Black Shard

Find the holes before someone else does.

We attack your systems the way a real adversary would, then hand you a ranked fix list.

Offensive testing is the fastest way to know where you actually stand. We probe your applications, networks, and people the same way an attacker would. Every finding is validated by hand and written up in plain English with reproduction steps and remediation; we do not forward raw scanner output.

The line between a scan and a penetration test is a human adversary.

What a real engagement must have

  • A human who validates every finding
  • An objective an attacker actually wants, not a checklist walk
  • Proof at the end that the holes closed

Penetration testing

Web app, API, and network testing against the OWASP and ASD playbooks.

What you get

  • Ranked findings report with severity, impact, and reproduction steps
  • Plain-English remediation guidance for each issue
  • A re-test to confirm the fixes landed

Red teaming & adversary simulation

A goal-driven, multi-vector simulation against the systems and data an attacker actually wants.

What you get

  • A scoped objective attacked across people, process, and technology
  • An attack narrative showing exactly how far we got and how
  • Prioritised hardening recommendations

Phishing & social-engineering simulation

Controlled phishing and pretext campaigns that measure real-world susceptibility.

What you get

  • A campaign measuring click-through and credential-capture rates
  • Per-team results, without naming and shaming individuals
  • Targeted awareness follow-up for the gaps found

How it is shaped

A fixed-scope engagement with a defined target and timeframe, plus a re-test.

Every engagement includes

  • A director on the work

    A director reads the brief, scopes the engagement, and stays accountable for the result.

  • Fixed scope, quoted first

    Scope, timeframe, and price are agreed before work starts.

  • Findings validated by hand

    Every finding is checked by a human, written in plain English, and paired with a concrete fix. Raw scanner output is never forwarded.

  • A re-test to prove it

    Fixed-scope offensive work includes a re-test, so fixes are confirmed closed rather than assumed.

  • Least-privilege access

    We take only the access the work requires, and client data sits in Australian regions.

  • A report that is yours

    Written for your engineers and your board, and kept confidential.

Questions, answered

Who performs the testing?
Black Shard engineers. The same team that designs, builds, and runs production software performs the offensive work: one team, accountable for both practices. That matters because the person probing your API or reading your authentication flow has shipped and operated systems like it, so findings come back as engineering problems with engineering fixes. Every finding is validated by hand before it reaches the report.
How are our data and access handled during an engagement?
Least privilege, for the duration of the work and no longer. We take only the access the engagement requires, against a defined scope agreed before testing starts. Data is encrypted in transit and at rest, the set of third parties that touch client data is kept deliberately small, and the services that host it run in Australian regions. Anything sensitive an engagement surfaces is handled under the same incident and Privacy Act obligations we hold ourselves to. Our trust page sets these practices out in full, alongside the one certification we hold, SMB1001:2026 Gold.
What do we get at the end?
A ranked findings report. Each finding carries severity, impact, reproduction steps, and a concrete fix, ranked by what it would cost you rather than by scanner score. Red team engagements add an attack narrative showing how far we got and how. The report is written in plain English for the people who will act on it, so leadership and the engineers fixing the issues read the same document. Nothing in it is pasted from a scanner; every finding was proven by a person.
Is a re-test included?
Yes. Fixed-scope offensive work includes a re-test. Once your team has remediated, we re-run the reproduction steps for each finding and confirm the holes are actually closed. The re-test covers the findings from the original engagement; new surface or new features are a new scope, and we say so plainly rather than blur the line. A test that ends at the PDF proves nothing changed. The engagement is finished when the fixes are verified, which is the commitment our approach page describes: fix like an engineer, then prove it.
Do you work outside Brisbane?
Yes. A national firm, head office in Brisbane, delivering Australia-wide. Offensive testing runs against your systems wherever they are hosted: applications, APIs, networks, and people can all be tested remotely under a controlled scope. Scoping, reporting, and the re-test work identically for a client in Perth or Melbourne as for one across town.
What happens after the report lands?
Remediation starts the day it arrives, because each finding already carries a concrete fix. Work the list in ranked order. When the fixes are in, we re-test and confirm they landed. Where findings point at deeper design problems rather than one-line patches, that is where our secure development and advisory work picks up: threat modelling, line-level code review, or a standing security seat at your table.
How is the cost set?
By scope. Offensive work runs as a fixed-scope engagement: a defined target, a defined timeframe, and a re-test. Scoping names what is actually in play, the applications, APIs, networks, and people to be tested, so the price follows the work rather than a rate card. We do not publish indicative prices because a number without a scope misleads in both directions. If the target needs to grow mid-engagement, we re-scope in the open rather than quietly absorb it. A scoped brief gets you a real number.
How do we get started?
Send a brief to [email protected] or through the contact page: what the system is, roughly what it holds, and what prompted the test. It does not need to be polished; naming the target and the concern is enough. From there we scope a fixed-target, fixed-timeframe engagement with the re-test built in, and the scope is agreed before any testing starts.

See what an attacker would find.

Australia-wide, from our Brisbane head office. Someone will contact you as soon as possible.

Open a brief[email protected]