IOActive Logo
  • BLOGS
  • contact us
  • SERVICES
    • FULL STACK SECURITY ASSESSMENTS
    • SECURE DEVELOPMENT LIFECYCLE
    • RED TEAM AND PURPLE TEAM SERVICES
    • AI/ML SECURITY SERVICES
    • SUPPLY CHAIN INTEGRITY
    • ADVISORY SERVICES
    • TRAINING
    • OCP SAFE
  • INDUSTRIES
    • CRITICAL INFRASTRUCTURE
    • ENERGY
    • FINANCIAL SERVICES
    • HEALTHCARE
    • MANUFACTURING
    • MEDIA & ENTERTAINMENT
    • RETAIL & CONSUMER PRODUCTS
    • TECHNOLOGY
    • TELECOMMUNICATIONS
    • TRANSPORTATION
      • AVIATION
      • MARITIME
      • RAIL
      • VEHICLE
  • RESOURCES
    • BLOGS
    • RESEARCH
    • DISCLOSURES
    • LIBRARY
    • TOOLS
  • CAREERS
  • WHO WE ARE
    • TEAM
    • EVENTS
    • PRESS
    • PHILANTHROPY
    • CORPORATE OVERVIEW
IOActive Logo
  • SERVICES
    • FULL STACK SECURITY ASSESSMENTS
    • SECURE DEVELOPMENT LIFECYCLE
    • RED TEAM AND PURPLE TEAM SERVICES
    • AI/ML SECURITY SERVICES
    • SUPPLY CHAIN INTEGRITY
    • ADVISORY SERVICES
    • TRAINING
    • OCP SAFE
  • INDUSTRIES
    • CRITICAL INFRASTRUCTURE
    • ENERGY
    • FINANCIAL SERVICES
    • HEALTHCARE
    • MANUFACTURING
    • MEDIA & ENTERTAINMENT
    • RETAIL & CONSUMER PRODUCTS
    • TECHNOLOGY
    • TELECOMMUNICATIONS
    • TRANSPORTATION
      • AVIATION
      • MARITIME
      • RAIL
      • VEHICLE
  • RESOURCES
    • BLOGS
    • RESEARCH
    • DISCLOSURES
    • LIBRARY
    • TOOLS
  • CAREERS
  • WHO WE ARE
    • TEAM
    • EVENTS
    • PRESS
    • PHILANTHROPY
    • CORPORATE OVERVIEW

Article Categories: PRESS RELEASE

PRESS RELEASE | April 29, 2019

IOActive Chief Operating Officer Matt Rahman Keynotes Middle East Security Awards (MESA) in Dubai

IOActive Demonstrates Commitment to Continued Expansion of Global Services

Seattle, Wash., April 29, 2019 – IOActive, Inc., the worldwide leader in research-fueled security services, today announced that its chief operating officer, Matt Rahman, will keynote the Middle East Security Awards (MESA) 2019 in Dubai on Tuesday, April 30. In his speech, “Going Digital: Hackers Own Your Digital Transformation,” Rahman will address the threats that hackers, cyber criminals and nation states present to the digital transformation.

“The rapid adoption of new technologies and digital transformation projects in the Middle East and other nearby regions attracts all types of adversaries and nation states who are attempting to cause setbacks and major disruptions,” said Rahman. “IOActive is committed to expanding our international capabilities and services in emerging and growing markets in the GCC, Middle East and Asia and and I’m pleased to have this opportunity to present at the MESA conference.”

With operations and clients across more than 30 countries, IOActive brings world-class services to businesses and operations with its advisory services, full stack security assessments, secure development lifecycle, security team development, red and purple team services.

“Our mission is to make the connected world a safer and more secure place. As the Middle East continues to embrace digital ecosystems, organizations need to address the heightened cybersecurity risks they face,” said Jennifer Steffens, chief executive officer at IOActive. “Whether infiltrating software, hardware, networks or human resources, our consultants combine the latest security research with time-tested techniques to improve our client’s security posture and operational resiliency.”

About IOActive

IOActive is a trusted partner for Global 1000 enterprises, providing research-fueled security services across all industries. Our cutting-edge security teams provide highly specialized technical and programmatic services including full stack penetration testing, program efficacy assessments, and hardware hacking. IOActive brings a unique attacker’s perspective to every client engagement to maximize security investments and improve client’s overall security posture and business resiliency. Founded in 1998, IOActive is headquartered in Seattle with global operations. For more information, visit ioactive.com.

