Course · OT, ICS & IoT Security
IoT Security: Hacking & Hardening Connected Devices
An IoT product is four attack surfaces wearing one plastic shell: hardware, firmware, radio and cloud. This course takes you through all four — first as an attacker, then as the engineer who has to ship it safely under the EU Cyber Resilience Act.
FirmwareUART/JTAGBLEOWASP IoTETSI EN 303 645EU CRA

What you will be able to do
- Attack the hardware layer: UART, JTAG, SPI flash extraction and the debug ports vendors forget to fuse
- Unpack and analyse firmware, find hardcoded secrets, and rebuild modified images
- Assess radio protocols — BLE, Zigbee, LoRa and Wi-Fi — for pairing and replay weaknesses
- Test the device cloud and mobile app: API authorisation, device identity and provisioning flows
- Harden with secure boot, signed updates, hardware-backed keys and least-privilege device identity
- Map your product against OWASP IoT Top 10, ETSI EN 303 645, NIST IR 8259 and EU CRA obligations
Who this course is for
Product security engineers building connected devices
Penetration testers expanding into hardware and firmware
Compliance leads preparing for EU CRA and ETSI conformance
Course facts
- Level
- All Levels
- Platform
- Udemy — lifetime access, mobile and TV, 30-day refund
- Includes
- Downloadable resources, Q&A support and a certificate of completion
- Instructor
- Nexus Academy — cybersecurity, compliance, cloud and AI
Next step
Start IoT Security today
Enrol on Udemy and keep the course for life, or read the full briefing on this topic first.