT security challenges. Our public training is exclusively offered by our partner HM Training Solutions or during our TROOPERS conference.

  • service-operations

    Secure IT Operations

    The secure operation of IT systems can be a very specialized task requiring expert knowledge. We are offering the operation of both IT services in a secure way as well as the (secure) operation of IT security services (such as [Web] Application Firewalls, IDPS, or SIEM systems).

More on More articles on our company blog