No travel, no waiting list

Testing is delivered by the platform over the network, so there is no consultant to fly in and no booking queue between you and a first scan.

Data stays in Australia

Extranet Systems operates the hosting infrastructure itself, inside Australia. Customer data is stored in Australia.

Proof, not guesswork

Every severity comes with a demonstrated attack path, executed safely under signed Rules of Engagement with scope enforced automatically.

No inbound firewall rules

About 5 minutes to deploy the on-premise agent, which dials out over TLS 443 only. 0 inbound rules, no VPN, no jump host.

The Melbourne attack surface

Melbourne carries a dense concentration of superannuation and funds management, insurance, health services, universities, logistics and a deep technology sector, and the estates behind them are rarely tidy. A typical organisation runs a cloud-hosted customer platform, a corporate network spread across a CBD head office and suburban or regional sites, an on-premise directory that has absorbed a decade of mergers and restructures, and a supplier list with credentialed access to all three.

Change velocity is the harder problem. A product squad ships to production, a marketing team stands up a campaign site, a contractor is onboarded for a project and never fully offboarded, and a new subdomain starts answering on the public internet before the asset register catches up. An annual assessment only ever describes the version of the estate that existed during the week it ran.

That is the gap PentestOps was built for. A scheduled cadence, 7-day asset re-verification and a drift ledger keep the inventory honest, while safe automated exploitation separates the exposures an attacker could genuinely reach from the ones that merely score highly on a report.

Australian-built, delivered to Victoria

We will be straight about this: PentestOps does not have a Melbourne office. Extranet Systems Pty Ltd is headquartered at 77 Market Street, Wollongong NSW 2500, with a Sydney office at Level 39, Suite 4, 264 George Street. Victorian customers are served from there. We would rather say so plainly than publish an address we do not occupy.

In practice that changes very little, because PentestOps is software rather than a body-shop engagement. External testing runs from the platform over the internet with no agent at all, and internal testing runs through an agent your own team installs in about 5 minutes. Nobody has to travel to a Docklands data hall or a Southbank office to start a scan, which also means there is no scheduling delay while a consultant becomes available. Melbourne runs on the same clock as our support and operations teams all year, so escalations do not wait for an overseas business day to begin.

On residency: the platform is hosted in Australia on infrastructure Extranet Systems operates, and customer data is stored in Australia. Enterprise plans add specific data-residency arrangements on request and an on-premise deployment option for estates that need scan data to stay inside their own boundary. On assurance: Extranet Systems Pty Ltd is ISO/IEC 27001:2022 certified, independently audited by Atom Assurances, and the platform is built to SOC 2-aligned controls with a SOC 2 attestation on our roadmap. The full picture lives in the Trust Centre.

What we test for Melbourne organisations

Every assessment moves through the same seven phases, built on PTES, the OWASP Web Security Testing Guide v4.2 and NIST SP 800-115, and aligned to CREST testing methodology guidance. Signed Rules of Engagement sit behind every scan and every exploitation attempt, and scope enforcement stops activity against anything you have not authorised.

  • Perimeter. 24+ external recon modules establish what an outsider can reach, campaign sites and forgotten subdomains included. See external network testing.
  • Internal network. 18+ internal modules run on the LAN through the on-premise agent, which is both faster and quieter than tunnelling every packet to a remote scanner. See internal network testing.
  • Applications and APIs. OWASP Top 10 and API Top 10 coverage over REST and GraphQL, with findings appearing live while the scan is still running.
  • Cloud. 800+ automated checks across AWS, Azure, GCP and M365 measured against CIS Benchmarks, plus an agentless Kubernetes audit that needs only a read-only kubeconfig.
  • Identity. Active Directory enumeration, credential testing and password-policy auditing show how far an ordinary account travels before anything stops it.
  • Prioritisation. CVE correlation, CVSS v3.1 scoring, exploit availability and CISA KEV flags order the queue, which matters when the security team is also the platform team.

