Hardware makers without a security team
Mid-size manufacturers with product lines that are still selling and have not been security tested.
Fractional CTO and embedded security tester. For the investors who buy connected products and the companies that run them.
IoT and SaaS legacy modernization, embedded security testing, and compliance with the EU Cyber Resilience Act (CRA), RED / EN 18031, IEC 62443 and the EU Machinery Regulation (MR 2023/1230). I build the team, then drive the transformation with them.
Fractional CTO for SaaS platforms with connected devices behind them.
I build the team and the architecture, keep delivery predictable and quality high, and work closely with product, DevOps and the other engineering leads as the platform grows.
IoT and hardware penetration testing of the device itself: board, debug ports, buses, radio and boot chain.
The defensive side, as a reviewer and advisor. I run the threat analysis and risk assessment and guide your engineers through the requirements and how to implement them.
For investors in IoT and SaaS companies. An independent look at the technology before you invest or buy, from every angle that affects its value.
You get a written report: what works, the risks, and what fixing them would take.
Companies with a connected product, a device and the platform it reports to, that now has to meet new security rules or the standards its industry requires.
Mid-size manufacturers with product lines that are still selling and have not been security tested.
Machines built on CAN, J1939 and ECUs, with telematics.
Devices that pair with a phone app and send patient data to the cloud.
Device plus cloud, selling into the EU, with a growing fleet and a small team.
Engineering leader who builds teams and platforms, and looks at every device with an attacker’s mindset.
The deliverable is not my presence. It is a team and an architecture that no longer need me.
From web agencies and hosting, through automotive firmware and hardware penetration testing, to SaaS platforms for connected devices.
Builds and leads the engineering team of a cybersecurity SaaS platform for connected vehicles, does security research on robotics, and helps companies with compliance.
Hardware penetration testing of vehicles and IoT devices. Helped build the automotive security team, and trained security teams.
Safety-critical automotive firmware. Gateway, HSM, bootloader, RTOS.
Digital agencies and a clustered hosting platform. Built the team that delivered high-load websites, web applications and payment integrations.
| Year | Project | Type | What |
|---|---|---|---|
| 2026 | tcprog | Tool | Flash programmer for Infineon AURIX TC2xx/TC3xx over FTDI debug probes. Reverse-engineered the DAP protocol from captured USB traffic |
| 2025 | libopencm3 | Upstream fix | Fixed clock source selection |
| 2022 | Hacktivity | Workshop | Co-presented “Introduction to Automotive CAN Bus Hacking”, 7 October 2022 |
| 2021 | blueman | Upstream fix | Increased the status icon visibility timeout. I made everyone wait more. |
| 2015 | Linux kernel, OCFS2 | Bug report, patch | Found the broken hard links bug and sent a patch, then tested the reworked fix that was merged |
| 2012 | lirc_rpi | Linux driver | Author of the Raspberry Pi infrared GPIO driver, vendored into 260+ public source trees |
| 2008 | Linux kernel, em28xx | Patch | Added support for the GrabBeeX+ USB2800 video capture device |
Tell me about the product and what you need.
We start with a 30 minute call. By the end of it we will both know whether I can help and what a good first step would be.