Internal testing, no inbound rules

A single on-premise agent per site deploys in about five minutes, needs 0 inbound firewall rules and runs 18+ internal modules.

Active Directory under pressure

Credential testing, password-policy auditing and lateral movement validation across sites joined at different times.

Scope you control

Rules of Engagement, scan exclusions and Stealth, Balanced or Aggressive profiles keep testing inside what you authorise.

Perimeter and remote access

24+ external recon modules map what the internet can see, including vendor support paths and sites inherited through acquisition.

Evidence for customer audits

Compliance-mapped reports export as PDF, CSV and JSON/API, so supplier questionnaires get evidence instead of policy text.

Coverage between shutdowns

Scheduled scans, 7-day asset re-verification and drift detection catch change that an annual report never sees.

The manufacturing attack surface

Manufacturers are measured on uptime, and that single fact shapes the security problem. Production hosts are rarely patched during a run. Engineering workstations are rebuilt from images that are years old. Segmentation that looked clean on a diagram has been quietly bridged by a laptop, a maintenance link, or a temporary firewall rule that outlived the outage that justified it.

The compromise almost never starts on the plant floor. It starts in the ordinary parts of the estate: an exposed remote access service, a supplier portal with a weak password policy, a reused local administrator credential, a service account that has held domain rights since an ERP migration. From there an attacker moves sideways towards the file shares, ERP and scheduling systems that production actually depends on.

Downtime is the loss event. Encrypting a file server does not need to touch a controller to stop a line. Manufacturing testing should therefore focus on access paths and lateral movement, not only on counting missing patches. These are the conditions testing surfaces most often:

  • Flat or partially segmented networks where corporate IT can reach plant-adjacent systems.
  • Vendor and remote support access that stays enabled long after the job that needed it finished.
  • Shared or reused local administrator credentials across engineering and office workstations.
  • Over-privileged service accounts tied to ERP, MES and historian integrations.
  • Legacy Windows hosts kept alive because the software driving a line will not run on anything newer.
  • Acquired sites connected to the corporate network faster than they were ever assessed.
  • Internet-facing supplier portals, order APIs and file transfer services that partners rely on daily.

Where we test, and where we stop

PentestOps is an IT penetration testing platform. It tests corporate and site IT networks, Windows and Active Directory environments, web applications, APIs, cloud accounts and the external perimeter. It does not scan industrial control protocols, interrogate PLCs, or test safety instrumented systems. Automated protocol activity against live control equipment carries real safety risk, so the platform does not do it.

That boundary is enforced, not merely promised. Every scan is tied to per-tenant Rules of Engagement with scope enforcement that automatically stops activity outside authorised assets. You declare the ranges that are in scope, exclude the ones that are not, and pick a Stealth, Balanced or Aggressive profile to match how tolerant each segment is. Sensitive segments are commonly tested with the Stealth profile inside a planned maintenance window.

What IT testing can tell you about the OT boundary is still valuable. From an authorised position on the corporate network, internal testing reports what is reachable across the segmentation you believe exists. If a route towards plant-adjacent infrastructure answers when it should not, that appears as a finding with evidence attached. Standards such as IEC 62443 govern the OT programme itself; PentestOps covers the IT half of that picture, which is where most intrusions begin.

Regulatory and customer pressure

Manufacturers rarely have one regulator driving security work. The pressure arrives from several directions at once.

  • Supply chain assurance. Large buyers, primes and defence-adjacent customers send security questionnaires and contract clauses asking for evidence of regular penetration testing and remediation.
  • The Essential Eight. The Australian Cyber Security Centre's mitigation strategies shape many local programmes, particularly around patching, restricting administrative privileges and hardening user applications.
  • Critical infrastructure obligations. Some manufacturing activity falls within Australia's critical infrastructure regime. Whether it applies to you depends on your sector and assets, so confirm scope with your legal advisers.
  • ISO 27001 and equivalent certifications. Certification programmes expect technical testing and demonstrable remediation, not a policy binder.
  • Insurance and renewal questionnaires. These commonly ask about privileged access, remote access controls and testing cadence.

Mapping, not certification

PentestOps does not issue an Essential Eight maturity rating and does not certify anyone against anything. What it produces is evidence. Reports map findings to 8 compliance reporting frameworks (OWASP Top 10, PCI DSS v4.0, NIST 800-53, SOC 2, HIPAA, GDPR, ISO 27001, SMB1001) plus CIS Benchmarks for AWS, Azure, GCP and Kubernetes, so one assessment answers several questionnaires at once. The mappings show where findings sit against each framework; they are not a certification of your environment.

