Client data custodianship

Test the systems that hold other people's confidential material: document stores, client portals, mailboxes and file transfer.

Email and M365 posture

Email audit and Microsoft 365 audit on Enterprise examine the tenant that most professional firms genuinely run their business on.

Answer questionnaires with evidence

Findings map to 8 compliance reporting frameworks and export as PDF, CSV or JSON/API when a client asks how you were tested.

Validated, not theoretical

Safe automated exploitation proves which findings are genuinely reachable, so a small team fixes what matters first.

Internal testing without a VPN

One outbound-only agent deploys in about 5 minutes with 0 inbound firewall rules, including on networks an external IT provider runs.

Australian-hosted, self-hosted AI

Customer data is stored in Australia, and AI analysis runs in-house rather than through third-party model providers.

The professional services attack surface

Professional services firms are unusual targets because almost nothing valuable in the building belongs to them. A law firm holds transaction documents, litigation strategy and privileged advice. An accounting practice holds tax file numbers, payroll and financial statements for hundreds of businesses. A consultancy holds the strategy decks and system diagrams of clients far larger than itself. Compromising one firm can be worth more to an attacker than compromising any single client.

The technical picture is usually the opposite of a bank. Small or outsourced IT, a Microsoft 365 tenant doing the heavy lifting, a practice management system that is either hosted by a vendor or quietly ageing in a comms cupboard, and partners who work from anywhere on any device. Attackers rarely need a novel exploit here; they need one valid mailbox and patience. That is why attack path validation matters more than the length of a vulnerability list.

The exposures that recur across firms of every size:

  • Microsoft 365 tenants where legacy authentication, weak conditional access or mailbox forwarding rules quietly undo the rest of the security programme.
  • Client portals, secure file transfer and document sharing platforms exposed to the internet so clients can self-serve.
  • Practice management, time and billing, and trust accounting systems, often internet-reachable for remote work and rarely tested.
  • Remote access left over from earlier ways of working: forgotten remote desktop gateways, old VPN appliances and vendor support tools.
  • Flat internal networks where one compromised laptop reaches the document management server, the file shares and the backups.
  • Active Directory carrying stale partner accounts, shared administrator credentials and password policies nobody has revisited in years.
  • Outsourced IT providers holding standing privileged access, which makes their security posture part of yours.
  • Marketing sites, event microsites and acquired firms' domains that no one has owned since the person who built them left.

What clients, insurers and regulators expect

Very little of the pressure on professional services firms comes from a single dedicated regulator. It arrives instead through clients. An enterprise or government client sends a due diligence questionnaire before you touch their data. A bank or insurer that engages you is managing its own third-party obligations under APRA CPS 234 and pushes those expectations down its supply chain. A multinational client asks whether your controls line up with ISO 27001, the Essential Eight or SMB1001. Answering with intent rather than evidence is where deals slow down.

Underneath that sit obligations you hold directly. The Privacy Act and the Notifiable Data Breaches scheme require reasonable steps to protect personal information and prompt notification when it is compromised. Firms handling personal data from the EU or UK deal with GDPR expectations. Firms taking card payments for fees fall within PCI DSS v4.0. Professional obligations of confidentiality and privilege sit above all of it, and they do not soften because the failure was technical.

PentestOps is not a certification and does not make your firm compliant with any of these. It produces the technical evidence those obligations depend on, with findings mapped to 8 compliance reporting frameworks (OWASP Top 10, PCI DSS v4.0, NIST 800-53, SOC 2, HIPAA, GDPR, ISO 27001, SMB1001) plus CIS Benchmarks for AWS, Azure, GCP and Kubernetes. Scope and sign-off remain with you and your assessor.

DriverWhat it expectsHow PentestOps supports it
Client due diligence questionnairesRecent independent testing, findings and evidence that they were remediatedScheduled assessments with reports in PDF, CSV and JSON/API, plus scan comparison showing issues verified as fixed
Privacy Act and Notifiable Data Breaches schemeReasonable steps to protect personal information held on behalf of clients and staffExploit-validated evidence of what an attacker could actually reach, rather than a theoretical list
Clients regulated under APRA CPS 234Third-party providers to demonstrate tested and effective information security controlsRepeatable testing across external, internal, application, identity and cloud surfaces with a full audit trail
ISO 27001 or Essential Eight programmesTechnical testing that feeds the risk treatment cycle and closes outFindings mapped to ISO 27001 and re-tested on demand at no extra asset cost
PCI DSS v4.0, where card payments are takenInternal and external penetration testing at least annually and after significant changeOn-demand internal and external testing with PCI DSS v4.0 mapping in the report
Cyber insurance renewalQuestions about testing, multi-factor authentication and privileged accessCurrent, dated reports and remediation history retained for 1 to 7 years depending on plan

Regulatory landscape

Professional obligations bite before any cyber regulation does. A law practice owes confidentiality over client information under the Legal Profession Uniform Law and the conduct rules made under it, and that duty does not soften because the failure was technical rather than a loose conversation. An accounting or tax practice carries comparable duties through the Tax Practitioners Board Code of Professional Conduct, which expects client information to stay confidential and reasonable care in the systems used to handle it.

