TechKnowSurge
VideoSecurityFree

Common Process Vulnerabilities

Security processes are meant to reduce human vulnerability, but poorly defined, undocumented, or outdated procedures introduce their own risks. Understanding where process gaps exist is the first step toward building consistent, reliable security controls.

Complete this video to capture a CTF flag worth 1 point.

About this video

Security processes are designed to address human vulnerability, but the procedures organizations put in place can carry their own weaknesses if not carefully developed and maintained. Process maturity exists on a spectrum: at one extreme, no formal procedures exist at all, making consistent security outcomes impossible; at the other, processes are so complex and time-consuming that they become obstacles to normal business operations. Most organizations fall somewhere in the middle, relying on underdeveloped procedures that are vaguely defined, inconsistently applied, or never formally documented. The goal is to establish controls that are well-defined, properly documented, kept up to date, and genuinely appropriate for the environment they are meant to protect. Even when solid processes exist, change itself introduces risk. Rolling out a new control — including a change management process — is itself a change, and every modification to systems or infrastructure carries potential for new vulnerabilities. Staffing transitions are a particularly high-risk category: promotions, role changes, new hires, and terminations can all create gaps if access rights and responsibilities are not managed carefully. A terminated employee whose account remains active, for example, represents a direct and preventable exposure. Large-scale organizational events compound these risks significantly. Mergers, acquisitions, and divestitures all disrupt established workflows, blur accountability, and create periods of operational uncertainty during which security controls may be inconsistently enforced or temporarily overlooked. A strong security program addresses these vulnerabilities through foundational security principles embedded in approved policy, supported by clear procedures, and monitored through tools such as encryption, logging, alerting, and SIEM platforms to ensure ongoing compliance and visibility.

What you'll learn

What's covered

Process Vulnerabilities

Key terms

Vulnerability
A weakness in a system, application, or process that can be exploited by a threat actor.
Security Policy
A formal document that defines an organization's security goals, rules, and responsibilities.
Configuration Management
The process of tracking and controlling changes to hardware, software, and documentation throughout a system's lifecycle.
Encryption
The process of converting readable data into an unreadable format using an algorithm and key to prevent unauthorized access.
Security Information and Event Management
SIEM
A system that aggregates and analyzes security event data from across an organization to detect and respond to threats.
Least Privilege
A security principle that grants users and systems only the minimum access rights needed to perform their functions.
Change Management
A structured process for requesting, reviewing, approving, and documenting changes to IT systems or organizational procedures. Change management reduces security risk by ensuring modifications are tested and authorized before deployment.
Staffing Transition
A change in personnel — such as hiring, termination, or role reassignment — that can introduce security vulnerabilities if access rights and procedures are not properly updated.
Merger
An organizational event in which two companies combine into one, often creating process gaps and security vulnerabilities during integration.
Acquisition
An organizational event in which one company purchases another, introducing security risks due to misaligned processes and systems.
Divestiture
An organizational event in which a company splits into two or more separate entities, creating security vulnerabilities as systems and processes are divided.

Topics

Process Vulnerabilities Security Procedures Organizational Change Management Security Governance Risk Management Security Controls

Transcript

Humans are susceptible to certain types of tricks and vulnerabilities, and so what we need to do is start putting processes into place to help guard against that. But those processes themselves can have vulnerabilities with them. So let's talk about some common process vulnerabilities.

Processes and Their Vulnerabilities

In each one of these areas, we see a lot of common vulnerabilities, but we compensate sometimes by putting a process into place. One example might be a change management process, a process in which people roll out changes within our networks and within our infrastructure. The problem is that this process in itself could have some vulnerabilities in it — things that we have to change over time and make sure that we get rid of these vulnerabilities.

The Spectrum of Processes

I find when it comes to processes and the vulnerabilities of those processes, there's really a spectrum. The spectrum starts on one side where nothing really exists in writing, or nothing's written down, or there's really no processes at all. So the process is non-existent. This is a problem, because not having any process at all, you can't really create any kind of consistency with it, and so that is problematic.

The other side of it is that you can create processes that are way too complex, that people don't really want to do, or time consuming, or become a hindrance to the business. What I find is that most people veer towards this side of it and just have some underdeveloped processes. Maybe they have some processes in place but they're just not really defined well and cause problems.

So our goal is to get things well defined, making sure that they're documented, making sure that they stay up to date, and making sure that they're the right process in place. These are the other things that I find: that things are not documented, or they're outdated, or they have the wrong process in place. They need to change the process. And so these are the things that create vulnerabilities with how we do things.

Creating Processes

So where do we create processes? There's a whole course on that. I have a whole course on how to create these processes and these policies. We need to follow basic security principles, and there's a lot of basic security principles that we need to implement. We put those basic security principles in as some sort of policies that people are going to approve of, that the execs and the management is going to approve of, so that way we can reinforce this. And then we create these procedures that we'll follow in order to implement these processes, and then people will follow those. And then we'll use encryption and logging and monitoring alerts and SIEM to monitor, to make sure all of our processes are being done accurately.

A lot of this involves rolling out and creating a full security program. Once again, I've got other full courses on how to do this. So I could get real in depth into any one of these components. In fact, any one of these components could be a course in themselves.

Change Itself Is a Risk

Now, we put the process into place to create change, but change itself comes with a large amount of risk. Anytime we change things, then that can be problematic and create vulnerabilities. It adds a level of risk, and so one thing we need to do is just be conscious of that, which is one reason why we have a change control process. But even rolling out a change control process is a change in itself.

Staffing Changes

A lot of vulnerabilities come into place when we see staffing changes — when somebody moves up in a position, or moves into a different position, or maybe somebody gets hired, or maybe somebody gets fired. During those times, we see that there's potential for a lot of vulnerabilities to happen. For instance, if somebody gets fired and then they're mad against the company, but their account wasn't properly turned off, that can be problematic.

Organizational Changes

Many vulnerabilities could happen also when there's big changes to the organization. In fact, a lot of vulnerabilities can occur during this time. For instance, mergers. A merger is when two companies come together and merge together. Or there could be some sort of acquisition. Acquisition is when one company buys another company. And then divestiture is when a company splits into two companies. Anytime that all of this happens, there's really a lot of turmoil in processes and the way we do things, and there's a lot of vulnerabilities that open up during this time.

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →