Secure Design

Secure Design

Threat modeling and design review that build security in from the start, when changes are cheapest to make.

Security is easiest to build in while a product is still being designed. Decisions made early, like which microcontroller to use or how devices authenticate to the cloud, are hard to change later. Getting them right means fewer surprises when it’s time to pentest.

I can help at any stage of development, from early architecture decisions through pre-launch verification.

Threat Modeling

Threat modeling is a systematic way to evaluate security concerns in a product or system. If you don’t know how your product could be attacked, you can’t prioritize what to protect.

First, we identify every component of the system and how the components connect. Then we map the assets that need protecting, such as data, access, keys and other secrets, and identify the likely threat actors.

From there, we list the attacks that apply to your specific system. We rank them by likelihood, meaning how difficult they are and how much insider knowledge they need, and by the damage they would cause. Your engineering and design teams can then:

  • Build in mitigations through design and UX choices that would prevent attacks like enumeration or social engineering.
  • Build in hardware mitigations like secure boot or encryption at rest to prevent reverse engineering access that would uncover secrets or further access.
  • Build in software mitigations like validation, encryption, removing debug access, etc to prevent technical attacks from being carried out.
  • Guide technical choices such as what type of microcontroller to use, or what cloud service(s).
  • Make a list of items to be verified during pentesting.

The result is a prioritized list of security work you can tackle before pentesting or certification.

Verification testing

Before launch, I can test your product against its security requirements, confirming that each control in the design was implemented and works as specified. That can include secure boot, debug access locked on production units, message authentication, and encrypted storage.

A pentest looks for any way an attacker could get in. Verification testing checks that the protections you planned are in place and working.

Working Together

Secure design work can be anything from a one-off conversation to a full threat model or ongoing support through a project. Past work includes threat models, TARAs, presentations on design concerns, and security implementation guides written for a team’s specific hardware.

For a quick start, a Security Review covers your product’s biggest risks in a single session.

Pentesting

Pentesting

Hands-on testing of your hardware, firmware and software, with findings your engineers can act on.

Trainings & CTFs

Trainings & CTFs

Give your engineers hands-on security skills through custom workshops and hacking challenges.