No travel, no waiting list

Testing is delivered by the platform over the network, so distance from a capital city office never decides when your next assessment happens.

Data stays in Australia

Scan results, findings and reports are stored in Australia, on infrastructure Extranet Systems operates.

Proof, not guesswork

Exposures are proven rather than asserted: safe exploitation under signed Rules of Engagement, with scope limits enforced automatically.

Built for distributed sites

The on-premise agent deploys in about 5 minutes, connects outbound-only over TLS 443 with 0 inbound rules, and one host can cover many subnets.

The Brisbane attack surface

Brisbane heads up a state economy built on resources and energy, ports and logistics, construction and engineering, agribusiness, health and aged care, tourism, and a growing technology sector. The common pattern is a corporate head office in the CBD or inner north with operations scattered across regional Queensland, which produces an IT estate stretched over many sites, patchy links, long-lived remote access paths and a directory that has absorbed years of acquisitions.

That distribution is what attackers use. A remote site with a legacy management interface, a contractor account issued for a shutdown and never removed, or a supplier with credentialed access to a corporate application are all far more common entry points than an exotic zero-day. Add the change velocity of cloud and weekly releases and an annual assessment only ever describes the version of the estate that existed during the week it ran.

Closing that gap is the whole point of the platform. Scheduled scans, 7-day re-verification and drift detection track every site rather than just head office, and safe automated exploitation shows which exposures are genuinely reachable instead of returning a ranked list of possibilities.

Australian-built, delivered to Queensland

We will be straight about this: PentestOps does not have a Brisbane office. Extranet Systems Pty Ltd is headquartered at 77 Market Street, Wollongong NSW 2500, with a Sydney office at Level 39, Suite 4, 264 George Street. Queensland customers are served from there. We would rather say so plainly than publish an address we do not occupy.

For a platform-delivered assessment that matters far less than it would for a traditional consulting engagement. External testing runs from the platform over the internet with no agent at all, and internal testing runs through an agent your own team installs in about 5 minutes. Nothing waits on a flight to Brisbane, a hire car to Gladstone or Townsville, or a consultant becoming free next quarter, which is exactly the constraint that keeps regional sites out of scope year after year.

Where the data sits matters as much as who does the testing. Hosting is in Australia on infrastructure Extranet Systems operates, and customer data is stored in Australia. Enterprise customers can ask for specific data-residency arrangements, or run the on-premise deployment option instead. Extranet Systems Pty Ltd is ISO/IEC 27001:2022 certified and independently audited by Atom Assurances, and the platform is built to SOC 2-aligned controls with a SOC 2 attestation on our roadmap. The Trust Centre has the specifics.

What we test for Queensland organisations

Testing follows seven phases grounded in PTES, the OWASP Web Security Testing Guide v4.2 and NIST SP 800-115, and aligned to CREST testing methodology guidance. Signed Rules of Engagement authorise every scan and every exploitation attempt, and scope enforcement shuts down anything reaching past the authorised asset list.

  • Perimeter. 24+ external recon modules map what the internet can see, including remote-site services published years ago and never decommissioned. See external network testing.
  • Internal network. The on-premise agent runs 18+ internal modules natively on the LAN instead of tunnelling every packet out to a remote scanner, which matters on constrained regional links. See internal network testing.
  • Applications and APIs. OWASP Top 10 and API Top 10 coverage over REST and GraphQL endpoints, with findings streaming live instead of arriving in a report a fortnight later.
  • Cloud. 800+ automated checks over AWS, Azure, GCP and M365 measured against CIS Benchmarks, plus an agentless Kubernetes audit driven from a read-only kubeconfig.
  • Identity. Active Directory enumeration, credential testing and password-policy auditing show where a standard account, or a forgotten contractor account, reaches administrative control.
  • Prioritisation. CVE correlation, CVSS v3.1 scoring, exploit-availability indicators and CISA KEV flags put the queue in order, which is what a small central team needs when it covers a dozen sites.

