An MSP is a high-value target
Start with the provider estate, because that is where exposure concentrates. An MSP holds privileged access into every client it serves: remote monitoring and management tooling, domain administrator credentials, backup consoles, shared password vaults and support accounts that never expire. Attackers understand that arithmetic perfectly. Compromising one provider is a route into many organisations at once, which is why supply chain expectations increasingly reach past the client to the people who manage the client's infrastructure.
The uncomfortable version is that your security posture already sits on your clients' risk registers, whether or not anyone has said so out loud. A client cannot inherit assurance from a provider that has never tested the paths connecting the two networks, and the questionnaires arriving from their customers increasingly ask about you by name.
Testing your own estate with the rigour you sell is both good practice and a strong sales position. That means your own perimeter and management tooling, your own Active Directory and identity posture, and the access paths that connect your network to your clients'. See common Active Directory security issues for the weaknesses that matter most where shared administrative credentials are the norm.
- Remote management and support tooling reachable from the internet, sometimes with authentication that predates the current threat model.
- Shared or reused administrator credentials across multiple client environments, where one disclosure has a very wide blast radius.
- Standing privileged access into client tenants and domains that outlived the project it was created for.
- Backup and recovery consoles, which attackers reach for before anything else in a ransomware scenario.
- Client-facing portals and ticketing systems holding network diagrams, credentials and asset inventories.
- Your own Microsoft 365 tenant, where business email compromise against an MSP is a direct route into client trust.
Regulatory landscape
Almost none of the pressure on a managed service provider arrives as a cyber regulation written for MSPs. It arrives through the clients you serve and the contracts you sign, and it lands on your own environment rather than theirs. A client regulated under APRA CPS 234 must assess the information security capability of the third parties that manage its information assets, which means you. A government client or tender panel asks for Essential Eight alignment and evidence of independent testing before you are listed.
Some obligations you hold directly. The Privacy Act 1988 and the Notifiable Data Breaches scheme apply to personal information you hold or handle, including the client asset inventories, network diagrams and credentials sitting in your own ticketing and documentation systems. Managed services agreements increasingly name controls, a testing cadence and breach notification timeframes, and your own insurer asks about privileged access management at renewal.
The table reads obligation to evidence, and only for your own estate. PentestOps makes neither you nor your clients compliant with anything; it produces the technical evidence these obligations expect you to be able to show.
| Obligation on the provider | What it asks of you | Evidence testing can contribute |
|---|---|---|
| Privacy Act 1988 and the Notifiable Data Breaches scheme | Reasonable steps to protect personal information you hold or handle, and prompt notification of eligible data breaches | Exploit-validated testing of your own perimeter, identity and documentation systems, with a dated remediation history behind each fix |
| Clients regulated under APRA CPS 234 | The regulated entity must assess the information security capability of the third parties managing its information assets, which includes you | Independent, repeatable evidence of your own controls across external, internal, application, identity and cloud surfaces |
| Managed services agreements and flow-down clauses | Named controls, a testing cadence and breach notification timeframes written into the contract rather than the marketing | Scheduled assessments of your own estate, reported against 8 compliance reporting frameworks and exported as PDF, CSV or JSON/API |
| Government and tender panel requirements | Evidence of Essential Eight alignment and independent testing before you can be listed, and again at renewal | Findings on patching, administrative privilege and credential weakness that feed your own uplift plan. PentestOps does not issue a maturity rating |
| ISO 27001 certification of your own management system | Technical testing that feeds the risk treatment cycle, with findings closed out and re-tested rather than merely logged | Findings mapped to ISO 27001, scan comparison confirming a fix, and a 365-day audit log behind the platform activity itself |
| Cyber insurance for your own business | Renewal questions about privileged access management, multi-factor authentication and how often you test | Current, dated reports covering the privileged access paths that connect your network to your clients' environments |
Where the partner programme picks up
This page is about the provider's own security posture. The commercial question, where you deliver testing to your clients under your own brand, has its own page. The MSP security platform covers per-client isolation, white-label branding, custom domains with auto-managed SSL, the fleet orchestrator and the separate MSP plan catalogue in full.
Commercial terms, margin model and onboarding run through the sales-led Partner programme. The sections that follow sketch the sell-through side for context, because the two conversations usually start together; treat the platform page as the authority on how the tenancy and branding actually work.
Your clients are being asked, so you are being asked
Security testing used to be something a client's board raised once a year. It now arrives through the front door of the business: an enterprise customer sends a due diligence questionnaire, an insurer asks what testing is performed at renewal, a bank or insurer client pushes third-party expectations down from APRA CPS 234, and a government tender asks for evidence against the Essential Eight. The client forwards all of it to their managed service provider, because that is who runs their network.
For an MSP that creates two problems at once. The first is commercial: you are being asked to deliver something outside the current stack, and referring it to a consultancy hands the relationship, the margin and the follow-up remediation work to someone else. The second is practical: vulnerability scanners already produce more output than any service desk can action, and clients cannot tell the difference between a long list and a real risk. What changes the conversation is proof of exploitability, which is what attack path validation describes.
Building the capability in-house is not usually the answer either. It means licensing tooling per client, standing up scanning infrastructure in each network, writing report templates, and hiring or renting the skills to interpret the output. Most of that cost is fixed and lands before the first invoice goes out.
