Test your own blast radius

Your perimeter, identity and management tooling carry privileged access into every client network you support. Start there.

Hard isolation per client

Each client runs in its own Kubernetes namespace with a dedicated database. No shared tenant data store between your customers.

Fleet-wide agent management

Manage every deployed client agent from one console, with a fleet orchestrator that can force-update agents across your customer base.

Reports your clients can use

Findings map to 8 compliance reporting frameworks and export as PDF, CSV or JSON/API for client boards, auditors and insurers.

Fast client onboarding

The on-premise agent deploys in about 5 minutes with 0 inbound firewall rules, so a new site is testable the same day.

Sales-led Partner programme

Selling testing on to clients runs through the Partner programme, scoped to your client base.

An MSP is a high-value target

Start with the provider estate, because that is where exposure concentrates. An MSP holds privileged access into every client it serves: remote monitoring and management tooling, domain administrator credentials, backup consoles, shared password vaults and support accounts that never expire. Attackers understand that arithmetic perfectly. Compromising one provider is a route into many organisations at once, which is why supply chain expectations increasingly reach past the client to the people who manage the client's infrastructure.

The uncomfortable version is that your security posture already sits on your clients' risk registers, whether or not anyone has said so out loud. A client cannot inherit assurance from a provider that has never tested the paths connecting the two networks, and the questionnaires arriving from their customers increasingly ask about you by name.

Testing your own estate with the rigour you sell is both good practice and a strong sales position. That means your own perimeter and management tooling, your own Active Directory and identity posture, and the access paths that connect your network to your clients'. See common Active Directory security issues for the weaknesses that matter most where shared administrative credentials are the norm.

  • Remote management and support tooling reachable from the internet, sometimes with authentication that predates the current threat model.
  • Shared or reused administrator credentials across multiple client environments, where one disclosure has a very wide blast radius.
  • Standing privileged access into client tenants and domains that outlived the project it was created for.
  • Backup and recovery consoles, which attackers reach for before anything else in a ransomware scenario.
  • Client-facing portals and ticketing systems holding network diagrams, credentials and asset inventories.
  • Your own Microsoft 365 tenant, where business email compromise against an MSP is a direct route into client trust.

Regulatory landscape

Almost none of the pressure on a managed service provider arrives as a cyber regulation written for MSPs. It arrives through the clients you serve and the contracts you sign, and it lands on your own environment rather than theirs. A client regulated under APRA CPS 234 must assess the information security capability of the third parties that manage its information assets, which means you. A government client or tender panel asks for Essential Eight alignment and evidence of independent testing before you are listed.

Some obligations you hold directly. The Privacy Act 1988 and the Notifiable Data Breaches scheme apply to personal information you hold or handle, including the client asset inventories, network diagrams and credentials sitting in your own ticketing and documentation systems. Managed services agreements increasingly name controls, a testing cadence and breach notification timeframes, and your own insurer asks about privileged access management at renewal.

The table reads obligation to evidence, and only for your own estate. PentestOps makes neither you nor your clients compliant with anything; it produces the technical evidence these obligations expect you to be able to show.

Obligation on the providerWhat it asks of youEvidence testing can contribute
Privacy Act 1988 and the Notifiable Data Breaches schemeReasonable steps to protect personal information you hold or handle, and prompt notification of eligible data breachesExploit-validated testing of your own perimeter, identity and documentation systems, with a dated remediation history behind each fix
Clients regulated under APRA CPS 234The regulated entity must assess the information security capability of the third parties managing its information assets, which includes youIndependent, repeatable evidence of your own controls across external, internal, application, identity and cloud surfaces
Managed services agreements and flow-down clausesNamed controls, a testing cadence and breach notification timeframes written into the contract rather than the marketingScheduled assessments of your own estate, reported against 8 compliance reporting frameworks and exported as PDF, CSV or JSON/API
Government and tender panel requirementsEvidence of Essential Eight alignment and independent testing before you can be listed, and again at renewalFindings on patching, administrative privilege and credential weakness that feed your own uplift plan. PentestOps does not issue a maturity rating
ISO 27001 certification of your own management systemTechnical testing that feeds the risk treatment cycle, with findings closed out and re-tested rather than merely loggedFindings mapped to ISO 27001, scan comparison confirming a fix, and a 365-day audit log behind the platform activity itself
Cyber insurance for your own businessRenewal questions about privileged access management, multi-factor authentication and how often you testCurrent, dated reports covering the privileged access paths that connect your network to your clients' environments

Where the partner programme picks up

This page is about the provider's own security posture. The commercial question, where you deliver testing to your clients under your own brand, has its own page. The MSP security platform covers per-client isolation, white-label branding, custom domains with auto-managed SSL, the fleet orchestrator and the separate MSP plan catalogue in full.