Assurance drivers across Queensland

The prompt is rarely internal. In Queensland it tends to be a tender requirement, an insurer, an auditor, a customer's security questionnaire, or a board that wants more than a status update. Penetration testing confers compliance with nothing. It produces evidence, and evidence is the part those conversations are usually missing.

Queensland contextWhere testing usually starts
Resources, energy and heavy industry corporate estatesExternal perimeter, remote-site internal networks and identity, covering the IT estate rather than plant systems
Ports, logistics and transport operatorsPerimeter discovery across every site, then internal testing and supplier access review
Banking, mutuals and insurers under APRA CPS 234External perimeter and internal network, then continuous coverage between independent annual assessments
Health services and aged care providersPerimeter and identity first, then application testing on the systems clinicians and patients actually reach
Retail, eCommerce and payments in scope for PCI DSS v4.0Web application and API testing across OWASP Top 10 and API Top 10 risks, re-run after each release
Government delivery partners and councilsPerimeter discovery and identity testing, with customer data stored in Australia
Privacy Act 1988 and the Notifiable Data Breaches schemeWhich paths reach systems holding personal information, and how far an attacker gets before detection

Local compliance landscape

Queensland's local instrument is Information Security Policy IS18. It applies to Queensland Government departments and flows out to the suppliers and delivery partners they contract with. IS18 is a policy and reporting instrument rather than a certification, and no scan satisfies it. What it does create is a recurring need for technical evidence about systems that are frequently spread across a very large state.

IS18 sits alongside the national picture, not in place of it. The Essential Eight, the Privacy Act 1988 and the Notifiable Data Breaches scheme still apply to most Queensland organisations, and none of them, IS18 included, is one of the 8 frameworks PentestOps maps findings to in reports. Testing supplies what sits underneath: what is reachable, what is exploitable, and how far it goes. See penetration testing Australia for the national view.

Queensland instrumentWho it reachesWhat testing can evidence
Information Security Policy IS18Queensland Government departments, plus suppliers and delivery partners bound by contractWhether the controls being reported against hold at the perimeter, at remote sites and inside the corporate network
Essential Eight expectations carried into Queensland programmesDepartments, agencies and the partners delivering for themPatch currency on internet-facing and internal systems, and whether administrative privilege restrictions hold when a standard account is compromised
Privacy Act 1988 and the Notifiable Data Breaches schemePublic and private organisations holding personal informationWhich reachable paths lead to personal information, and how far an attacker gets before detection
Local government and tender security clausesCouncils and the vendors bidding to serve themDated findings mapped to the reporting frameworks a tender or security questionnaire actually names

How a Brisbane engagement starts

Nothing here waits on a purchase order or a booked site visit. Authorise the scope, load the assets, and a real scan can be running the same day you sign up, with scope widening from there as your confidence grows.

  • Authorise scope in writing. The Rules of Engagement list what you own or are authorised to test, and scope enforcement blocks everything else without anyone needing to remember.
  • Register the assets, head office and sites alike. Public IPs, hostnames, web applications, internal subnet targets, cloud accounts and Kubernetes clusters each count as one asset, with CSV or XLSX import for long lists.
  • Sweep the perimeter first. No agent is needed, so remote-site exposures surface in the same pass as the CBD ones.
  • Put an agent where the LAN is. Docker, RPM or DEB, about 5 minutes, outbound-only over TLS 443, no VPN and no jump host. One host covers multiple subnets and survives restrictive proxies and flaky regional links. See the agent.
  • Hold a cadence. Scheduled scans, continuous perimeter re-checks and drift detection mean the next assessment starts from a current picture. See continuous penetration testing.

Why Queensland teams choose PentestOps

  • Distance stops deciding scope. A site at Gladstone, Townsville or Cairns gets the same testing as head office, with no travel budget attached to the decision.
  • The vendor is Australian and independently certified. Extranet Systems Pty Ltd holds ISO/IEC 27001:2022, audited by Atom Assurances, and customer data is stored in Australia.
  • Exploit validation separates the exposures that matter from the ones that only look severe on a scanner report.
  • Reports carry mappings to 8 compliance reporting frameworks (OWASP Top 10, PCI DSS v4.0, NIST 800-53, SOC 2, HIPAA, GDPR, ISO 27001, SMB1001) and CIS Benchmarks for AWS, Azure, GCP and Kubernetes, exported as PDF, CSV or JSON/API.
  • AI analysis is self-hosted by default, so findings and evidence are not passed to third-party model providers. External providers remain opt-in per tenant.
  • Asset-wise pricing: one asset is one thing you asked us to scan, and re-testing it costs nothing extra within fair use.

