Black Shard

Penetration testing in Brisbane.

Manual penetration testing of web applications, APIs, networks and cloud environments, scoped in writing and delivered from our Brisbane head office.

Black Shard conducts manual penetration testing of web applications, APIs, networks and cloud environments for businesses in Brisbane and across Australia. We agree the target and testing boundaries before starting. Findings are reproduced, assessed for business impact and documented with the technical information required to remediate them.

A re-test of agreed fixes can be included so closure is based on the deployed system rather than the remediation plan. The head office is on Eagle Street in Brisbane, and scoping, internal network testing and the debrief can run in person for Brisbane organisations.

Scoping and rules of engagement

Every test starts with a written scope and quote. Scope is set against the assets in question: applications, APIs, cloud environments, network segments, or a combination. The quote names its drivers: the size of the attack surface, the number of environments in scope, tenancy count for multi-tenant products, and whether any of the work needs to run on-site.

Rules of engagement are agreed in writing before testing begins. They cover the scope boundary and exclusions, the testing window and any blackout periods, techniques excluded by default such as denial-of-service testing, written authorisation naming who can vary or halt scope, and a stop-work procedure with a named contact on both sides. Access granted for the engagement is least-privilege and time-boxed to the testing window.

What we test

Web applications and APIs are tested against OWASP guidance: authentication and session handling, access control, injection, and application logic. Multi-tenant systems have the tenant boundary tested specifically. Black Shard built and operates Aurii, clinical software that isolates tenant data with PostgreSQL row-level security, and the tenancy checks run on client systems follow the ones applied to that data layer.

Networks are tested against ASD guidance. External testing establishes what is reachable from the internet. Internal testing starts from an assumed foothold and establishes how far it extends, and can run on-site at your Brisbane premises.

Cloud environments are reviewed for identity, network exposure and configuration alongside the application work. Secure code review, red teaming, social engineering testing and Azure security review are separate engagements from the same firm where a test surfaces problems outside its scope.

Findings and reporting

Every finding in the report has been reproduced by a tester before it is written up. Automated tooling is used for coverage; its output is reported as a finding only after a person has confirmed it. Each finding is written with severity, business impact, reproduction steps and the technical detail required to remediate it, for the engineers applying the fix and for the executive signing off on it.

Findings are the client's information. They are held in confidence, and any disclosure to a third-party vendor is made only with the client's consent.

  • A written scope, quote and rules of engagement before testing starts
  • A findings report with severity, business impact, reproduction steps and remediation detail for each issue
  • A debrief with the tester, in person in Brisbane or by video call
  • A re-test of agreed fixes, limited to the findings in the original report

Re-testing

A re-test confirms that each reported finding has been closed on the deployed system. Its scope is limited to the findings raised in the original report. If the environment has changed materially between the test and the re-test, that change is flagged and re-scoping is discussed before the re-test proceeds.

Delivery in Brisbane

Black Shard's head office is on Eagle Street in Brisbane, and penetration testing is delivered Australia-wide from it. For Brisbane organisations, scoping, internal network testing and the debrief can run in person at Eagle Street or at your office. Elsewhere the same engagement runs remotely, with the same report and the same re-test.

Black Shard builds and operates production software as well as testing it. GRM LAW, a Brisbane law firm, runs on an operations and compliance portal Black Shard built and operates, in which every state change is written to an append-only audit ledger.

How much does a penetration test cost?

Penetration testing is quoted as a fixed scope before work starts. Cost is driven by the size of the attack surface, the number of environments in scope, tenancy count for multi-tenant products, and whether on-site internal testing is included. The re-test sits inside the fixed scope.

Send a brief to info@blackshard.com.au and scoping starts from the detail you have.

Questions, answered

Is a vulnerability scan the same as a penetration test?
No. A scanner enumerates known issues. A penetration test confirms which of them are exploitable, chains them where they combine, and assesses the business impact of what is reachable.
Can you test on-site in Brisbane?
Yes. Internal network testing can run from your Brisbane premises, and scoping and the debrief can be held at Eagle Street or at your office. Where on-site work adds nothing, the engagement runs remotely.
How long does a penetration test take?
The timeframe is fixed at scoping and depends on the attack surface, the environments in scope and whether on-site internal testing is included. It is in writing before work starts.
Will a penetration test disrupt production?
Rules of engagement set the testing window, any blackout periods, and the techniques excluded by default. A stop-work procedure with a named contact on both sides is agreed before testing begins, and access is least-privilege for the duration.
Is a re-test included?
A re-test of the findings in the original report can be included in the fixed scope. It confirms closure on the deployed system.

Scope a penetration test with Black Shard.

Brisbane head office. Work delivered across Australia.

Open a briefinfo@blackshard.com.au