The manufacturing attack surface
Manufacturers are measured on uptime, and that single fact shapes the security problem. Production hosts are rarely patched during a run. Engineering workstations are rebuilt from images that are years old. Segmentation that looked clean on a diagram has been quietly bridged by a laptop, a maintenance link, or a temporary firewall rule that outlived the outage that justified it.
The compromise almost never starts on the plant floor. It starts in the ordinary parts of the estate: an exposed remote access service, a supplier portal with a weak password policy, a reused local administrator credential, a service account that has held domain rights since an ERP migration. From there an attacker moves sideways towards the file shares, ERP and scheduling systems that production actually depends on.
Downtime is the loss event. Encrypting a file server does not need to touch a controller to stop a line. Manufacturing testing should therefore focus on access paths and lateral movement, not only on counting missing patches. These are the conditions testing surfaces most often:
- Flat or partially segmented networks where corporate IT can reach plant-adjacent systems.
- Vendor and remote support access that stays enabled long after the job that needed it finished.
- Shared or reused local administrator credentials across engineering and office workstations.
- Over-privileged service accounts tied to ERP, MES and historian integrations.
- Legacy Windows hosts kept alive because the software driving a line will not run on anything newer.
- Acquired sites connected to the corporate network faster than they were ever assessed.
- Internet-facing supplier portals, order APIs and file transfer services that partners rely on daily.
Where we test, and where we stop
PentestOps is an IT penetration testing platform. It tests corporate and site IT networks, Windows and Active Directory environments, web applications, APIs, cloud accounts and the external perimeter. It does not scan industrial control protocols, interrogate PLCs, or test safety instrumented systems. Automated protocol activity against live control equipment carries real safety risk, so the platform does not do it.
That boundary is enforced, not merely promised. Every scan is tied to per-tenant Rules of Engagement with scope enforcement that automatically stops activity outside authorised assets. You declare the ranges that are in scope, exclude the ones that are not, and pick a Stealth, Balanced or Aggressive profile to match how tolerant each segment is. Sensitive segments are commonly tested with the Stealth profile inside a planned maintenance window.
What IT testing can tell you about the OT boundary is still valuable. From an authorised position on the corporate network, internal testing reports what is reachable across the segmentation you believe exists. If a route towards plant-adjacent infrastructure answers when it should not, that appears as a finding with evidence attached. Standards such as IEC 62443 govern the OT programme itself; PentestOps covers the IT half of that picture, which is where most intrusions begin.
Regulatory and customer pressure
Manufacturers rarely have one regulator driving security work. The pressure arrives from several directions at once.
- Supply chain assurance. Large buyers, primes and defence-adjacent customers send security questionnaires and contract clauses asking for evidence of regular penetration testing and remediation.
- The Essential Eight. The Australian Cyber Security Centre's mitigation strategies shape many local programmes, particularly around patching, restricting administrative privileges and hardening user applications.
- Critical infrastructure obligations. Some manufacturing activity falls within Australia's critical infrastructure regime. Whether it applies to you depends on your sector and assets, so confirm scope with your legal advisers.
- ISO 27001 and equivalent certifications. Certification programmes expect technical testing and demonstrable remediation, not a policy binder.
- Insurance and renewal questionnaires. These commonly ask about privileged access, remote access controls and testing cadence.
Mapping, not certification
PentestOps does not issue an Essential Eight maturity rating and does not certify anyone against anything. What it produces is evidence. Reports map findings to 8 compliance reporting frameworks (OWASP Top 10, PCI DSS v4.0, NIST 800-53, SOC 2, HIPAA, GDPR, ISO 27001, SMB1001) plus CIS Benchmarks for AWS, Azure, GCP and Kubernetes, so one assessment answers several questionnaires at once. The mappings show where findings sit against each framework; they are not a certification of your environment.
Regulatory landscape
Three named instruments shape most Australian manufacturing security programmes. The Security of Critical Infrastructure Act captures responsible entities in designated sectors, and where it applies it expects a written risk management programme covering cyber and information security hazards, annual reporting, and mandatory reporting of cyber incidents. Whether your sector and assets are captured is a legal question for your advisers, not something a scanner determines.
The Defence Industry Security Program applies where you hold or are seeking membership to work on defence contracts. It expects documented security governance and ICT controls proportionate to the membership level, maintained over time rather than demonstrated once at entry. Alongside both sits the least formal but most frequent pressure: supply-chain assurance, where primes and large buyers write testing and remediation expectations into contracts and questionnaires.
