Contacts
Follow us:
Get an Estimate
Close

Penetration Testing in Australia: Web, Network, Internal & External Methods Explained

penetration testing

Penetration Testing in Australia: Web, Network, Internal & External Methods Explained

18 minutes read

Cyber threats are no longer something Australian businesses can afford to think about only after an incident occurs. A compromised website, exposed server, stolen credentials, vulnerable API, or poorly protected internal network can quickly become a business problem involving financial losses, operational disruption, reputational damage, and potentially sensitive customer information. That is why penetration testing in Australia has become an important part of a modern cybersecurity strategy. Instead of simply asking whether a vulnerability exists, penetration testing asks a more practical question: Could a real attacker actually use this weakness to gain access, move through the environment, or reach something valuable? The Australian Signals Directorate’s current Information Security Manual (ISM), updated in June 2026, distinguishes penetration testing from broader vulnerability identification by describing it as an activity designed to test real-world scenarios against specific objectives. For businesses in Melbourne, Sydney, Brisbane, Perth, Adelaide and other Australian locations, that distinction matters because a security report full of technical findings is useful only when those findings help an organisation understand and reduce genuine risk. This guide explains major penetration testing methods, including web application, network, internal, and external testing, and covers how Australian organisations can approach testing, what a professional engagement should include, and how to choose the right testing strategy for a particular business environment.

What Is Penetration Testing and Why Does It Matter in Australia?

Penetration testing, often called pen testing, is an authorised security assessment in which skilled security professionals simulate realistic attack techniques against a defined system, application, network or environment. The objective is not simply to collect a long list of vulnerabilities. Instead, a good penetration test aims to understand how weaknesses can be chained together and what an attacker could realistically accomplish by exploiting them. Think of it like hiring someone to test the locks, doors, windows and security procedures of a building before a burglar does it for you. A vulnerability scanner might tell you that a particular door has a weak lock; a penetration tester goes further by asking whether that lock can actually be bypassed, what can be reached after entry, and whether the compromise can lead to something more serious. This approach is particularly relevant for Australian organisations because the current ASD ISM recommends security assessment activities that identify vulnerabilities, analyse their potential impact, and implement mitigations based on risk, effectiveness, and cost. Penetration testing therefore works best as part of a broader cybersecurity program rather than as a one-time technical exercise performed to obtain a report.

For an Australian business, the potential value extends beyond discovering a technical flaw. A successful test can reveal weaknesses in authentication, access controls, application logic, network segmentation, exposed services, administrative privileges, security configurations and other areas that automated tools may not fully understand. It can also help an organisation validate whether security controls actually work when confronted with realistic attack paths. This is important because cybersecurity is rarely about one isolated vulnerability. An attacker may combine several small weaknesses, such as an exposed service, a stolen credential and excessive internal privileges, to create a much larger compromise. A professional penetration testing company in Australia should therefore look at the environment as an interconnected system rather than treating every vulnerability as an independent checkbox. For Melbourne businesses in particular, working with a provider that understands the local business environment while delivering testing across Australia can make communication, scoping, and remediation easier.

Melbourne businesses

Penetration Testing vs Vulnerability Assessment

A vulnerability assessment and a penetration test are related, but not interchangeable. A vulnerability assessment generally focuses on identifying known weaknesses across systems, applications, devices, or infrastructure. Automated scanners can be extremely useful for this purpose because they can inspect large environments efficiently and repeatedly. Penetration testing takes a different approach, using manual analysis, security expertise, and controlled exploitation to determine whether selected weaknesses can be combined or exploited in realistic scenarios. The current ASD ISM makes this distinction explicit: vulnerability identification aims to find weaknesses, while a penetration test tests real-world scenarios against a specific goal, such as compromising critical components or data. That difference is crucial when deciding what your business actually needs.

Vulnerability AssessmentFind known weaknessesAutomated scanning and analysisContinuous vulnerability managementPenetration TestingValidate exploitable security weaknessesManual testing plus controlled exploitationMeasuring real-world attack riskSecurity AuditEvaluate controls against defined requirementsDocumentation and control reviewGovernance and assuranceSecurity ReviewExamine a specific technology or processTechnical and procedural analysisTargeted security improvementA business should not choose one and ignore the others. Vulnerability management can continuously identify weaknesses, while penetration testing can more deeply validate critical systems. Security reviews and audits can then provide additional assurance around policies, processes and controls. The strongest approach is usually layered: automate what can be automated, investigate what requires human judgement, and use controlled testing to determine whether important weaknesses translate into meaningful attack paths.

