The Melbourne attack surface
Melbourne carries a dense concentration of superannuation and funds management, insurance, health services, universities, logistics and a deep technology sector, and the estates behind them are rarely tidy. A typical organisation runs a cloud-hosted customer platform, a corporate network spread across a CBD head office and suburban or regional sites, an on-premise directory that has absorbed a decade of mergers and restructures, and a supplier list with credentialed access to all three.
Change velocity is the harder problem. A product squad ships to production, a marketing team stands up a campaign site, a contractor is onboarded for a project and never fully offboarded, and a new subdomain starts answering on the public internet before the asset register catches up. An annual assessment only ever describes the version of the estate that existed during the week it ran.
That is the gap PentestOps was built for. A scheduled cadence, 7-day asset re-verification and a drift ledger keep the inventory honest, while safe automated exploitation separates the exposures an attacker could genuinely reach from the ones that merely score highly on a report.
Australian-built, delivered to Victoria
We will be straight about this: PentestOps does not have a Melbourne office. Extranet Systems Pty Ltd is headquartered at 77 Market Street, Wollongong NSW 2500, with a Sydney office at Level 39, Suite 4, 264 George Street. Victorian customers are served from there. We would rather say so plainly than publish an address we do not occupy.
In practice that changes very little, because PentestOps is software rather than a body-shop engagement. External testing runs from the platform over the internet with no agent at all, and internal testing runs through an agent your own team installs in about 5 minutes. Nobody has to travel to a Docklands data hall or a Southbank office to start a scan, which also means there is no scheduling delay while a consultant becomes available. Melbourne runs on the same clock as our support and operations teams all year, so escalations do not wait for an overseas business day to begin.
On residency: the platform is hosted in Australia on infrastructure Extranet Systems operates, and customer data is stored in Australia. Enterprise plans add specific data-residency arrangements on request and an on-premise deployment option for estates that need scan data to stay inside their own boundary. On assurance: Extranet Systems Pty Ltd is ISO/IEC 27001:2022 certified, independently audited by Atom Assurances, and the platform is built to SOC 2-aligned controls with a SOC 2 attestation on our roadmap. The full picture lives in the Trust Centre.
What we test for Melbourne organisations
Every assessment moves through the same seven phases, built on PTES, the OWASP Web Security Testing Guide v4.2 and NIST SP 800-115, and aligned to CREST testing methodology guidance. Signed Rules of Engagement sit behind every scan and every exploitation attempt, and scope enforcement stops activity against anything you have not authorised.
- Perimeter. 24+ external recon modules establish what an outsider can reach, campaign sites and forgotten subdomains included. See external network testing.
- Internal network. 18+ internal modules run on the LAN through the on-premise agent, which is both faster and quieter than tunnelling every packet to a remote scanner. See internal network testing.
- Applications and APIs. OWASP Top 10 and API Top 10 coverage over REST and GraphQL, with findings appearing live while the scan is still running.
- Cloud. 800+ automated checks across AWS, Azure, GCP and M365 measured against CIS Benchmarks, plus an agentless Kubernetes audit that needs only a read-only kubeconfig.
- Identity. Active Directory enumeration, credential testing and password-policy auditing show how far an ordinary account travels before anything stops it.
- Prioritisation. CVE correlation, CVSS v3.1 scoring, exploit availability and CISA KEV flags order the queue, which matters when the security team is also the platform team.
Assurance drivers across Victoria
Almost nobody commissions testing because they feel like it. In Victoria the prompt is normally an auditor, a regulator, a large customer's security questionnaire, or a board paper that needs more than reassurance. Testing will not make an organisation compliant with anything. It produces the technical evidence those discussions keep circling back to.