###

PRESS RELEASE | April 23, 2019

IOActive Partners with the Institute for Critical Infrastructure Technology (ICIT) to Drive Public and Private Sector Collaboration

Partnership will facilitate focused research on cyber and public safety issues impacting critical infrastructure

Seattle, Wash., April 23, 2019 – IOActive, Inc., the worldwide leader in research-fueled security services, today announced that the company is partnering with the Institute for Critical Infrastructure Technology (ICIT), America’s cybersecurity think tank, to focus and conduct research on cybersecurity and public safety related issues impacting critical infrastructure. Through this collaboration, ICIT will leverage IOActive’s deep security expertise to inform public and private sectors on how to better defend against modern-day cybersecurity threats.

“IOActive and ICIT will focus on investigating the most pressing security risks facing our nation’s critical infrastructures right now and well into the future,” said Matt Rahman, chief operating officer at IOActive. “Whether it’s financial services, energy, healthcare, telecommunications or transportation security, this collaboration will enable us to share best practices and guidance on improving security policies and procedures across these important areas.”

The global research team at IOActive specializes in a number of key cybersecurity consulting services across major industries and critical infrastructure. As the driving force behind the nonprofit Securing Smart Cities initiative, IOActive prioritizes and invests in helping the world build smart cities with cybersecurity in mind. The team will also leverage its 21-year history of groundbreaking research and innovation to offer its expertise on how organizations can identify and strengthen their defenses against critical infrastructure threats.

“ICIT’s mission is to cultivate a cybersecurity renaissance that will improve the resiliency of our nation’s critical infrastructure sectors, defend our democratic institutions, and empower generations of cybersecurity leaders,” said Parham Eftekhari, executive director at ICIT. “This partnership will augment government and private sector decision makers’ access to bleeding edge insights and resources surrounding critical infrastructure cybersecurity with research from a world-renowned global security services firm.”

IOActive and ICIT share a history prior to this partnership. In 2015, the two organizations briefed government leaders and executives on Capitol Hill regarding the state of automotive vulnerabilities after IOActive published a 2015 technical whitepaper detailing how its researchers were able to remotely exploit an unaltered passenger vehicle.

“IOActive is proud to build this partnership with ICIT, who is dedicated to making a difference for our nation and the connected world,” said Jennifer Steffens, chief executive officer at IOActive. “For the last 21 years, our company’s team has dedicated its resources to making the interconnected world safer and more secure. We look forward to furthering this mission through the increased information sharing and collaboration that this partnership will bring.”

About ICIT
ICIT is a 501(c)3 non-partisan cybersecurity think tank with a mission to cultivate a cybersecurity renaissance that will improve the resiliency of our Nation’s critical infrastructure sectors, defend our democratic institutions, and empower generations of cybersecurity leaders. Our freely available research, Fellows, and educational events offer a trusted source of objective learning for public and private sector policymakers, technology and cybersecurity leaders, and business executives. Together, we can defend today’s vulnerabilities while changing cultures for a more secure future.

About IOActive
IOActive is a trusted partner for Global 1000 enterprises, providing research-fueled security services across all industries. Our cutting-edge security teams provide highly specialized technical and programmatic services including full stack penetration testing, program efficacy assessments, and hardware hacking. IOActive brings a unique attacker’s perspective to every client engagement to maximize security investments and improve client’s overall security posture and business resiliency. Founded in 1998, IOActive is headquartered in Seattle with global operations. For more information, visit ioactive.com.

###

PRESS RELEASE | March 26, 2019

IOActive Appoints Matt Rahman as Chief Operating Officer

Security Industry Veteran Joins IOActive to Create Global Partnerships and Expand Global Footprint in Industry Verticals

Seattle, Wash., March 26, 2019 –IOActive, Inc., the worldwide leader in research-fueled security services, today announced that Matt Rahman has joined the organization as its Chief Operating Officer (COO). As COO, Rahman will be responsible for guiding IOActive through its next stage of growth, supporting the sales, delivery and marketing teams from an operational perspective and creating efficiencies wherever possible.

“Over the past two decades, IOActive has built an expert team of global cybersecurity consultants that continue to push the bar with their ground-breaking vulnerability research and ability to help the Global 1000 navigate the most critical security issues,” said Matt Rahman, Chief Operating Officer of IOActive. “I truly believe in the mission of IOActive to make the interconnected world a safer place and I’m thrilled to re-join the leadership team as we continue growing operations globally in new markets and through new strategic partnerships.”

As COO, Rahman will focus on IOActive’s continuous growth and global expansion into different vertical markets with expanded service offerings. IOActive already has a strong footprint throughout the U.S. and European markets. Moving forward, the company will focus on further growth in new markets such as Asia and the Middle East, as well as establishing new partnerships and other joint ventures.

