Penetration testing for Australian businesses.
Manual penetration testing of web applications, APIs, networks and cloud environments, scoped and quoted in writing before work starts.
Black Shard conducts manual penetration testing of web applications, APIs, networks and cloud environments. We agree the target and testing boundaries before starting. Findings are reproduced, assessed for business impact and documented with the technical information required to remediate them. A re-test of agreed fixes can be included so closure is based on the deployed system rather than the remediation plan.
Black Shard is an Australian software engineering and cybersecurity firm working nationally and internationally. Testing runs against systems wherever in Australia they are operated. It requires a defined scope, provisioned access and an agreed testing window.
Scoping and rules of engagement
Every test starts with a written scope and quote. Scope is set against the assets in question: applications, APIs, cloud environments, network segments, or a combination. The quote names its drivers: the size of the attack surface, the number of environments in scope, tenancy count for multi-tenant products, and whether any of the work needs to run on-site.
Rules of engagement are agreed in writing before testing begins. They cover the scope boundary and exclusions, the testing window and any blackout periods, techniques excluded by default such as denial-of-service testing, written authorisation naming who can vary or halt scope, and a stop-work procedure with a named contact on both sides. Access granted for the engagement is least-privilege and time-boxed to the testing window.
What we test
Web applications and APIs are tested against OWASP guidance: authentication and session handling, access control, injection, and application logic. Multi-tenant systems have the tenant boundary tested specifically. Networks are tested against ASD guidance; external testing establishes what is reachable from the internet, and internal testing starts from an assumed foothold and establishes how far it extends. Cloud environments are reviewed for identity, network exposure and configuration alongside the application work.
Black Shard builds and operates systems in regulated industries. GRM LAW, a Brisbane law firm, runs on an operations and compliance portal in which every state change is written to an append-only audit ledger. Aurii, clinical software Black Shard built and operates, isolates tenant data with PostgreSQL row-level security in Azure's Australia East region. Stone Leaf Capital operates a staff portal Black Shard built, with a sealed compliance audit log structured around the firm's AFSL perimeter. Multi-tenant, audit-logged and regulated systems are tested with those designs as the reference.
Findings and reporting
Every finding in the report has been reproduced by a tester before it is written up. Automated tooling is used for coverage; its output is reported as a finding only after a person has confirmed it. Each finding is written with severity, business impact, reproduction steps and the technical detail required to remediate it, for the engineers applying the fix and for the executive signing off on it.
Findings are the client's information. They are held in confidence, and any disclosure to a third-party vendor is made only with the client's consent.
- A written scope, quote and rules of engagement before testing starts
- A findings report with severity, business impact, reproduction steps and remediation detail for each issue
- A debrief with the tester by video call, or in person in Brisbane
- A re-test of agreed fixes, limited to the findings in the original report
Re-testing
A re-test confirms that each reported finding has been closed on the deployed system. Its scope is limited to the findings raised in the original report. If the environment has changed materially between the test and the re-test, that change is flagged and re-scoping is discussed before the re-test proceeds.
Test material and data handling
A penetration test generates sensitive material: credentials, configuration detail, and evidence of how systems fail. Black Shard is an Australian company, subject to the Privacy Act 1988 and the Notifiable Data Breaches scheme, and the platforms that hold client data run in Australian regions on Microsoft Azure. Engagement data is encrypted in transit and at rest, and access is least-privilege and time-boxed to the testing window.
Black Shard holds SMB1001:2026 Gold, verifiable on the CyberCert public registry. OWASP and ASD guidance are methodologies we test against.
How much does penetration testing cost?
Penetration testing is quoted as a fixed scope before work starts. Cost is driven by the size of the attack surface, the number of environments in scope, tenancy count for multi-tenant products, and whether on-site work is included. The re-test sits inside the fixed scope.
Send a brief to info@blackshard.com.au and scoping starts from the detail you have.
Questions, answered
- Can you test an organisation outside Brisbane?
- Yes. Testing runs remotely against your applications and networks over the same paths they are exposed on, so location is a scoping detail. On-site internal testing is available where the scope calls for it.
- What methodologies do you test against?
- OWASP guidance for applications and APIs, and ASD guidance, including the Essential Eight mitigation strategies, for the surrounding environment. These are methodologies we work against. The firm holds SMB1001:2026 Gold, verifiable on the CyberCert public registry.
- Is a re-test included?
- A re-test of the findings in the original report can be included in the fixed scope. It confirms closure on the deployed system.
- Do you just run a scanner?
- Automated tooling is used for coverage. Nothing is reported as a finding until a tester has reproduced it, and every finding carries the reproduction steps.
- Can I share the report with my board or insurer?
- Yes. Each finding is written with severity, business impact, reproduction steps and remediation detail, so it can be read by an executive and worked from by an engineer.
- How long does a penetration test take?
- The timeframe is fixed at scoping and depends on the attack surface, the environments in scope and tenancy count. It is in writing before testing begins.
- What access do you need?
- Only what the scope requires. Access is least-privilege and time-boxed to the testing window, and the access model is agreed at scoping with the targets and the timeframe.
Scope a penetration test with Black Shard.
Brisbane head office. Work delivered across Australia.