Rootworks Cyber Security

Automotive and embedded systems security

Specialist security assessment, device hardware testing and assurance for connected vehicles, embedded platforms, mobile applications and the software that supports them.

North West based, near Liverpool, Manchester and Leeds Nationwide coverage

20+ years in offensive and defensive security
Lifecycle assurance from early design to deployed products
Specialist automotive, IoT and embedded platform knowledge

Security without guesswork

Find the risk that matters.
Fix it before it becomes expensive.

Connected products bring together applications, operating systems, cloud services and specialist hardware. Rootworks examines the whole system, turning technical findings into practical decisions for engineering and security teams.

How we work

Services

Security work built around your product

Focused engagements that give technical teams a clear view of exposure, priority and next action.

01

Device hardware security testing

Hands-on assessment including chip-off and in-circuit firmware extraction, secure boot and debug access verification, controlled device modification and custom test harness development.

Turn restricted hardware into an observable, repeatable test environment
02

Automotive & embedded assessment

Security assessment for infotainment, telematics, IoT devices and embedded platforms, including Linux and QNX environments.

Expose attack paths across the complete system
03

Mobile application security

Assessment and reverse engineering for mobile applications that control, configure or communicate with connected products.

Understand application and API exposure
04

Vulnerability management

Track vulnerabilities across software components and deployed products, then prioritise remediation using real product context.

Focus engineering time on credible risk
05

Security architecture & consulting

Engage specialist security knowledge early in design and development, before weaknesses become costly production problems.

Build defensible products from the outset
06

Onsite GSM & Osmocom training

A two-day practical course where engineering teams build, connect and troubleshoot a private GSM lab using the Osmocom stack and an ip.access nanoBTS.

Turn GSM architecture into hands-on engineering knowledge

Engagement approach

From system context to engineering action

Every engagement is scoped around the product, its environment and the decisions your team needs to make.

  1. 01

    Define

    Map the product, interfaces, threat model and assurance goals.

  2. 02

    Examine

    Assess the implementation using targeted offensive and analytical techniques.

  3. 03

    Prioritise

    Separate credible product risk from noise and theoretical exposure.

  4. 04

    Improve

    Give engineering teams clear evidence and practical remediation direction.

Technical expertise

Comfortable below the application layer

Rootworks works across the boundaries between hardware, operating systems, applications and connected services, where product security issues are often hardest to see.

Explore hardware testing

Platforms

  • Embedded Linux
  • QNX
  • Android & mobile
  • IoT devices

Product areas

  • Infotainment
  • Telematics
  • Connected products
  • Supporting software

Techniques

  • Chip-off & in-circuit access
  • Secure boot & firmware analysis
  • JTAG, eMMC & UFS
  • Test harness engineering

Outcomes

  • Evidence-led findings
  • Risk prioritisation
  • Remediation advice
  • Lifecycle monitoring
AutoRecon vehicle identification interface analysing a vehicle

Rootworks product

Rootworks

Vehicle intelligence for difficult imagery

AutoRecon uses AI-powered visual analysis to identify vehicles from real-world images and video, including compressed, low-light, partial exterior and interior views.

  • Exterior and interior visual recognition
  • Partial and low-quality image analysis
  • Investigation and media workflows

Rootworks lab product

Private GSM lab operations without the log-file archaeology

Osmo Observer brings live subscriber evidence, repeatable Osmocom configuration, APN traffic controls and radio hardware management into one local-first interface.

  • Follow device joins, authentication, addressing and disconnects
  • Control virtual, nanoBTS and Ettus USRP radio backends
  • Turn APN, DNS and TLS activity into durable evidence
Explore Osmo Observer
Osmo Observer mission control showing subscriber activity and Osmocom stack health
Mission controlLive lab activity and service health

Start a conversation

Bring us the product.
We’ll help clarify the risk.

Tell us what you are building, assessing or trying to understand. We will respond with a practical next step.