The Privacy Act 1988 and the Notifiable Data Breaches scheme sit underneath both, applying to personal information the firm holds for clients, staff and applicants. In day-to-day practice, though, the most common trigger for testing is none of these. It is a client security questionnaire: an enterprise or government client, or a bank passing down its own third-party expectations, asking for evidence of recent independent testing before you touch their data. That request usually arrives with a deadline attached to a deal.

The table reads obligation to evidence. Interpreting how each obligation applies to your practice is a matter for the firm and its advisers; PentestOps supplies the technical evidence side and certifies nothing.

ObligationWhat it asks of the firmEvidence testing can contribute
Legal Profession Uniform Law and the conduct rulesConfidentiality over client information and privileged material, held to the same standard however the disclosure happensEvidence of which systems holding matter files, mail and document management are actually reachable, and proof the paths found were closed
Tax Practitioners Board Code of Professional ConductClient information kept confidential and reasonable care taken in the systems that hold tax, payroll and financial recordsDated assessments of practice management, tax and payroll systems, with prioritised remediation and a retained testing history
Privacy Act 1988 and the Notifiable Data Breaches schemeReasonable steps to protect personal information held for clients and staff, and prompt notification of eligible data breachesExploit-validated findings across perimeter, applications, identity and cloud, rather than a theoretical vulnerability list
Client security questionnaires and panel applicationsRecent independent testing, a summary of findings and evidence they were remediated, often before you are given access to client dataAn executive summary alongside technical detail, mapped to 8 compliance reporting frameworks and exported as PDF, CSV or JSON/API
Handling of the assessment report itselfA report describes your weaknesses, so most firms agree in advance who holds it, who may see it and on what termsReports stay in your isolated tenant, retained for 1 to 7 years depending on plan, and leave only when you export or share them

Email, identity and Microsoft 365

For most professional firms, the Microsoft 365 tenant is the business. Client correspondence, engagement letters, matter files and approvals all live in mail and the document stores behind it. That makes identity, not the network perimeter, the real front door, and business email compromise the most consequential attack a firm faces: an attacker with a partner's mailbox does not need malware to redirect a settlement payment.

On Enterprise, PentestOps adds an email audit and a Microsoft 365 audit to the standard scope. Combined with Azure and M365 testing and cloud posture auditing, that covers tenant configuration, identity posture and the administrative roles that quietly accumulate over the years. Each cloud account counts as a single asset, so covering your tenant does not blow out the subscription.

Where a firm still runs an on-premise domain, the same logic applies inside. Active Directory testing covers enumeration, credential testing and password-policy auditing, and common Active Directory security issues explains the weaknesses that turn one phished user into a firm-wide incident.

How PentestOps maps to a professional services firm

One platform and one asset-wise subscription covers the layers a firm actually exposes, without hiring a team to run it:

  • Perimeter. 24+ external recon modules map what the internet can see across your domains, including sites nobody remembers, with no agent required for external testing.
  • Client portals and web applications. Web application testing against OWASP Top 10 risks, with a live finding stream rather than a report weeks later.
  • Integrations. API testing across REST and GraphQL for the connections between practice management, billing and client-facing systems.
  • Internal network. An on-premise agent deploys in about 5 minutes, needs 0 inbound firewall rules and runs internal testing natively on the LAN instead of tunnelling every packet out to a remote scanner, using 18+ internal modules.
  • Identity and mail. Active Directory testing, plus email and Microsoft 365 auditing on Enterprise.
  • Cloud. 800+ automated checks across AWS, Azure, GCP and M365 using read-only credentials, mapped to CIS Benchmarks.
  • Prioritisation. CVSS v3.1 scoring, exploit-availability indicators and CISA KEV prioritisation feed an exposure management view of what to fix first, which matters when the fixing is done by two people and a managed service provider.

Turning testing into a commercial asset

Security testing in professional services is rarely bought purely for defence. It is bought because a client asked, because a panel application requires it, or because a partner wants the risk off the table before a large engagement. That means the output has to be usable by non-technical readers as well as whoever fixes the issues.

Every assessment produces an executive summary alongside the technical detail, evidence for validated findings, prioritised remediation guidance and compliance mappings. Reports export as PDF, CSV or JSON/API, and are retained for 1 year on Starter, 3 years on Professional and up to 7 years on Enterprise, with 365-day audit logs. When a client asks what changed since the last report, scan comparison answers it directly.

Because scans against an in-scope asset are unlimited within fair use, re-testing after a fix costs nothing extra. Firms that previously tested once a year, then spent eleven months hoping, can move to a continuous programme where the perimeter is re-checked between assessments and assets are re-verified every 7 days.

