A real Sydney presence

Level 39, Suite 4, 264 George Street, Sydney NSW 2000, running sales and operations, with our Asia-Pacific headquarters in Wollongong.

Data stays in Australia

Hosting runs on Australian infrastructure that Extranet Systems operates itself. Customer data is stored in Australia, not offshore.

Proof, not guesswork

Findings are confirmed by safe automated exploitation, bounded by signed Rules of Engagement and scope enforcement, with evidence kept.

No inbound firewall rules

The on-premise agent deploys in about 5 minutes and connects outbound-only over TLS 443, so 0 inbound rules are required.

The Sydney attack surface

Sydney carries a heavy concentration of corporate head offices, financial services firms, NSW government entities and technology companies, and the estates behind them are rarely tidy. A typical organisation runs a cloud-hosted customer platform, a corporate network spanning a CBD office and a hybrid workforce, an on-premise directory inherited from a decade of restructures and acquisitions, and a supplier list with credentialed access to all three.

Change velocity is the harder problem. Teams reorganise, contractors rotate, a product squad ships to production, and a new subdomain starts answering on the public internet before anyone updates the asset register. An annual assessment only ever describes the version of the estate that existed during the week it ran.

PentestOps exists to shrink that gap. Scans run on a schedule, assets are re-verified every 7 days, drift detection records what changed since the last look, and safe automated exploitation shows which exposures an attacker could actually use rather than producing another ranked list of possibilities.

Local office, Australian platform

PentestOps is a product of Extranet Systems Pty Ltd. Our Sydney office is at Level 39, Suite 4, 264 George Street, Sydney NSW 2000, covering sales and operations, and our Asia-Pacific headquarters is at 77 Market Street, Wollongong NSW 2500.

Being local matters less for the scanning itself than people expect, because the platform is delivered as software and testing happens over the network. It matters a great deal for everything around the testing: scoping, Rules of Engagement, procurement paperwork, security questionnaires, and having someone in your own time zone when a critical finding needs explaining to an executive team.

Hosting sits in Australia on infrastructure Extranet Systems operates, and customer data is stored in Australia. Enterprise customers can request specific data-residency arrangements or take the on-premise deployment option instead. On the vendor side, Extranet Systems Pty Ltd holds ISO/IEC 27001:2022 certification, independently audited by Atom Assurances; the platform itself is built to SOC 2-aligned controls, and a SOC 2 attestation is on our roadmap. Our Trust Centre sets the controls out in full.

What we test for Sydney organisations

Scope is worked through a seven-phase methodology drawn from PTES, the OWASP Web Security Testing Guide v4.2 and NIST SP 800-115, and aligned to CREST testing methodology guidance. Nothing runs without signed Rules of Engagement behind it, and scope enforcement halts any activity that strays outside the authorised asset list.

  • Perimeter. 24+ external recon modules build a picture of what the internet can reach, including the service someone published for a project years ago and never turned off. See external network testing.
  • Internal network. 18+ internal modules execute on the LAN itself through the on-premise agent, rather than dragging every packet out to a remote scanner and back. See internal network testing.
  • Applications and APIs. REST and GraphQL endpoints tested against OWASP Top 10 and API Top 10 risks, with findings streaming live rather than landing in a report weeks later.
  • Cloud. 800+ automated checks spanning AWS, Azure, GCP and M365 with CIS Benchmark coverage, plus an agentless Kubernetes audit driven by a read-only kubeconfig.
  • Identity. Active Directory enumeration, credential testing and password-policy auditing answer the question of what an ordinary user account can reach once somebody else is holding it.
  • Prioritisation. CVE correlation, CVSS v3.1 scores, exploit-availability indicators and CISA KEV flags, so a two-person team knows what to work on come Monday morning.

Assurance drivers across NSW

Testing in Sydney is usually triggered from outside the security team: a regulator, an external auditor, a customer questionnaire, or a board that has started asking harder questions. Penetration testing does not make an organisation compliant with anything. What it supplies is the technical evidence those conversations keep asking for and rarely have.

Sydney contextWhere testing usually starts
Financial services and insurance under APRA CPS 234External perimeter and internal network, then continuous coverage between independent annual assessments
NSW agencies, councils and their delivery partnersPerimeter discovery and identity testing, with customer data stored in Australia
Retail and payments in scope for PCI DSS v4.0Web application and API testing across OWASP Top 10 and API Top 10 risks, re-run after each release
Technology and SaaS product teamsWeb, API and cloud posture testing wired into the release cadence rather than an annual event
Professional services holding client dataExternal perimeter first, then email and M365 posture auditing on Enterprise plans
Privacy Act 1988 and the Notifiable Data Breaches schemeWhich paths reach systems holding personal information, and how far an attacker gets before detection

Local compliance landscape

The local instrument that shapes NSW scoping most often is the NSW Cyber Security Policy. It applies to NSW government agencies, and it reaches their suppliers through contract terms, which is why a private company selling into a department frequently inherits its expectations without being named in it. It is a governance and reporting instrument, not a certification, and no amount of scanning satisfies it on its own.

It sits on top of the national picture rather than replacing it. The Essential Eight, the Privacy Act 1988 and the Notifiable Data Breaches scheme still apply, and none of them, the NSW policy included, is one of the 8 frameworks PentestOps maps findings to in reports. What testing contributes is dated technical evidence you can attach to a report or a supplier response instead of a written assurance. The national view is on penetration testing Australia.