Assurance drivers across Victoria

Almost nobody commissions testing because they feel like it. In Victoria the prompt is normally an auditor, a regulator, a large customer's security questionnaire, or a board paper that needs more than reassurance. Testing will not make an organisation compliant with anything. It produces the technical evidence those discussions keep circling back to.

Victorian contextWhere testing usually starts
Superannuation, funds management and insurance under APRA CPS 234External perimeter and internal network, then continuous coverage between independent annual assessments
Public sector bodies and their delivery partnersPerimeter discovery and identity testing, with customer data stored in Australia
Retail, eCommerce and payments in scope for PCI DSS v4.0Web application and API testing across OWASP Top 10 and API Top 10 risks, re-run after each release
Health services and providers holding patient recordsPerimeter and identity first, then application testing on the systems clinicians and patients actually reach
Technology and SaaS teams shipping weeklyWeb, API and cloud posture testing wired into the release cadence rather than an annual event
Privacy Act 1988 and the Notifiable Data Breaches schemeWhich paths reach systems holding personal information, and how far an attacker gets before detection

Local compliance landscape

Victoria has its own instrument. The Victorian Protective Data Security Framework sets the shape, and the Victorian Protective Data Security Standards issued under it set the expectations. Together they apply to Victorian public sector organisations, and they reach contracted service providers through the arrangements those organisations sign. Like every framework on this page they are governance instruments: no scan satisfies them, and we will not suggest otherwise.

The VPDSS sit alongside the national picture rather than replacing it. The Essential Eight, the Privacy Act 1988 and the Notifiable Data Breaches scheme still apply to most Victorian organisations, and none of them, VPDSS included, is one of the 8 frameworks PentestOps maps findings to in reports. Testing supplies the technical evidence layer underneath. Wider context sits on penetration testing Australia.

Victorian instrumentWho it reachesWhat testing can evidence
Victorian Protective Data Security FrameworkVictorian public sector organisations, and the contracted service providers they engageA current, dated view of the technical exposure sitting underneath the governance narrative
Victorian Protective Data Security Standards (VPDSS)The same organisations, through the standards issued under the frameworkEvidence for the ICT and access control themes: exposed services, weak configuration, and where a standard account reaches administrative control
Essential Eight expectations carried into Victorian programmesPublic sector bodies and their delivery partnersPatch currency on internet-facing and internal systems, tested rather than asserted
Privacy Act 1988 and the Notifiable Data Breaches schemeAny Victorian organisation holding personal informationWhich reachable paths lead to personal information, and how far an attacker gets before detection

How a Melbourne engagement starts

There is no procurement cycle required to see your first result, and no site visit to schedule. You can authorise scope, add assets and run a real scan the same day you sign up, then expand scope from there.

  • Sign the Rules of Engagement. Scope is authorised in writing before anything runs, and scope enforcement stops activity against assets you did not list.
  • Load the estate. A public IP, hostname, web application, internal subnet target, cloud account or Kubernetes cluster is one asset each. CSV and XLSX import handles the long list.
  • Start outside. The external perimeter needs no agent, so you can see what the internet sees on day one without touching internal infrastructure.
  • Then go inside. Your team installs the agent as Docker, RPM or DEB in about 5 minutes. It dials out over TLS 443 only, needs no VPN or jump host, and one host reaches multiple subnets. See the agent.
  • Keep it running. Put scans on a schedule, leave perimeter re-checks and drift detection on, and the picture stays current. See continuous penetration testing.

Why Victorian teams choose PentestOps

  • No travel line item and no waiting list. The platform starts scanning the day you authorise scope, which is usually faster than booking a consultant into Melbourne.
  • An Australian company stands behind it. Extranet Systems Pty Ltd is ISO/IEC 27001:2022 certified, independently audited by Atom Assurances, and customer data is stored in Australia.
  • Findings arrive with a proven attack path attached, which shortens the argument about whether a severity rating reflects real risk.
  • Reporting maps to 8 frameworks (OWASP Top 10, PCI DSS v4.0, NIST 800-53, SOC 2, HIPAA, GDPR, ISO 27001, SMB1001) plus CIS Benchmarks for AWS, Azure, GCP and Kubernetes, in PDF, CSV and JSON/API.
  • AI runs on infrastructure Extranet Systems operates by default, so your scan data is not sent to a third-party model provider unless you choose to enable one.
  • Asset-wise pricing means you pay for scope, not for scan volume. Scans against an in-scope asset are unlimited within fair use.

