The widest attack surface in any sector
A university does not have one network. It has a corporate environment, a student environment, research computing, teaching labs, residential accommodation, conference and event infrastructure, and a wireless network that welcomes visiting staff from other institutions by design. Schools and TAFEs run a smaller version of the same problem with a fraction of the staff.
Openness is the point, which is exactly what makes the estate hard to defend. Academics publish. Faculties stand up their own sites, conference microsites and project pages, often on infrastructure central IT never sees. Devices arrive unmanaged in their thousands each February and leave again in November. Accounts churn on the academic calendar rather than an HR cycle, and legacy systems survive because a single course still depends on them.
The data behind all of that is genuinely valuable: student and staff personal information, fee payments, health and welfare records, and research that may be commercially or nationally sensitive. Attackers know the sector combines high-value data with thin security teams, and they treat it accordingly.
What drives testing in education
There is rarely one regulator to satisfy. Instead, obligations arrive from several directions at once, and each of them eventually asks the same question: can you show that your controls actually work?
| Driver | What it usually means in practice |
|---|---|
| Privacy Act 1988 and the NDB scheme | Student, staff and applicant records are personal information, so exposure paths to those systems need to be understood and closed |
| State and territory privacy and records legislation | Public schools, TAFEs and many universities carry additional jurisdictional obligations and audit expectations |
| PCI DSS v4.0 | Fee, accommodation, parking and merchandise payment journeys pull cardholder data into scope |
| GDPR | International student and research collaboration data can attract European obligations |
| Essential Eight and ISO 27001 | Commonly referenced in public education security programmes, grant conditions and procurement questionnaires |
| Research and funding conditions | Grants and industry partnerships increasingly require evidence that sensitive research data is protected |
Mapping is not certification
PentestOps reports map findings to 8 compliance reporting frameworks (OWASP Top 10, PCI DSS v4.0, NIST 800-53, SOC 2, HIPAA, GDPR, ISO 27001, SMB1001) plus CIS Benchmarks for AWS, Azure, GCP and Kubernetes. Those mappings show where each finding sits against a framework so your team can route the work and evidence the fix.
They are not a statement that your institution is certified or compliant, and no testing platform can make that claim on your behalf. Certification is an audit outcome; testing supplies part of the evidence an auditor will ask for.
Regulatory landscape
Those drivers become concrete once you name the instruments behind them. Higher education providers are registered and monitored by TEQSA against the Higher Education Standards Framework, which expects sound corporate and academic governance and active management of risks to students and to the information held about them. Information security is not a separate standard inside that framework; it is part of governing the institution properly.
Privacy obligations run alongside it. The Privacy Act 1988 and the Notifiable Data Breaches scheme apply to student, staff and applicant records, and public schools, TAFEs and many universities carry further duties over student data under state and territory privacy and records regimes. Where the institution is publicly funded, the Essential Eight turns up in grant conditions, tender responses and internal audit programmes as the expected baseline.
No testing platform satisfies any of these on your behalf. What testing does is produce the technical evidence each obligation eventually asks for, which is how the table below should be read.
| Obligation | What it asks of the institution | Evidence testing can contribute |
|---|---|---|
| TEQSA and the Higher Education Standards Framework | Sound corporate and academic governance, including active management of risks to students and to the information the institution holds about them | Dated technical assessments of the systems carrying student records and teaching delivery, with remediation tracked through to closure |
| Privacy Act 1988 and the Notifiable Data Breaches scheme | Reasonable steps to protect personal information, and prompt notification when it is compromised | Exploit-validated evidence of which exposure paths to student, staff and applicant records are genuinely reachable, and proof that they were closed |
| State and territory privacy regimes covering student data | Further jurisdictional duties for public schools, TAFEs and many universities, usually with their own audit and reporting cycle | Repeatable testing across external, internal, application, identity and cloud surfaces, exported as PDF, CSV or JSON/API for the reviewer |
| Essential Eight, where the institution is publicly funded | Uplift against the mitigation strategies, commonly written into grant conditions, tender responses and internal audit programmes | Findings on patching, administrative privilege, application hardening and credential weakness that feed your uplift plan. PentestOps does not issue a maturity rating |
| ISO 27001 or an equivalent certification programme | Technical testing that feeds the risk treatment cycle, and evidence that findings were closed out rather than merely logged | Findings mapped to ISO 27001 among 8 compliance reporting frameworks, with scan comparison showing an issue verified as fixed |
How PentestOps maps to a campus estate
Assessments follow a seven-phase methodology aligned to PTES, OWASP Web Security Testing Guide v4.2 and NIST SP 800-115. Every scan is tied to signed Rules of Engagement, with scope enforcement that automatically stops activity outside authorised assets: important when a campus network hosts systems owned by student associations, partners and spin-outs.
