Before starting a Vulnerability Assessment and Penetration Testing engagement, one of the most important questions is not only “What should we test?” but “What could create real business risk if it were compromised?”
This is where scoping becomes critical.
A digital assets VAPT assessment should cover more than the company website or the most visible application. Modern businesses rely on websites, APIs, cloud platforms, email systems, remote access tools, employee devices, databases, backups, identity platforms, and third-party integrations. Attackers could use any exposed, misconfigured, outdated, or poorly protected asset as an entry point.
The goal of this guide is to help organisations decide which digital assets should be included in a VAPT assessment, how to prioritise them, and what information should be shared with the testing provider before work begins. If you are still new to VAPT, refer to our guide on ‘What is VAPT’. You may also want to review the difference between vulnerability assessment and penetration testing for better understanding.
Why Asset Selection Matters in VAPT? The quality of a VAPT assessment depends heavily on the quality of the scope. If important assets are excluded, the final report may give a false sense of security. A company may test its main website but overlook hidden risks such as old subdomains, exposed cloud storage, mobile APIs, VPN portals, weak admin panels, overexposed databases, or inactive privileged accounts.
This is why many organisations frequently remove inactive accounts to build cyber resilience. These assets may not appear important at first glance, but they can create serious security risk. A strong VAPT scope helps ensure the assessment reflects how the business actually operates, not just what is easiest to test.
Digital Assets That Should Commonly Be Included
Before deciding what to include, the organisation should create a simple asset inventory covering key systems, owners, business purpose, URLs or IPs, exposure level, sensitive data, authentication requirements, environment type, third-party dependencies, and potential business impact. This inventory helps define the VAPT scope and shows the provider which assets need deeper testing.
1. Websites and Web Applications
Public websites, customer portals, admin panels, dashboards, and business applications should usually be considered for VAPT.
These assets may contain login forms, payment flows, customer records, file uploads, contact forms, search functions, or integrations with internal systems. Testing can help identify weaknesses such as broken authentication, insecure forms, access control flaws, session issues, injection vulnerabilities, exposed files, or insecure configuration.
Web applications are especially important when they are internet-facing or handle sensitive business or customer data.
2. APIs
APIs are often overlooked because they are less visible than websites, but they can expose sensitive data or business functions. A VAPT scope should include APIs used by:
- web applications
- mobile apps
- partner integrations
- internal systems
- customer platforms
- automation tools
API testing should consider authentication, authorisation, rate limiting, excessive data exposure, insecure endpoints, weak token handling, and whether users can access actions or records they should not be able to access. If the business has a mobile application, the API behind it should almost always be reviewed.
3. Cloud Environments
Cloud platforms should be included when they host applications, data, workloads, storage, identity services, or business-critical infrastructure. Relevant assets may include storage buckets, virtual machines, containers, serverless functions, databases, IAM users and roles, security groups, firewalls, load balancers, backups, and logging settings. During testing, the focus should be on misconfiguration, public exposure, excessive permissions, insecure storage, weak access controls, and lack of monitoring.
4. Remote Access Systems
Remote access systems are high-priority assets because they can provide direct entry into internal environments.
These may include:
- VPN portals
- remote desktop services
- zero-trust access platforms
- privileged access tools
- remote administration panels
- employee access gateways
Testing should review authentication controls, MFA enforcement, exposed services, account lockout behaviour, access restrictions, logging, and whether remote access provides broader internal access than intended.
5. Identity and Access Management Systems
Identity systems are central to modern security. One weak identity control can affect multiple applications and services.
Assets in this category may include:
- Single Sign-On platforms
- cloud IAM
- Active Directory
- user directories
- privileged accounts
- service accounts
- inactive accounts
- shared accounts
- access policies
- MFA settings
Identity assets should be included when the organisation uses centralised login, cloud platforms, remote access, admin accounts, or role-based permissions. Testing should identify excessive privileges, weak authentication, poor account lifecycle management, and risky trust relationships.
6. Internal Networks and Infrastructure
Internal systems may not be exposed to the internet, but they still matter. If an attacker gains access through phishing, stolen credentials, malware, or a vulnerable endpoint, internal weaknesses can allow wider compromise.
Internal VAPT scope may include network segments, firewalls, routers and switches, internal servers, file shares, directory services, databases, workstations, backup servers, and monitoring systems.
The purpose is to understand whether an attacker could move across the environment, access sensitive systems, escalate privileges, or disrupt operations after gaining an initial foothold.
7. Endpoints and Employee Devices
Employee laptops and workstations can become entry points into the business environment.
Endpoint-related testing may review:
- missing patches
- weak device configuration
- local administrator rights
- endpoint protection status
- disk encryption
- insecure software
- exposed services
- weak remote access settings
Endpoints are especially important for organisations with remote or hybrid teams, bring-your-own-device policies, or staff who access sensitive systems from laptops.
8. Databases and Data Stores
Any system that stores sensitive information should be considered for VAPT scoping.
