How PentestOps works in New Zealand
Start with the part most vendor pages bury. PentestOps does not have an office in New Zealand and does not employ staff there. The platform is built and operated by Extranet Systems Pty Ltd, an Australian company headquartered in Wollongong NSW, and New Zealand customers are served remotely as software. Nobody flies over, and nobody needs to.
That works because testing happens over the network rather than in a meeting room. External testing runs with no agent at all. Internal testing uses an on-premise agent your own team installs as a Docker container, RPM or DEB package in about 5 minutes, connecting outbound-only over TLS 443 with 0 inbound firewall rules and no VPN. One host can cover multiple subnets, which suits sites across both islands.
What you lose by not having a local vendor is someone who can sit in your building. What you gain is a platform you can start using the same day, without a procurement cycle, and a testing cadence that keeps running between assessments rather than arriving once a year. Decide which of those matters more to your programme before you shortlist.
Where your data goes, stated plainly
The platform is hosted in Australia on infrastructure operated by Extranet Systems. Customer data is stored in Australia. For a New Zealand organisation that means scan results, asset inventory, findings, evidence and reports relating to your estate are held outside New Zealand.
We flag this rather than leaving it in a schedule at the back of a contract, because it is a decision your privacy officer and your procurement team should make deliberately. The New Zealand Privacy Act 2020 governs how your organisation handles personal information, including when that information is held or handled overseas. We cannot give you legal advice about your own obligations, and we will not tell you the arrangement is automatically fine. Take your own advice, using the facts on this page and in our Trust Centre.
The supporting detail: Extranet Systems Pty Ltd is ISO/IEC 27001:2022 certified, independently audited by Atom Assurances. The platform is built to SOC 2-aligned controls, and a SOC 2 attestation is on our roadmap. Every customer runs in an isolated environment with its own dedicated database, data is encrypted at rest, traffic is protected with TLS in transit, and audit logs are retained for 365 days. You are the data controller and Extranet Systems is the data processor; a signable DPA is available to customers on request. Enterprise customers can request specific data-residency arrangements, or the on-premise deployment option that keeps scan data inside your own boundary.
What gets tested
Every engagement runs the same seven phases, grounded in PTES, the OWASP Web Security Testing Guide v4.2 and NIST SP 800-115, and aligned to CREST testing methodology guidance. Signed Rules of Engagement authorise each scan and each exploitation attempt, and scope enforcement stops anything that reaches outside the assets you listed.
- Perimeter. 24+ external recon modules map the internet-facing surface, including services stood up years ago and never retired. See external network testing.
- Internal network. With the on-premise agent in place, 18+ internal modules execute on the LAN itself rather than tunnelling every packet across the Tasman and back. See internal network testing.
- Applications and APIs. REST and GraphQL coverage against OWASP Top 10 and API Top 10 risks, with findings streaming live during the scan.
- Cloud. 800+ automated checks across AWS, Azure, GCP and M365 against CIS Benchmarks, plus an agentless Kubernetes audit run from a read-only kubeconfig.
- Identity. Active Directory enumeration, credential testing and password-policy auditing establish what one ordinary account can reach once somebody else is using it.
- Prioritisation. CVE correlation, CVSS v3.1 scoring, exploit-availability indicators and CISA KEV flags, which matters most when the entire security function is one or two people.
What drives testing for New Zealand organisations
New Zealand estates are often smaller than their Australian equivalents and just as exposed, run by a security team of one or two people wearing several other hats. The pressure to test usually arrives from outside: an insurer, a customer questionnaire, an Australian parent company, or an incident. Teams following CERT NZ advisories already know which exposures matter; what they lack is evidence of whether those exposures exist in their own estate today.