NSW obligationWho it reachesWhat testing can evidence
NSW Cyber Security PolicyNSW government agencies, plus suppliers and delivery partners pulled in through contract termsWhether the controls an agency or its supplier reports on actually hold at the perimeter and inside the corporate network
Essential Eight expectations carried into NSW programmesAgencies and the delivery partners assessed alongside themPatch currency on internet-facing and internal systems, and whether administrative privilege restrictions survive a compromised standard account
Privacy Act 1988 and the Notifiable Data Breaches schemeAgencies and private sector organisations holding personal informationWhich reachable paths lead to personal information, and how far an attacker gets before anything detects them
Third-party assurance clauses in NSW contractsVendors selling into NSW government and large NSW enterprisesIndependent, dated findings mapped to the reporting frameworks a security questionnaire usually names

How a Sydney engagement starts

There is no procurement cycle required to see your first result. You can authorise scope, add assets and run a real scan the same day you sign up, then expand scope from there.

  • Authorise the scope. Sign the Rules of Engagement covering assets you own or are authorised to test. Anything outside that list is blocked automatically by scope enforcement.
  • Add assets. Each public IP, hostname, web application, internal subnet target, cloud account or Kubernetes cluster counts as one asset. Larger estates can bulk import from CSV or XLSX.
  • Run the perimeter first. External testing needs no agent, so the internet-facing picture arrives before anything touches the internal network.
  • Deploy the agent for internal scope. Docker, RPM or DEB, about 5 minutes, outbound-only over TLS 443, no VPN and no jump host. A single host reaches multiple subnets. See the agent.
  • Set a cadence. Scheduled scans, continuous perimeter re-checks and drift detection keep coverage current between assessments. See continuous penetration testing.

Why Sydney teams choose PentestOps

  • A vendor you can meet. Sales and operations sit at 264 George Street, the platform is built and supported out of Wollongong, and nothing gets handed offshore when a finding needs explaining.
  • Extranet Systems Pty Ltd holds ISO/IEC 27001:2022 certification, independently audited by Atom Assurances, with a copy available to customers and prospects on request.
  • Exposures are demonstrated rather than asserted, so a board paper can describe what an attacker reached instead of what a scanner scored.
  • Every finding carries compliance mappings across 8 reporting frameworks (OWASP Top 10, PCI DSS v4.0, NIST 800-53, SOC 2, HIPAA, GDPR, ISO 27001, SMB1001) and CIS Benchmarks for AWS, Azure, GCP and Kubernetes, exportable as PDF, CSV or JSON/API.
  • Scan data is analysed by AI that Extranet Systems hosts itself by default, so it is not handed to third-party model providers. Tenants that want an external provider can opt in.
  • Asset-wise pricing with scans unlimited within fair use, so a retest on release day is not a budget decision.

Reaching the Sydney team

Extranet Systems Pty Ltd, ABN 29 632 743 189. The Sydney office is at Level 39, Suite 4, 264 George Street, Sydney NSW 2000, and the phone number is +61 1300 290 196. Support runs Mon-Fri 9am-6pm AEST, 24/7 for Enterprise customers, or use contact to book a scoping call.

Frequently Asked Questions

Do you actually have an office in Sydney?

Yes. Extranet Systems runs a Sydney office at Level 39, Suite 4, 264 George Street, Sydney NSW 2000, covering sales and operations. Our Asia-Pacific headquarters is at 77 Market Street, Wollongong NSW 2500. We list every office we have and never claim ones we do not.

Does anyone need to come on site to run a test?

No. PentestOps is delivered as software. External testing runs with no agent at all, and internal testing runs through an on-premise agent your team installs in about 5 minutes as a Docker container, RPM or DEB package. Being in Sydney means we can meet for scoping, executive briefings or procurement conversations when that helps.

Where is our scan data stored?

On Australian infrastructure that Extranet Systems operates. Customer data is stored in Australia, which for a NSW agency or a supplier bound by NSW contract terms is usually the first question asked. Enterprise plans add specific data-residency arrangements on request and an on-premise deployment option.

Can you test our internal network without a VPN or firewall changes?

Yes. The agent dials out over TLS 443 through a reverse tunnel and listens on nothing, so 0 inbound firewall rules are needed. It works through restrictive corporate proxies using HTTP CONNECT and reconnects by itself after a link drop. One host reaches multiple subnets, which suits a CBD office with a separate data centre or DR site.

We are an NSW agency. Does this help with the Essential Eight?

Testing is not a maturity assessment and the Essential Eight is not one of the reporting frameworks findings map to. What testing does produce is technical evidence relevant to several of the strategies, particularly patch currency on internet-facing and internal systems and whether administrative privilege restrictions hold when a standard account is compromised. Use it alongside a maturity assessment, not instead of one.

Does this replace an independent penetration test?

No. Think of it as the coverage layer underneath one. The platform handles the repetitive, high-volume work at a cadence no consulting engagement could sustain, which frees your own people and your independent testers for business logic flaws and process abuse, where automation is weakest. Keep the periodic independent assessment and run PentestOps between them.

How is it priced?

By asset, not by scan. An asset is a single thing the platform can scan or monitor: a public IP, a hostname, a web application, an internal subnet target, a cloud account or a Kubernetes cluster. Once an asset is in scope you can test it as often as you like within fair use, so a weekly cadence costs the same as an annual one. Current plan detail is on pricing.

What support do we get, and in which time zone?

Support runs Mon-Fri 9am-6pm AEST, with 24/7 support for Enterprise customers. Sydney sits in the same time zone as our support and operations teams, so escalations do not wait for an overseas business day to start.

Can we try it before committing?

Yes, in two steps. A free demo scan at demo scan shows you the output format without an account. When you want the real thing against your own scope, all paid plans start with a 7-day free trial. A card is required to start your trial and is only charged after the trial ends, unless you cancel first.

Test your Sydney estate this week

Map the perimeter first, bring the internal network in when it suits you, then leave the cadence running. Call +61 1300 290 196 or start online: all paid plans begin with a 7-day free trial, and a card is required to start your trial and is only charged after the trial ends, unless you cancel first.