Services
Threat, vulnerability and risk analysis engineered for connected products under CRA, NIS 2 and sector-specific regimes.
Introduction
Connected products now operate inside regulated supply chains where a single weak entry point reshapes enterprise risk and time-to-market. CRA, NIS 2, UN R155 and sectorial mandates demand evidence — not intuition — that architectures, firmware and operational processes withstand realistic adversaries.
Internet of Trust runs cybersecurity analyses on architectures, products and end-to-end services with methodologies aligned to the standards below, calibrated to your regulatory anchor and assurance target.
This page details our four-phase delivery method, the three engagement modes available, deliverables across analytical reports and corrective roadmaps, and how we keep analyses live across the product life-cycle.
ISO/IEC 27005
EBIOS RM
TARA
SAHARA
Process
A typical engagement runs as an iterative four-phase loop. The cadence accommodates legacy devices, tight patching windows and multi-cloud key silos without losing analytical rigor — each phase feeds the next and can be revisited as scope evolves.
01
Workshop to set objectives, products/services in scope, use cases, risk owners, methodology and the right level of abstraction.
02
Compile specifications, standards, processes and assets. Interview architects, developers, risk managers and admins. Select relevant CVE / vulnerability databases.
03
Build the technical and organizational cartography, define exposure surface, security-relevant parameters and the scales of likelihood, severity and impact.
04
Scan the system against vulnerabilities, threats and risks — from focused fast analysis to system-wide systematic review.
Delivery plan
Deliverables are tailored to customer milestones — from executive overviews to traceable engineering artefacts ready for evaluation labs and certification bodies.
Full traceability from assets to threats, vulnerabilities and residual risk.
Justified verdicts that survive lab challenge and audit.
Concrete countermeasures mapped to AES-GCM, ML-KEM and platform controls.
Security requirements pushed into the supply chain and configuration baselines.
Prioritized roadmap with owners, effort estimates and target dates.
Engagement modes
Three engagement shapes, selected by scope, target assurance and product life-cycle stage.
Mode 01
Targets selected aspects — a core function, a property such as data reliability or privacy, robustness against specific attack vectors — within a mutually agreed time-box.
Mode 02
Systematic review producing a vulnerabilities catalog, risk mitigation plan, supplier requirements and configuration policy across the full architecture.
Mode 03
Continuous review tied to CVE feeds, regulatory updates and product evolutions, keeping the analysis live across the product life-cycle.
Field record
We’ll send you access by email.