Company and contact details

PentestOps is a product of Extranet Systems Pty Ltd, ABN 29 632 743 189, registered and operating in New South Wales. There is no Melbourne office, so the way to reach us is +61 1300 290 196 or contact. Support hours are Mon-Fri 9am-6pm AEST, with 24/7 support for Enterprise customers.

Frequently Asked Questions

Do you have an office in Melbourne?

No, and we will not pretend otherwise. Extranet Systems Pty Ltd is headquartered at 77 Market Street, Wollongong NSW 2500, with a Sydney office at Level 39, Suite 4, 264 George Street. Victorian customers are served from New South Wales. We list every office we have and never claim ones we do not.

Does that mean slower or lesser service for Melbourne customers?

No. PentestOps is delivered as software, so the testing itself does not depend on anyone being in the same city. If anything it removes delay: there is no travel to arrange and no wait for a consultant to become available, so you can start a scan the day you sign up. Scoping, briefings and questionnaire support happen by video and phone, in your time zone.

Where is our scan data stored?

In Australia, on infrastructure Extranet Systems operates rather than resells. Customer data is stored in Australia, which is the answer Victorian public sector buyers and their contracted providers usually need in writing. Enterprise customers can request specific data-residency arrangements, or take the on-premise deployment option.

Can you test our internal network without a VPN or firewall changes?

Yes. The on-premise agent opens an outbound TLS 443 tunnel and accepts no inbound connections at all, so the answer to your firewall team is 0 new rules. It negotiates restrictive corporate proxies over HTTP CONNECT and re-establishes itself after a link drop. One host covers multiple subnets, so a CBD office and a suburban site can share it. See the agent.

We are a Victorian public sector body. Does this help with VPDSS or the Essential Eight?

It contributes evidence to both and satisfies neither. The VPDSS and the Essential Eight are governance instruments assessed through their own processes, and neither is one of the reporting frameworks findings map to. What testing delivers is the technical layer those processes ask about: patch currency on internet-facing and internal systems, exposed or weakly configured services, and whether administrative privilege restrictions hold once a standard account is compromised. Run it alongside your maturity or VPDSS work, never instead of it.

Does this replace an independent penetration test?

No, and treating it that way would be a mistake. The platform is very good at breadth and repetition: everything reachable, checked again and again, at a frequency no engagement could match. It is weakest exactly where skilled testers are strongest, on business logic flaws and process abuse. Most Victorian customers keep their periodic independent assessment and use PentestOps to hold coverage between them. See automated penetration testing.

How is it priced?

Per asset in scope, never per scan. An asset is one thing the platform can scan or monitor: a public IP, hostname, web application, internal subnet target, cloud account or Kubernetes cluster. Because scans against an in-scope asset are unlimited within fair use, testing after every release costs no more than testing once. Live plan detail sits on pricing.

What support do we get, and in which time zone?

Support runs Mon-Fri 9am-6pm AEST, with 24/7 support for Enterprise customers. Melbourne and our NSW teams keep the same business hours through the year, including daylight saving, so escalations are handled inside your working day.

Can we try it before committing?

Yes. Start with a free demo scan at demo scan if you just want to see what the reporting looks like. When you are ready to point it at your own scope, every paid plan opens with a 7-day free trial. A card is required to start your trial and is only charged after the trial ends, unless you cancel first.

Test your Melbourne estate this week

No flights to book and no queue to join. Begin at the perimeter, bring the internal network in next, and hold the cadence from there. Questions first? Call +61 1300 290 196. Every paid plan opens with a 7-day free trial, and a card is required to start your trial and is only charged after the trial ends, unless you cancel first.