The professional services attack surface
Professional services firms are unusual targets because almost nothing valuable in the building belongs to them. A law firm holds transaction documents, litigation strategy and privileged advice. An accounting practice holds tax file numbers, payroll and financial statements for hundreds of businesses. A consultancy holds the strategy decks and system diagrams of clients far larger than itself. Compromising one firm can be worth more to an attacker than compromising any single client.
The technical picture is usually the opposite of a bank. Small or outsourced IT, a Microsoft 365 tenant doing the heavy lifting, a practice management system that is either hosted by a vendor or quietly ageing in a comms cupboard, and partners who work from anywhere on any device. Attackers rarely need a novel exploit here; they need one valid mailbox and patience. That is why attack path validation matters more than the length of a vulnerability list.
The exposures that recur across firms of every size:
- Microsoft 365 tenants where legacy authentication, weak conditional access or mailbox forwarding rules quietly undo the rest of the security programme.
- Client portals, secure file transfer and document sharing platforms exposed to the internet so clients can self-serve.
- Practice management, time and billing, and trust accounting systems, often internet-reachable for remote work and rarely tested.
- Remote access left over from earlier ways of working: forgotten remote desktop gateways, old VPN appliances and vendor support tools.
- Flat internal networks where one compromised laptop reaches the document management server, the file shares and the backups.
- Active Directory carrying stale partner accounts, shared administrator credentials and password policies nobody has revisited in years.
- Outsourced IT providers holding standing privileged access, which makes their security posture part of yours.
- Marketing sites, event microsites and acquired firms' domains that no one has owned since the person who built them left.
What clients, insurers and regulators expect
Very little of the pressure on professional services firms comes from a single dedicated regulator. It arrives instead through clients. An enterprise or government client sends a due diligence questionnaire before you touch their data. A bank or insurer that engages you is managing its own third-party obligations under APRA CPS 234 and pushes those expectations down its supply chain. A multinational client asks whether your controls line up with ISO 27001, the Essential Eight or SMB1001. Answering with intent rather than evidence is where deals slow down.
Underneath that sit obligations you hold directly. The Privacy Act and the Notifiable Data Breaches scheme require reasonable steps to protect personal information and prompt notification when it is compromised. Firms handling personal data from the EU or UK deal with GDPR expectations. Firms taking card payments for fees fall within PCI DSS v4.0. Professional obligations of confidentiality and privilege sit above all of it, and they do not soften because the failure was technical.
PentestOps is not a certification and does not make your firm compliant with any of these. It produces the technical evidence those obligations depend on, with findings mapped to 8 compliance reporting frameworks (OWASP Top 10, PCI DSS v4.0, NIST 800-53, SOC 2, HIPAA, GDPR, ISO 27001, SMB1001) plus CIS Benchmarks for AWS, Azure, GCP and Kubernetes. Scope and sign-off remain with you and your assessor.
| Driver | What it expects | How PentestOps supports it |
|---|---|---|
| Client due diligence questionnaires | Recent independent testing, findings and evidence that they were remediated | Scheduled assessments with reports in PDF, CSV and JSON/API, plus scan comparison showing issues verified as fixed |
| Privacy Act and Notifiable Data Breaches scheme | Reasonable steps to protect personal information held on behalf of clients and staff | Exploit-validated evidence of what an attacker could actually reach, rather than a theoretical list |
| Clients regulated under APRA CPS 234 | Third-party providers to demonstrate tested and effective information security controls | Repeatable testing across external, internal, application, identity and cloud surfaces with a full audit trail |
| ISO 27001 or Essential Eight programmes | Technical testing that feeds the risk treatment cycle and closes out | Findings mapped to ISO 27001 and re-tested on demand at no extra asset cost |
| PCI DSS v4.0, where card payments are taken | Internal and external penetration testing at least annually and after significant change | On-demand internal and external testing with PCI DSS v4.0 mapping in the report |
| Cyber insurance renewal | Questions about testing, multi-factor authentication and privileged access | Current, dated reports and remediation history retained for 1 to 7 years depending on plan |
Regulatory landscape
Professional obligations bite before any cyber regulation does. A law practice owes confidentiality over client information under the Legal Profession Uniform Law and the conduct rules made under it, and that duty does not soften because the failure was technical rather than a loose conversation. An accounting or tax practice carries comparable duties through the Tax Practitioners Board Code of Professional Conduct, which expects client information to stay confidential and reasonable care in the systems used to handle it.
The Privacy Act 1988 and the Notifiable Data Breaches scheme sit underneath both, applying to personal information the firm holds for clients, staff and applicants. In day-to-day practice, though, the most common trigger for testing is none of these. It is a client security questionnaire: an enterprise or government client, or a bank passing down its own third-party expectations, asking for evidence of recent independent testing before you touch their data. That request usually arrives with a deadline attached to a deal.