The Main Penetration Testing Methods

No single penetration testing method fits every Australian business. A company operating a public-facing SaaS platform may need extensive web application and API penetration testing. At the same time, a professional services organisation may place greater emphasis on external infrastructure, identity systems and internal network security. A business with offices across multiple locations could require internal testing that examines segmentation and lateral movement. At the same time, an organisation with a heavily internet-facing infrastructure may need a detailed external assessment. Understanding the difference between these methods helps decision-makers spend their security budget where it can have the greatest impact. The four categories discussed below web, network, internal and external testing are often combined rather than treated as completely separate engagements. In many environments, the most useful assessment begins externally and then considers what could happen after an attacker obtains an initial foothold.

Web Application Penetration Testing

Web application penetration testing focuses on the security of websites, portals, web-based platforms, customer dashboards, business applications and related APIs. Modern applications are rarely simple collections of web pages. They often handle authentication, payments, customer records, employee information, business workflows, integrations and privileged administrative functions. That complexity creates opportunities for security weaknesses that a basic automated scan may not detect. A tester may examine authentication mechanisms, authorisation rules, session handling, input validation, business logic, file handling, API behaviour and other application-specific functionality to determine whether an attacker could manipulate the system in an unintended way. For Australian businesses that rely heavily on online services, this type of testing can be particularly valuable because the web application may be one of the organisation’s most accessible attack surfaces. A secure-looking login page does not necessarily mean the application behind it is secure; the real question is whether each user can access only what they are supposed to access and whether the application’s underlying logic withstands realistic abuse.

What Web Application Testing Looks For

Web application testing can examine a wide range of security conditions, including broken access controls, authentication weaknesses, insecure session handling, injection risks, insecure file functionality, exposed administrative features, and business logic weaknesses. API testing is also increasingly important because applications often communicate through APIs even when users interact with a polished frontend. An application might appear secure to a normal user while an API exposes data or functionality that should never be available to that user. Manual testing becomes particularly valuable when the security issue depends on understanding how multiple functions interact. For example, a tester may discover that an individual endpoint appears harmless but becomes dangerous when combined with another workflow. The goal is to understand the attack path, not merely identify isolated technical symptoms. Australian organisations developing new applications or making significant changes should consider security testing before exposing important functionality to customers or users. ASD’s current ISM also includes guidance on security assessments before deployment and before significant changes, with the current control recommending vulnerability assessments and penetration tests before deployment and at least annually thereafter.

Network Penetration Testing

Network penetration testing examines the security of network infrastructure and services that support an organisation’s technology environment. Depending on the agreed scope, this can involve servers, firewalls, routers, remote access infrastructure, VPN services, network services, exposed ports, authentication systems and other infrastructure components. The purpose is to determine whether an attacker could exploit network weaknesses to gain unauthorised access or increase their access level. Network testing can be particularly useful for businesses that maintain physical offices, cloud infrastructure, hybrid environments or multiple connected systems. A network can have many layers, and a weakness in one layer may give an attacker a route to another system. Professional testing therefore looks beyond whether a port is open and considers what that service means in context, whether it is appropriately secured and whether it creates an unnecessary route into the environment.

Network testing also highlights why perimeter security alone is not enough. Firewalls and security gateways can reduce exposure, but an organisation may still have vulnerable services, outdated systems, weak authentication configurations or overly permissive network relationships. In a modern Australian business environment, cloud services and remote work can make the traditional concept of a single corporate perimeter less relevant. Security testing needs to reflect the actual architecture rather than assuming everything sits behind one office firewall. A well-scoped network penetration test can help an organisation understand what an attacker can see from outside, what weaknesses could be exploited, and whether the organisation’s network design limits the impact of a compromise.

