Vulnerability Assessment and Penetration Testing for Organisations

A structured, applied course in vulnerability assessment and penetration testing — designed to be used the week you return.

📍 Abu Dhabi🗓️ 5 training days📚 4 modules🎓 Accredited certificate
5intensive training days
4scientific modules
8training sessions
32detailed points

Course Overview

Guard force performance on vulnerability assessment and penetration testing reflects supervision, not instruction. Most security failures involving penetration testing exploit a process gap rather than a technical one. Content is organised around the decisions practitioners actually face in the corporate security practice discipline, not around theory headings. Participants come from operational and oversight roles, and both perspectives on vulnerability assessment and penetration testing are used deliberately. The result is the confidence to make and defend decisions about this strand of corporate security practice under scrutiny. The professional literature on penetration testing converges on a small set of controls that reliably work. Buying a tool rarely fixes vulnerability assessment and penetration testing; the underlying capability has to be built internally first. The teaching approach is deliberately practical: participants build a security procedure for penetration testing as they go. It ends with a prioritised list of changes to the practice within corporate security practice that the participant is prepared to defend internally.

Expected Learning Outcomes

01

Address insider risk and personnel vetting relevant to vulnerability assessment and penetration testing.

02

Design layered controls for penetration testing across deterrence, detection, delay and response.

03

Identify vulnerabilities in vulnerability assessment and penetration testing and rank them by consequence.

04

Build the security operating procedures governing penetration testing.

05

Set acceptance criteria for vulnerability assessment and penetration testing before work begins rather than after.

06

Agree the first three actions on penetration testing that will be taken on returning to work.

07

Set the minimum documentation for vulnerability assessment and penetration testing that is genuinely necessary, and stop there.

Who Should Attend

01

Members of committees that take decisions affecting vulnerability assessment and penetration testing.

02

Guard force supervisors delivering penetration testing.

03

Information security staff whose remit overlaps vulnerability assessment and penetration testing.

04

Security managers and officers responsible for penetration testing.

05

Executives responsible for approving investment in vulnerability assessment and penetration testing.

06

Coordinators responsible for keeping records and documentation of penetration testing current.

Course Modules

01

Vulnerability assessment and penetration testing: investigation, evidence and reporting

2 sessions · 8 points

Session 1Finding the vulnerability in vulnerability assessment and penetration testing an adversary would use

  • Identify the data already collected that bears on vulnerability assessment and penetration testing.
  • Check guard force instructions for penetration testing are current and understood.
  • Reduce the variation in how vulnerability assessment and penetration testing is carried out between teams.
  • Set out how exceptions to penetration testing are requested and approved.

Session 2The hard cases in penetration testing and how to reason about them

  • Identify vulnerabilities in vulnerability assessment and penetration testing and rank them by consequence, not ease of fix.
  • Supervise and spot-check performance on penetration testing rather than relying on reports.
  • Confirm that contractual obligations around vulnerability assessment and penetration testing are understood.
  • Agree what will be standardised in penetration testing and what will not.
02

Penetration testing: incident response and escalation

2 sessions · 8 points

Session 1Access control on penetration testing that people do not bypass

  • Review vulnerability assessment and penetration testing after every incident, exercise or change in threat.
  • Check that penetration testing still works when volumes rise unexpectedly.
  • Identify single points of dependency in vulnerability assessment and penetration testing and reduce them.
  • Coordinate arrangements for penetration testing with civil defence and police in advance.

Session 2Moving penetration testing from approval to execution

  • Protect sensitive information relating to vulnerability assessment and penetration testing from casual disclosure.
  • Set the review interval for penetration testing and who attends.
  • Assess insider risk in roles with privileged access to vulnerability assessment and penetration testing.
  • Confirm recorded material from penetration testing is retained long enough to be useful.
03

Penetration testing: threat assessment and intelligence

2 sessions · 8 points

Session 1The first fifteen minutes of an incident involving penetration testing

  • Map the handovers in vulnerability assessment and penetration testing between functions and secure them.
  • Name a single owner for each element of penetration testing.
  • Review surveillance coverage for vulnerability assessment and penetration testing against likely approach routes.
  • Benchmark the organisation's penetration testing against comparable operations.

Session 2Surveillance on vulnerability assessment and penetration testing that supports an investigation later

  • Confirm that those complying with vulnerability assessment and penetration testing understand why it exists.
  • Set escalation criteria and out-of-hours contacts for penetration testing.
  • Verify identity checks applied at entry points relevant to vulnerability assessment and penetration testing.
  • Set out the decisions in penetration testing that require sign-off and by whom.
04

Penetration testing: insider risk, vetting and personnel security

2 sessions · 8 points

Session 1Making the investment case for penetration testing

  • Rank the weaknesses in vulnerability assessment and penetration testing by consequence rather than by ease of fixing.
  • Identify where judgement in penetration testing is legitimate and where it is not.
  • Prepare the response for the most likely failure in vulnerability assessment and penetration testing.
  • Confirm vetting standards applied to staff and contractors in penetration testing.

Session 2Escalation and decision rights in penetration testing

  • Establish evidence handling and chain of custody for vulnerability assessment and penetration testing.
  • Exercise the plan for penetration testing under realistic conditions and record failures.
  • Confirm access control on vulnerability assessment and penetration testing cannot be routinely bypassed.
  • Define the first response actions for an incident involving penetration testing.

Choose the package that suits you

Silver Package

At least 3 people

USD1,250
  • Workshop or Program Participation
  • Airport Transfers
  • Customized Badge
  • Expert Mentorship (Private Sessions)
  • Supervision & Secretarial Services
  • Accredited Certificate of Participation
  • Complete Training Kit
  • Coffee Break
  • Closing Ceremony

Gold Package

At least 3 people

USD1,850
  • 5-night stay in a 5-star hotel
  • Workshop or Program Participation
  • Airport Transfers
  • Customized Badge
  • Expert Mentorship (Private Sessions)
  • Supervision & Secretarial Services
  • Accredited Certificate of Participation
  • Complete Training Kit
  • Coffee Break
  • Closing Ceremony

Complete your registration

We will contact you within one business day to confirm.