The table reads obligation to evidence. Interpreting how each obligation applies to your practice is a matter for the firm and its advisers; PentestOps supplies the technical evidence side and certifies nothing.
| Obligation | What it asks of the firm | Evidence testing can contribute |
|---|---|---|
| Legal Profession Uniform Law and the conduct rules | Confidentiality over client information and privileged material, held to the same standard however the disclosure happens | Evidence of which systems holding matter files, mail and document management are actually reachable, and proof the paths found were closed |
| Tax Practitioners Board Code of Professional Conduct | Client information kept confidential and reasonable care taken in the systems that hold tax, payroll and financial records | Dated assessments of practice management, tax and payroll systems, with prioritised remediation and a retained testing history |
| Privacy Act 1988 and the Notifiable Data Breaches scheme | Reasonable steps to protect personal information held for clients and staff, and prompt notification of eligible data breaches | Exploit-validated findings across perimeter, applications, identity and cloud, rather than a theoretical vulnerability list |
| Client security questionnaires and panel applications | Recent independent testing, a summary of findings and evidence they were remediated, often before you are given access to client data | An executive summary alongside technical detail, mapped to 8 compliance reporting frameworks and exported as PDF, CSV or JSON/API |
| Handling of the assessment report itself | A report describes your weaknesses, so most firms agree in advance who holds it, who may see it and on what terms | Reports stay in your isolated tenant, retained for 1 to 7 years depending on plan, and leave only when you export or share them |
Email, identity and Microsoft 365
For most professional firms, the Microsoft 365 tenant is the business. Client correspondence, engagement letters, matter files and approvals all live in mail and the document stores behind it. That makes identity, not the network perimeter, the real front door, and business email compromise the most consequential attack a firm faces: an attacker with a partner's mailbox does not need malware to redirect a settlement payment.
On Enterprise, PentestOps adds an email audit and a Microsoft 365 audit to the standard scope. Combined with Azure and M365 testing and cloud posture auditing, that covers tenant configuration, identity posture and the administrative roles that quietly accumulate over the years. Each cloud account counts as a single asset, so covering your tenant does not blow out the subscription.
Where a firm still runs an on-premise domain, the same logic applies inside. Active Directory testing covers enumeration, credential testing and password-policy auditing, and common Active Directory security issues explains the weaknesses that turn one phished user into a firm-wide incident.
How PentestOps maps to a professional services firm
One platform and one asset-wise subscription covers the layers a firm actually exposes, without hiring a team to run it:
- Perimeter. 24+ external recon modules map what the internet can see across your domains, including sites nobody remembers, with no agent required for external testing.
- Client portals and web applications. Web application testing against OWASP Top 10 risks, with a live finding stream rather than a report weeks later.
- Integrations. API testing across REST and GraphQL for the connections between practice management, billing and client-facing systems.
- Internal network. An on-premise agent deploys in about 5 minutes, needs 0 inbound firewall rules and runs internal testing natively on the LAN instead of tunnelling every packet out to a remote scanner, using 18+ internal modules.
- Identity and mail. Active Directory testing, plus email and Microsoft 365 auditing on Enterprise.
- Cloud. 800+ automated checks across AWS, Azure, GCP and M365 using read-only credentials, mapped to CIS Benchmarks.
- Prioritisation. CVSS v3.1 scoring, exploit-availability indicators and CISA KEV prioritisation feed an exposure management view of what to fix first, which matters when the fixing is done by two people and a managed service provider.
Turning testing into a commercial asset
Security testing in professional services is rarely bought purely for defence. It is bought because a client asked, because a panel application requires it, or because a partner wants the risk off the table before a large engagement. That means the output has to be usable by non-technical readers as well as whoever fixes the issues.
Every assessment produces an executive summary alongside the technical detail, evidence for validated findings, prioritised remediation guidance and compliance mappings. Reports export as PDF, CSV or JSON/API, and are retained for 1 year on Starter, 3 years on Professional and up to 7 years on Enterprise, with 365-day audit logs. When a client asks what changed since the last report, scan comparison answers it directly.
Because scans against an in-scope asset are unlimited within fair use, re-testing after a fix costs nothing extra. Firms that previously tested once a year, then spent eleven months hoping, can move to a continuous programme where the perimeter is re-checked between assessments and assets are re-verified every 7 days.
Typical use cases
- Law firms testing client portals, document management and secure file transfer before a major client onboards.
- Accounting and advisory practices proving that tax, payroll and trust systems are not reachable from a compromised workstation.
- Consultancies completing enterprise or government due diligence questionnaires with current, dated evidence.
- Firms serving banks and insurers meeting third-party expectations that flow down from APRA CPS 234.
- Practices with outsourced IT wanting independent verification of what their provider says is secure.
- Multi-office or recently merged firms discovering what the other side of the merger left exposed on the internet.
- Firms preparing for ISO 27001 certification or an Essential Eight uplift that needs technical testing evidence.
Why professional services firms choose PentestOps
Most firms do not have a security team. They have a practice manager, an IT provider and a partner who owns risk on top of a full workload. The platform is built so that constraint is not fatal.
- Proof, not guesswork: exploitation is gated by per-tenant rules of engagement, scope enforcement automatically stops activity outside authorised assets, and validated findings carry an evidence trail.
- Findings arrive prioritised with per-issue remediation steps, so a small team knows the order of work rather than receiving a hundred-page list.
- Self-hosted AI by default: scan data is analysed on infrastructure Extranet Systems operates and is not sent to third-party model providers. External providers are opt-in per tenant, which matters when the material is privileged.
- Australian-built and operated. The platform is hosted in Australia, customer data is stored in Australia, and specific data-residency arrangements are available to Enterprise customers on request.
- Every customer runs in an isolated environment with its own dedicated database, with SSO available on Professional and Enterprise. Details are in the Trust Centre.
- Extranet Systems Pty Ltd is ISO/IEC 27001:2022 certified, independently audited by Atom Assurances, and operates SOC 2-aligned controls.
- Asset-wise pricing: pay for the assets in scope, with scans against them unlimited within fair use.