External vs Internal Network Testing

External and internal network penetration tests answer different questions. External penetration testing generally starts from the perspective of an attacker who has access to the internet but no trusted position inside the organisation. It focuses on publicly accessible systems and services and asks, “What can an attacker reach from outside?” Internal penetration testing starts from an assumed or authorised position inside the environment and asks, “What could an attacker do after gaining internal access?” These perspectives are complementary. A business could have a strong external perimeter but still suffer significant risk if an attacker compromises one employee account, device or application and can then move freely across internal systems. Conversely, an organisation may have strong internal segmentation but accidentally expose a sensitive administrative service to the internet. Testing both perspectives provides a more complete picture of the attack surface.

internal vs external testing

Internal Penetration Testing

Internal penetration testing evaluates security from within an organisation’s trusted environment. The test may simulate scenarios such as an attacker gaining access through a compromised employee account, a compromised workstation, an exposed internal service or another authorised starting point. The purpose is to determine how effectively the organisation can prevent privilege escalation, lateral movement and access to sensitive systems after an initial compromise. This is especially important because attackers do not always need to break through the front door if they can obtain access through another route. Once inside, weaknesses in segmentation, identity management, permissions and administrative controls can allow a relatively small compromise to become a much larger incident.

For Australian businesses, internal testing can also provide useful evidence about the practical effectiveness of access controls and network architecture. The Essential Eight, for example, includes restricting administrative privileges as one of its eight mitigation strategies. The framework also includes patching applications and operating systems, multi-factor authentication, application control, user application hardening, restricting Microsoft Office macros and regular backups. Penetration testing does not replace these controls, but it can help an organisation understand what could happen if one or more controls fail. That is the difference between assuming a security control works and testing its real-world resilience.

External Penetration Testing

External penetration testing examines an organisation from the perspective of an unauthorised attacker operating outside the trusted environment. The assessment typically focuses on internet-facing systems and services that are within the agreed scope. These may include public websites, remote access services, externally accessible applications, exposed infrastructure and other assets that an attacker could potentially discover. The key question is simple but powerful: If someone targeted your organisation from the internet today, what would they find and what could they potentially exploit?

External testing is particularly valuable because organisations frequently accumulate internet-facing assets over time. A forgotten subdomain, an old application, an unnecessary service or a misconfigured cloud resource can remain accessible long after the original project has ended. A security team may know about the major production systems while overlooking less obvious assets. An external penetration test can help reveal weaknesses in that exposed attack surface. It also provides an outside perspective that internal teams cannot always reproduce because they naturally understand the environment and may unconsciously overlook assumptions that an external attacker would challenge.

How Penetration Testing Works

A professional penetration test is more than running a security tool and exporting its results. A structured engagement normally begins with planning and scoping, followed by reconnaissance, vulnerability analysis, controlled testing, validation, documentation and reporting. The exact methodology varies by target, rules of engagement, and business objectives. Still, the fundamental principle remains the same: testing should be authorised, controlled, and aligned with a defined security goal. Poorly scoped testing can create unnecessary risk or produce findings that are difficult for the business to act upon. A properly scoped engagement establishes what may be tested, when testing can occur, what systems are excluded, how potentially disruptive activities are handled and how urgent findings should be communicated.

Planning, Reconnaissance and Scoping

The planning phase determines what the test is actually supposed to achieve. A business may want to assess a web application before launch, validate external infrastructure after a major architecture change, test internal segmentation, or evaluate a particular high-value system. The tester and organisation should agree on the target, testing window, authorised techniques, communication procedures and reporting requirements before testing begins. Reconnaissance then helps the testing team understand the environment and identify relevant assets within the agreed scope. This is important because an effective test depends heavily on context. Knowing what systems exist, how they interact and which assets are business-critical allows the assessment to focus on meaningful attack paths rather than generating noise.

The current ASD ISM emphasises that security assessments should have suitable scope and that assessors should be appropriately skilled and independent of the system being assessed. It also recommends producing a security assessment report that explains the assessment scope, system strengths and weaknesses, security risks, control effectiveness and recommended remediation actions. That is a useful benchmark when evaluating a penetration testing provider. If the provider cannot clearly explain the scope, methodology, objectives and reporting process, the business should ask more questions before authorising testing.

Exploitation and Security Validation

Once reconnaissance and analysis are complete, testers validate selected vulnerabilities through controlled exploitation. This is where penetration testing becomes significantly different from simple scanning. The tester wants to determine whether a vulnerability is genuinely exploitable within the agreed rules and what level of access or impact it could create. The process should remain controlled and should avoid unnecessary disruption to production systems. When a weakness is successfully validated, the tester can document the attack path, affected assets, potential impact and recommended remediation.

