Industrial cybersecurity moves at the pace set by the threats driving it. Staying ahead requires continuous research: opening what nobody has audited, understanding new malware before it reaches a plant and testing what has not yet made it into any manual.
Why we research
We do not research for prestige, but because our services need it. When a client calls us about an incident, the malware may be new; when a manufacturer wants to sell in Europe, its product may never have been opened up; when a new attack technique appears, it must be understood before it can be defended against. Research keeps the rest of our work ahead of the adversary.
The work takes place in Ti Lab, our laboratory, which houses real control equipment, a hardware bench, radio capabilities and analysis tools. This page explains what we research and what results come from it; the Ti Lab page explains with what and how.
And we follow one rule: when we find a flaw in someone else's product, we disclose it responsibly. It is neither concealed nor sold; disclosure is coordinated with the party responsible for fixing it.
Applied research
Vulnerabilities discovered and disclosed
Ten CVE identifiers resulting from the team's research and published through coordinated disclosure with vendors, INCIBE-CERT and CISA. Each link opens the public advisory with scope, scoring and remediation information.
2023 · IoT
CVE-2023-5499
Shenzhen Reachfar GPS v28
Exposure of logs and sensitive data in a personal GPS tracker. High severity, CVSS 7.5.
Six active fronts. They are not isolated areas: an incident at a substation may involve an IED's firmware, its IEC 61850 protocol and the radio link used for remote control, all at once.
Embedded-device and firmware security
What lies inside a device: forgotten debugging interfaces, factory-embedded credentials and firmware that nobody has audited. We work on PLCs, RTUs, sensors and connected medical devices, including physical extraction.
Finding the flaw before the attacker does. We dedicate specialist time to searching for previously unknown vulnerabilities in proprietary or third-party software using targeted fuzzing and instrumentation.
Understanding what comes without source code: a sample from an incident or an undocumented protocol. We closely track malware designed for industry—a small but very serious catalogue.
The spectrum nobody watches: wireless telemetry, LPWAN, industrial Bluetooth, private 5G and remote control. With Software Defined Radio, we capture, analyse and test what an attacker would test.
AI where it genuinely adds value, not because it is fashionable: anomaly detection in industrial protocols, support for malware analysis and models that run locally when data cannot leave the plant.
The language of the plant: Modbus, DNP3, S7, IEC 61850 and GOOSE. We study how control systems communicate to detect anomalies and design resilient architectures.
What we are developing with artificial intelligence
Models for detecting anomalies, explaining alerts and making risk decisions in industrial networks. We distinguish work that has already been applied or published from research still on the roadmap.
Applied and published
Applied
IIoT intrusion detection with transformers
Sequential models for analysing industrial traffic in real time and detecting behaviour that departs from the normal baseline.
M. Eceiza, J. L. Flores & M. Iturbe · IEEE Internet of Things Journal 8(13)
Responsible disclosure
Have you found a flaw in something we make?
As a security company, we publish how to report a vulnerability. If you have found an issue on this website or in any of our products, write to us: we respond, do not pursue good-faith research and credit anyone who wishes to be acknowledged.