GlossaryAttack surface and pentesting

Vulnerability

Short answer

A vulnerability is a weakness in a system, application, configuration or process that an attacker could exploit to gain access, steal data or disrupt operations. Managing vulnerabilities means finding them, prioritising them by real risk and fixing them before they are exploited.

Types of vulnerability

Vulnerabilities can be software flaws (a bug in code that allows unauthorised access), misconfigurations (a storage bucket left public, a default password), missing patches, weak authentication, or process and human weaknesses that attackers exploit through social engineering.

Vulnerability, threat and risk

A vulnerability is a weakness. A threat is someone or something that could exploit it. Risk is the combination: how likely the weakness is to be exploited and how much damage it would cause. A vulnerability with no realistic threat carries little risk.

Vulnerability management

Managing vulnerabilities is a continuous cycle: discover assets, scan for weaknesses, prioritise by real risk, fix or mitigate, and verify the fix. Scanning, attack surface management and pentesting all feed this cycle.

Where it shows up in compliance

ISO 27001 (Annex A 8.8), the ENS, NIS2 and SOC 2 all require organisations to manage technical vulnerabilities and to fix them within defined timeframes.

Related terms

Keep reading on this topic

External and internal attack surface management, cloud configuration and application security: finding exposures and prioritising them by real risk.

Go to the topic hub