Regulatory landscape

Three named instruments shape most Australian manufacturing security programmes. The Security of Critical Infrastructure Act captures responsible entities in designated sectors, and where it applies it expects a written risk management programme covering cyber and information security hazards, annual reporting, and mandatory reporting of cyber incidents. Whether your sector and assets are captured is a legal question for your advisers, not something a scanner determines.

The Defence Industry Security Program applies where you hold or are seeking membership to work on defence contracts. It expects documented security governance and ICT controls proportionate to the membership level, maintained over time rather than demonstrated once at entry. Alongside both sits the least formal but most frequent pressure: supply-chain assurance, where primes and large buyers write testing and remediation expectations into contracts and questionnaires.

Read the table as obligation to evidence. PentestOps does not determine whether an obligation applies to you, and it certifies nothing. It produces the dated technical evidence each obligation eventually asks you to hold.

ObligationWhat it asks of the businessEvidence testing can contribute
SOCI Act, where your sector and assets are capturedA written risk management programme covering cyber and information security hazards, with annual reporting and mandatory cyber incident reportingDated technical testing of the IT estate supporting the asset, with findings, evidence and remediation history retained for the reporting cycle
Defence Industry Security Program, where relevantDocumented security governance and ICT controls proportionate to the membership level, maintained over time rather than at entryRecurring assessment of the corporate and site IT networks, Active Directory and remote access paths that carry controlled information
Supply-chain assurance from primes and large buyersContract clauses and questionnaires asking for regular penetration testing, a cadence tied to change, and evidence of remediationReports mapped to 8 compliance reporting frameworks in PDF, CSV and JSON/API, plus scan comparison showing an issue verified as fixed
Privacy Act 1988 and the Notifiable Data Breaches schemeReasonable steps to protect employee, customer and supplier personal information held in ERP, HR and CRM systemsExploit-validated evidence of which paths to those systems are genuinely reachable from the corporate network, rather than a theoretical list
IEC 62443 and the wider OT security programmeZone and conduit design, and assurance that the boundary between corporate IT and plant networks holds in practiceIT-side reporting of what actually answers across that boundary from an authorised position. OT protocol testing stays with a specialist assessor

The scope boundary does not move for a regulator

PentestOps tests IT environments: corporate and site IT networks, Windows and Active Directory, web applications, APIs, cloud accounts and the external perimeter. It does not perform OT or ICS protocol testing. It does not interrogate PLCs, speak industrial protocols, or touch safety instrumented systems, and no regulatory driver changes that. Automated protocol activity against live control equipment carries real safety risk.

Where an obligation reaches into operational technology, that portion needs a specialist OT assessor. PentestOps evidences the IT half, which is where most intrusions that end in production downtime actually begin.

How PentestOps maps to a manufacturing programme

A typical manufacturing engagement has three layers: the perimeter partners and attackers see, the internal estate that carries the business, and the applications sitting between the two.

LayerWhat gets testedHow it runs
Internet-facing perimeterRemote access services, supplier and customer portals, mail and file transfer endpoints, forgotten hosts from acquisitionsAgentless, 24+ external recon modules
Corporate and site networksHost and service discovery, credential testing, lateral movement validation, drift detection between scansOn-premise agent, 18+ internal modules
Active DirectoryPrivilege sprawl, stale accounts, password-policy auditing, exploit chains from a single weak credentialOn-premise agent
Web apps and APIsSupplier portals, order and tracking APIs and public sites against OWASP Top 10 and API Top 10 risksAgentless
Cloud accountsIdentity, storage and network configuration for ERP-adjacent and analytics workloads, against CIS BenchmarksAgentless, read-only credentials

One container per site

Internal coverage comes from a single on-premise agent. It deploys in about five minutes, requires 0 inbound firewall rules, and connects outbound only over TLS 443, so nothing new is exposed at a site. It ships as a Docker container, RPM or DEB package, one host can cover multiple subnets, and internal scans run natively on the LAN instead of tunnelling every packet out to a cloud scanner. For a multi-site manufacturer that means a small container per site rather than a VPN mesh, and discovered credentials are redacted before findings ship.

