Skip to content
Review Open access

The Role of Penetration Testing in Identifying Cybersecurity Vulnerabilities

Sep 2026 · International Journal of Digital Research · 0 citations

TL;DR

It is found that regular, authorized penetration testing can support vulnerability identification, risk assessment, and the implementation of appropriate remediation measures, and the study concludes that regular, authorized penetration testing can support vulnerability identification, risk assessment, and the implementation of appropriate remediation measures.

Abstract

The rapid development of digital technologies has increased both the efficiency of information systems and the complexity of cybersecurity threats. As organizations increasingly depend on digital infrastructures, identifying vulnerabilities before they can be exploited has become an essential part of cybersecurity management. This study examines the role of penetration testing in identifying security weaknesses and evaluates several commonly used penetration-testing approaches, frameworks, and techniques. The paper combines a review of established approaches, including OSSTMM, OWASP, PTES, and NIST, with a practical penetration-testing demonstration using Nmap. The experimental scan identified several accessible network services, including Telnet (port 23), DNS (port 53), and HTTP (port 80), while FTP (port 21) and SSH (port 22) were found to be filtered. The scan also provided information about the target device and its operating environment. These findings demonstrate how penetration testing can reveal potentially exposed services and provide useful information for assessing security risks and improving system protection. The study concludes that regular, authorized penetration testing can support vulnerability identification, risk assessment, and the implementation of appropriate remediation measures. However, the practical demonstration is limited to a single target environment and should therefore be interpreted as an illustrative case rather than a comprehensive security assessment.

Read PDF

Similar papers

Review Open access Sep 2026

Cybersecurity In Fintech Ecosystems: A Systematic Review of Threats and Security Strategies

FinTech's tremendous expansion has revolutionized the financial industry by making services like online lending, mobile banking and digital payments possible. Financial systems are becoming more vulnerable to cybersecurity risks, data breaches and financial fraud as a result of this digital transition. Strong cybersecu...

Vedankita Mohod, R. Jugele · 0 citations
Open access Sep 2026

An Integrated Framework to Enhance Penetration Testing for ICT Market Applications

The increasing complexity of Information and Communication Technology (ICT) systems has created significant challenges for cybersecurity professionals in ensuring comprehensive security assessments. Traditional penetration testing methodologies (e.g., PTES, OWASP WSTG, NIST SP 800-115) often lack systematic integration...

Abdulrahman Mohammed Abdulrahman Ahmed Abutaleb · 0 citations
Open access Aug 2026

Comparative Analysis of ICS Cybersecurity Testbeds Using a Purdue-Aligned Approach

Industrial Control Systems (ICSs), which underpin communications and operations in industrial environments in general and in critical infrastructures in particular, are targeted by malicious actors for diverse reasons. To strengthen their resilience against cybersecurity attacks, testbeds play a fundamental role in sup...

Jovan Andrés Guillén-Mass, Roberto Magán-Carrión · 0 citations
Open access 2026

Examining the Impact of Cybersecurity Investment on Organizational Performance in Bosaso, Somalia

In the 20th century, the increasing reliance on technology by organizations has led to a significant rise in cyber threats, including malware, ransom ware, and phishing attacks. These threats pose serious challenges to business success, jeopardizing the availability, integrity, and confidentiality of organizational ass...

Mohamed Abdirisak Burale, Aedah Binti Abd Rahman, Prof, Dr. Syed Sajjad Hussain Rizvi · 0 citations
Preprint Aug 2026

A Roadmap to Available ICS Datasets and Testbeds for Cybersecurity Research

Industrial Control Systems (ICS) are the backbone of many critical infrastructure sectors; however, their growing level of connectivity, long lifespan and integration with the Information Technology (IT) environment introduces numerous cybersecurity challenges. The merging of Operational Technology (OT) and IT along wi...

Ebtesam S. Alqahtani, Mohammad Hammoudeh · 0 citations
Open access Aug 2026

Comparative Effectiveness of OWASP WSTG and Top Ten in Web Security Audits

The findings indicate that while the OWASP Top Ten serves as a strategic reference, the WSTG is superior as a primary technical auditing framework, which enhances audit consistency, precision, and efficiency in evaluating modern web environments.

Moch Wahyu Sampurno Utomo, H. Wahanani, Achmad Junaidi · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.