Computer skills from scratch·Where this leads·Lesson 125 of 180
The vulnerability assessment: checking the fence
Ellis Dennis GrahamFounder, Cyber Elias Academy 2026-04-17 3 min
A vulnerability assessment is the systematic walk around your own walls before thieves do it for you — find the weak boards, rank them, fix the loudest first. Here is the honest method.
A vulnerability is a weakness in a wall that still stands: the loose board in the fence, the window the bar removed, the lock that turns with any key of its brand. Every organisation is such a compound, and its walls — computers, programs, doors, people — carry weaknesses nobody has counted. A vulnerability assessment is the disciplined count: walk your own fence deliberately, in daylight, with a list, and find what a thief would find at night. Not paranoia. Maintenance. The same instinct as checking the generator before the wedding, and it answers the question every owner should be able to answer: where exactly are we weak?
The walk has a shape. First, count what you own — every machine, app, and account; you cannot check a fence you have not listed, and the forgotten door is every compound's favourite entrance. Then scan: tools run against the list, knocking on known weaknesses the way a mechanic's diagnostic machine queries an engine — thousands of known weaknesses, checked in minutes. Then the human pass, because tools miss what eyes catch: the password on a sticky note, the software that stopped receiving updates, the server room held shut with tape. The result is a report — not a shaming, an inventory: this weakness, here, this severe, this loud, fix it this way.

Ranking the holes: not all silence is equal
A compound always has several weaknesses at once; money and hours are finite; so the report ranks. Severity scoring — the industry's CVSS numbers, zero to ten — is triage at a clinic: the bleeding patient first, the stubborn cough after. A weakness that lets a stranger in without any key outranks one that needs the janitor's help, an open office, and good luck. The discipline the good assessors bring is honesty about exposure: a hole in the fence facing the market street is a different animal from the same hole facing the lagoon. Fix the loudest, then the next, then the next — and re-scan, because walls do not stay mended by one speech.
Two words people confuse, cleared now: the assessment is the inspection — systematic, listed, non-destructive; a penetration test goes further and hires the lockpicker — one weakness, chosen with permission, exploited to prove how far it opens. Inspection first, lockpicker second, always. And for the small businesses reading this over a shoulder: the walk scales down beautifully. List your doors — the phones, the laptops, the email, that one app the whole shop runs on. Update everything the update lesson taught you to update. Turn on the second lock everywhere it exists. Change the defaults the installer left. You have just done the small business version, and most of your competitors have not.

- List what you own — machines, apps, accounts — before you scan anything. The unlisted door is the common door.
- Scan with a reputable tool, then walk with your own eyes. Tools count, humans understand.
- Rank by severity and exposure. Fix the bleeding first; keep the receipts of every repair.
- Re-walk the fence on a calendar, not on a mood. Walls drift; the walk is maintenance, not an event.
The fence, the room, the ledger
See how the profession knits: the assessment finds the weak boards; zero trust builds inner doors so one board cannot cost the building; the SOC and its SIEM watch the fence between walks, because thieves do not wait for reports. Nothing mystical anywhere — just owners who count their own weaknesses before somebody else does it for them, at night, without permission. The next lesson steps back from the compound to the roads that connect every compound: the grammar the whole internet speaks.


