Find the sites you forgot

24+ external recon modules map the published estate, including faculty, project and event sites created outside central IT.

Campus network testing

The on-premise agent runs 18+ internal modules natively on the LAN instead of tunnelling out, with 0 inbound firewall rules.

Identity under pressure

Active Directory enumeration, credential testing and password-policy auditing across accounts that turn over every semester.

Student-facing applications

Web and API testing against OWASP Top 10 and API Top 10 risks for portals, enrolment systems and payment journeys.

Asset-wise pricing

Pay for the assets in scope, not per test. Scans against an asset are unlimited within fair use, so re-testing costs nothing extra.

Reporting your auditors know

Findings map to 8 compliance reporting frameworks plus CIS Benchmarks, exported as PDF, CSV and JSON/API.

The widest attack surface in any sector

A university does not have one network. It has a corporate environment, a student environment, research computing, teaching labs, residential accommodation, conference and event infrastructure, and a wireless network that welcomes visiting staff from other institutions by design. Schools and TAFEs run a smaller version of the same problem with a fraction of the staff.

Openness is the point, which is exactly what makes the estate hard to defend. Academics publish. Faculties stand up their own sites, conference microsites and project pages, often on infrastructure central IT never sees. Devices arrive unmanaged in their thousands each February and leave again in November. Accounts churn on the academic calendar rather than an HR cycle, and legacy systems survive because a single course still depends on them.

The data behind all of that is genuinely valuable: student and staff personal information, fee payments, health and welfare records, and research that may be commercially or nationally sensitive. Attackers know the sector combines high-value data with thin security teams, and they treat it accordingly.

What drives testing in education

There is rarely one regulator to satisfy. Instead, obligations arrive from several directions at once, and each of them eventually asks the same question: can you show that your controls actually work?

DriverWhat it usually means in practice
Privacy Act 1988 and the NDB schemeStudent, staff and applicant records are personal information, so exposure paths to those systems need to be understood and closed
State and territory privacy and records legislationPublic schools, TAFEs and many universities carry additional jurisdictional obligations and audit expectations
PCI DSS v4.0Fee, accommodation, parking and merchandise payment journeys pull cardholder data into scope
GDPRInternational student and research collaboration data can attract European obligations
Essential Eight and ISO 27001Commonly referenced in public education security programmes, grant conditions and procurement questionnaires
Research and funding conditionsGrants and industry partnerships increasingly require evidence that sensitive research data is protected

Mapping is not certification

PentestOps reports map findings to 8 compliance reporting frameworks (OWASP Top 10, PCI DSS v4.0, NIST 800-53, SOC 2, HIPAA, GDPR, ISO 27001, SMB1001) plus CIS Benchmarks for AWS, Azure, GCP and Kubernetes. Those mappings show where each finding sits against a framework so your team can route the work and evidence the fix.

They are not a statement that your institution is certified or compliant, and no testing platform can make that claim on your behalf. Certification is an audit outcome; testing supplies part of the evidence an auditor will ask for.

Regulatory landscape

Those drivers become concrete once you name the instruments behind them. Higher education providers are registered and monitored by TEQSA against the Higher Education Standards Framework, which expects sound corporate and academic governance and active management of risks to students and to the information held about them. Information security is not a separate standard inside that framework; it is part of governing the institution properly.

Privacy obligations run alongside it. The Privacy Act 1988 and the Notifiable Data Breaches scheme apply to student, staff and applicant records, and public schools, TAFEs and many universities carry further duties over student data under state and territory privacy and records regimes. Where the institution is publicly funded, the Essential Eight turns up in grant conditions, tender responses and internal audit programmes as the expected baseline.

No testing platform satisfies any of these on your behalf. What testing does is produce the technical evidence each obligation eventually asks for, which is how the table below should be read.

ObligationWhat it asks of the institutionEvidence testing can contribute
TEQSA and the Higher Education Standards FrameworkSound corporate and academic governance, including active management of risks to students and to the information the institution holds about themDated technical assessments of the systems carrying student records and teaching delivery, with remediation tracked through to closure
Privacy Act 1988 and the Notifiable Data Breaches schemeReasonable steps to protect personal information, and prompt notification when it is compromisedExploit-validated evidence of which exposure paths to student, staff and applicant records are genuinely reachable, and proof that they were closed
State and territory privacy regimes covering student dataFurther jurisdictional duties for public schools, TAFEs and many universities, usually with their own audit and reporting cycleRepeatable testing across external, internal, application, identity and cloud surfaces, exported as PDF, CSV or JSON/API for the reviewer
Essential Eight, where the institution is publicly fundedUplift against the mitigation strategies, commonly written into grant conditions, tender responses and internal audit programmesFindings on patching, administrative privilege, application hardening and credential weakness that feed your uplift plan. PentestOps does not issue a maturity rating
ISO 27001 or an equivalent certification programmeTechnical testing that feeds the risk treatment cycle, and evidence that findings were closed out rather than merely loggedFindings mapped to ISO 27001 among 8 compliance reporting frameworks, with scan comparison showing an issue verified as fixed

How PentestOps maps to a campus estate

Assessments follow a seven-phase methodology aligned to PTES, OWASP Web Security Testing Guide v4.2 and NIST SP 800-115. Every scan is tied to signed Rules of Engagement, with scope enforcement that automatically stops activity outside authorised assets: important when a campus network hosts systems owned by student associations, partners and spin-outs.

