
A personal perspective on how cybersecurity standards and practice evolved from 1990 to 2026 — from foundational frameworks to adversarial simulation.
Section 01
Click any milestone to learn more.
Section 02
From a shared origin in ~1990, two distinct disciplines emerged and matured in parallel. Click a track to explore.
Compliance assessment evolved from point-in-time checkbox exercises into continuous, risk-based evaluation frameworks aligned to ISM, Essential Eight, and ISO 27001.
~1990
Audit-based compliance begins — paper checklists, annual reviews.
2000s
Regulatory frameworks (PCI DSS, ACSI 33) formalise compliance requirements.
2010s
iRAP assessors and ISMS certifications professionalise the discipline.
2026
Continuous compliance monitoring, automated evidence collection, and maturity-model reporting.
Technical testing evolved from basic vulnerability scanning into sophisticated adversarial simulation — red teaming, assumed breach operations, and full kill-chain emulation.
~1990
Ad-hoc vulnerability scanning and basic network enumeration.
2000s
Penetration testing formalised; methodologies like PTES and OWASP emerge.
2010s
Red teaming and threat-intelligence-led testing (TIBER) introduced.
2026
Assumed breach operations, purple teaming, and continuous adversarial simulation.
Observation — 2026
By 2026, these two tracks are converging. The Essential Eight mandates technical validation of compliance controls. Regulators increasingly require evidence from adversarial testing — not just policy review. The gap between "are we compliant?" and "are we secure?" is finally being closed through integrated programmes that demand both.