Australian-built and hosted

Built and operated by Extranet Systems, an ISO/IEC 27001:2022 certified Australian company, with customer data stored in Australia.

Evidence, not just severity

Safe, RoE-gated exploitation shows which findings are genuinely reachable, with a full evidence trail behind each one.

Reporting that maps to frameworks

Findings auto-map to 8 compliance reporting frameworks plus CIS Benchmarks, in formats an assessor can read.

Testing for the Canberra market

Canberra's security work is shaped by the people who buy it: federal agencies, the contractors and consultancies that serve them, and the technology firms that sell into both. The common thread is that someone else sets the bar, and you have to show evidence you cleared it.

PentestOps is built for that. Testing runs continuously rather than once a year, every confirmed finding carries evidence rather than a severity score alone, and reports map findings to the frameworks assessors actually ask about.

How we serve Canberra

We should be direct about this: Extranet Systems does not have a Canberra office. Our Australian offices are the Asia-Pacific headquarters at 77 Market Street, Wollongong NSW 2500, and a Sydney office at Level 39, Suite 4, 264 George Street, Sydney NSW 2000.

PentestOps is software, so that matters less than it would for a consultancy. There is no travel to schedule and no consultant to book. You authorise scope, connect your assets, and testing runs. For internal networks the on-premise agent deploys in about five minutes and needs no inbound firewall rules.

Local compliance landscape

These are the regimes Canberra buyers most often test against. Naming them is not a claim that PentestOps certifies you against any of them: testing produces evidence, and an assessor draws the conclusion.

RegimeWhat it expectsWhat testing provides
ACSC Essential EightMitigation strategies assessed at a maturity levelEvidence on patching, application control and administrative privilege exposure
Information Security Manual (ISM)Controls selected against a system's risk profileTechnical findings and evidence to support control assessment
IRAP assessmentIndependent assessment of security controlsTest artefacts and evidence an assessor can review
Protective Security Policy FrameworkProtective security governance and risk practiceRecurring test results demonstrating ongoing assurance
Privacy Act and the NDB schemeProtection of personal information and breach reportingIdentification of exposures that could lead to a notifiable breach

An honest note on accreditation

PentestOps is not IRAP assessed and holds no government accreditation, and we will not imply otherwise. What Extranet Systems does hold is ISO/IEC 27001:2022 certification, independently audited by Atom Assurances, with a copy of the certificate available on request.

If your procurement requires an assessed platform, tell us early and we will tell you plainly whether we fit. Details of hosting, retention and access are in the Trust Centre.

Talk to us

Extranet Systems Pty Ltd, ABN 29 632 743 189. Phone +61 1300 290 196. Support runs Monday to Friday, 9am to 6pm AEST, and 24/7 for Enterprise customers.

You can start with a free demo scan against a domain you own, or contact us to scope a programme.

Frequently Asked Questions

Do you have an office in Canberra?

No. Our Australian offices are the Wollongong headquarters and a Sydney office. PentestOps is delivered as software, so Canberra customers are served the same way as everyone else in Australia, with no travel or scheduling involved.

Is PentestOps IRAP assessed?

No. We do not hold IRAP assessment or any government accreditation, and we will not imply that we do. Extranet Systems is ISO/IEC 27001:2022 certified, and the certificate is available on request. If assessed status is mandatory for your procurement, raise it early.

Can testing support an Essential Eight maturity assessment?

It can provide evidence toward one. Testing surfaces missing patches, exposed administrative interfaces and privilege paths, which map to several of the mitigation strategies. The maturity rating itself is determined by your assessor, not by a tool.

Where is our data stored?

The platform is hosted in Australia on infrastructure operated by Extranet Systems, and customer data is stored in Australia. Authorised personnel in our overseas offices may access it to operate and support the platform; this is set out in the Trust Centre.

How quickly can we start?

There is no procurement cycle needed to see a first result. You can authorise scope, add assets and run a real scan the same day you sign up. For internal network testing the on-premise agent deploys in about five minutes with no inbound firewall rules.

Do you replace our existing pentest provider?

Not necessarily. PentestOps is built to sit alongside a periodic independent assessment, providing continuous coverage between engagements. Many buyers keep both because an assessor may expect an independent test.

What does it cost?

Pricing is asset-wise: you pay for the distinct assets in scope, and scans against them are unlimited within fair use. Live figures are on the pricing page. Partner and MSP arrangements are scoped separately.

Security testing for Canberra teams

Australian-built, with customer data stored in Australia. Start with a free demo scan against a domain you own, or talk to us about scoping a continuous programme.