The goal is not to cause damage or prove that the tester can break everything. Ethical penetration testing provides useful security evidence while respecting the organisation’s operational requirements. The most valuable finding is often not the most technically complex one; it is the one that exposes a realistic path to something the business genuinely needs to protect.

Penetration Testing and Australian Cybersecurity Requirements

Australian organisations operate within a cybersecurity environment shaped by industry expectations, government guidance, contractual obligations, privacy considerations and individual organisational risk. The Australian Signals Directorate’s Information Security Manual provides a cybersecurity framework that organisations can apply through their risk management processes to protect IT and operational technology systems and data from cyber threats. The ISM is particularly relevant for organisations that need structured security assurance, but its principles can also provide useful context for broader cybersecurity programs. The current June 2026 release includes updated guidance on vulnerability assessments and penetration testing, including a control recommending these activities be conducted before deployment, before significant changes, and at least annually thereafter. Businesses should still determine their own requirements based on their systems, risk profile, contracts, and applicable obligations, rather than assuming one generic testing schedule applies to everyone.

Essential Eight and Penetration Testing

The Essential Eight is another important part of the Australian cybersecurity conversation. ASD describes it as a baseline of eight mitigation strategies designed to make it harder for adversaries to compromise systems. The strategies include patching applications and operating systems, multi-factor authentication, restricting administrative privileges, application control, restricting Microsoft Office macros, hardening user applications, and regular backups. Penetration testing should not be presented as a replacement for implementing these controls. Instead, testing can complement a broader security program by helping organisations validate whether weaknesses remain exploitable despite their existing controls.

This distinction is particularly useful for business owners searching for penetration testing services in Australia because it prevents a common misunderstanding. A penetration test is not simply a compliance certificate, and passing one test does not mean a company is permanently secure. Cybersecurity changes whenever applications change, infrastructure changes, identities change, and attackers develop new techniques. Testing should therefore be viewed as one part of an ongoing process of identifying, prioritising and reducing security risk.

ISM, Risk Management and Security Assurance

The ISM provides practical guidance for protecting IT and OT environments and is intended for audiences including cybersecurity professionals, IT managers, CIOs and CISOs. For organisations using the ISM as part of their security framework, penetration testing can contribute evidence to the broader security assurance process. A useful report should explain not just what was found but why it matters, which systems were affected, how the weakness could be exploited, and what remediation should be prioritised. The current ISM guidance specifically calls for security assessment reporting that addresses scope, strengths and weaknesses, security risks, control effectiveness and recommended remediation actions.

Which Penetration Testing Method Does Your Business Need?

The right testing approach depends on your technology environment, business model, exposure and security objectives. A small Melbourne business with a public website and cloud-based SaaS platform may benefit most from web application and external testing. A larger organisation with offices, servers, identity infrastructure and multiple network segments may require external, internal and network testing together. A software company preparing to launch a customer-facing platform may prioritise application and API testing before launch. A business that has recently experienced major infrastructure changes may want targeted testing to validate whether the new architecture introduced unexpected exposure.

Public-facing website or web platform Web application testing
Customer portal or SaaS application Web + API penetration testing
Internet-facing infrastructure External penetration testing
Corporate network Internal + network testing
Hybrid cloud environment External + network + application testing
Major application release Web application testing
Significant infrastructure change Targeted network/external testing
Mature security program Combined periodic penetration testing

The key point is to avoid buying a test simply because another organisation bought it. Security testing should begin with the business’s attack surface and objectives. A provider should be willing to discuss what you operate, what you are trying to protect and what scenario you want to simulate before recommending a testing package.

Choosing Testing Based on Your Attack Surface

Start by asking four questions: What is exposed to the internet? What applications process important information? What would happen if an attacker gained an internal foothold? And which systems would cause the greatest business damage if compromised? The answers will usually reveal which testing methods deserve priority. From there, your penetration testing provider can build a scope that reflects your actual environment. This risk-based approach is more valuable than simply selecting the cheapest or broadest package.

For example, imagine an Australian online retailer whose most important asset is its e-commerce platform. Testing the internal office network alone would not answer the most important security question. The company should first understand whether its customer-facing application, APIs, authentication and payment-related workflows can withstand realistic attacks. Conversely, a professional services organisation with sensitive internal documents may need significant attention on identity, endpoint and internal network security. The best penetration test is therefore not necessarily the largest one; it is the one that answers the questions that matter most to the organisation.

