Black Shard

Social engineering testing for Australian organisations.

Phishing, vishing, SMS, MFA fatigue, helpdesk and physical pretexting, scoped in writing, reported per team, and tied to the verification step that failed.

Open a brief

Lures are written for your business and its suppliers. Credential submission is measured separately from clicks, nothing typed into a simulated login page is stored as a credential, and physical pretexting runs at sites named in writing.

What each test measures

Channels are scoped together as one campaign or run individually, and rules of engagement are agreed in writing before anything runs.

Each test measures the response as well as the click: who reported the lure, how fast the report reached someone who could act, and which verification step was missing or skipped. Results are reported per team, and the awareness follow-up is written against the steps that failed.

Social engineering channels we test

Phishing simulation is a controlled campaign against your own domain and your own people, with lures written for your business and its suppliers. Credential submission is measured separately from clicks, and nothing typed into a simulated login page is stored as a credential.

Vishing, SMS, MFA fatigue, helpdesk and physical

Vishing and SMS lures reach the channels a mail filter never sees: calls claiming to be IT, a vendor or an executive, and text messages naming an internal system. MFA fatigue testing measures whether staff approve a push prompt they did not start when a caller asks them to.

Helpdesk pretexting calls your own service desk as a staff member and asks for a password reset or an MFA re-enrolment. Several of the most damaging publicly reported intrusions of recent years began with a call to a service desk, and this test measures whether identity is verified through a channel the organisation controls.

Physical pretexting tests what a stranger can reach inside your premises: tailgating through a controlled door, passing reception with a plausible reason, and reaching a workstation or an area that should have stopped them. It runs only where the scope includes it, at sites named in writing, anywhere in Australia.

What a social engineering test measures

Click rate mostly measures how good the lure was. The results that predict how a real attack ends are the ones that describe the organisation's response, so each campaign is reported on those first.

  • Report rate: the share of recipients who reported the lure through the agreed channel
  • Time to first report, and time from that report to triage by the security or IT team
  • Credential submission and MFA approval, tracked separately from clicks
  • Callback verification: whether a payment or reset request was checked on an independently sourced number
  • Helpdesk outcome: whether the reset or re-enrolment was refused, escalated or completed
  • Physical reach: the furthest point reached, and where the first challenge came from

How a social engineering engagement runs

Scoping agrees the channels, the departments and sites in scope, the topics excluded, who inside the organisation is aware the test is running, and the stop procedure if an attempt goes further than intended. Rules of engagement are signed before any lure is sent or any call is made.

  • Rules of engagement in writing: channels, departments, sites, exclusions and who is aware
  • Pretexts written for your business, approved before use
  • Campaign window with live monitoring and a named contact on both sides
  • Per-team results with the failed verification step identified for each finding
  • An awareness follow-up written against the steps that failed
  • A second wave after training, to measure whether the change held
How pretexts are built

Pretexts are built from public information about the business, the way an attacker would build them. Campaigns run in the agreed window, and every interaction is logged with its time and outcome so the report can be checked against what happened.

Reporting without naming individuals

Results are reported per team, and no individual is named. A well-built pretext eventually lands on almost anyone, so the finding that matters is the verification step that was missing or skipped under pressure, the helpdesk script that did not exist, or the alert that never fired.

Who the report is written for

The report is written for the people who own those steps: the helpdesk lead, the finance controller who approves payments, the facilities manager, and the executive who signs off the remediation. It carries enough detail to rebuild each step and to evidence the test to an insurer or a customer.

Social engineering testing across Australia

Phishing, vishing, SMS and helpdesk testing run remotely and run the same way in every state. Physical pretexting is scheduled at your premises, travelled to and priced within the fixed scope. Scoping and the debrief run by video call, or in person where the organisation prefers it.

Related testing and fixes

Black Shard runs social engineering testing alongside penetration testing and red teaming, and builds the controls these tests target: password reset paths, MFA enrolment and helpdesk verification in production software. Where a test finds a broken step, the same firm can engineer the fix. Defence against lures built with AI-generated voice and video runs as AI phishing and deepfake defence.

How much does social engineering testing cost?

Every test is quoted as a fixed scope before anything runs. Cost is driven by the channels in scope, the headcount and number of sites, whether an on-site physical component is included, and whether a second wave after training is included.

Across the Australian market a single phishing or social engineering campaign broadly sits between $4,000 and $10,000.

Scoping call

A free 30-minute scoping call settles the channels and the quote, or a brief to info@blackshard.com.au starts scoping from the detail you have.

Questions, answered

What is social engineering testing?

Social engineering testing measures whether staff and processes hold against an attacker who targets people instead of systems. It covers phishing simulation, vishing and SMS lures, MFA fatigue, helpdesk pretexting and physical pretexting, run under written rules of engagement and reported per team.

Is phishing simulation the same as a social engineering test?

Phishing simulation is one channel. A social engineering test can also cover vishing, SMS lures, MFA fatigue, helpdesk pretexting and physical pretexting, scoped together as one campaign or run individually.

Do you tell us who clicked or who let someone in?

No. Results are reported as per-team figures with the failed verification step identified. Individuals are not named.

Can you test our helpdesk?

Yes. Helpdesk pretexting calls your service desk as a staff member and requests a password reset or MFA re-enrolment. It measures whether identity is verified through a channel the organisation controls before the change is made.

Can physical social engineering tests run at sites in any state?

Yes. Physical pretexting is scheduled at your premises anywhere in Australia, travelled to and priced within the fixed scope. Phishing, vishing, SMS and helpdesk testing run remotely nationwide.

Will the test disrupt our staff or operations?

Rules of engagement are agreed in writing before anything runs, including the channels, the excluded topics, who is aware and the stop procedure. Simulated login pages store nothing typed into them as a credential.

How often should social engineering testing run?

The cadence is set at scoping. Quarterly phishing campaigns with rising pretext difficulty show the trend in report rate and time to report, and a second wave after awareness training measures whether the change held.

How much does a social engineering test cost?

Every test is quoted as a fixed scope. The price follows the channels in scope, headcount, the number of sites, any on-site physical component and whether a second wave is included. Across the Australian market a single campaign broadly sits between $4,000 and $10,000.

Scope a social engineering test with Black Shard.

Brisbane head office.

Open a briefinfo@blackshard.com.au