(T20) (CFI) Nos retours d'expérience du pentesting dans le secteur de la mobilité

(T20) (CFI) Nos retours d'expérience du pentesting dans le secteur de la mobilité

🎙 Noir Zerby (XPO Group) 👥 7K 📅 April 9, 2026 ⏱ 15 min 👁 51 📄 expert opinion 🧭 2026-08-13
Available in: English (current) Français

Keywords

pentestingmobilitysecure by designOT/IT convergenceembedded systems

Summary

In this conference talk, Noir Zerby from XPO Group shares their experience in pentesting within the mobility sector. He introduces their lab dedicated to testing embedded systems, connected objects, and PLCs. He identifies that 90% of vulnerabilities stem from a lack of ‘secure by design’ principles. He highlights three main causes: the conflict between legacy architectures (like ECUs) and modern connected systems, hidden attack surfaces (e.g., debug ports, maintenance interfaces), and the illusion of network segmentation between IT and OT, leading to unmanaged junction zones. He illustrates with examples: an attack on an infotainment system that disrupted a CAN network function, and a connected bike where data was exfiltrated via a diagnostic tool. He concludes by advocating for integrating security from the start, improving communication between IT and OT developers, and staying updated with new testing methods from the offensive security community.

142 words

Critical Evaluation

Value of the Information & Strength of the Argument

The talk provides valuable insights from real-world pentesting experiences, particularly highlighting the systemic issue of legacy systems in modern connected environments. The argumentation is coherent, with concrete examples that support the claims. However, the presentation is high-level and lacks technical depth, and the speaker does not provide quantitative data or detailed case studies. The emphasis on ‘secure by design’ is well-founded and aligns with industry best practices.

Scientific Rigor, Source Quality, Title Accuracy

The talk is based on the speaker’s professional experience, but no specific sources or references are cited. The description provides links to the INCYBER forum and LinkedIn, which are not directly related to the content. The title accurately reflects the content, and the talk is part of a conference series, suggesting a certain level of credibility. However, the lack of citations and the informal nature limit its scientific rigor.

151 words

Title / Content Match

The title accurately reflects the content: a feedback session on pentesting in the mobility sector.

Quality & Reliability

7/10

The speaker is a professional in offensive security with direct field experience, but the talk is an informal conference presentation without detailed technical evidence or citations. Claims are plausible and align with industry knowledge, but lack rigorous verification.

Key Moments

Cited Sources

Concurring Sources

  • Secure by Design — Wikipedia article explaining the concept that aligns with the talk's main argument.

Contribution & Novelties

The talk provides practical insights from pentesting in the mobility sector, emphasizing the recurring issue of legacy systems and the need for secure by design. It highlights the convergence of IT and OT as a critical attack surface. The speaker’s experience adds real-world context to theoretical concepts.

Pour aller plus loin :

  • Secure by Design — Foundational concept for building security into systems from the start.
  • CAN bus — The in-vehicle network protocol mentioned in the talk.
  • OT/IT convergence — The integration of operational technology with information technology, a key theme.
  • Penetration test — The methodology used in the described activities.

101 words

Radar Profile

The radar profile shows moderate scores across all dimensions, with slightly higher quality and reliability scores, indicating a balanced but not exceptional presentation. The talk is informative but lacks depth and citations.

Reliability 7/10