Midnight Blue is a specialist security consultancy firm engaged in high-end security research with a particular focus on embedded systems in domains ranging from Cyber Physical Systems (CPS) to communications and security equipment.
Understand the inner workings of complex systems, gain insight into vulnerabilities, and identify cost-effective mitigations.
From brand new, highly integrated embedded systems that fit in the palm of your hand to large, geographically dispersed cyber-physical systems running on legacy technology stacks, we’ve got you covered.
Building strong in-house capabilities is hard, particularly when it comes to domains requiring a rare intersection of skills. Our capability development services can help you deliver unique results and rapidly build expertise within your organization.
A mature security posture is something which cannot be bolted onto an existing product. However, many products used in critical settings nowadays have their roots in a very different era and struggle to keep up with an evolving threat landscape.
Midnight Blue assists to re-architect such systems in order to ensure secure and future-proof operations.
Our researchers have presented numerous talks at top industry conferences such as Black Hat, DEF CON, Chaos Communication Congress, CanSecWest, Infiltrate, OffensiveCon, REcon, hardwear.io and USENIX. In addition, Midnight Blue has served as SME for the industry standard MITRE ATT&CK for ICS framework as well as government commissions and conference review boards.
We tailor all our services to our clients’ specific needs, and follow a general approach to bring structure to complex and often opaque projects. Depending on the nature of our clients’ needs, we can follow our usual approach or find a more bespoke fit.
Every project starts off with an intake session during which we explore the client’s problem space, identify goals and obstacles and determine a scope.
Before an actual plan of approach is drafted we prefer to conduct a prestudy in order to truly understand the problem at hand, decompose it and determine pitfalls and come up with a good estimate on the execution timeframe and technical requirements.
The output of the prestudy is a plan of approach. It describes the client’s original problem and decomposes it into manageable and clear goals, obstacles and scoping. In addition, it provides an execution timeframe, technical requirements and a step-by-step walkthrough of the execution process as well as an overview of the deliverables produced by the project.
Execution can be tailored to the clients’ needs and can come in time-boxed or milestone-based forms. Deliverables can either be set at project conclusion or can be set as milestones throughout the execution phase.
Upon completion of execution, QA will take place as per the four eyes principle and deliverables will be handed over to the client. Assessment reports will have prioritized, reproducible findings and associated remediation advice. Technical deliverables will come with documentation and instructive examples.
More about our markets