“My goal is to create new efficiencies and synergies for IOActive — from operations to delivery to sales and everything around that,” said Rahman. “My focus will be ensuring we have the right team, chemistry and culture for continued growth and scalability. I’m also committed to forming new partnerships with companies that can benefit from our research-driven security consultancy services.”

Rahman brings over three decades of cybersecurity expertise to IOActive and previously served as the company’s Chief Strategy Officer and Executive Vice President, where he rolled out new Internet of Things (IoT), medical device, automobile, and other industry-driven solutions and services, increasing revenue, profitability and operational planning. A veteran of the industry, Rahman has spent the last 30 years in various executive roles in security software and services firms, helping companies grow from less than $10 million to over $120 million.

“Matt joins IOActive at a critical time as we’re rapidly expanding our services in vertical markets and increasing our global footprint,” said Jennifer Steffens, CEO of IOActive. “Our commitment to our team and customers has never been stronger and having Matt on board to help run operations will allow us to continue delivering on our promise to improve the security posture of the Global 1000.”

About IOActive
IOActive is a trusted partner for Global 1000 enterprises, providing research-fueled security services across all industries. Our cutting-edge security teams provide highly specialized technical and programmatic services including full stack penetration testing, program efficacy assessments, and hardware hacking. IOActive brings an unique attacker’s perspective to every client engagement to maximize security investments and improve client’s overall security posture and business resiliency. Founded in 1998, IOActive is headquartered in Seattle with global operations. For more information, visit ioactive.com.

PRESS RELEASE | March 20, 2019

IOActive Recognized as One of the Most Important Industry Companies of the Last 30 Years in SC Media’s 30th Anniversary Awards

Groundbreaking Vulnerability Discoveries and Cutting-Edge Research Helps Improve Security Globally

Seattle, Wash., March 20, 2019 – IOActive, Inc., the worldwide leader in research-fueled security services, today announced that the company was selected as one of the “Most Important Industry Companies of the Last 30 Years” for SC Media’s 30th Anniversary Awards. IOActive was recognized for this award alongside two other security firms, Proofpoint, Inc. and RSA Security.

As part of SC Media’s year-long celebration for their 30th anniversary in the cybersecurity industry, they expanded their annual SC Awards to include several special categories honoring those who have shaped the industry, as well as those who are just beginning their journey and will serve to impact the future. Winners were decided by SC Media’s editorial team with the assistance of the SC Awards co-chairs.

“Over the last three decades, the winners of our 30th Anniversary Awards have left an indelible imprint on the cybersecurity industry through their tireless work and visionary leadership,” said Illena Armstrong, VP, editorial, SC Media. “IOActive and its researchers have most assuredly earned this honor for their continued dedication to protecting enterprises from today’s sophisticated threats.”

For over 20 years, IOActive has not only helped its Global 500 customers stay ahead of threats, but they have also helped entire industries embrace security through ground-breaking research. With embedded device and silicon hacking labs in Seattle and Madrid, IOActive’s research has been on the cutting edge of securing many industries including automotive, medical devices, aviation, satellite communications, and more. The research is driven by IOActive’s unique “attacker’s perspective” and forms the foundation of the company’s global service offerings.

In addition to its client work and research, IOActive has implemented programs to further its mission of making the world a safer, more secure place. For example, with the evolution of smart cities, the team created IOActive’s Securing Smart Cities non-profit initiative, which serves as a resource to work through the complexities of securing a smart city. The goal of the initiative is to ensure cybersecurity is considered in the planning phase of a smart city, rather than an afterthought.

“It’s humbling and rewarding that SC Media has recognized IOActive as one of the top security firms that has made a positive impact across numerous industries,” said Jennifer Steffens, chief executive officer of IOActive. “As the threatscape continues to evolve, our team continues to focus on security that has real-world impact. Looking ahead, IOActive remains committed to driving research to improve public safety, privacy and security across private and public sectors.”

About SC Media
SC Media is cybersecurity. For over 30 years, they have armed information security professionals with in-depth and unbiased information through timely news, comprehensive analysis, cutting-edge features, contributions from thought leaders, and independent product reviews in partnership with and for top-level information security executives and their technical teams.

In addition to their comprehensive website, SC Media offers magazines, ebooks, and newsletters. They also host digital and live events such as SC Awards and RiskSec Conference to provide cybersecurity professionals all the information needed to safeguard their organizations and contribute to their longevity and success.

About IOActive
IOActive is a trusted partner for Global 1000 enterprises, providing research-fueled security services across all industries. Our cutting-edge security teams provide highly specialized technical and programmatic services including full-stack pen testing, program efficacy assessments, and hardware hacking. IOActive brings an unique attacker’s perspective to every client engagement to maximize security investments and improve client’s overall security posture and business resiliency. Founded in 1998, IOActive is headquartered in Seattle with global operations. For more information, visit ioactive.com.