Launching a testing service line
The MSP security platform is the same full-stack platform sold to end customers, wrapped in the isolation, branding and fleet management a partner business needs. Each client you onboard gets its own Kubernetes namespace and dedicated PostgreSQL database, so one client's findings, credentials and reports are never visible to another. Clients can sit behind a custom domain with SSL certificates auto-managed via ACME, under your brand rather than ours.
Delivery scales through the fleet orchestrator. Every deployed client agent is visible from one console, with the ability to force-update agents across your customer base rather than scheduling a dozen separate maintenance windows. Because the on-premise agent is outbound-only over TLS 443 and requires 0 inbound firewall rules, onboarding a new client site does not require a firewall change request, a VPN or a jump host.
The Partner and MSP programme is sales-led rather than self-serve. Pricing lives in a separate MSP catalogue with 3 tiers so you can match small clients and large ones without reselling the public plan structure. Findings and reports are retained for 7 years on MSP and Partner arrangements, with 365-day audit logs. Start the conversation through the Partner and MSP programme contact form.
| What the client asks for | What you deliver | How the platform supports it |
|---|---|---|
| Evidence of independent testing for a questionnaire or tender | A dated assessment report under your brand | Findings mapped to 8 compliance reporting frameworks, exported as PDF, CSV or JSON/API |
| Proof that a finding is actually exploitable | A validated finding with evidence, not a scanner score | Safe automated exploitation gated by per-tenant rules of engagement, with a full evidence trail |
| Internal network testing without opening the firewall | Same-day onboarding of a new site | Outbound-only agent, 0 inbound rules, about 5 minutes to deploy, one host can cover multiple subnets |
| Ongoing assurance between annual reviews | A managed continuous testing service | Scheduled assessments, 7-day asset re-verification, drift detection and perimeter re-checks between scans |
| Cloud and Microsoft 365 posture review | A per-tenant posture assessment | 800+ automated checks across AWS, Azure, GCP and M365 via read-only credentials, mapped to CIS Benchmarks |
| Confidence that their data is not mixed with another client's | A dedicated environment per client | Per-client Kubernetes namespace and dedicated database, with no shared tenant data store |
How PentestOps maps to an MSP practice
The coverage you can offer under your own brand spans the same layers your clients already pay you to run:
- Perimeter. 24+ external recon modules map what the internet can see for each client, with no agent required for external testing.
- Internal networks. 18+ internal modules run natively on the LAN through the agent instead of tunnelling every packet out to a remote scanner. See internal network testing.
- Identity. Active Directory testing covers enumeration, credential testing and password-policy auditing across client domains.
- Applications and APIs. Web application testing against OWASP Top 10 risks and API testing across REST and GraphQL.
- Cloud and Kubernetes. Cloud posture auditing via read-only credentials, plus agentless Kubernetes auditing using a read-only kubeconfig with no DaemonSet to install.
- Continuous assurance. External attack surface management re-checks each client perimeter between assessments, which turns a project sale into a recurring service.
- Prioritisation and remediation. CVSS v3.1 scoring, exploit-availability indicators and CISA KEV prioritisation feed an exposure management view, with AI-guided remediation steps your engineers can action directly.
Typical use cases
- MSPs testing their own estate, management tooling and identity posture with the same rigour they sell.
- Providers proving to a regulated client that the paths between their network and the client's have been tested and closed.
- MSPs adding a security testing line without licensing separate tooling for every client environment.
- Providers whose clients are being asked for evidence under the Essential Eight, ISO 27001, SMB1001 or PCI DSS v4.0.
- Resellers and consultancies delivering assessments under their own brand rather than referring work to a third party.
- Providers serving regulated clients that push third-party expectations down from APRA CPS 234.
- Practices running quarterly or monthly assurance for clients instead of a single annual project.
- Providers consolidating agents, findings and reporting for many clients into one console instead of a dozen disconnected tools.
Why MSPs choose PentestOps
Reselling someone else's security product usually means inheriting their branding, their tenancy model and their support hours. This programme is built the other way around.
- Built for resale from the start: white-label branding, custom domains with auto-managed SSL, and a separate 3-tier MSP plan catalogue rather than the public plans structure.
- Isolation you can defend in a client meeting: per-client Kubernetes namespace and dedicated database, with no shared tenant data store.
- Proof, not guesswork: exploitation is gated by per-tenant rules of engagement, scope enforcement automatically stops activity outside authorised assets, and validated findings carry an evidence trail.
- Operationally light: one outbound-only agent per client network, operator-controlled update windows, and no agent orchestrator hub for you to host and maintain.
- Self-hosted AI by default: client scan data is analysed on infrastructure Extranet Systems operates and is not sent to third-party model providers. External providers are opt-in per tenant.
- Australian-built and operated. The platform is hosted in Australia, customer data is stored in Australia, and specific data-residency arrangements are available on request.
- Extranet Systems Pty Ltd is ISO/IEC 27001:2022 certified, independently audited by Atom Assurances, and operates SOC 2-aligned controls. Details are in the Trust Centre.
- Asset-wise economics: your clients pay for the assets in scope, and scans against them are unlimited within fair use, so re-testing after remediation does not eat your margin.