Commercial terms, margin model and onboarding run through the sales-led Partner programme. The sections that follow sketch the sell-through side for context, because the two conversations usually start together; treat the platform page as the authority on how the tenancy and branding actually work.

Your clients are being asked, so you are being asked

Security testing used to be something a client's board raised once a year. It now arrives through the front door of the business: an enterprise customer sends a due diligence questionnaire, an insurer asks what testing is performed at renewal, a bank or insurer client pushes third-party expectations down from APRA CPS 234, and a government tender asks for evidence against the Essential Eight. The client forwards all of it to their managed service provider, because that is who runs their network.

For an MSP that creates two problems at once. The first is commercial: you are being asked to deliver something outside the current stack, and referring it to a consultancy hands the relationship, the margin and the follow-up remediation work to someone else. The second is practical: vulnerability scanners already produce more output than any service desk can action, and clients cannot tell the difference between a long list and a real risk. What changes the conversation is proof of exploitability, which is what attack path validation describes.

Building the capability in-house is not usually the answer either. It means licensing tooling per client, standing up scanning infrastructure in each network, writing report templates, and hiring or renting the skills to interpret the output. Most of that cost is fixed and lands before the first invoice goes out.

Launching a testing service line

The MSP security platform is the same full-stack platform sold to end customers, wrapped in the isolation, branding and fleet management a partner business needs. Each client you onboard gets its own Kubernetes namespace and dedicated PostgreSQL database, so one client's findings, credentials and reports are never visible to another. Clients can sit behind a custom domain with SSL certificates auto-managed via ACME, under your brand rather than ours.

Delivery scales through the fleet orchestrator. Every deployed client agent is visible from one console, with the ability to force-update agents across your customer base rather than scheduling a dozen separate maintenance windows. Because the on-premise agent is outbound-only over TLS 443 and requires 0 inbound firewall rules, onboarding a new client site does not require a firewall change request, a VPN or a jump host.

The Partner and MSP programme is sales-led rather than self-serve. Pricing lives in a separate MSP catalogue with 3 tiers so you can match small clients and large ones without reselling the public plan structure. Findings and reports are retained for 7 years on MSP and Partner arrangements, with 365-day audit logs. Start the conversation through the Partner and MSP programme contact form.

What the client asks forWhat you deliverHow the platform supports it
Evidence of independent testing for a questionnaire or tenderA dated assessment report under your brandFindings mapped to 8 compliance reporting frameworks, exported as PDF, CSV or JSON/API
Proof that a finding is actually exploitableA validated finding with evidence, not a scanner scoreSafe automated exploitation gated by per-tenant rules of engagement, with a full evidence trail
Internal network testing without opening the firewallSame-day onboarding of a new siteOutbound-only agent, 0 inbound rules, about 5 minutes to deploy, one host can cover multiple subnets
Ongoing assurance between annual reviewsA managed continuous testing serviceScheduled assessments, 7-day asset re-verification, drift detection and perimeter re-checks between scans
Cloud and Microsoft 365 posture reviewA per-tenant posture assessment800+ automated checks across AWS, Azure, GCP and M365 via read-only credentials, mapped to CIS Benchmarks
Confidence that their data is not mixed with another client'sA dedicated environment per clientPer-client Kubernetes namespace and dedicated database, with no shared tenant data store

How PentestOps maps to an MSP practice

The coverage you can offer under your own brand spans the same layers your clients already pay you to run:

  • Perimeter. 24+ external recon modules map what the internet can see for each client, with no agent required for external testing.
  • Internal networks. 18+ internal modules run natively on the LAN through the agent instead of tunnelling every packet out to a remote scanner. See internal network testing.
  • Identity. Active Directory testing covers enumeration, credential testing and password-policy auditing across client domains.
  • Applications and APIs. Web application testing against OWASP Top 10 risks and API testing across REST and GraphQL.
  • Cloud and Kubernetes. Cloud posture auditing via read-only credentials, plus agentless Kubernetes auditing using a read-only kubeconfig with no DaemonSet to install.
  • Continuous assurance. External attack surface management re-checks each client perimeter between assessments, which turns a project sale into a recurring service.
  • Prioritisation and remediation. CVSS v3.1 scoring, exploit-availability indicators and CISA KEV prioritisation feed an exposure management view, with AI-guided remediation steps your engineers can action directly.

Typical use cases

  • MSPs testing their own estate, management tooling and identity posture with the same rigour they sell.
  • Providers proving to a regulated client that the paths between their network and the client's have been tested and closed.
  • MSPs adding a security testing line without licensing separate tooling for every client environment.
  • Providers whose clients are being asked for evidence under the Essential Eight, ISO 27001, SMB1001 or PCI DSS v4.0.
  • Resellers and consultancies delivering assessments under their own brand rather than referring work to a third party.
  • Providers serving regulated clients that push third-party expectations down from APRA CPS 234.
  • Practices running quarterly or monthly assurance for clients instead of a single annual project.
  • Providers consolidating agents, findings and reporting for many clients into one console instead of a dozen disconnected tools.