PRESS RELEASE | February 20, 2019

Renowned Architecture and Threat Modeling Visionary Brook S.E. Schoenfield Joins IOActive World-Class Advisory Practice

Industry Programmatic Security Expert Will Advise IOActive’s Global 1000 Clients with Strategic Security Programs

Seattle, Wash., February 20, 2019 — IOActive, Inc., the worldwide leader in research-driven security services, today announced that Brook S.E. Schoenfield has joined the company’s Advisory Services team, bringing more than three decades of development and security expertise to the team. In his role as Advisory Services Director at IOActive, Schoenfield is focused on leveraging threat modeling and building robust software security programs for IOActive’s Global 1000 customers.

“Brook’s thorough understanding of cyber risks and the threat landscape enables our clients to make more informed decisions when it comes to security spending and prioritization,” said Jennifer Steffens, CEO of IOActive. “He has trained hundreds of people in threat modeling, as well as trained, coached and mentored hundreds of security architects, so I am confident in his ability to help our clients build and improve their security programs.”

“The bottom line is that cyber threats are constantly evolving and enterprises need to have a full view into the gaps in their security posture,” said Schoenfield. “At IOActive, we’re helping our clients fully understand their security gaps, while explaining their attackers’ capabilities. We provide critical guidance to close the cyber exposure gap to lower their risk. We also can help security teams dictate where to spend security budget and how much to spend.”

Most recently, Schoenfield worked at McAfee LLC (formerly Intel Security Group and McAfee, Inc.) as the Principal Engineer leading product security architecture. In this capacity, he provided strategic technical leadership, training and mentoring 80 security architects and a team of over 120 professionals. He also served as Director of Product Security Architecture at McAfee, where he led a 60 person virtual architect team to cover all aspects of product security, from coding and testing, to secure design and architecture, including SaaS operations and vulnerability discovery, vetting, and disclosure. Prior to McAfee, Schoenfield spent over 11 years at Cisco as a Senior Security Architect, where he was originally hired as the company’s first application security architect and charged with leading the application security team.

About IOActive’s Advisory Services
IOActive’s Advisory Services leverages their unique attacker’s perspective to provide clients with comprehensive security program management, including an organizational assessment that dives deep into understanding the existing risk posture, current threat actors, real-world threat scenarios, and effectiveness of adversary-focused defensive capabilities. Based upon this current state understanding, IOActive works closely with clients to create a roadmap designed to enhance defensive capabilities and develop a framework to continuously monitor progress, benchmark against peers, and effectively communicate the risk posture to their board and stakeholders. These assessments are designed to provide actionable, prioritized recommendations for how to prevent, detect, respond and adjust to security attacks to ultimately improve business resiliency.

About IOActive
IOActive is a trusted partner for Global 1000 enterprises, providing research-fueled security services across all industries. Our cutting-edge security teams provide highly specialized technical and programmatic services including full stack penetration testing, program efficacy assessments, and hardware hacking. IOActive brings an unique attacker’s perspective to every client engagement to maximize security investments and improve client’s overall security posture and business resiliency. Founded in 1998, IOActive is headquartered in Seattle with global operations. For more information, visit ioactive.com.

PRESS RELEASE | February 11, 2019

IOActive’s CEO Joins Advisory Board for the London Office for Rapid Cybersecurity Advancement (LORCA)

Initiative Combines Industry Leaders’ Expertise and Investors’ Support to Bolster Growth of UK Cybersecurity Startups

LONDON, February 11, 2019 — IOActive, Inc., the worldwide leader in research-fueled security services, today announced that its CEO, Jennifer Steffens, has joined the industry advisory board for the London Office for Rapid Cybersecurity Advancement (LORCA). LORCA is a government-funded cybersecurity centre in East London focused on supporting cybersecurity innovation. The program provides support for UK innovators in solving critical cybersecurity challenges, while building the UK’s international cybersecurity profile.

As an advisory board member and top influencer in the security community, Steffens will support LORCA’s goals and champion the growth of its cybersecurity cohort members. The program will launch a new cohort every six months with tailored support to help them scale and meet the needs of the industry. LORCA advisory board members ensure the success of the program by providing real-time market insights and feedback, guidance on resources and connections to global market opportunities that will propel the cybersecurity innovators’ success.

“LORCA is creating a trusted digital environment where cybersecurity startups and scaleups can proactively anticipate and meet the needs of industry,” said Lydia Ragoonanan, Director of LORCA. “We’re glad to have access to Jennifer’s deep security expertise and leadership as a new addition to our advisory board, which will help shape the direction of our next cohorts and make sure we’re supporting the most relevant and useful innovations.”