Read the table as obligation to evidence. PentestOps does not determine whether an obligation applies to you, and it certifies nothing. It produces the dated technical evidence each obligation eventually asks you to hold.
| Obligation | What it asks of the business | Evidence testing can contribute |
|---|---|---|
| SOCI Act, where your sector and assets are captured | A written risk management programme covering cyber and information security hazards, with annual reporting and mandatory cyber incident reporting | Dated technical testing of the IT estate supporting the asset, with findings, evidence and remediation history retained for the reporting cycle |
| Defence Industry Security Program, where relevant | Documented security governance and ICT controls proportionate to the membership level, maintained over time rather than at entry | Recurring assessment of the corporate and site IT networks, Active Directory and remote access paths that carry controlled information |
| Supply-chain assurance from primes and large buyers | Contract clauses and questionnaires asking for regular penetration testing, a cadence tied to change, and evidence of remediation | Reports mapped to 8 compliance reporting frameworks in PDF, CSV and JSON/API, plus scan comparison showing an issue verified as fixed |
| Privacy Act 1988 and the Notifiable Data Breaches scheme | Reasonable steps to protect employee, customer and supplier personal information held in ERP, HR and CRM systems | Exploit-validated evidence of which paths to those systems are genuinely reachable from the corporate network, rather than a theoretical list |
| IEC 62443 and the wider OT security programme | Zone and conduit design, and assurance that the boundary between corporate IT and plant networks holds in practice | IT-side reporting of what actually answers across that boundary from an authorised position. OT protocol testing stays with a specialist assessor |
The scope boundary does not move for a regulator
PentestOps tests IT environments: corporate and site IT networks, Windows and Active Directory, web applications, APIs, cloud accounts and the external perimeter. It does not perform OT or ICS protocol testing. It does not interrogate PLCs, speak industrial protocols, or touch safety instrumented systems, and no regulatory driver changes that. Automated protocol activity against live control equipment carries real safety risk.
Where an obligation reaches into operational technology, that portion needs a specialist OT assessor. PentestOps evidences the IT half, which is where most intrusions that end in production downtime actually begin.
How PentestOps maps to a manufacturing programme
A typical manufacturing engagement has three layers: the perimeter partners and attackers see, the internal estate that carries the business, and the applications sitting between the two.
| Layer | What gets tested | How it runs |
|---|---|---|
| Internet-facing perimeter | Remote access services, supplier and customer portals, mail and file transfer endpoints, forgotten hosts from acquisitions | Agentless, 24+ external recon modules |
| Corporate and site networks | Host and service discovery, credential testing, lateral movement validation, drift detection between scans | On-premise agent, 18+ internal modules |
| Active Directory | Privilege sprawl, stale accounts, password-policy auditing, exploit chains from a single weak credential | On-premise agent |
| Web apps and APIs | Supplier portals, order and tracking APIs and public sites against OWASP Top 10 and API Top 10 risks | Agentless |
| Cloud accounts | Identity, storage and network configuration for ERP-adjacent and analytics workloads, against CIS Benchmarks | Agentless, read-only credentials |
One container per site
Internal coverage comes from a single on-premise agent. It deploys in about five minutes, requires 0 inbound firewall rules, and connects outbound only over TLS 443, so nothing new is exposed at a site. It ships as a Docker container, RPM or DEB package, one host can cover multiple subnets, and internal scans run natively on the LAN instead of tunnelling every packet out to a cloud scanner. For a multi-site manufacturer that means a small container per site rather than a VPN mesh, and discovered credentials are redacted before findings ship.
Typical use cases
- Pressure-test segmentation assumptions. Scan from the corporate network and see what actually answers across the boundary you rely on, with evidence rather than a diagram.
- Clean up Active Directory after growth. Active Directory testing surfaces privilege sprawl, stale accounts and weak password policy; our guide to common AD security issues covers the patterns found most often.
- Assess an acquired site before you trust it. Deploy an agent, scan, and find out what you have inherited before it is fully integrated into the corporate domain.
- Reduce the pre-conditions for ransomware. Validate the access paths operators actually use: exposed remote access, weak or reused credentials, over-privileged accounts and unrestricted lateral movement.
- Answer supplier questionnaires with evidence. Export compliance-mapped reports in multiple formats including PDF, CSV and JSON/API instead of restating policy.
- Keep coverage between annual tests. Scheduled scans plus continuous testing catch the change an annual report misses, backed by 7-day asset re-verification and a full change ledger.
Why manufacturers choose PentestOps
Manufacturing security programmes fail for practical reasons: no budget for a consultant per site, no appetite for inbound firewall changes, and no tolerance for a scanner that surprises the plant. The platform is built around those constraints.
- Honest scope: IT testing, clearly bounded, with scope enforcement that automatically stops activity outside authorised assets.
- Testing that fits a maintenance window: scheduled scans, scan exclusions, and Stealth, Balanced or Aggressive profiles.
- Safe exploitation with a full evidence trail, so remediation debates end quickly. Proof, not guesswork.
- Asset-wise pricing across sites: pay for the assets in scope, with unlimited scans within fair use. See pricing.
- Self-hosted AI by default: scan data is analysed on infrastructure operated by Extranet Systems, not sent to third-party model providers. External providers are opt-in per tenant.
- Australian-built and operated. The platform is hosted in Australia, customer data is stored in Australia, and Extranet Systems Pty Ltd is ISO/IEC 27001:2022 certified.