Business Simulation – Cyber Security
2,500 words
L7 Business Simulation – Cyber Security: Ethical Hacking and Vulnerability Assessment
This assessment is an individual cybersecurity portfolio based on a simulated business environment involving a fictional client, VulnTech Inc. Students take the role of a junior cybersecurity analyst and investigate vulnerabilities within a server deployed for the organisation’s legacy systems. The practical activities use the TryHackMe platform to simulate the web server environment and require students to apply ethical hacking techniques within an authorised scenario. The assessment focuses on the first three phases of ethical hacking: footprinting, scanning and enumeration, and gaining access. Students are required to gather information about the VulnTech server, including relevant details about its domain, IP range, network infrastructure, operating system, name servers, open ports and other technical information. They must provide evidence of the tools used, justify their selection, critically evaluate the methodology adopted and recommend appropriate mitigation strategies. The second task involves scanning and enumerating the server using information obtained during the footprinting stage. Students must identify potential vulnerabilities and provide evidence of the tools and methods used. The assessment requires students to critically evaluate their available options, explain the reasoning behind their decisions and recommend suitable strategies for mitigating identified risks. The third task requires students to gain access to the VulnTech server by exploiting one of the vulnerabilities identified during scanning and enumeration. Evidence of the tools and methodology must be provided, together with a critical evaluation of the approach, justification of decisions and recommendations for addressing the identified vulnerabilities. Students must also provide evidence of completing at least four different TryHackMe rooms or modules undertaken during the semester. The final component is a 1,500-word summary report reflecting on the key insights gained throughout the tasks. This report should consolidate the student's learning, discuss the main challenges and vulnerabilities identified, evaluate mitigation recommendations and critically examine the legal and ethical considerations associated with cybersecurity and ethical hacking practices. The assessment is designed to develop students' ability to analyse business and cybersecurity environments, identify organisational issues, evaluate alternative approaches, make informed management decisions and justify resource allocation. It also requires consideration of Environmental, Social and Governance (ESG) implications and the potential effect of cybersecurity practices on organisational perception and performance. The portfolio uses Harvard referencing, with appropriate academic and external sources cited throughout.
Read Model Answer →
Cyber Security / Internet of Things / Connected Systems
4,500 words
Security Evaluation for Connected Systems: IoT Strategy, Secure Design, Security Auditing and Organisational Change
This Security of Connected Systems assessment requires students to act as an external IoT Security and Scaling Strategist for a rapidly expanding Coventry-based technology startup specialising in connected devices and smart energy-monitoring systems. The client intends to scale its operations and enter new markets and therefore requires both organisational-change guidance and a comprehensive evaluation of its cybersecurity posture. 38f2fba9a933f212c9e46e8cc591cf2… The report combines business strategy with technical cybersecurity analysis. Students must review different secure design and development methodologies, compare their strengths and weaknesses, and recommend an appropriate approach for integrating security into the client's IoT software-development lifecycle. 38f2fba9a933f212c9e46e8cc591cf2… 38f2fba9a933f212c9e46e8cc591cf2… A major component of the assessment focuses on organisational change strategy. Students examine the internal and external factors driving organisational growth, develop a comprehensive strategy for achieving the client's business objectives, and explain how that strategy should be implemented and monitored. The report must also critically evaluate relevant change-management theories and models and address the complexities of leading and managing strategic transformation. This section carries 35% of the marks and is allocated approximately 2,000 words. 38f2fba9a933f212c9e46e8cc591cf2… The Security Audit Strategy section requires students to design a guide for auditing the client's connected system. Different approaches, including methodologies such as PTES and OWASP, should be compared and evaluated. Students must explain each stage of the selected testing methodology and justify why the individual steps are required. 38f2fba9a933f212c9e46e8cc591cf2… The final technical component applies these principles to an IoT vulnerability case study. Students research a real vulnerability in an IoT device, explain where the security flaw was introduced, identify weaknesses in the secure-design or audit process, assess the resulting security impact and propose appropriate corrective actions. 38f2fba9a933f212c9e46e8cc591cf2… Overall, the coursework integrates IoT cybersecurity, secure software development, security auditing, vulnerability analysis, organisational strategy and strategic change management. The marking scheme allocates 35% to organisational-change strategy, 20% each to secure design and development, security auditing and security recommendations, and 5% to report structure. 38f2fba9a933f212c9e46e8cc591cf2… Important: the brief states that it is for Coventry University Group students' own use and must not be passed to third parties or posted on a website. 38f2fba9a933f212c9e46e8cc591cf2… So use an original public summary like the one above, but do not upload the original brief itself.
Read Model Answer →