Our embedded security and cryptography expert Joachim Strömbergson guested a Swedish security podcast (Bli Säker @nikkasystems@social.nikkasystems.com) and discussed Post Quantum Cryptography. Find our English summary and the link to the episode in our blog.
https://www.assured.se/posts/podcast-spotlight-threat-from-quantum-computers
#pqc #security #cryptography
Assured Security Consultants
From chip to ship: we put applications, infrastructure, IoT, embedded devices and vehicles to the test. Your security Assured.
We are proud to have worked with Open Technology Fund (OTF) and @EngageMedia@mastodon.social to help secure Cinemata, an open source video platform for communities that operate in politically sensitive environments. Of 26 identified vulnerabilities, all have been verified fixed.
#pentest #cybersecurity #privacy
https://www.assured.se/posts/pentest-report-cinemata
We want to share the 5 most common infrastructure security issues we've seen in our penetration testing and advisory assignments during the year of 2022:
https://www.assured.se/posts/common-infrastructure-issues-2022
We 💛 #security #infosec
We 💛 #automotive
How are we at Assured contributing to the marriage of the two domains? How can you tackle security practically? Read the first installment of a series on automotive security in our blog!
https://www.assured.se/posts/assured-loves-automotive
To help developers shift left and introduce #security #testing and #awareness early on in the development process we're offering a mix-and-match range of training seminars and workshops, in Gothenburg or elsewhere. Read more:
https://www.assured.se/posts/security-training-for-developers
What would motivate pulling the plug during a security incident? Our dear colleague @boset@infosec.exchange wrote a blog post to hypothesize, with the current Swedish unemployment benefit services outage following a cyber #security incident.
We help our customers with detection strategies, red/purple team adversary simulation, penetration testing, threat modeling, risk analysis and much more.
https://www.assured.se/posts/pulling-the-plug-security-incident
Hello World! We are a boutique security consultancy specialized in the technical aspects of information security. We provide a diverse set of experts for all your security needs, such as #penetrationtesting #infrastructure #cryptography and #automotive #security. Find us at https://assured.se #introductions
Aftonbladet charges SEK 49/m. Not for journalism, fewer ads, nor anything extra.
For the right to say no to profiling.
Schibsted calls this "advertising choice". Call it what it is: charging users to keep what should never have been up for sale in the first place.
https://www.assured.se/posts/monetizing-privacy
Celebrating 100 security assessments, over 1000 findings, and over 2000 pages of pentest reports in 2025!
https://www.assured.se/posts/100-security-assessments-in-2025
#pentest #cybersecurity
Modern vehicles are complex, connected systems with an ever-expanding attack surface. In this environment, documentation alone is no longer sufficient — to meet regulatory requirements, cybersecurity must be demonstrated in practice.
Testing is carried out under witnessed conditions, with each step documented and reproducible. These tests play a critical role in vehicle type approval under UNECE R155 and have effectively become the vehicle’s digital crash test.
We have extensive experience in penetration testing of vehicles and automotive components, including expert advisory services and the execution of witnessed tests for vehicle type approval.
Read more in our article: https://www.assured.se/areas/automotive-security/robust-cybersecurity-vehicles-new-airbag
#automotive #cybersecurity #r155 #uneceR155 #iso21434 #typeapproval #wvta
New international regulations are raising the bar for cybersecurity in the automotive industry, with significant risk for manufacturers that fail to act early.
A systematic, structured approach to cybersecurity is increasingly critical for faster approvals, a secure market launch, and maintaining competitiveness.
In this article, we describe how these requirements impact vehicle development in practice, what is needed to demonstrate compliance during type approval, and why many manufacturers must move away from ad-hoc measures toward a traceable, lifecycle-wide cybersecurity process.
Read the article: https://www.assured.se/areas/automotive-security/cybersecurity-requirements-for-vehicles-eu
#cybersecurity #automotive #r155 #uneceR155 #iso21434 #nis2 #typeapproval #wvta #tara
Why cybersecurity is business-critical in MedTech
#Cybersecurity in #MedTech is not only about protecting systems. It directly affects commercial outcomes.
Security influences time-to-market, interactions with notified bodies, and the ability to maintain products throughout their lifecycle. In practice, it weighs just as heavily as functionality when launch decisions are made.
When testing is performed at the right stages, risks are identified early and addressed before they become costly or cause delays. When security is owned at the management level, it becomes a decision-support tool rather than a late-stage obstacle.
Read our article: https://www.assured.se/areas/medtech-security/cybersecurity-is-business-critical-in-medtech
Cybersecurity requirements in MedTech
Even when #cybersecurity is included in #MedTech product development, it is often still treated as a technical detail rather than what it actually is: a regulatory and business-critical requirement.
Under #MDR and #IVDR cybersecurity is directly tied to market access. Weak or late security work doesn’t just create technical debt. It can delay approvals, increase remediation costs, or stop a product from being launched altogether.
Building security in from the design phase, and validating it continuously, is increasingly a prerequisite for operating in regulated healthcare markets.
Read our article: https://www.assured.se/areas/medtech-security/cybersecurity-requirements-in-medtech
We just published a blog post on how insecure default settings in Google Kubernetes Engine (GKE) can be exploited to gain control over cloud environments. Learn how chaining multiple vulnerabilities can lead to significant risks and discover practical tips for securing your GKE clusters. Don't miss out on our detailed attack chain analysis and essential recommendations for robust GKE security.
Read the full post here: https://www.assured.se/posts/exploiting-insecure-gke-defaults
#CyberSecurity #GKE #CloudSecurity #Kubernetes #Infosec #DevSecOps
A fresh blog post on Zabbix Agent security! Penetration testers, #security researchers and defenders alike will find good value in this post!
https://www.assured.se/posts/zabbix-agent-security
What's important to know, now that the SHA-1 hashing algorithm has (finally) been retired by NIST? Should you worry?
Here's some good insight in a fresh blog post:
https://www.assured.se/posts/what-the-sha1-retirement-means-for-you
Assured 😍 #AdventOfCode
We love to partake in technical challenges, be it security capture-the-flag (CTF) contests or coding challenges such as Advent of Code.
As a company it feels natural to sponsor such events.