Red teaming for Australian organisations.
An objective-driven exercise across people, process and technology, reported as the path taken, the detection timeline, and the controls that would have interrupted it.
Black Shard conducts red team exercises for Australian organisations. The scope is an objective rather than a list of hosts: a named dataset, a transaction, or administrative control of a named system. The exercise works toward that objective across the paths the rules of engagement permit, over a longer window than a penetration test.
The deliverable is the path taken from first contact to the objective, the detection timeline showing what your defenders observed and when, and hardening recommendations ordered by which step in the path they would have interrupted.
Red team or penetration test
A penetration test is scoped by surface and reports what is exploitable across it. A red team exercise is scoped by objective and reports the path that reached it; findings that did not advance the objective are left out of the narrative. The exercise also measures detection: whether monitoring, an internal security function or a managed detection provider observed the activity, when, and what followed.
Organisations without prior testing generally get more from a penetration test first. A red team exercise against an untested surface tends to reach the objective through the first available weakness, which a shorter engagement would have reported.
A penetration test is usually run with the technical team informed. A red team exercise can run with knowledge held by a small authorising group, which is what makes the detection measurement meaningful. That decision is the client's, and the rules of engagement record it.
How an engagement runs
The objective and the rules of engagement are agreed in writing before anything else. The objective is specific enough to be provable: reaching a named dataset, executing a transaction, or holding administrative control of a named system. The rules set what is in bounds and out, which techniques are excluded, who is aware the exercise is running, and the deconfliction path if activity is mistaken for a live incident.
Reconnaissance is conducted from outside: what the organisation publishes about itself, what its suppliers publish about it, what its infrastructure discloses, and who works there in what role. Initial access follows the route reconnaissance made cheapest: an exposed service, a credential reused where it should not have been, a pretext aimed at a person with the access required. From a foothold, the exercise proceeds by escalation and lateral movement toward the objective, with each step recorded as it happens.
The exercise ends with a debrief that walks the path from first contact to objective and stops at each point where a control could have interrupted it.
- A written objective and rules of engagement, including the deconfliction path
- An attack narrative recording the path taken and how far it reached
- The detection timeline: what your defenders observed, when, and what followed
- Hardening recommendations ordered by which step in the path they interrupt
- A re-test of the specific path once hardening lands, where included in scope
Constraints on the exercise
The exercise does not destroy data, does not disrupt production to demonstrate access, and does not exfiltrate personal, clinical or client records. Where proving the objective would mean taking data that matters, it is proven with the smallest possible artefact and the report records what could have been taken.
Phishing and pretext results are reported as per-team figures with the failed verification step identified. Individuals are not named.
A written deconfliction path exists from the first day, so your team can confirm whether an alert is the exercise. If the exercise finds evidence of an intrusion already in progress, it stops and you are told immediately.
Systems we operate
Black Shard builds and operates production software. Aurii, clinical software Black Shard built and operates, isolates tenant data with PostgreSQL row-level security on Azure in Australia. GRM LAW, a Brisbane law firm, runs on an operations and compliance portal in which every state change is written to an append-only audit ledger.
Objectives in red team exercises are commonly reached through undocumented trust relationships, integration accounts with more scope than the integration needs, and administrative paths left over from a migration. The exercise looks for those first.
Black Shard holds SMB1001:2026 Gold, held by the legal entity and verifiable on CyberCert's public registry. OWASP and the ASD Essential Eight are methodologies we work against. Client data stays in Australian regions on the services that host it.
What does a red team exercise cost?
A red team exercise is quoted as a fixed scope before it starts. The window is usually the largest single driver of cost, since the exercise runs longer than a penetration test. The other drivers are the objective, and how many trust boundaries stand between an outsider and it; the vectors in bounds, including whether people and physical access are included; whether the exercise runs without the defenders' knowledge, which adds coordination and deconfliction work; and whether a re-test of the specific path is included once hardening lands. Where physical or on-site vectors are in scope, that portion is scheduled, travelled to, and priced within the fixed scope.
Send a brief to [email protected] with the objective you have in mind, in whatever terms you have. Scoping starts from the objective.
Questions, answered
- How is red teaming different from a penetration test?
- A penetration test is scoped by surface and reports what is exploitable across it. A red team exercise is scoped by objective, takes the path that reaches one named target across whatever vectors the rules allow, and reports the path and the detection timeline.
- Should our IT team know the exercise is running?
- That is your decision, and it changes what is measured. With the team informed, the exercise measures controls. With knowledge held by a small authorising group, it also measures detection and response. In either case a written deconfliction path separates the exercise from a live incident.
- Will a red team exercise break something?
- The exercise does not destroy data, disrupt production to demonstrate access, or exfiltrate records. Where proving the objective would mean taking data that matters, it is proven with the smallest possible artefact and the report records what could have been taken. Boundaries are agreed in writing before the exercise starts.
- How long does a red team engagement take?
- Longer than a penetration test. The window is agreed at scoping and is the largest single driver of cost. A short window pushes the exercise toward noisier techniques, which weakens the detection measurement, and we will say so if the window under discussion undermines the question being asked.
- What do we get at the end?
- An attack narrative recording the path from first contact to objective, the detection timeline showing what your defenders observed and when, hardening recommendations ordered by which step in the path they interrupt, and a debrief with the people who ran the exercise.
- Do you name the people who fell for the phishing?
- No. Social engineering results are reported as per-team figures with the failed verification step identified, and the follow-up is written against that step.
- We have never had a penetration test. Should we start with a red team?
- Generally not. Against an untested surface, a red team exercise tends to reach the objective through the first available weakness, which a penetration test would have reported in a shorter engagement. Test the surface, close what comes back, then run the red team exercise for the questions a test does not answer.
Related reading
The full practice: Penetration testing & red teaming.
Scope a red team exercise with Black Shard.
Brisbane head office. Work delivered across Australia.