Skip to Content

Cyber-Physical Systems Cybersecurity Testing

Virtual
Pricing/Discount Options: Call #2
Unique Identifier: 11028e8f-b711-45e3-9ed0-8558bb19b34a

Service Description

Cyber-Physical Systems Cybersecurity Testing ensures cyber-physical systems (CPS), such as robotic systems, comply with security requirements and standards (such as Cyber Resilience Act). Security testing includes security functional testing of the whole system, and vulnerability scanning of the software components. The overall goal is to release your product without known important vulnerabilities.

How can the service help you? Our service is based on a custom platform that automates vulnerability scanning, penetration testing and security functional testing, with the possibility to integrate our platform in your DevSecOps activities for full security activities automation. The focus on cyber-physical systems takes the form of support for physical interfaces and buses/protocols, with possible attacks on RF signals (GPS or WiFi), for example. Our offer differentiates from existing ones with a unique risk-based approach, where a security risk analysis drives the whole process of security testing, and by the use of open-source tools to avoid vendor lock-in. The method is based on existing standards : PTES, Etsi, NIST, FDAM...

How the service will be delivered? Based on information provided by the customer about their system, this service offers to use our Automated Cybersecurity Testing platform, tools and method to define and perform cybersecurity tests, either on site or in our lab. Optionally, we can integrate our platform in your DevSecOps chain for full automation of security activities. Optionally, we can perform the security risk analysis that is used as input for the whole process. We will provide complete test reports as well as recommendations to lower the residual risk level and attack surface of your system. Together with the risk analysis, they can be used as a complete set of evidences towards authorities and customers.

Service deployment: The service is deployed either on site or in our lab. Our test platform is made of several components : a server that stores all relevant information and generate the reports, and test workstations that can be used in our lab or at customer sites directly.

Service standards: PTES, Etsi, NIST, FDAM...

Offerings: Software (Cybersecurity and privacy-protecting enhancements, development, maintenance, deployment, administration, etc.)
Provider Logo

Provider & Contact

Provider Country Belgium
Published Email tef-health-services@cetic.be

Pricing is available to registered users. SMEs receive significant state-aid reductions (GBER) — or, depending on the call, free services during the funded project. Sign in or register to see the price for your organisation.

Operational Details

Service Inputs The customer should provide at least the system to be tested or an access to this system. In case no other information is provided, the test are considered as black box testing. Optionally, in case of grey box testing, additional documentation can be provided such as specification, architecture description, etc... If the customer expects white box testing, all documentation together with the system configuration and source code should be provided. Also, the risk analysis can be provided if it exists to help prioritize the tests to be realised
Service Outputs The service output is an integrated report containing : - all actions performed; - all results found; - all vulnerabilities and findings (bugs, bad configuration, ...); - recommendations related to the vulnerabilities and findings.
Service Standards PTES, Etsi, NIST, FDAM...
  • Etsi
  • FDAM
  • NIST
  • PTES