Penetration Testing Services in Melbourne and Across Australia

Businesses searching for penetration testing Melbourne or penetration testing Australia often want more than a generic vulnerability report. They need a security partner that understands their technology, defines an appropriate scope, communicates findings clearly, and helps technical teams prioritise remediation. For a Melbourne-based business, having access to a local provider can also make scoping discussions and stakeholder communication easier. At the same time, Australia-wide delivery allows organisations with distributed teams and infrastructure to work with the same security partner.

DevVibe provides penetration testing services for businesses in Australia, with a Melbourne presence and the capability to support organisations that need application, network, internal and external security testing. The focus should be on understanding the customer’s actual environment rather than applying the same checklist to every engagement. Whether the target is a customer-facing web application, external infrastructure, internal network or a combination of environments, the assessment should be designed around the organisation’s risk and objectives.

Why Australian Businesses Choose DevVibe

DevVibe can position its penetration testing services around a simple principle: find the weaknesses that matter, validate realistic attack paths and give the business a clear way forward. For Australian businesses, this means providing testing that is understandable to both technical and non-technical stakeholders. A security leader may need detailed technical evidence, while a business owner or executive may primarily need to understand the potential business impact and which issues require immediate attention. A strong report should serve both audiences.

For organisations in Melbourne and elsewhere in Australia, DevVibe can support penetration testing across web applications, networks, internal environments and externally exposed systems. The scope can be adapted to the technology being assessed and the objectives of the engagement. The outcome should not simply be a document that sits in a security folder; it should help the organisation make better security decisions, prioritise remediation and understand whether important weaknesses have been addressed.

External testing

How Much Does Penetration Testing Cost in Australia?

There is no universal price for penetration testing because the scope can vary dramatically between organisations. Testing a single small web application is very different from assessing a large enterprise environment containing multiple applications, networks, APIs, cloud systems and authentication platforms. Factors that influence cost include the number of targets, application complexity, number of APIs, authenticated user roles, infrastructure size, testing depth, required testing windows, reporting requirements and whether retesting is included. A responsible penetration testing provider should therefore scope the engagement before giving a meaningful price rather than offering a misleading one-size-fits-all figure.

Also Read: How much does penetration testing cost in Australia?

For businesses comparing penetration testing companies in Australia, price should not be the only selection criterion. A cheap test that misses important attack paths can provide a false sense of security, while an unnecessarily broad assessment can consume budget without addressing the organisation’s most important risks. Ask potential providers what is included, what is excluded, whether testing is manual and automated, how findings are validated, how critical issues are communicated and what the final report contains. If remediation guidance and retesting are important to your organisation, confirm those services before signing the engagement.

How Often Should Australian Businesses Conduct Penetration Testing?

Testing frequency depends on the organisation’s risk, technology changes and security requirements. A penetration test performed once and then forgotten will become less representative as the environment evolves. New features, infrastructure changes, integrations, authentication mechanisms, third-party services and cloud configurations can introduce new attack paths. That is why penetration testing is best treated as part of an ongoing security lifecycle rather than a one-off event.

The current June 2026 ASD ISM contains a control recommending vulnerability assessments and penetration tests before deployment, before significant changes and at least annually thereafter. Organisations should interpret that guidance in the context of their own systems and applicable requirements. At a practical level, businesses should consider testing when launching major applications, making significant architecture changes, introducing high-risk functionality, undergoing major infrastructure changes and regularly, appropriate to their risk profile.

What Should a Penetration Testing Report Include?

A penetration testing report should turn technical discoveries into actionable security information. It should clearly describe the scope of the engagement, methodology, limitations, findings, evidence, affected assets, risk levels and remediation recommendations. For significant findings, the report should explain the attack path clearly enough that the organisation understands how the weakness could affect the business. A strong report distinguishes between a theoretical vulnerability and a validated security issue, which helps security teams prioritise remediation more intelligently.

The current ASD ISM guidance says a security assessment report should cover the assessment scope, system strengths and weaknesses, security risks associated with system operation, effectiveness of implemented controls and recommended remediation actions. This framework helps businesses decide what to expect from a testing provider. The report should also be understandable. Technical detail is valuable, but decision-makers should not need to decode pages of jargon to determine which findings deserve immediate attention.