In her role as IOActive’s CEO, Steffens manages a world-class team of cybersecurity researchers to advise Global 1000 enterprises and discover groundbreaking vulnerabilities. Her team provides security services across all industries and maintains global operations. Steffens and her team have presented their self-funded research on pressing cybersecurity trends and topics at over 500 conferences around the world.

“LORCA provides an exceptional platform for developing new and innovative cybersecurity solutions,” said Steffens. “It’s great to be involved in a program that is committed to boosting cybersecurity efforts and leadership in the UK.”

LORCA officially launched in 2018 and plans to stimulate the growth of at least 72 high-potential companies, grow up to 2,000 jobs, and secure £40m in investment by 2021.

About LORCA
Delivered by Plexal, Deloitte and the Centre for Secure Information Technologies (CSIT), LORCA is the UK’s dedicated space for industry-led cybersecurity innovation.

Based within Plexal’s workspace, it supports the most promising cybersecurity innovators in scaling and growing solutions to meet the most pressing industry challenges.

LORCA brings together innovators, corporates, investors, academics, and engineers to maximise the commercial potential of great cyber solutions, minimise the barriers to scale and increase speed to market. By 2021, it will have stimulated the growth of at least 72 high-potential companies, grown up to 2,000 jobs, and secured £40m in investment. LORCA is a key pillar of the wider National Cyber Security Strategy 2016 to 2021, which aims to position the UK as a world leader in cybersecurity innovation and, ultimately, make the UK the safest place to be online. LORCA is funded by the Department for Digital, Culture, Media & Sport as part of the government’s five-year, £1.5bn investment to keep the UK safe online.

For more information, visit lorca.co.uk.

About IOActive
IOActive is a trusted partner for Global 1000 enterprises, providing research-fueled security services across all industries. Our cutting-edge security teams provide highly specialized technical and programmatic services including full stack penetration testing, program efficacy assessments, and hardware hacking. IOActive brings a unique attacker’s perspective to every client engagement to maximize security investments and improve client’s overall security posture and business resiliency. Founded in 1998, IOActive is headquartered in Seattle with global operations. For more information, visit ioactive.com.

PRESS RELEASE | January 9, 2019

IOActive CEO Jennifer Steffens Named to Washington’s Diversity Power 50 by National Diversity Council

Seattle-Based Cybersecurity Executive Recognized for Commitment to Diversity and Inclusion, Empowering Women in STEM Globally

Seattle, Wash., January 9, 2019 — IOActive, Inc., the worldwide leader in research-fueled security services, today announced that its CEO Jennifer Steffens has been named a National Diversity Power 50 recipient. The 2018 Washington Power 50 Awardees are a definitive list of female executives, influencers and achievers, impacting various industries in corporate America. The recognition is given by the National Diversity Council, the first nonprofit organization to bring together private, public, and nonprofit sectors to champion diversity and inclusion across the country.

“The 2018 Washington Power 50 Award honors an amazing group of women that exemplify effective leadership in their industry,” said Dennis Kennedy, Founder and Chair of the National Diversity Council. “We hope their success inspires all women in their industries to continue striving for success.”

In her role as IOActive’s CEO, Steffens manages a world-class team of cybersecurity researchers to advise Global 1000 enterprises on how to improve their security posture. A proponent of unique ways to fill the cybersecurity talent gap, Steffens celebrates global diversity at IOActive with a diverse team throughout every area of their business. She founded and hosts IOActive’s “Women, Wisdom, & Wine” events in major cities across the globe with the goal of bringing women and non-binary individuals together to foster a greater social network amongst peers in security. She has hosted over 50 events across the United States, as well as London, Amsterdam, Berlin and Buenos Aires, and often in tandem with leading security conferences such as RSA, Black Hat, DEF CON, and InfoSecurity Europe.

“The cybersecurity industry has historically struggled with diversity. The irony is that diversity is a critical strength, as our industry seeks to understand various types of cyber attacks and methodologies,” said Steffens. “It is one of my top priorities to see individuals and teams empowered as advocates for diversity in the field of security. At IOActive, we embrace a diverse, global team, which speaks numerous languages, includes a broad range of ages, celebrates various religions, and are strong supporters of the LGBT community.”

In addition to their security consulting services, IOActive is also well known for its discovery of groundbreaking vulnerabilities. Steffens and her team have presented their self-funded research on pressing cybersecurity trends and topics at over 500 conferences around the world. They have donated their time to charities and university training programs, with the goal of making security and IOActive’s work digestible by the masses to make innovative technology across industries more secure. Steffens is also an active member of the Executive Women’s Forum, the Information Security Systems Association (ISSA) and the Open Web Application Security Project (OWASP).