  • Discovery first. External recon maps the published estate, and 7-day asset re-verification with drift detection catches the site a faculty stood up last month. Enterprise adds continuous attack surface management between scheduled scans.
  • Internal and wireless-adjacent networks. One agent host can cover multiple subnets, so staff, student and lab networks are reachable without a VPN or jump host. See internal network testing.
  • Identity. Active Directory testing targets the weaknesses that semester churn creates: stale accounts, weak password policy and over-privileged groups.
  • Student and staff applications. Web application and API testing covering SQL injection, cross-site scripting, SSRF, IDOR and authentication bypass across REST and GraphQL.
  • Cloud and research computing. 800+ automated checks across AWS, Azure, GCP and M365 with CIS Benchmark coverage, plus agentless Kubernetes auditing through a read-only kubeconfig for research and platform clusters. Email and M365 audits are Enterprise capabilities.
  • Prioritisation that respects a small team. CVE correlation, CVSS v3.1 scoring, exploit-availability indicators and CISA KEV prioritisation, with false-positive reduction so the queue stays workable.

Covering a large estate with a small budget

Education security teams are usually asked to protect an enterprise-scale estate on a departmental budget. Traditional consulting prices per engagement, which pushes institutions towards testing a narrow slice once a year and hoping the rest holds.

Asset-wise pricing changes that calculation. You pay for how many distinct assets are in scope, and scans against those assets are unlimited within fair use. Re-testing after a fix, re-testing before an audit and re-testing after a semester rollover all cost the same as the first scan. Annual billing saves around 25 per cent, and live plan detail sits on pricing.

Practically, most institutions start narrow and grow: bring the internet-facing estate under test first, add the student-facing applications that handle payments or personal information, then extend into internal networks and identity once the perimeter backlog is under control.

Typical use cases

  • Semester-start hardening, run before enrolment traffic arrives and re-run once the new cohort's systems are live.
  • Shadow IT discovery across faculty, research and event subdomains that were never registered centrally.
  • Pre-audit evidence for a certification programme, grant condition or an industry partner's security questionnaire.
  • Research environment review, covering the cloud accounts and clusters that host sensitive data sets.
  • Post-incident validation, proving that the path used against you is genuinely closed rather than assumed closed. Read more on attack path validation.
  • Multi-campus or multi-school coverage, where one team supports several sites and needs consistent, comparable reporting.

Why education providers choose PentestOps

  • Breadth first: external, internal, web, API, cloud, identity and Kubernetes coverage in one subscription instead of six vendors.
  • Evidence, not just severity ratings. Safe automated exploitation under Rules of Engagement proves which findings are real.
  • About 5 minutes to deploy the agent, no VPN, no jump host and no inbound firewall rules to negotiate with the network team.
  • Self-hosted AI by default, so scan data is analysed on infrastructure Extranet Systems operates rather than sent to third-party model providers. External providers are opt-in per tenant.
  • Australian-built and operated. Customer data is stored in Australia, and Extranet Systems Pty Ltd is ISO/IEC 27001:2022 certified.
  • Predictable, asset-wise cost that a faculty or department budget can actually plan around.

Frequently Asked Questions

Will testing disrupt teaching, enrolment or exams?

It should not, and you control the risk. Scans can be scheduled outside peak periods, and Stealth, Balanced and Aggressive profiles let you dial down intensity for sensitive systems. Exploitation only runs where you have authorised it under signed Rules of Engagement, with scope enforcement that automatically stops activity outside authorised assets. Many institutions avoid enrolment and exam windows entirely as a matter of policy.

Can you test student-owned or BYOD devices?

Nothing is installed on student devices. Internal discovery run by the on-premise agent will identify unmanaged hosts present on networks you have authorised for testing, which is usually the point: you want to know what is on the network and what it exposes. Devices outside your authorised scope are not tested.

How do we find the sites nobody remembers publishing?

That is what external discovery is for. 24+ external recon modules map the internet-facing estate, assets are re-verified on a 7-day cycle, and drift detection records changes in a full change ledger. Enterprise customers can add continuous monitoring so the perimeter is re-checked between scheduled scans, with real-time alerts. See EASM explained.

Where is our data stored, including research data findings?

The platform is hosted in Australia on infrastructure operated by Extranet Systems, and customer data is stored in Australia. Every customer runs in an isolated Kubernetes namespace with its own dedicated database. Specific data-residency arrangements are available to Enterprise customers on request.

How is this priced for a school, TAFE or university?

Pricing is asset-wise. One asset is one item the platform can scan or monitor: a public IP, hostname, web application, internal subnet target, cloud account or Kubernetes cluster. Scans against an asset are unlimited within fair use, so testing more often does not increase the bill. Live plan detail is on pricing, and larger multi-campus scopes are best discussed with us directly.

Does it help with our compliance obligations?

Reports map findings to 8 compliance reporting frameworks (OWASP Top 10, PCI DSS v4.0, NIST 800-53, SOC 2, HIPAA, GDPR, ISO 27001, SMB1001) plus CIS Benchmarks for AWS, Azure, GCP and Kubernetes. That gives auditors and questionnaire reviewers dated technical evidence in a structure they recognise. It is a mapping of findings, not a certification of your institution.

Do we need an agent for the campus network?

Only for internal testing. External, web application and API testing run without an agent. For internal networks, the agent ships as a Docker container, RPM or DEB, deploys in about 5 minutes, connects outbound-only over TLS 443 with 0 inbound firewall rules, and one host can cover multiple subnets. See the agent.

Can several faculties or schools work in the same platform?

Yes. Team management, scheduled scans and scan comparison are available from Professional upwards, so different groups can own different assets while reporting stays consistent. Institutions that want fully separated environments per entity should ask about Enterprise, and providers delivering IT to multiple schools should look at the MSP platform.

See what your campus actually exposes

Start with the internet-facing estate and expand once you know what is out there. All paid plans start with a 7-day free trial. A card is required to start your trial and is only charged after the trial ends, unless you cancel first.