Black Shard

Penetration testing and red teaming.

We test applications, APIs, networks and cloud environments for vulnerabilities that can be reproduced and exploited.

Talk to us about a penetration test

Findings are manually verified before they are reported. Each report explains the affected system, the attack path, the likely impact and the remediation required. Penetration testing is suited to a defined application or environment. Red teaming is broader.

Penetration testing, red teaming and social engineering

It starts with an objective and tests whether an attacker could reach it across multiple technical and human controls. Social-engineering assessments are included when staff processes form part of the attack surface.

Penetration testing

Web application, API, network and cloud environment testing against OWASP guidance and ASD playbooks.

What you get

  • Findings ranked by severity, with the affected system, attack path, likely impact and reproduction steps
  • Remediation guidance for each finding, written for the engineers who will apply it
  • Retest of agreed remediated findings, included in the fixed scope

Red teaming

An objective-led assessment of whether an attacker could reach a defined target across technical and human controls.

What you get

  • A scoped objective tested across people, process and technology
  • An attack narrative recording the path taken and how far it went
  • Prioritised hardening recommendations

Phishing & social-engineering simulation

Controlled phishing and pretext campaigns that measure susceptibility where staff processes form part of the attack surface.

What you get

  • A campaign measuring click-through and credential-capture rates
  • Results reported per team, without identifying individuals
  • Awareness follow-up targeted at the gaps found

How it is shaped

A fixed-scope engagement with a defined target and timeframe. Fixed-scope testing includes verification of agreed remediated findings.

A tester never assesses a system they built.

Recent work of this kind

  • Client confidential

    Authenticated application and cloud-configuration penetration test of a Queensland financial-services platform, under signed authority, retested to closure.

Questions, answered

Who performs the testing?

Black Shard engineers. The team that designs, builds and runs production software also performs the offensive work, so the person probing your API has shipped and operated systems like it, and findings come back as engineering problems with engineering fixes. An engineer confirms every finding before it reaches the report.

How are our data and access handled during an engagement?

Least privilege, for the duration of the work and the agreed scope. Data is encrypted in transit and at rest, few third parties touch it, and the services that host it run in Australian regions. Anything sensitive the engagement surfaces falls under our own incident and Privacy Act obligations. We hold SMB1001:2026 Gold, issued by CyberCert.

What do we get at the end?

A ranked findings report. Each finding carries severity, impact, reproduction steps and a fix, ranked by what it would cost you. Red team engagements add an attack narrative showing how far we got and how. Leadership and the engineers fixing the issues read the same document, and every finding was proven by a person.

Is a re-test included?

Yes. Fixed-scope offensive work includes a re-test: once your team has remediated, we re-run the reproduction steps for each finding and confirm it is closed. The re-test covers the findings from the original engagement; new surface or new features are a new scope. The engagement finishes when the fixes are verified.

Do you work outside Brisbane?

Yes. Offensive testing runs against your systems wherever they are hosted: applications, APIs, networks and people are all tested remotely under a controlled scope. Scoping, reporting and the re-test work identically for a client in Perth or Melbourne and one across town, and on-site work is scheduled and travelled to inside the fixed scope.

What happens after the report lands?

Remediation starts the day the report arrives, because each finding carries a fix. Work the list in ranked order, and we re-test when the fixes are in. Where findings point at deeper design problems, our secure development and advisory work picks up: threat modelling, line-level code review, or a standing security seat.

How is the cost set?

By scope. Offensive work runs as a fixed-scope engagement: a defined target, a defined timeframe and a re-test. Scoping names the applications, APIs, networks and people to be tested, and the price follows that. We do not publish indicative prices, because a number without a scope misleads. If the target grows mid-engagement, we re-scope openly.

How do we get started?

Send a brief to info@blackshard.com.au or through the contact page: what the system is, roughly what it holds, and what prompted the test. It does not need to be polished; naming the target and the concern is enough. From there we scope a fixed-target, fixed-timeframe engagement with the re-test built in, and the scope is agreed before any testing starts.

Tell us what you need tested.

Brisbane head office.

Open a briefinfo@blackshard.com.au