The Brisbane attack surface
Brisbane heads up a state economy built on resources and energy, ports and logistics, construction and engineering, agribusiness, health and aged care, tourism, and a growing technology sector. The common pattern is a corporate head office in the CBD or inner north with operations scattered across regional Queensland, which produces an IT estate stretched over many sites, patchy links, long-lived remote access paths and a directory that has absorbed years of acquisitions.
That distribution is what attackers use. A remote site with a legacy management interface, a contractor account issued for a shutdown and never removed, or a supplier with credentialed access to a corporate application are all far more common entry points than an exotic zero-day. Add the change velocity of cloud and weekly releases and an annual assessment only ever describes the version of the estate that existed during the week it ran.
Closing that gap is the whole point of the platform. Scheduled scans, 7-day re-verification and drift detection track every site rather than just head office, and safe automated exploitation shows which exposures are genuinely reachable instead of returning a ranked list of possibilities.
Australian-built, delivered to Queensland
We will be straight about this: PentestOps does not have a Brisbane office. Extranet Systems Pty Ltd is headquartered at 77 Market Street, Wollongong NSW 2500, with a Sydney office at Level 39, Suite 4, 264 George Street. Queensland customers are served from there. We would rather say so plainly than publish an address we do not occupy.
For a platform-delivered assessment that matters far less than it would for a traditional consulting engagement. External testing runs from the platform over the internet with no agent at all, and internal testing runs through an agent your own team installs in about 5 minutes. Nothing waits on a flight to Brisbane, a hire car to Gladstone or Townsville, or a consultant becoming free next quarter, which is exactly the constraint that keeps regional sites out of scope year after year.
Where the data sits matters as much as who does the testing. Hosting is in Australia on infrastructure Extranet Systems operates, and customer data is stored in Australia. Enterprise customers can ask for specific data-residency arrangements, or run the on-premise deployment option instead. Extranet Systems Pty Ltd is ISO/IEC 27001:2022 certified and independently audited by Atom Assurances, and the platform is built to SOC 2-aligned controls with a SOC 2 attestation on our roadmap. The Trust Centre has the specifics.
What we test for Queensland organisations
Testing follows seven phases grounded in PTES, the OWASP Web Security Testing Guide v4.2 and NIST SP 800-115, and aligned to CREST testing methodology guidance. Signed Rules of Engagement authorise every scan and every exploitation attempt, and scope enforcement shuts down anything reaching past the authorised asset list.
- Perimeter. 24+ external recon modules map what the internet can see, including remote-site services published years ago and never decommissioned. See external network testing.
- Internal network. The on-premise agent runs 18+ internal modules natively on the LAN instead of tunnelling every packet out to a remote scanner, which matters on constrained regional links. See internal network testing.
- Applications and APIs. OWASP Top 10 and API Top 10 coverage over REST and GraphQL endpoints, with findings streaming live instead of arriving in a report a fortnight later.
- Cloud. 800+ automated checks over AWS, Azure, GCP and M365 measured against CIS Benchmarks, plus an agentless Kubernetes audit driven from a read-only kubeconfig.
- Identity. Active Directory enumeration, credential testing and password-policy auditing show where a standard account, or a forgotten contractor account, reaches administrative control.
- Prioritisation. CVE correlation, CVSS v3.1 scoring, exploit-availability indicators and CISA KEV flags put the queue in order, which is what a small central team needs when it covers a dozen sites.
Assurance drivers across Queensland
The prompt is rarely internal. In Queensland it tends to be a tender requirement, an insurer, an auditor, a customer's security questionnaire, or a board that wants more than a status update. Penetration testing confers compliance with nothing. It produces evidence, and evidence is the part those conversations are usually missing.