Company and contact details

PentestOps is a product of Extranet Systems Pty Ltd, ABN 29 632 743 189, headquartered at 77 Market Street, Wollongong NSW 2500. We hold no Queensland office, so the way in is +61 1300 290 196 or contact. Support runs Mon-Fri 9am-6pm AEST, with 24/7 support for Enterprise customers.

Frequently Asked Questions

Do you have an office in Brisbane?

No, and we will not pretend otherwise. Extranet Systems Pty Ltd is headquartered at 77 Market Street, Wollongong NSW 2500, with a Sydney office at Level 39, Suite 4, 264 George Street. Queensland customers are served from New South Wales. We list every office we have and never claim ones we do not.

Does that mean slower or lesser service for Queensland customers?

No. PentestOps is delivered as software, so the testing itself does not depend on anyone being in the same city or state. If anything it removes delay: there is no travel to arrange and no wait for a consultant to become available, so you can start a scan the day you sign up. Scoping, briefings and questionnaire support happen by video and phone.

Can you test sites outside Brisbane, including regional Queensland?

Yes, and this is where platform delivery earns its keep. External testing reaches any internet-facing asset regardless of where it sits. For internal testing, the on-premise agent installs on a host at the site as Docker, RPM or DEB, and one host can cover multiple subnets. No travel and no per-site consulting day rate means remote sites stop being the scope that gets cut.

Do you test operational technology or industrial control systems?

No. PentestOps tests IT estates: the external perimeter, internal corporate networks, web applications, APIs, cloud, identity and Kubernetes. We do not scan OT or ICS networks and we will not claim otherwise. What we can do is test the corporate IT estate that commonly sits next to those environments, since that is the side attackers usually reach first. See manufacturing for how we frame that boundary.

Can you test our internal network without a VPN or firewall changes?

Yes. The on-premise agent makes a single outbound TLS 443 connection and accepts nothing inbound, so the count of new firewall rules is 0. It tolerates restrictive corporate proxies via HTTP CONNECT and re-dials on its own when a regional link drops, which matters more in Queensland than it does in a CBD tower. See the agent.

Does this replace an independent penetration test?

No. The platform covers breadth and repetition, which is where distributed Queensland estates usually lose ground, while skilled testers cover depth: business logic flaws, process abuse and the creative work automation handles badly. Most customers keep the periodic independent assessment and use PentestOps to stop the estate drifting between them. See automated penetration testing.

How is it priced?

You pay for assets in scope, not for how often they are tested. An asset is one item the platform can scan or monitor: a public IP, hostname, web application, internal subnet target, cloud account or Kubernetes cluster. A remote site therefore costs the same to test as a CBD one, and testing it monthly costs the same as testing it once. Live plan detail is on pricing.

What support do we get, and in which time zone?

Support runs Mon-Fri 9am-6pm AEST, with 24/7 support for Enterprise customers. Queensland does not observe daylight saving, so for part of the year Brisbane runs an hour behind our NSW teams and the rest of the year the clocks match. Either way you are inside the same working day.

Can we try it before committing?

Yes. A free demo scan at demo scan shows the reporting without an account or a purchase order. For a real assessment against your own scope, every paid plan opens with a 7-day free trial. A card is required to start your trial and is only charged after the trial ends, unless you cancel first.

Test your Queensland estate this week

Sweep the perimeter first, then bring head office and the remote sites in together and leave the cadence running. Prefer to talk it through? Call +61 1300 290 196. All paid plans start with a 7-day free trial, and a card is required to start your trial and is only charged after the trial ends, unless you cancel first.