- Discovery first. External recon maps the published estate, and 7-day asset re-verification with drift detection catches the site a faculty stood up last month. Enterprise adds continuous attack surface management between scheduled scans.
- Internal and wireless-adjacent networks. One agent host can cover multiple subnets, so staff, student and lab networks are reachable without a VPN or jump host. See internal network testing.
- Identity. Active Directory testing targets the weaknesses that semester churn creates: stale accounts, weak password policy and over-privileged groups.
- Student and staff applications. Web application and API testing covering SQL injection, cross-site scripting, SSRF, IDOR and authentication bypass across REST and GraphQL.
- Cloud and research computing. 800+ automated checks across AWS, Azure, GCP and M365 with CIS Benchmark coverage, plus agentless Kubernetes auditing through a read-only kubeconfig for research and platform clusters. Email and M365 audits are Enterprise capabilities.
- Prioritisation that respects a small team. CVE correlation, CVSS v3.1 scoring, exploit-availability indicators and CISA KEV prioritisation, with false-positive reduction so the queue stays workable.
Covering a large estate with a small budget
Education security teams are usually asked to protect an enterprise-scale estate on a departmental budget. Traditional consulting prices per engagement, which pushes institutions towards testing a narrow slice once a year and hoping the rest holds.
Asset-wise pricing changes that calculation. You pay for how many distinct assets are in scope, and scans against those assets are unlimited within fair use. Re-testing after a fix, re-testing before an audit and re-testing after a semester rollover all cost the same as the first scan. Annual billing saves around 25 per cent, and live plan detail sits on pricing.
Practically, most institutions start narrow and grow: bring the internet-facing estate under test first, add the student-facing applications that handle payments or personal information, then extend into internal networks and identity once the perimeter backlog is under control.
Typical use cases
- Semester-start hardening, run before enrolment traffic arrives and re-run once the new cohort's systems are live.
- Shadow IT discovery across faculty, research and event subdomains that were never registered centrally.
- Pre-audit evidence for a certification programme, grant condition or an industry partner's security questionnaire.
- Research environment review, covering the cloud accounts and clusters that host sensitive data sets.
- Post-incident validation, proving that the path used against you is genuinely closed rather than assumed closed. Read more on attack path validation.
- Multi-campus or multi-school coverage, where one team supports several sites and needs consistent, comparable reporting.
Why education providers choose PentestOps
- Breadth first: external, internal, web, API, cloud, identity and Kubernetes coverage in one subscription instead of six vendors.
- Evidence, not just severity ratings. Safe automated exploitation under Rules of Engagement proves which findings are real.
- About 5 minutes to deploy the agent, no VPN, no jump host and no inbound firewall rules to negotiate with the network team.
- Self-hosted AI by default, so scan data is analysed on infrastructure Extranet Systems operates rather than sent to third-party model providers. External providers are opt-in per tenant.
- Australian-built and operated. Customer data is stored in Australia, and Extranet Systems Pty Ltd is ISO/IEC 27001:2022 certified.
- Predictable, asset-wise cost that a faculty or department budget can actually plan around.