About the National Diversity Council
A non-profit organization committed to fostering a learning environment for organizations to grow in their knowledge of diversity. The council affords opportunities for organizations to share best practices and learn from top corporate leaders in the areas of diversity and inclusion.

More information about the National Diversity Council is available at: nationaldiversitycouncil.org

About IOActive
IOActive is a trusted partner for Global 1000 enterprises, providing research-fueled security services across all industries. Our cutting-edge security teams provide highly specialized technical and programmatic services including full stack penetration testing, program efficacy assessments, and hardware hacking. IOActive brings a unique attacker’s perspective to every client engagement to maximize security investments and improve client’s overall security posture and business resiliency. Founded in 1998, IOActive is headquartered in Seattle with global operations. For more information, visit ioactive.com.

PRESS RELEASE | October 10, 2018

IOActive Engages Tom Brennan to Accelerate East Coast Client Operations

Industry Veteran Joins IOActive to Serve as Software Security Strategist

Seattle, Wash., October 10, 2018 – IOActive, Inc., the worldwide leader in research-fueled security services, today announced that Tom Brennan will serve the organization as its East Coast Director. In this role, Brennan will be responsible for helping IOActive’s Global 1000 customers architect and customize software security programs based on Software Development Lifecycle (SDLC) best practices.

Tom will represent IOActive’s full range of technical and programmatic professional services to help bolster security for IOActive’s clients along the East Coast, including critical infrastructure and financial services. He will also work directly with IOActive’s clients to help them understand the full impact of their world-renowned vulnerability research.

“For the past 20 years, IOActive’s team has discovered countless application security vulnerabilities that we’ve shared with clients and the broader industry to help them improve their software security practices,” said Jennifer Steffens, CEO of IOActive. “Tom’s intricate knowledge and understanding of how to code properly in order to build solid software security strategies will be a huge asset to our customer base as we continue to expand our service offerings.”

Brennan brings over 20 years of software security expertise to this role and is widely known across the cybersecurity industry for his dedication and contributions to improving the SDLC. Brennan is currently the Chairman of the Americas Board for CREST International, a not-for-profit accreditation and certification body that represents and supports the information security market. He also spent the last decade serving on the Global Board of Directors at the Open Web Application Security Project (OWASP) Foundation and worked with SAFEcode to create several software security standards and publications. He founded the New Jersey OWASP Chapter and grew the New York City OWASP Chapter as its President for 13 years.

Brennan is also a member of Proactive Risk, where he co-developed PENTESTON® at New York University FutureLabs and conducted penetration tests to help improve data protection for critical infrastructure. He has also held a variety of software security leadership roles with McAfee, Intel Security, Trustwave SpiderLabs, WhiteHat Security, ADP and Datek Online. Tom also served in the United States Marines.
In his spare time, Brennan participates as technical advisor for New Jersey Institute of Technology, County College of Morris, Morris County Economic Development Corporation, is a Rockaway Township Official and is a member of the CERT team. He is a technical advisor for the Science Technology Education and Math (STEM) program for kids at Morris County School of Technology and is a technical advisor to “The Cyber Hero Adventures, Defenders of the Digital Universe” comic book.

“To me, service to this country doesn’t stop when you get out of uniform,” said Brennan. “For the past two decades, my personal mission is to make the interconnected world a safer place by collaborating with the software supply chain community to improve software security and define standards and best practices around them. I’m excited to take on this new role with IOActive that will not only help customers build resilient and safe software, but also help build better cyber cultures.”

About IOActive
IOActive is the industry’s only research-driven, high-end information security services firm with a proven history of better securing our customers through real-world scenarios created by our security experts. Our world-renowned consulting and research teams deliver a portfolio of specialist security services ranging from security advising to penetration testing and application code assessment to chip reverse engineering across multiple industries. IOActive is the only security services firm that has a dedicated practice focusing on Smart Cities and the transportation and technology that connects them. Global 1000 companies across every industry trust IOActive with their most critical and sensitive security issues. Founded in 1998, IOActive is headquartered in Seattle, US, with global operations through the Americas, EMEA, and Asia Pac regions. Visit www.ioactive.com for more information. Read the IOActive Labs Research Blog: http://blog.ioactive.com. Follow IOActive on Twitter: http://twitter.com/ioactive.