Why MSPs choose PentestOps

Reselling someone else's security product usually means inheriting their branding, their tenancy model and their support hours. This programme is built the other way around.

  • Built for resale from the start: white-label branding, custom domains with auto-managed SSL, and a separate 3-tier MSP plan catalogue rather than the public plans structure.
  • Isolation you can defend in a client meeting: per-client Kubernetes namespace and dedicated database, with no shared tenant data store.
  • Proof, not guesswork: exploitation is gated by per-tenant rules of engagement, scope enforcement automatically stops activity outside authorised assets, and validated findings carry an evidence trail.
  • Operationally light: one outbound-only agent per client network, operator-controlled update windows, and no agent orchestrator hub for you to host and maintain.
  • Self-hosted AI by default: client scan data is analysed on infrastructure Extranet Systems operates and is not sent to third-party model providers. External providers are opt-in per tenant.
  • Australian-built and operated. The platform is hosted in Australia, customer data is stored in Australia, and specific data-residency arrangements are available on request.
  • Extranet Systems Pty Ltd is ISO/IEC 27001:2022 certified, independently audited by Atom Assurances, and operates SOC 2-aligned controls. Details are in the Trust Centre.
  • Asset-wise economics: your clients pay for the assets in scope, and scans against them are unlimited within fair use, so re-testing after remediation does not eat your margin.

Frequently Asked Questions

Should we test our own estate before we sell testing to clients?

Most providers do, and it is the reason this page leads with your own environment. You hold privileged access into every client you support, so your perimeter, identity, management tooling and backup consoles carry a wider blast radius than any single client network. Testing those first gives you the evidence a regulated client will eventually ask for, and a much better position to sell from.

Where does the commercial white-label detail live?

On the MSP security platform page, which covers per-client isolation, branding, custom domains, the fleet orchestrator and the separate MSP plan catalogue. Commercial terms and onboarding run through the sales-led Partner programme. This page stays focused on the provider's own security posture.

Can we sell this under our own brand?

Yes. The Partner and MSP programme is built for white-label delivery and resale. Clients can log in on a custom domain with SSL certificates auto-managed via ACME, under your branding. See the MSP security platform page for how the tenancy, branding and fleet management fit together.

How is one client's data kept separate from another's?

Every client runs in its own Kubernetes namespace with a dedicated PostgreSQL database. There is no shared tenant data store, so one client's findings, credentials and reports are not visible to another. Access is role-based, multi-factor authentication is available on every account and required for administrators, and activity is recorded in a 365-day audit log.

How do we price it to our clients?

MSP and Partner pricing is sales-led and sits in a separate catalogue with 3 tiers, so it is scoped to your client base and margin model rather than the public plans. The underlying model is asset-wise: an asset is one item the platform can scan or monitor, such as a public IP, hostname, web application, internal subnet target, cloud account or Kubernetes cluster. Talk to us through the Partner and MSP programme form.

How long does it take to onboard a new client?

External testing needs no agent at all, so a client's perimeter can be assessed as soon as authorisation is in place. For internal testing, the agent ships as a Docker container, RPM or DEB, deploys in about 5 minutes, connects outbound-only over TLS 443 with 0 inbound firewall rules, and a single host can cover multiple subnets.

Do we need penetration testers on staff to deliver this?

The platform runs the repeatable work: discovery, scanning, safe exploitation, prioritisation and reporting, with AI-generated executive summaries and per-finding remediation steps. Your engineers interpret the results and do the fixing, which is the part clients already pay you for. It is not a replacement for human penetration testers on complex, creative engagements, and we do not claim otherwise.

Who is authorised to test the client's systems?

Every client needs its own signed rules of engagement before testing starts, naming the in-scope assets and the authorising party. Scope enforcement then automatically stops activity outside those assets. Where a client uses a third-party host, that provider's written authorisation is required as well.

Can we manage all client agents from one place?

Yes. The fleet orchestrator gives you visibility of every deployed client agent from one console, including the ability to force-update agents across your customer base. Agent updates run in operator-controlled change windows, or can be frozen, so nothing changes inside a client network without your say-so.

Does this make our clients compliant with the Essential Eight or ISO 27001?

No. Those are assessed against a client's whole programme, and certification is granted by an accredited certification body. What the platform provides is technical testing evidence, with findings mapped to 8 compliance reporting frameworks (OWASP Top 10, PCI DSS v4.0, NIST 800-53, SOC 2, HIPAA, GDPR, ISO 27001, SMB1001) plus CIS Benchmarks for AWS, Azure, GCP and Kubernetes. Position it as evidence, not as a certificate.

Test the estate that reaches every client

Start with your own perimeter, identity and management tooling, then decide how far the service line goes. The Partner and MSP programme is sales-led, so tell us about your client base and we will scope it with you.