Awakening Security

Request the PDF

Enter your email and we will send you a code; your request is then recorded at once, and once I have reviewed it a link to download your copy reaches your email.

By continuing, your email and progress are kept in your account. Privacy

* The file is for your own reading; sharing follows the terms of use, and commercial use is not permitted.

Reading progress
0 of 34 sections read
14 / 34

Chapter 12

12Vulnerability Management, Assessment and Penetration Testing (VAPT)

3 min read14 of 34Read it in the book · page 73

“Find your vulnerabilities before someone else does.”

In an age of increasingly sophisticated and aggressive threats, vulnerability assessment and penetration testing (VAPT) has become an indispensable defence. This is even truer in the creative industries, where the value of intellectual property is incalculable. This chapter focuses on how to use VAPT to identify, assess and proactively remediate vulnerabilities in systems and applications, and on the vulnerability management cycle around it.

The Vulnerability Management Cycle

Control 8.8 requires management of technical vulnerabilities: obtaining timely information about them, assessing the organisation’s exposure, and taking appropriate action. It is a cycle that never stops.

The vulnerability management cycleThe vulnerability management cycle
The vulnerability management cycle
Text in this figure

Manage · flaws · Discover · Scans · reports · intel · Assess · Severity and impact · Prioritise · Severity · exploitability · Treat · Patch · config · control · Verify · Rescan and close · Figure 16

Understanding Vulnerability Assessment and Penetration Testing

  • Vulnerability assessment (VA): A systematic, automated review of weaknesses in an information system: is it exposed to known vulnerabilities? How severe are they? What remediation is recommended? Its goal is to identify and quantify the extent of vulnerabilities.
  • Penetration testing (PT): Also known as ethical hacking: an active, manual process that simulates a real attack to understand how well the system defends itself. Its goal is to exploit discovered vulnerabilities to learn what data could be extracted or what damage a successful attacker could do.

Why VAPT Matters to the Creative Industries

Creative sectors handle vast amounts of high-value intellectual property, and its compromise means serious financial loss and reputational harm. Through VAPT an organisation can:

  • Identify vulnerabilities in its creative tools and platforms before malicious actors exploit them.
  • Ensure the integrity and availability of its digital assets: multimedia, designs, scripts and other proprietary information.
  • Comply with regulations and industry standards that mandate regular security assessments.
  • Gain a deeper understanding of its security posture and make better-informed decisions about security investment.

Implementing VAPT in Creative Environments

Stages of vulnerability assessment and penetration testing (VAPT)Stages of vulnerability assessment and penetration testing (VAPT)
Stages of vulnerability assessment and penetration testing (VAPT)
Text in this figure

Plan and scope · Rules of engagement · Reconnaissance · Network, systems, people · Vulnerability scan · Automated (VA) · Penetration test · Manual exploit (PT) · Analysis and report · Risks, recommendations · Treat · Patches, config, controls · The first measures the flaws; the second proves what a real attacker could do with them · Figure 17

  • Planning and scoping: Define the systems, networks and data to be tested according to their sensitivity and exposure, and set rules of engagement: test timing and how to reach key stakeholders.
  • Information gathering: The tester gathers as much information as possible about the targets: network architecture, operating systems and applications, and the organisation’s staff.
  • Vulnerability assessment: Automated scanning for known vulnerabilities, then analysis of results to identify the most serious.
  • Penetration testing: Attempting to exploit discovered vulnerabilities through techniques such as social engineering, password cracking and software exploits.
  • Analysis and reporting: A detailed report setting out the vulnerabilities found, their risks and recommended remediation actions.
  • Remediation: Applying updates, changing configurations and implementing new controls, then retesting to confirm.

From the Field

Penetration testing without written permission is a crime even when done by a well-meaning employee. Sign the rules of engagement before any test, and obtain your cloud provider’s approval where required.

2026 Update

AI systems now have their own testing: “AI red teaming” attempts prompt injection, training data extraction, guardrail bypass, and pushing an agent to use its tools harmfully. OWASP ranks these risks in a dedicated list for large language model applications.

By understanding and applying VAPT, creative organisations manage their risks proactively, so their output is both innovative and secure. This proactive approach is essential to protecting asset value and keeping client trust.

Lessons Learned

  1. 1Vulnerability management is a continuous cycle, not an annual scan.
  2. 2Vulnerability assessment measures; penetration testing proves impact.
  3. 3VAPT has six stages that start with scope and end with remediation and retesting.
  4. 4AI systems need a red team of their own.

Tip: use ← → to move between sections.