PRESS RELEASE | September 11, 2018

IOActive Awarded CREST Accreditation for its Leading Penetration Testing Services

Accreditation reinforces IOActive’s commitment to protecting its Global 1000 clients from the latest cyber threats and attacks

Seattle, Wash., September 11, 2018 — IOActive, Inc., the worldwide leader in research-driven security services, today announced the company has been awarded CREST accreditation for its penetration testing services and will join CREST as its newest member company. By achieving CREST accreditation, IOActive’s global customers are assured that IOActive’s penetration tests meet the highest standards and that the work will be carried out by highly-qualified security consultants with all of the required skill, competence, and knowledge of the latest vulnerabilities and techniques exploited by attackers.

“This CREST accreditation is incredibly valuable as we continue expanding our global base of critical infrastructure and financial services clients who utilize our penetration testing services,” said Jennifer Steffens, CEO of IOActive. “For two decades, IOActive has invested in hiring only the best and brightest penetration testers and security consultants that can provide our clients with the highest quality of security services. This CREST membership underscores our commitment to protecting our customers from the most sophisticated cyber attacks and threats.”

CREST is a not-for-profit accreditation and certification body that represents and supports the information security market. CREST accreditation is a prerequisite for suppliers to engage with many public sector and private enterprise customers, including some of the world’s largest public companies. To achieve CREST membership, IOActive went through a very demanding assessment process that examines test methodologies, legal and regulatory requirements, data protection standards, logging and auditing, internal and external communications with stakeholders and how test data security is maintained.

“Congratulations to IOActive on its CREST membership,” said CREST President, Ian Glover. “In addition to being one of the leading penetration testing companies, the ability to work collaboratively with IOActive’s research teams will provide the opportunity to expand the understanding of how to address technical cyber security issues in complex environments, including critical national infrastructure.”

With proficiency far beyond off-the-shelf tools or remotely managed services, IOActive leverages an attacker’s perspective to identify the highest risk vulnerabilities and provide actionable recommendations for remediation. IOActive has been at the forefront of penetration testing across the full stack of technologies including: mobile applications, infrastructure, wireless, cloud environments, embedded devices and web services. Going deeper than traditional pen test companies, IOActive incorporates each industry’s unique requirements and risk factors into our methodologies and analysis to ensure the most effective testing and remediation recommendations.

About CREST
CREST provides internationally recognized accreditations for organizations providing technical security services and professional level certifications for individuals providing penetration testing, cyber incident response, threat intelligence and security operations center (SOC) services.   CREST Member companies undergo regular and stringent assessment, whilst CREST certified individuals undertake rigorous examinations to demonstrate the highest levels of knowledge, skill and competence.  To ensure currency of knowledge in fast changing technical security environments the certification process is repeated every three years.

CREST is governed by an elected Executive of experienced security professionals who also promote and develop awareness, ethics and standards within the cyber security industry. CREST supports its members and the wider information security industry by creating collaborative research material. This provides a strong voice for the industry, opportunities to share knowledge and delivers good practice guidance to the wider community.

About IOActive
IOActive is the industry’s only research-driven, high-end information security services firm with a proven history of better securing our customers through real-world scenarios created by our security experts. Our world-renowned consulting and research teams deliver a portfolio of specialist security services ranging from security advising to penetration testing and application code assessment to chip reverse engineering across multiple industries. IOActive is the only security services firm that has a dedicated practice focusing on Smart Cities and the transportation and technology that connects them. Global 1000 companies across every industry trust IOActive with their most critical and sensitive security issues. Founded in 1998, IOActive is headquartered in Seattle, US, with global operations through the Americas, EMEA, and Asia Pac regions. Visit ioactive.com for more information. Follow IOActive on Twitter: http://twitter.com/ioactive.

PRESS CONTACTS:
Allie Andrews, CREST
UK: +44 (0) 7940 452710
allie.andrews@crest-approved.org

PRESS RELEASE | August 10, 2018

IOActive Reveals Major Satellite Communication and Operating System Vulnerabilities at Black Hat USA 2018 & DEF CON 26

Researcher Ruben Santamarta discusses major vulnerabilities discovered in SATCOM equipment; Researcher Josep Rodriguez discloses security flaws in Extreme Networks WingOS, used in millions of devices globally

Las Vegas, NV – August 10, 2018 — IOActive, Inc., the worldwide leader in research-driven security services, today announced two new research papers that were fully disclosed this week at Black Hat Las Vegas and DEF CON 26. Ruben Santamarta, Principal Security Consultant, presented his Black Hat talk “Last Call for SATCOM Security” on Thursday, August 9 at 2:30pm PT and Josep Pi Rodriguez, Senior Security Consultant, will present his DEF CON talk, “Breaking Extreme Networks WingOS: How to Own Millions of Devices Running on Aircrafts, Government, Smart Cities and More” on Sunday, August 12 at 11am PT.