Typical use cases

  • Pressure-test segmentation assumptions. Scan from the corporate network and see what actually answers across the boundary you rely on, with evidence rather than a diagram.
  • Clean up Active Directory after growth. Active Directory testing surfaces privilege sprawl, stale accounts and weak password policy; our guide to common AD security issues covers the patterns found most often.
  • Assess an acquired site before you trust it. Deploy an agent, scan, and find out what you have inherited before it is fully integrated into the corporate domain.
  • Reduce the pre-conditions for ransomware. Validate the access paths operators actually use: exposed remote access, weak or reused credentials, over-privileged accounts and unrestricted lateral movement.
  • Answer supplier questionnaires with evidence. Export compliance-mapped reports in multiple formats including PDF, CSV and JSON/API instead of restating policy.
  • Keep coverage between annual tests. Scheduled scans plus continuous testing catch the change an annual report misses, backed by 7-day asset re-verification and a full change ledger.

Why manufacturers choose PentestOps

Manufacturing security programmes fail for practical reasons: no budget for a consultant per site, no appetite for inbound firewall changes, and no tolerance for a scanner that surprises the plant. The platform is built around those constraints.

  • Honest scope: IT testing, clearly bounded, with scope enforcement that automatically stops activity outside authorised assets.
  • Testing that fits a maintenance window: scheduled scans, scan exclusions, and Stealth, Balanced or Aggressive profiles.
  • Safe exploitation with a full evidence trail, so remediation debates end quickly. Proof, not guesswork.
  • Asset-wise pricing across sites: pay for the assets in scope, with unlimited scans within fair use. See pricing.
  • Self-hosted AI by default: scan data is analysed on infrastructure operated by Extranet Systems, not sent to third-party model providers. External providers are opt-in per tenant.
  • Australian-built and operated. The platform is hosted in Australia, customer data is stored in Australia, and Extranet Systems Pty Ltd is ISO/IEC 27001:2022 certified.

Frequently Asked Questions

Do you test ICS, SCADA or PLCs?

No. PentestOps tests IT: corporate and site networks, Windows and Active Directory, web applications, APIs, cloud accounts and the external perimeter. It does not scan industrial control protocols or interact with controllers and safety systems. Most intrusions that end in production downtime begin on the IT side, which is the half we cover; specialist OT assessors cover the rest.

Will testing disrupt production?

Testing is bounded by design. Every scan runs against assets you authorise in your Rules of Engagement, scope enforcement stops activity outside them, and scan exclusions keep named hosts and ranges untouched. Choose the Stealth profile for sensitive segments, schedule scans inside a maintenance window, and keep exploitation gated to the assets where you have approved it.

How do you scan a plant site without opening firewall ports?

You deploy the on-premise agent as a Docker container, RPM or DEB package. It takes about five minutes, requires 0 inbound firewall rules, and connects outbound only over TLS 443. One host can cover multiple subnets, so a single small container usually covers a site. See the on-prem agent page for the deployment detail.

Can you validate segmentation between corporate IT and plant networks?

Within IT scope, yes. From an authorised position on the corporate network the platform reports which hosts and services respond across the boundary, so you can compare reality against the design. It does not speak industrial protocols or test the devices themselves, and any range you exclude is never touched.

We run several plants. How does pricing work across sites?

Pricing is asset-wise. One asset is one item the platform can scan or monitor, such as a public IP, hostname, web application, internal subnet target, cloud account or Kubernetes cluster. Scans against an asset are unlimited within fair use, so testing more often costs nothing extra. Current plan detail is on pricing.

Our customers send security questionnaires. Do your reports help?

Yes. Reports map findings to 8 compliance reporting frameworks (OWASP Top 10, PCI DSS v4.0, NIST 800-53, SOC 2, HIPAA, GDPR, ISO 27001, SMB1001) plus CIS Benchmarks for AWS, Azure, GCP and Kubernetes, and export as PDF, CSV and JSON/API. The mappings show where findings sit against each framework; they are not a certification of your environment.

How often should a manufacturer test?

Match cadence to change. Annual testing is a snapshot, and most manufacturing estates change more often than that through new lines, vendor access, acquisitions and integrations. Most teams schedule recurring scans and re-test after significant change; Enterprise customers add continuous monitoring so the perimeter is re-checked between scheduled scans.

Can testing reduce our ransomware exposure?

It targets the pre-conditions. The platform does not simulate encryption; it validates the access paths operators depend on, such as exposed remote access, weak or reused credentials, over-privileged accounts and unrestricted lateral movement, then prioritises fixes by CVSS v3.1 score, exploit availability and CISA KEV status.

See what an attacker could reach from your office network

Deploy one agent at one site and find out what is actually reachable. All paid plans start with a 7-day free trial. A card is required to start your trial and is only charged after the trial ends, unless you cancel first.