Pentesting & Vulnerability Management: Hack to Protect

Think like an attacker to defend like a pro. This track covers end-to-end offensive security: penetration testing, ethical hacking, and red teaming. It also explores how to turn findings into action with modern vulnerability management. You'll prioritize what matters using CVSS v4 (including the new Safety metric for OT and critical infrastructure), practise on deliberately vulnerable applications, and explore emerging threats like quantum attacks on cryptography.

Pentesting, Vulnerability Management & Forensics

What you can learn:

  • Penetration testing & ethical hacking: find and exploit vulnerabilities before attackers do
  • Vulnerability management & prioritization: rank and remediate risk with CVSS v4
  • OT & critical infrastructure security: assess risk where safety, not just data, is at stake
  • Hands-on hacking labs: practise on deliberately vulnerable apps (e.g. WebGoat)
  • Threat modeling: map attack surface and trust boundaries in real systems
  • Emerging threats: quantum computing’s impact on cryptography
  • Digital forensics & incident response: investigate and respond after a breach

Track Speakers Munich 2026

Track Speakers Berlin 2026

Track Program Munich 2026

Track Program Berlin 2026

Track Sessions Berlin 2026

Track Sessions Berlin 2026

View all sessions

Track Sessions Munich 2026

Track Sessions Munich 2026

View all sessions

FAQ

What is penetration testing?

Penetration testing is authorized, simulated hacking of a system to find and demonstrate exploitable vulnerabilities before real attackers do.

What's the difference between penetration testing and vulnerability scanning?

Scanning automatically flags known weaknesses while penetration testing goes further: a human tester exploits and chains vulnerabilities to show their real-world impact.

What is CVSS v4?

CVSS v4 is the latest Common Vulnerability Scoring System. It refines severity scoring and adds a Safety metric that is important for OT and critical infrastructure where incidents can affect human safety.

How do you prioritize which vulnerabilities to fix first?

Combine severity (CVSS) with exploitability and business/asset context, so you fix what's genuinely risky rather than everything at once.

What is red teaming?

Red teaming is a goal-driven, adversarial exercise that emulates real attackers across people, process, and technology to test how well an organization detects attacks and responds to them.

Enjoying the content?

Get the most out of IT Security Summit by becoming a free community member — curated resources, weekly newsletter, and member-only perks.

Weekly
Articles + tutorials

The reads you'd find if you had time

2× / mo
Live webinars

Experts you can actually ask

Monthly
Magazine + whitepapers

Deep dives worth your weekend

On-demand
Recordings + courses

Past conferences, ready when you are

AI-Powered Security
Harness AI for security automation, threat detection, and integrating AI-driven solutions into DevSecOps.

Cloud, API Security & Identity
Safeguard your cloud environments, APIs, and identities with advanced strategies.

DevSecOps
Integrate security into your DevOps processes with precision.

Pentesting, Vulnerability Management & Forensics
Advance your offensive security skills with cutting-edge penetration testing techniques.

Secure Coding & Software Development Lifecycle
Create secure software from the ground up by mastering secure coding practices and embedding security throughout the Software Development Lifecycle (SDLC).