Ethical Penetration Testing and Security Vulnerability Assessment

A practical programme in ethical penetration testing for professionals who are accountable for results, not just awareness.

📍 Tunis🗓️ 5 training days📚 4 modules🎓 Accredited certificate
5intensive training days
4scientific modules
8training sessions
32detailed points

Course Overview

Most organisations now hold more data about ethical penetration testing than they can actually act on. The constraint on this strand of digital and data-driven work is rarely the model or the platform — it is the data and the operating discipline behind it. Plans for this part of digital and data-driven work often fail at the handover point between functions. Benchmarking exercises repeatedly place ethical penetration testing among the areas with the widest performance spread. The outcome is a practitioner who can hold a position on the digital and data-driven work capability and revise it on evidence. The material serves both public bodies and commercial organisations dealing with the practice within digital and data-driven work. It concentrates on the parts of ethical penetration testing that determine outcomes and treats the rest proportionately. Discussion is anchored to worked examples of this part of digital and data-driven work rather than to abstract argument. The programme closes with an action plan for this strand of digital and data-driven work that each participant writes for their own organisation.

Expected Learning Outcomes

01

Build a register of the risks attaching to ethical penetration testing and keep it current.

02

Establish version control and rollback for every component of ethical penetration testing that reaches production.

03

Draw practical lessons from failures in ethical penetration testing without assigning blame that suppresses reporting.

04

Communicate the purpose of ethical penetration testing to those who have to comply with it.

05

Design the integration points between ethical penetration testing and the systems already in production.

06

Agree the retirement plan for the legacy process ethical penetration testing replaces.

07

Set retention, lineage and deletion rules for the data flowing through ethical penetration testing.

Who Should Attend

01

Operations staff who encounter the consequences of ethical penetration testing directly.

02

Information security officers reviewing the exposure created by ethical penetration testing.

03

Programme managers coordinating delivery of ethical penetration testing across teams.

04

Business analysts translating requirements for ethical penetration testing.

05

Members of committees that take decisions affecting ethical penetration testing.

06

Technology and digital transformation managers leading ethical penetration testing.

Course Modules

01

Ethical penetration testing: monitoring, drift and operational ownership

2 sessions · 8 points

Session 1Where ethical penetration testing touches systems nobody wants to change

  • Estimate compute and licensing cost for ethical penetration testing at expected and at peak load.
  • Review whether ethical penetration testing is aligned with the objectives of the transformation programme.
  • Identify every system ethical penetration testing must read from or write to.
  • Identify the data already collected that bears on ethical penetration testing.

Session 2The governance ethical penetration testing needs and the governance it does not

  • Test ethical penetration testing against edge cases drawn from real historical records.
  • Agree who is on call for ethical penetration testing outside working hours.
  • Verify that ethical penetration testing still performs when input volume doubles unexpectedly.
  • Assess the regulatory obligations ethical penetration testing triggers in each jurisdiction.
02

Ethical penetration testing: measuring benefit and retiring what it replaces

2 sessions · 8 points

Session 1Closing out ethical penetration testing and capturing what was learned

  • Rehearse the briefing on ethical penetration testing that would follow an incident.
  • Map the handovers in ethical penetration testing between functions and secure them.
  • Benchmark the organisation's ethical penetration testing against comparable operations.
  • Distinguish symptoms from causes when ethical penetration testing underperforms.

Session 2Reading the true cost of running ethical penetration testing

  • Establish the boundary of ethical penetration testing and record what sits outside it.
  • Close out actions on ethical penetration testing rather than leaving them open indefinitely.
  • Write down the assumptions underpinning the approach to ethical penetration testing.
  • Plan how ethical penetration testing is versioned and how a bad release is rolled back.
03

Ethical penetration testing: governance, ethics and explainability

2 sessions · 8 points

Session 1What to measure in ethical penetration testing and what to ignore

  • Identify single points of dependency in ethical penetration testing and reduce them.
  • Measure the current quality of the data feeding ethical penetration testing before assuming it is usable.
  • Confirm that those complying with ethical penetration testing understand why it exists.
  • Define the service level ethical penetration testing must meet and what happens when it is missed.

Session 2Reading the current state of ethical penetration testing honestly

  • Specify the fallback path when ethical penetration testing is unavailable.
  • Classify the data in ethical penetration testing and apply access controls that match the classification.
  • Decide which legacy process ethical penetration testing retires, and set the date.
  • Define the exit route from the supplier supporting ethical penetration testing.
04

Ethical penetration testing: from pilot to production

2 sessions · 8 points

Session 1Proving ethical penetration testing paid for itself

  • List the data sources ethical penetration testing consumes and confirm each has a named owner.
  • Rank the weaknesses in ethical penetration testing by consequence rather than by ease of fixing.
  • Anticipate the objections ethical penetration testing will raise and prepare the answers.
  • Set the metrics that will show whether ethical penetration testing is drifting from its intended behaviour.

Session 2Making ethical penetration testing secure without making it unusable

  • Record the reasoning behind each architectural choice in ethical penetration testing.
  • Plan the sequence in which improvements to ethical penetration testing will be introduced.
  • Prepare the response for the most likely failure in ethical penetration testing.
  • Remove steps in ethical penetration testing that add effort without adding assurance.

Choose the package that suits you

Silver Package

At least 3 people

USD1,250
  • Workshop or Program Participation
  • Airport Transfers
  • Customized Badge
  • Expert Mentorship (Private Sessions)
  • Supervision & Secretarial Services
  • Accredited Certificate of Participation
  • Complete Training Kit
  • Coffee Break
  • Closing Ceremony

Gold Package

At least 3 people

USD1,850
  • 5-night stay in a 5-star hotel
  • Workshop or Program Participation
  • Airport Transfers
  • Customized Badge
  • Expert Mentorship (Private Sessions)
  • Supervision & Secretarial Services
  • Accredited Certificate of Participation
  • Complete Training Kit
  • Coffee Break
  • Closing Ceremony

Complete your registration

We will contact you within one business day to confirm.