“Even though they are two unique bodies of research, both Ruben and Josep’s talks address supply chain risks that underscore the importance of why we must prioritize security for mission critical networks that many vital industries, including aviation and transportation, rely upon,” said Jennifer Steffens, CEO of IOActive. “As we celebrate our 20th anniversary this year, IOActive’s commitment has never been stronger in helping vendors find and fix major vulnerabilities like these ones. Our mission is and always has been to improve security overall and make the world a safer place.”

Santamarta’s research builds on his 2014 findings, describing theoretical scenarios that could result from the weak security posture of satellite communications products. Four years later, Santamarta’s Black Hat research reveals how hundreds of in-flight aircraft, military bases and maritime vessels are accessible through vulnerable SATCOM infrastructure.

IOActive’s team worked with the aviation industry, in conjunction with the Aviation Information Sharing and Analysis Center (A-ISAC), to ensure that the potential risks identified but couldn’t be tested were satisfactorily addressed. In addition, they confirmed that no critical flight operation systems were affected.

“The consequences of these vulnerabilities are shocking. Essentially, the theoretical cases I developed four years ago are no longer theoretical,” said Santamarta. “To my knowledge, my Black Hat talk is the first public demonstration of taking control, from the ground and through the Internet, of SATCOM equipment running on an actual aircraft.”

Santamarta tested additional devices in his latest research and examined attacks using SATCOM antennas, finding that several of the largest airlines in the U.S. and Europe had their entire fleets accessible from the Internet with hundreds of connections exposed. Maritime vessels around the world could also be placed at risk to attackers, as their SATCOM antennas could be used to expose the crew to RF radiation. Ultimately, this turns SATCOM devices into tools to cause radiation hazards and disruptive RF transmissions.

In related research, Rodriguez’s DEF CON presentation will highlight several critical vulnerabilities he found in Extreme Networks embedded WingOS, which was originally created by Motorola. This operating system is used globally in millions of Motorola, Zebra and Extreme Networks devices.

“This research actually started with a focus on an access point widely used in many aircrafts in worldwide airlines,” Rodriguez said. “As time went by, we realized this embedded operating system is not only used in access points for aircrafts, but also in healthcare, government, transportation, smart cities, small to big enterprises and more.”

To learn more about Santamarta’s research, please download his white paper.

To learn more about Rodriguez’s research, please read his blog.

 

About IOActive
IOActive is the industry’s only research-driven, high-end information security services firm with a proven history of better securing our customers through real-world scenarios created by our security experts. Our world-renowned consulting and research teams deliver a portfolio of specialist security services ranging from security advising to penetration testing and application code assessment to chip reverse engineering across multiple industries. IOActive is the only security services firm that has a dedicated practice focusing on Smart Cities and the transportation and technology that connects them. Global 1000 companies across every industry trust IOActive with their most critical and sensitive security issues. Founded in 1998, IOActive is headquartered in Seattle, US, with global operations through the Americas, EMEA, and Asia Pac regions. Visit www.ioactive.com for more information. Follow IOActive on Twitter: http://twitter.com/ioactive.

Posts pagination

Previous page Page 1 Page 2 Page 3 … Page 7 Next page
IOActive Logo
  • NEWSLETTER SIGN UP

  • COPYRIGHT AND AI WARNING 

  • ©2025 IOActive Inc. All Rights Reserved. This website, including all material, images, and data contained herein, are protected by copyright. All rights are reserved. Content may not be used, copied, reproduced, transmitted, or otherwise exploited in any manner, including without limitation, to train generative artificial intelligence (AI) technologies, without IOActive’s prior written consent. Without limiting IOActive’s exclusive rights under copyright laws, IOActive reserves all rights to license uses of this work for generative AI training and development of machine learning language models.

    • SERVICES
      • Full Stack Security Assessments
      • Secure Development Lifecycle
      • AI/ML Security Services
      • Red and Purple Team Services
      • Supply Chain Integrity
      • Advisory Services
      • Training
      • OCP SAFE
    • RESOURCES
      • Blogs
      • Research
      • Disclosures
      • Library
      • Tools
    • INDUSTRIES
      • Critical Infrastructure
      • Energy
      • Financial Services
      • Healthcare
      • Manufacturing
      • Media & Entertainment
      • Retail & Consumer Products
      • Technology
      • Telecommunications
      • Transportation
    • WHO WE ARE
      • Team
      • Philanthropy
      • Press
      • Events
      • Corporate Overview
    • CAREERS
    • CONTACT US
    ©2025 IOActive Inc. All Rights Reserved.
    • Privacy Policy
    • Cookie Policy
    • Terms of Use
    • Disclosure Policy