How to Prepare for a Penetration Test

Preparation can make a penetration test more efficient and reduce unnecessary disruption. Start by identifying the systems to include and exclude, confirming ownership, documenting critical business functions, and deciding who should be available during the engagement. Make sure the testing provider has accurate scope information and understands whether the environment contains production systems, staging environments, third-party services or sensitive workflows. If the test includes authenticated application functionality, arrange the required test accounts and permissions in advance.

It is also useful to establish an escalation process for critical findings. If testers discover a severe vulnerability during an engagement, the business should know who to contact and how quickly. Production testing requires particular care because certain techniques can potentially affect system availability. Clear rules of engagement allow the testing team to work effectively while protecting business operations. Preparation is not about making the environment look perfect before testing; it is about ensuring that the assessment answers the right questions safely and efficiently.

Penetration testing in Australia

Conclusion

Penetration testing in Australia is most valuable when it moves beyond simply finding vulnerabilities and helps an organisation understand realistic attack paths. Web application testing can reveal weaknesses in customer-facing applications and APIs, network testing can expose infrastructure risks, external testing can show what an attacker can reach from the internet, and internal testing can demonstrate what may happen after an attacker gains an initial foothold. These methods answer different questions, which is why Australian businesses often benefit from a testing strategy built around their actual attack surface rather than a generic checklist.

The Australian cybersecurity landscape also makes it important to understand the relationship between penetration testing and broader security practices. The current ASD Information Security Manual provides a risk-based cybersecurity framework, while the Essential Eight provides a baseline of mitigation strategies designed to make compromise harder. Penetration testing complements these practices by providing practical evidence about whether weaknesses and controls withstand realistic attack scenarios. The current ISM guidance also recommends vulnerability assessments and penetration tests before deployment, before significant changes and at least annually thereafter, reinforcing the value of making security testing part of an ongoing security lifecycle.

For businesses looking for penetration testing services in Melbourne or across Australia, the next step is not necessarily to order the biggest assessment available. Start by identifying your most important systems, your internet-facing attack surface, your critical applications and what an attacker could potentially gain if they obtained an initial foothold. From there, a properly scoped assessment can focus security expertise where it matters most. DevVibe helps Australian businesses assess web applications, networks, internal environments and external infrastructure through structured penetration testing services, giving organisations clearer insight into their security weaknesses and practical priorities for improvement.

Faqs

How Do I Choose a Penetration Testing Company Near Me?

Choose a provider based on its experience, testing methodology, security expertise, reporting, and understanding of your industry. For businesses in Melbourne and across Australia, DevVibe provides professional penetration testing services tailored to different security needs.

What Are the Top Penetration Testing Service Providers in Australia?

Australia has many penetration testing providers, so compare their expertise, testing scope, methodology, pricing, and reporting before choosing one. DevVibe is an Australia-focused software company that offers penetration testing services to businesses across Australia.

How Much Do Professional Penetration Testing Services Cost in Australia?

Penetration testing costs vary based on scope, the number of systems and applications, and testing complexity. Australian businesses can request a tailored quote from DevVibe based on their specific security requirements.

Are There Affordable Penetration Testing Packages for Small Businesses?

Yes, small businesses can choose focused penetration testing that targets their most critical applications, networks, or systems. DevVibe can provide testing options based on your business requirements and security scope.

What Are the Key Differences Between a Vulnerability Scan and a Penetration Test?

A vulnerability scan uses automated tools to identify potential weaknesses, while penetration testing involves actively testing whether those weaknesses can be exploited. Penetration testing provides deeper insight into real-world security risks and their potential impact.

Is a vulnerability scan enough instead of a penetration test?

A vulnerability scan can be valuable, but it does not necessarily answer the same questions as a penetration test. Scanning can identify known weaknesses efficiently, while penetration testing uses controlled exploitation and manual analysis to determine whether weaknesses can form realistic attack paths. ASD’s current ISM guidance explicitly distinguishes vulnerability identification from penetration testing.

Can penetration testing make my business completely secure?

No security assessment can guarantee complete security. A penetration test provides evidence about the security of a defined environment at a particular point in time and within a particular scope. New vulnerabilities, software changes, configuration changes and emerging attack techniques can alter the risk landscape.