Testing does not make an organisation compliant with anything, and we will never say it does. What it supplies is technical evidence: what is reachable, what is exploitable, how far an attacker gets, and what to fix first.
| New Zealand context | Where testing usually starts |
|---|---|
| Organisations handling personal information under the Privacy Act 2020 | Which paths reach systems holding personal information, and how far an attacker gets before detection |
| Teams acting on CERT NZ advisories about exposed services | Perimeter discovery with continuous re-checks, so an advisory can be answered with evidence rather than assumption |
| Merchants and payment platforms in scope for PCI DSS v4.0 | Web application and API testing across OWASP Top 10 and API Top 10 risks, re-run after each release |
| New Zealand subsidiaries of Australian groups | One platform covering both sides of the Tasman, with consistent methodology and comparable reporting |
| Vendors answering enterprise security questionnaires | Full-scope assessment with reports mapped to the frameworks the questionnaire asks about |
Local compliance landscape
New Zealand's landscape is its own, and it is worth naming precisely. The New Zealand Information Security Manual (NZISM) sets the technical baseline for government agencies and the suppliers that serve them. The Privacy Act 2020 governs how any organisation handles personal information. CERT NZ publishes the advisories most local teams actually work from. None of the three is a certification, and none is satisfied by running a scan.
The material fact for a New Zealand buyer belongs at the front, not in a schedule: customer data is stored in Australia, not in New Zealand. For an NZISM-scoped agency or a privacy officer applying the Privacy Act 2020, that is the first thing to weigh. It is also worth knowing that NZISM, the Privacy Act 2020 and CERT NZ guidance are not among the 8 frameworks PentestOps maps findings to in reports. We supply technical evidence; the compliance judgement stays with you and your advisers.
| New Zealand instrument | Who it reaches | What testing can evidence |
|---|---|---|
| New Zealand Information Security Manual (NZISM) | Government agencies and the suppliers that build, host or operate their systems | Exposed services, weak configuration and hardening gaps on in-scope systems, with evidence attached. Note that customer data is stored in Australia |
| Privacy Act 2020 | Any organisation handling personal information about New Zealanders | Which reachable paths lead to systems holding personal information, and how far an attacker gets before detection |
| CERT NZ advisories | Any team acting on published guidance about exposed or actively exploited services | Whether an advisory applies to your estate today, answered with perimeter evidence instead of assumption |
| Cross-border hosting review | Privacy officers and procurement teams assessing an Australian platform | The documented facts to assess: data stored in Australia, an ISO/IEC 27001:2022 certified processor, encryption at rest, TLS in transit, 365-day audit logs and a signable DPA |
Getting started from New Zealand
There is no onshore onboarding process to wait for. You can authorise scope, add assets and run a real scan the same day you sign up, then expand scope from there. See continuous penetration testing for how the ongoing cadence works once the first assessment is done.
- Authorise the scope. Sign the Rules of Engagement covering assets you own or are authorised to test. Scope enforcement stops activity outside them automatically.
- Add assets. A public IP, hostname, web application, internal subnet target, cloud account or Kubernetes cluster each count as one asset. Bulk CSV or XLSX import is available for larger estates.
- Run the perimeter first. External testing needs no agent, so you see the internet-facing surface before touching the internal network.
- Deploy the agent for internal scope. Docker, RPM or DEB, about 5 minutes, outbound-only over TLS 443. See the agent.
- Set a cadence. Scheduled scans, continuous perimeter re-checks and drift detection keep coverage current between assessments.
Being honest about the trade-off
If your organisation has a firm requirement that security data stay onshore in New Zealand, our standard offering does not meet it, and we would rather tell you now than three meetings in. Enterprise customers can discuss specific data-residency arrangements or the on-premise deployment option with us; anything else is a conversation, not a checkbox.
If cross-Tasman hosting works for your risk position, the trade generally favours you: an ISO/IEC 27001:2022 certified vendor, asset-wise pricing with scans unlimited within fair use, exploit-validated findings rather than a severity list, AI analysis that is self-hosted by default so scan data is not sent to third-party model providers, and reports mapped to 8 compliance reporting frameworks (OWASP Top 10, PCI DSS v4.0, NIST 800-53, SOC 2, HIPAA, GDPR, ISO 27001, SMB1001) plus CIS Benchmarks for AWS, Azure, GCP and Kubernetes.
Support runs Mon-Fri 9am-6pm AEST, with 24/7 support for Enterprise customers. New Zealand time runs ahead of that clock, so the earliest part of your morning sits outside standard hours. Scans, alerts and reporting run regardless.
Company and contact details
For the procurement file: PentestOps is a product of Extranet Systems Pty Ltd, an Australian company with ABN 29 632 743 189, headquartered at 77 Market Street, Wollongong NSW 2500. There is no New Zealand office and no New Zealand-based staff, so the contact number is the Australian one, +61 1300 290 196, or reach us through contact.