Typical use cases

  • Law firms testing client portals, document management and secure file transfer before a major client onboards.
  • Accounting and advisory practices proving that tax, payroll and trust systems are not reachable from a compromised workstation.
  • Consultancies completing enterprise or government due diligence questionnaires with current, dated evidence.
  • Firms serving banks and insurers meeting third-party expectations that flow down from APRA CPS 234.
  • Practices with outsourced IT wanting independent verification of what their provider says is secure.
  • Multi-office or recently merged firms discovering what the other side of the merger left exposed on the internet.
  • Firms preparing for ISO 27001 certification or an Essential Eight uplift that needs technical testing evidence.

Why professional services firms choose PentestOps

Most firms do not have a security team. They have a practice manager, an IT provider and a partner who owns risk on top of a full workload. The platform is built so that constraint is not fatal.

  • Proof, not guesswork: exploitation is gated by per-tenant rules of engagement, scope enforcement automatically stops activity outside authorised assets, and validated findings carry an evidence trail.
  • Findings arrive prioritised with per-issue remediation steps, so a small team knows the order of work rather than receiving a hundred-page list.
  • Self-hosted AI by default: scan data is analysed on infrastructure Extranet Systems operates and is not sent to third-party model providers. External providers are opt-in per tenant, which matters when the material is privileged.
  • Australian-built and operated. The platform is hosted in Australia, customer data is stored in Australia, and specific data-residency arrangements are available to Enterprise customers on request.
  • Every customer runs in an isolated environment with its own dedicated database, with SSO available on Professional and Enterprise. Details are in the Trust Centre.
  • Extranet Systems Pty Ltd is ISO/IEC 27001:2022 certified, independently audited by Atom Assurances, and operates SOC 2-aligned controls.
  • Asset-wise pricing: pay for the assets in scope, with scans against them unlimited within fair use.

Frequently Asked Questions

We are a small firm with outsourced IT. Is this too much for us?

No. Scope is set by the assets you put in, so a firm with one office, a Microsoft 365 tenant and a client portal pays for exactly that. Findings arrive prioritised with remediation steps, which most firms hand straight to their IT provider as a work list. Reports are written for both a partner and an engineer, so the person approving the spend can read the same document.

Will testing disrupt matters, billing or client access?

Testing is bound to your signed rules of engagement, and scope enforcement automatically stops activity outside authorised assets. Stealth, Balanced and Aggressive profiles let you control intensity, scans can be scheduled outside business hours, and specific hosts can be excluded. Exploitation is used to prove impact rather than to cause it, and every action is recorded.

Does PentestOps cover Microsoft 365 and email?

Yes, on Enterprise, which adds an email audit and a Microsoft 365 audit to the standard scope. Cloud posture auditing runs 800+ automated checks across AWS, Azure, GCP and M365 using read-only credentials, mapped to CIS Benchmarks. Each cloud account or tenant counts as one asset for pricing.

Can we use the report to answer a client security questionnaire?

That is one of the most common reasons firms buy it. Each assessment produces an executive summary, technical detail, evidence for validated findings and prioritised remediation, with findings mapped to 8 compliance reporting frameworks. Export as PDF for the client, or CSV and JSON/API to feed your own register. Share only what your engagement terms allow.

Does this make our firm ISO 27001 certified or compliant?

No. Certification is granted by an accredited certification body after auditing your whole management system, and compliance with the Privacy Act or any other obligation is assessed against your entire programme. PentestOps supplies the technical testing evidence that supports those processes, with findings mapped to ISO 27001 and seven other reporting frameworks. Separately, Extranet Systems Pty Ltd is ISO/IEC 27001:2022 certified as a company.

How does internal testing work if we have no on-site server?

The on-premise agent ships as a Docker container, RPM or DEB and runs on any suitable host on the network, including a small office machine or a virtual machine your IT provider manages. It connects outbound-only over TLS 443, requires 0 inbound firewall rules, no VPN and no jump host, deploys in about 5 minutes, and one host can cover multiple subnets.

How sensitive is the data PentestOps sees, and where does it go?

Scans record configuration and vulnerability evidence, not the contents of client files. Discovered credentials are redacted before findings leave the agent. The platform is hosted in Australia on infrastructure operated by Extranet Systems, customer data is stored in Australia, and AI analysis is self-hosted by default rather than sent to third-party model providers.

How often should a professional services firm test?

Tie the cadence to change rather than the calendar. A new client portal, a practice management upgrade, an office move, a merger or a change of IT provider each invalidate part of an earlier report. Because scans against an in-scope asset are unlimited within fair use, most firms run scheduled assessments plus targeted re-tests after change, with continuous monitoring of the external perimeter on Enterprise.

Prove your clients' data is where you say it is

Test your perimeter, portals, identity and Microsoft 365 from one platform, and keep the evidence current for the next questionnaire. All paid plans start with a 7-day free trial. A card is required to start your trial and is only charged after the trial ends, unless you cancel first.