Assured Security Consultants

@assured@infosec.exchange
42 Followers
3 Following
19 Posts
From chip to ship: we put applications, infrastructure, IoT, embedded devices and vehicles to the test. Your security Assured.
LocationGothenburg, Sweden
Websitehttps://www.assured.se
Blueskyhttps://bsky.app/profile/assuredab.bsky.social
LinkedInhttps://www.linkedin.com/company/assured-ab
We are proud to have worked with Open Technology Fund (OTF) and @EngageMedia to help secure Cinemata, an open source video platform for communities that operate in politically sensitive environments. Of 26 identified vulnerabilities, all have been verified fixed.
#pentest #cybersecurity #privacy
https://www.assured.se/posts/pentest-report-cinemata
Penetration Test Report: Cinemata

We performed a penetration test on the Cinemata video platform, serving communities that operate in politically sensitive environments. Supported by the Open Technology Fund, the pentest report is now published.

Assured AB
Our embedded security and cryptography expert Joachim Strömbergson guested a Swedish security podcast (Bli Säker @nikkasystems) and discussed Post Quantum Cryptography. Find our English summary and the link to the episode in our blog.
https://www.assured.se/posts/podcast-spotlight-threat-from-quantum-computers
#pqc #security #cryptography
Podcast Spotlight: The Threat from Quantum Computers

Our embedded security and cryptography expert Joachim Strömbergson guested a Swedish security podcast (Bli Säker) and discussed Post Quantum Cryptography.

Assured AB

Veckans specialavsnitt av Bli säker-podden gästas av Joachim Strömbergson från @assured. Han berättar om hotet från kvantdatorerna. Kommer de att knäcka krypteringen på internet?
https://www.youtube.com/watch?v=fonwbXwv5C8

#BliSäker

Podd 338: Hotet från kvantdatorerna – specialavsnitt med Joachim Strömbergson

YouTube
Celebrating 100 security assessments, over 1000 findings, and over 2000 pages of pentest reports in 2025!
https://www.assured.se/posts/100-security-assessments-in-2025
#pentest #cybersecurity
100 Security Assessments in One Year! Looking back at 2025

In 2025, Assured completed 100 security assessments covering many different industries and technologies. Here are the numbers, and what records we’re aiming to break in 2026.

Assured AB

Modern vehicles are complex, connected systems with an ever-expanding attack surface. In this environment, documentation alone is no longer sufficient — to meet regulatory requirements, cybersecurity must be demonstrated in practice.

Testing is carried out under witnessed conditions, with each step documented and reproducible. These tests play a critical role in vehicle type approval under UNECE R155 and have effectively become the vehicle’s digital crash test.

We have extensive experience in penetration testing of vehicles and automotive components, including expert advisory services and the execution of witnessed tests for vehicle type approval.

Read more in our article: https://www.assured.se/areas/automotive-security/robust-cybersecurity-vehicles-new-airbag

#automotive #cybersecurity #r155 #uneceR155 #iso21434 #typeapproval #wvta

Robust Cybersecurity is the Vehicle's New Airbag

Digital protection is now as critical as steel, airbags and crumple zones. Regulations require evidence, and real-world testing determines whether a vehicle’s cybersecurity truly holds.

Assured AB

New international regulations are raising the bar for cybersecurity in the automotive industry, with significant risk for manufacturers that fail to act early.

A systematic, structured approach to cybersecurity is increasingly critical for faster approvals, a secure market launch, and maintaining competitiveness.

In this article, we describe how these requirements impact vehicle development in practice, what is needed to demonstrate compliance during type approval, and why many manufacturers must move away from ad-hoc measures toward a traceable, lifecycle-wide cybersecurity process.

Read the article: https://www.assured.se/areas/automotive-security/cybersecurity-requirements-for-vehicles-eu

#cybersecurity #automotive #r155 #uneceR155 #iso21434 #nis2 #typeapproval #wvta #tara

Cyber-secured vehicle – no longer a choice, but a requirement

Cybersecurity is now mandatory for all vehicle manufacturers. Learn how UNECE R155, R156 and ISO 21434 reshape automotive development and compliance.

Assured AB

Why cybersecurity is business-critical in MedTech

#Cybersecurity in #MedTech is not only about protecting systems. It directly affects commercial outcomes.

Security influences time-to-market, interactions with notified bodies, and the ability to maintain products throughout their lifecycle. In practice, it weighs just as heavily as functionality when launch decisions are made.

When testing is performed at the right stages, risks are identified early and addressed before they become costly or cause delays. When security is owned at the management level, it becomes a decision-support tool rather than a late-stage obstacle.

Read our article: https://www.assured.se/areas/medtech-security/cybersecurity-is-business-critical-in-medtech

Why Cybersecurity is Business-Critical in Medtech

Cybersecurity in medtech is as vital as a pacemaker’s rhythm or an insulin pump’s dosage. For manufacturers, approved security can determine whether a product reaches the market—or is halted last minute.

Assured AB

Cybersecurity requirements in MedTech

Even when #cybersecurity is included in #MedTech product development, it is often still treated as a technical detail rather than what it actually is: a regulatory and business-critical requirement.

Under #MDR and #IVDR cybersecurity is directly tied to market access. Weak or late security work doesn’t just create technical debt. It can delay approvals, increase remediation costs, or stop a product from being launched altogether.

Building security in from the design phase, and validating it continuously, is increasingly a prerequisite for operating in regulated healthcare markets.

Read our article: https://www.assured.se/areas/medtech-security/cybersecurity-requirements-in-medtech

EU Tightens Cybersecurity Requirements for Medtech - MDR and IVDR

The EU is strengthening cybersecurity requirements in MDR and IVDR. Manufacturers must embed cybersecurity from the start, document processes, and ensure security throughout the entire device lifecycle.

Assured AB

We just published a blog post on how insecure default settings in Google Kubernetes Engine (GKE) can be exploited to gain control over cloud environments. Learn how chaining multiple vulnerabilities can lead to significant risks and discover practical tips for securing your GKE clusters. Don't miss out on our detailed attack chain analysis and essential recommendations for robust GKE security.
Read the full post here: https://www.assured.se/posts/exploiting-insecure-gke-defaults

#CyberSecurity #GKE #CloudSecurity #Kubernetes #Infosec #DevSecOps

Exploiting insecure GKE (Google Kubernetes Engine) defaults - Assured Security Consultants

This blog post will guide you through an attack chain exploiting insecure defaults in GKE, and explain how to harden a Kubernetes cluster to reduce the risk of compromise.

Don't miss the previous post addressing IT infrastructure and Active Directory security assessments conducted during 2023, with a breakdown of common vulnerabilities and strategies to mitigate them! Read here: https://www.assured.se/posts/retrospective-2023-infrastructure-security
#activedirectory #ITinfrastructure
2023 Retrospective: IT Infrastructure and Active Directory Security - Assured Security Consultants

A 2023 retrospective by Assured Security Consultants on security assessments conducted, highlighting key IT infrastructure and Active Directory vulnerabilities, the impact of new regulations, and strategies for a more secure future.