This may include:
- customer databases
- financial records
- employee records
- intellectual property
- file repositories
- data warehouses
- backups
- logs
- CRM data
- support ticket systems
The assessment should consider whether data is properly protected, whether access is restricted, whether storage is exposed, and whether users or systems have more access than they need.
9. Mobile Applications
If customers/employees/partners use mobile apps to access business services, it is important to run a mobile VAPT which must include:
- insecure local storage
- weak authentication
- insecure API communication
- hardcoded secrets
- weak session handling
- insufficient certificate validation
- excessive app permissions
- insecure business logic
The mobile app itself and the backend APIs should usually be tested together because many mobile security risks exist at the API level.
10. Third-Party Integrations
Lastly, many businesses rely on third-party tools for payments, marketing, analytics, customer support, file sharing, communication, and automation.
Third-party integrations should be reviewed when they connect to sensitive systems or data.
The VAPT scope may need to consider:
- API keys
- webhooks
- OAuth permissions
- data sharing
- integration accounts
- third-party admin access
- exposed tokens
- excessive permissions
Even if the third-party platform itself is not tested directly, the way the business uses and integrates with it should be assessed.
Risk-Based Prioritisation: What to Test First
Not every asset needs the same level of testing. A risk-based approach helps organisations prioritise high-value and high-exposure assets first, such as internet-facing systems, customer applications, sensitive APIs, cloud environments, remote access, identity platforms, payment systems, confidential databases, admin portals, and business-critical infrastructure.
Medium-priority assets may include internal applications, employee systems, staging environments, reporting tools, file shares, development systems, third-party integrations, and monitoring platforms, depending on exposure and business importance.
Lower-priority assets, such as isolated test systems, low-value informational pages, disconnected retired systems, or internal tools with no sensitive data, may be reviewed less frequently. However, low priority should not mean ignored, because forgotten systems can become serious risks if they remain connected, unpatched, or unmanaged.
Many VAPT scopes miss assets that are no longer clearly owned or actively maintained, such as old subdomains, staging environments, backup servers, cloud snapshots, forgotten virtual machines, test databases, admin panels, file-sharing platforms, DNS records, exposed documentation portals, legacy applications, service accounts, inactive users, shared mailboxes, and unmanaged employee devices. These should be reviewed during scoping because they can create hidden exposure.
What Information Should Be Shared With the VAPT Provider?
Clear information helps the provider test safely and effectively. Before testing begins, the organisation should prepare a scope document containing:
- list of assets to be tested
- URLs, IP addresses, domains, or cloud account details
- application roles and test accounts
- API documentation, where available
- testing restrictions
- business-critical systems
- sensitive periods when testing should be avoided
- emergency contact details
- exploitation permissions
- social engineering exclusions
- whether testing is black-box, grey-box, or white-box
- required reporting format
- retesting expectations
This prevents confusion and allows the assessment to focus on meaningful risk rather than basic discovery alone.
Sample Digital Assets VAPT Scope
A practical VAPT scope for a growing business may look like this:
|
Asset Category |
Example Assets | Priority | Reason for Inclusion |
|
Website |
Main company website, customer portal |
High |
Public-facing and used by customers |
|
API |
Mobile app API, partner API |
High |
Handles login, data access, and business functions |
|
Cloud |
Storage, virtual machines, IAM roles |
High |
Stores sensitive files and supports production systems |
| Remote Access | VPN or remote access gateway |
High |
Provides access to internal systems |
|
Identity |
SSO, privileged accounts, inactive users |
High |
Controls access across multiple services |
|
Internal Network |
File servers, internal applications |
Medium |
Important if attacker gains internal access |
|
Endpoints |
Employee laptops and admin workstations |
Medium |
Common entry point for compromise |
|
Data Stores |
Databases, backups, file repositories |
High |
Contains confidential business or customer data |
| Third-Party Integrations | Payment, CRM, support tools | Medium |
May expose data through connected services |
Common VAPT Scoping Mistakes
A VAPT assessment becomes less useful when the scope is too narrow, unclear, or based only on assumptions.
Common mistakes include:
- testing only the main website
- excluding APIs used by mobile or web applications
- ignoring cloud configuration
- leaving identity systems out of scope
- forgetting old subdomains and test environments
- excluding internal systems without considering lateral movement risk
- failing to provide test accounts
- not identifying sensitive data stores
- treating all assets as equally important
- not defining what testing methods are allowed
- failing to include retesting after remediation
Good scoping avoids these problems by connecting technical assets to business impact.
Final Thoughts
In conclusion, a VAPT assessment is most effective when the scope reflects the real technology environment of the business. Websites and applications matter, but they are only part of the picture. APIs, cloud platforms, identity systems, endpoints, remote access tools, databases, backups, and third-party integrations can all create risk if they are overlooked. For organisations planning a VAPT assessment, the best starting point is simple: know what you own, understand what matters most, and make sure the assessment covers the assets that could create the greatest business impact if compromised.
If you are looking for a security review, explore our VAPT services to understand how Aegixis can help make your more secure.