| Queensland context | Where testing usually starts |
|---|---|
| Resources, energy and heavy industry corporate estates | External perimeter, remote-site internal networks and identity, covering the IT estate rather than plant systems |
| Ports, logistics and transport operators | Perimeter discovery across every site, then internal testing and supplier access review |
| Banking, mutuals and insurers under APRA CPS 234 | External perimeter and internal network, then continuous coverage between independent annual assessments |
| Health services and aged care providers | Perimeter and identity first, then application testing on the systems clinicians and patients actually reach |
| Retail, eCommerce and payments in scope for PCI DSS v4.0 | Web application and API testing across OWASP Top 10 and API Top 10 risks, re-run after each release |
| Government delivery partners and councils | Perimeter discovery and identity testing, with customer data stored in Australia |
| Privacy Act 1988 and the Notifiable Data Breaches scheme | Which paths reach systems holding personal information, and how far an attacker gets before detection |
Local compliance landscape
Queensland's local instrument is Information Security Policy IS18. It applies to Queensland Government departments and flows out to the suppliers and delivery partners they contract with. IS18 is a policy and reporting instrument rather than a certification, and no scan satisfies it. What it does create is a recurring need for technical evidence about systems that are frequently spread across a very large state.
IS18 sits alongside the national picture, not in place of it. The Essential Eight, the Privacy Act 1988 and the Notifiable Data Breaches scheme still apply to most Queensland organisations, and none of them, IS18 included, is one of the 8 frameworks PentestOps maps findings to in reports. Testing supplies what sits underneath: what is reachable, what is exploitable, and how far it goes. See penetration testing Australia for the national view.
| Queensland instrument | Who it reaches | What testing can evidence |
|---|---|---|
| Information Security Policy IS18 | Queensland Government departments, plus suppliers and delivery partners bound by contract | Whether the controls being reported against hold at the perimeter, at remote sites and inside the corporate network |
| Essential Eight expectations carried into Queensland programmes | Departments, agencies and the partners delivering for them | Patch currency on internet-facing and internal systems, and whether administrative privilege restrictions hold when a standard account is compromised |
| Privacy Act 1988 and the Notifiable Data Breaches scheme | Public and private organisations holding personal information | Which reachable paths lead to personal information, and how far an attacker gets before detection |
| Local government and tender security clauses | Councils and the vendors bidding to serve them | Dated findings mapped to the reporting frameworks a tender or security questionnaire actually names |
How a Brisbane engagement starts
Nothing here waits on a purchase order or a booked site visit. Authorise the scope, load the assets, and a real scan can be running the same day you sign up, with scope widening from there as your confidence grows.
- Authorise scope in writing. The Rules of Engagement list what you own or are authorised to test, and scope enforcement blocks everything else without anyone needing to remember.
- Register the assets, head office and sites alike. Public IPs, hostnames, web applications, internal subnet targets, cloud accounts and Kubernetes clusters each count as one asset, with CSV or XLSX import for long lists.
- Sweep the perimeter first. No agent is needed, so remote-site exposures surface in the same pass as the CBD ones.
- Put an agent where the LAN is. Docker, RPM or DEB, about 5 minutes, outbound-only over TLS 443, no VPN and no jump host. One host covers multiple subnets and survives restrictive proxies and flaky regional links. See the agent.
- Hold a cadence. Scheduled scans, continuous perimeter re-checks and drift detection mean the next assessment starts from a current picture. See continuous penetration testing.
Why Queensland teams choose PentestOps
- Distance stops deciding scope. A site at Gladstone, Townsville or Cairns gets the same testing as head office, with no travel budget attached to the decision.
- The vendor is Australian and independently certified. Extranet Systems Pty Ltd holds ISO/IEC 27001:2022, audited by Atom Assurances, and customer data is stored in Australia.
- Exploit validation separates the exposures that matter from the ones that only look severe on a scanner report.
- Reports carry mappings to 8 compliance reporting frameworks (OWASP Top 10, PCI DSS v4.0, NIST 800-53, SOC 2, HIPAA, GDPR, ISO 27001, SMB1001) and CIS Benchmarks for AWS, Azure, GCP and Kubernetes, exported as PDF, CSV or JSON/API.
- AI analysis is self-hosted by default, so findings and evidence are not passed to third-party model providers. External providers remain opt-in per tenant.
- Asset-wise pricing: one asset is one thing you asked us to scan, and re-testing it costs nothing extra within fair use.
Company and contact details
PentestOps is a product of Extranet Systems Pty Ltd, ABN 29 632 743 189, headquartered at 77 Market Street, Wollongong NSW 2500. We hold no Queensland office, so the way in is +61 1300 290 196 or contact. Support runs Mon-Fri 9am-6pm AEST, with 24/7 support for Enterprise customers.