Testimonials and past Cybersecurity Clinic Projects

Here you find testimonials of some of our project partners and the clinic projects we carried out in the past.

Kevin Yar
CEO TrueYouOmics

«The clinic project gave us valuable insight into our safety situation and clearly showed us where there was room for improvement. The students’ detailed analysis and practical corrective actions are of great value to us and will help us to further improve our safety standards.»

Valentin Zahnd
Founder Secuteer GmbH

«The basis for the Penetration Testing Toolbox created in the Clinic project is ideal for enabling developers to test web applications independently in the future, thus simplifying access to cybersecurity knowledge.»

Tobias Ospelt
Managing Director Pentagrid AG

«Seeing local LLMs performing very well at certain tasks while failing at others gave us a clear indicator of the possibilities for usage with the Burp Suite MCP server. The evaluation done in the clinic project by the student leads the way for future research in the field.»

Projects from 2025

LLM-Penetration testing with the Burp Suite for Pentagrid

In this project, a student at ZHAW School of Engineering analyzed how LLMs could utilize the penetration testing tool Burp Suite to make penetration testing for the project partner Pentagrid more efficient. Through the implementation of three specific use cases—scan management, result verification, and report generation—the study evaluated the performance of various models, ranging from Llama 3.2 to GPT-4. By establishing a dedicated benchmark, the project demonstrated the feasibility of local LLM-driven security testing and identified the specific strengths and limitations of current models controlling the Burp Suite.

Security Consulting for University of Zurich

University of Zurich has a very heterogeneous environment, which makes it difficult to provide suitable recommendations for software components such as password managers or encryption tools. Faced with this challenge, two student teams developed prototypes that evaluate and recommend products based on personal weightings and priorities across various categories. These prototypes can be adjusted to the user’s individual level of knowledge in order to provide more differentiated assessments.

Security Consulting for a Swiss SME

A small and medium-sized enterprise (SME) with a limited budget and no dedicated IT department, yet handling sensitive data, had its infrastructure screened and hardened by a student group, resulting in a significant improvement in its overall security posture. For example, this included replacing and hardening the NAS, setting up a separate router with a customer VPN, and optimizing physical security through appropriate measures.

Data Leakage Prevention for Bernina Schweiz AG

In this project, a student at ZHAW School of Engineering designed a concept for a data leakage prevention solution for Bernina Schweiz AG. The project began with a survey of Bernina’s requirements and general conditions. This was used to derive various options for defining data protection classes. Finally, a product evaluation was carried out to determine which product best suited Bernina’s needs. The project thus laid the foundations for the successful introduction of a data leakage prevention solution.

Projects from 2024

Penetration Test of a Web Application from TrueYouOmics

TrueYouOmics, a Winterthur-based health tech start-up, offers AI-driven health risk assessments via a web application that processes sensitive DNA, RNA, and protein data. To ensure a high level of security, a penetration test was conducted as part of a ZHAW Bachelor’s project, requiring deep analysis of modern technologies and advanced attack techniques. While the application was found to be generally secure, several vulnerabilities—especially in core features and chatbot integration—were identified and accompanied by practical mitigation recommendations.

Cybersecurity on Farms

In a joint project between the Landwirtschaftliche Zentrum St. Gallen and ZHAW, students investigated cybersecurity risks on farms, finding frequent high-risk behavior—especially in IT infrastructure and access control—driven by low awareness and limited perceived relevance. Business Informatics students analyzed behavioral factors, while a Computer Science student assessed technical vulnerabilities in internet-connected devices on-site. The project delivered practical recommendations and laid the groundwork for targeted cybersecurity training and awareness materials for farmers.

Cybersecurity Hardening for an SME in the Canton of Zurich

In collaboration with an SME from the canton of Zurich, students from the ZHAW School of Management and Law conducted a cybersecurity hardening project focused on securing sensitive data exchange among staff and freelancers. After assessing IT systems, cloud services, and key risk areas such as access management and encryption, the team identified vulnerabilities and implemented targeted improvements. The project resulted in a prioritized set of actionable recommendations, giving the SME a stronger security foundation and clear next steps for further protection.

Toolbox for Penetration Testing of Web Applications

In cooperation with the company Secuteer, a prototype toolbox for web application penetration testing was developed as part of a Computer Science Bachelor’s project at ZHAW, with the goal of making cybersecurity more accessible.