Black Shard

Social engineering testing in Brisbane.

Phishing, vishing and physical pretexting, scoped in writing, reported per team, and mapped to an awareness follow-up.

Open a brief

Channels are scoped together as one campaign or run individually, and rules of engagement are agreed in writing before anything runs. Where a lure leads to a login page, nothing typed into it is stored as a credential.

Reporting per team

Results are reported per team. The report identifies the verification step that was missing or skipped, and the awareness follow-up is written against that step. No individual is named.

Channels

Phishing simulation is a controlled campaign against your own domain and your own people, with a lure written for your business. Click-through and credential-entry rates are measured. Where a lure leads to a login page, nothing typed into it is stored as a credential.

Vishing and physical pretexting

Vishing covers the channels a mail filter does not see: calls claiming to be IT, a vendor or an executive; SMS lures naming an internal system; MFA push fatigue, where approval prompts are repeated until one is accepted; and calls into your own helpdesk requesting a password reset or an MFA re-enrolment on a pretext. Each attempt targets a specific verification step.

Physical pretexting tests what a stranger can reach inside your building: following someone through a door, passing reception with a plausible reason, reaching a workstation or an area that should have stopped them earlier. It runs only where the scope includes it, only at your premises, and only on rules of engagement agreed and scheduled in writing.

Rules of engagement and reporting

Rules of engagement cover the channels in bounds, the departments in scope, the topics excluded, who is aware the exercise is running, and what happens if an attempt goes further than intended.

  • Rules of engagement in writing: channels, departments, exclusions, and who is aware
  • Per-team results with the verification step that failed identified
  • An awareness follow-up written against that step
  • A second wave after training, to measure whether the change held
Per-team results and a second wave

Results are reported as per-team figures. Staff reports of a lure are recorded alongside click-through, since a reported lure is the outcome awareness training exists to produce. Where training addresses the gap, a second wave can measure whether it held.

Delivery in Brisbane

Black Shard's head office is on Eagle Street in Brisbane, and social engineering testing is delivered Australia-wide from it. Phishing and vishing run the same way regardless of location.

Physical pretexting on site

Physical pretexting requires an engineer at your premises; for Brisbane organisations that runs from the office, and elsewhere it is scheduled, travelled to and priced within the fixed scope. Scoping and the debrief can run in person at Eagle Street or at your office.

Systems we build and operate

Black Shard builds and operates production software, including the operations and compliance portal GRM LAW runs on, and implements the password reset, MFA enrolment and helpdesk verification controls that these tests target.

How much does social engineering testing cost?

Testing is quoted as a fixed scope before anything runs. Cost is driven by the channels in scope, the headcount and number of sites covered, whether an on-site physical component is included, and whether a second wave after training is included.

Send a brief to info@blackshard.com.au and scoping starts from the detail you have.

Questions, answered

Is phishing simulation the same as a social engineering test?

Phishing simulation is one channel. A social engineering test can also cover vishing and physical pretexting, scoped together or run individually.

Do you tell us who clicked, who answered the call, or who let someone in?

No. Results are reported as per-team figures with the failed verification step identified. Individuals are not named.

Can physical pretexting run outside Brisbane?

Yes. It is scheduled and travelled to as part of the fixed scope. Phishing and vishing run the same way nationwide.

How does this map to our security awareness training?

The report identifies the verification step that was missing or skipped. The awareness follow-up is written against that step, and where training addresses it, a second wave can measure whether it held.

Will the test disrupt our staff or our operations?

Rules of engagement are agreed in writing before anything runs, including the channels, the excluded topics, and what happens if an attempt goes further than intended. Where a phishing lure leads to a login page, nothing typed into it is stored as a credential.

What if someone reports the phishing email or the call instead of acting on it?

It is recorded as a result. Reports of a lure are captured alongside the click-through figures.

Scope a social engineering test with Black Shard.

Brisbane head office.

Open a briefinfo@blackshard.com.au