| Victorian context | Where testing usually starts |
|---|---|
| Superannuation, funds management and insurance under APRA CPS 234 | External perimeter and internal network, then continuous coverage between independent annual assessments |
| Public sector bodies and their delivery partners | Perimeter discovery and identity testing, with customer data stored in Australia |
| Retail, eCommerce and payments in scope for PCI DSS v4.0 | Web application and API testing across OWASP Top 10 and API Top 10 risks, re-run after each release |
| Health services and providers holding patient records | Perimeter and identity first, then application testing on the systems clinicians and patients actually reach |
| Technology and SaaS teams shipping weekly | Web, API and cloud posture testing wired into the release cadence rather than an annual event |
| Privacy Act 1988 and the Notifiable Data Breaches scheme | Which paths reach systems holding personal information, and how far an attacker gets before detection |
Local compliance landscape
Victoria has its own instrument. The Victorian Protective Data Security Framework sets the shape, and the Victorian Protective Data Security Standards issued under it set the expectations. Together they apply to Victorian public sector organisations, and they reach contracted service providers through the arrangements those organisations sign. Like every framework on this page they are governance instruments: no scan satisfies them, and we will not suggest otherwise.
The VPDSS sit alongside the national picture rather than replacing it. The Essential Eight, the Privacy Act 1988 and the Notifiable Data Breaches scheme still apply to most Victorian organisations, and none of them, VPDSS included, is one of the 8 frameworks PentestOps maps findings to in reports. Testing supplies the technical evidence layer underneath. Wider context sits on penetration testing Australia.
| Victorian instrument | Who it reaches | What testing can evidence |
|---|---|---|
| Victorian Protective Data Security Framework | Victorian public sector organisations, and the contracted service providers they engage | A current, dated view of the technical exposure sitting underneath the governance narrative |
| Victorian Protective Data Security Standards (VPDSS) | The same organisations, through the standards issued under the framework | Evidence for the ICT and access control themes: exposed services, weak configuration, and where a standard account reaches administrative control |
| Essential Eight expectations carried into Victorian programmes | Public sector bodies and their delivery partners | Patch currency on internet-facing and internal systems, tested rather than asserted |
| Privacy Act 1988 and the Notifiable Data Breaches scheme | Any Victorian organisation holding personal information | Which reachable paths lead to personal information, and how far an attacker gets before detection |
How a Melbourne engagement starts
There is no procurement cycle required to see your first result, and no site visit to schedule. You can authorise scope, add assets and run a real scan the same day you sign up, then expand scope from there.
- Sign the Rules of Engagement. Scope is authorised in writing before anything runs, and scope enforcement stops activity against assets you did not list.
- Load the estate. A public IP, hostname, web application, internal subnet target, cloud account or Kubernetes cluster is one asset each. CSV and XLSX import handles the long list.
- Start outside. The external perimeter needs no agent, so you can see what the internet sees on day one without touching internal infrastructure.
- Then go inside. Your team installs the agent as Docker, RPM or DEB in about 5 minutes. It dials out over TLS 443 only, needs no VPN or jump host, and one host reaches multiple subnets. See the agent.
- Keep it running. Put scans on a schedule, leave perimeter re-checks and drift detection on, and the picture stays current. See continuous penetration testing.
Why Victorian teams choose PentestOps
- No travel line item and no waiting list. The platform starts scanning the day you authorise scope, which is usually faster than booking a consultant into Melbourne.
- An Australian company stands behind it. Extranet Systems Pty Ltd is ISO/IEC 27001:2022 certified, independently audited by Atom Assurances, and customer data is stored in Australia.
- Findings arrive with a proven attack path attached, which shortens the argument about whether a severity rating reflects real risk.
- Reporting maps to 8 frameworks (OWASP Top 10, PCI DSS v4.0, NIST 800-53, SOC 2, HIPAA, GDPR, ISO 27001, SMB1001) plus CIS Benchmarks for AWS, Azure, GCP and Kubernetes, in PDF, CSV and JSON/API.
- AI runs on infrastructure Extranet Systems operates by default, so your scan data is not sent to a third-party model provider unless you choose to enable one.
- Asset-wise pricing means you pay for scope, not for scan volume. Scans against an in-scope asset are unlimited within fair use.
Company and contact details
PentestOps is a product of Extranet Systems Pty Ltd, ABN 29 632 743 189, registered and operating in New South Wales. There is no Melbourne office, so the way to reach us is +61 1300 290 196 or contact. Support hours are Mon-Fri 9am-6pm AEST, with 24/7 support for Enterprise customers.