Tested the way people actually get fooled. Fixed the way a process can hold.
Phishing, vishing, and physical pretexting, scoped face to face from our Eagle Street office, reported per team, and mapped to a targeted awareness follow-up rather than a list of who clicked.
Black Shard is an Australian software engineering and cybersecurity firm with its head office on Eagle Street in Brisbane. We run social engineering tests from that office for businesses in Brisbane and across the country: phishing, vishing, and physical pretexting, run the way an attacker actually targets your people and reported in terms your team can act on.
The people who design the pretexts are the same engineers who build the systems those pretexts are aimed at: the password reset flow, the MFA enrolment screen, the verification step behind each. That changes what comes back: a report naming the verification step that failed and a targeted awareness follow-up aimed at that gap, not a generic reminder to be careful.
What a Black Shard social engineering test involves
A test measures whether your people, and the process behind them, hold up against the way people actually get fooled: an email that looks internal, a caller who already knows the org chart, a stranger who walks in behind someone holding the door. Channels are scoped together as one campaign or run on their own, depending on the question you are asking. Rules of engagement are agreed in writing before anything runs: which channels are in bounds, which topics are off-limits, and who is aware the exercise is happening.
What comes back is not a scoreboard of individuals. Results land as per-team numbers, the specific verification step that was missing or got skipped under pressure, and a targeted awareness follow-up aimed at the gap the test actually found. Where training addresses the gap, a second wave measures whether it held.
- Phishing, vishing, and physical pretexting, scoped together or run as a single channel on its own
- Rules of engagement agreed in writing before anything runs: channels in bounds, topics off-limits, who is aware
- Per-team results with the gaps named, never a list of individuals to discipline
- A targeted awareness follow-up aimed at the specific verification step that failed
- A second wave once training lands, to measure whether the gap actually closed
What we test
Phishing simulation is a controlled campaign against your own domain and your own people: a lure built to look like what an attacker would actually send your business, not a generic template. We measure click-through and credential-capture rates, and where a lure leads to a login page, nothing typed into it is a real credential.
Vishing tests the channels a phishing filter never sees. Calls that claim to be IT, a vendor, or an executive; SMS lures that name a real internal system; push-notification fatigue, where approval prompts are fired until one gets accepted out of exhaustion; and the reverse case, a call into your own helpdesk asking for a password reset or an MFA re-enrolment on a plausible pretext. Each of these targets the verification step that should have stopped it, not just the person who answered.
Physical pretexting tests what a stranger can achieve inside your building: walking in behind someone holding a door, talking past reception with a plausible reason to be there, reaching a workstation or a space that should have stopped them earlier. This runs only where the scope includes it, only at your premises, and only on rules of engagement agreed and scheduled in writing before anyone sets foot on site.
Why run this from Brisbane?
Scoping a social engineering test decides what gets tested and what stays off-limits, and some of that is easier to get right in the room: which departments, which pretexts are fair game, and which topics are excluded because a controlled fright is the point and real harm is not. At Eagle Street we scope across a table, agreeing rules of engagement before a single call is placed or a single lure goes out.
Physical pretexting only works where an engineer can actually be there. Phishing and vishing run the same everywhere; walking your building takes someone in your building. For Brisbane organisations, the whole engagement, scoping, the campaign, and the debrief, can run face to face.
The debrief runs the same way as every offensive engagement here: the engineer who ran the pretext explains what worked, why, and what the fix looks like, in the room with the people who have to act on it. We debrief face to face at Eagle Street or at your office.
Who does the testing
The same engineers who design, build, and run production software design these pretexts. GRM LAW, a Brisbane law firm, runs its intake and conflicts process on a portal Black Shard built and operates. Aurii, our clinical-software venture, carries live tenant health data on Azure in Australia. Engineers who have built a password reset flow, an MFA enrolment screen, and the audit log behind it know exactly which step a caller is trying to skip, because they built the step.
The posture behind the work is published, not implied. We hold one certification, SMB1001:2026 Gold, held by the legal entity and verifiable on CyberCert's public registry. This work sits alongside our penetration testing and red teaming practice, run against the same rule: results measure the process, never an individual to discipline. What we deliberately do not claim is on our trust page.
How much does social engineering testing cost?
You get a fixed quote before anything runs. Cost follows scope, and scope has named drivers rather than a number pulled from the air. We would rather name the drivers than publish a range that turns out wrong for your organisation.
Send a brief to [email protected]; scoping starts from whatever detail you have.
- Channels in scope: phishing, vishing, physical pretexting, or a combination
- Headcount and sites: how many people and how many locations the campaign covers
- Whether an on-site physical component is part of the engagement
- Whether a second wave after training is included
Do you only test in Brisbane?
No. The same team delivers social engineering testing Australia-wide, phishing, vishing, and physical pretexting, run from our Brisbane head office whether your people sit in Brisbane or somewhere else entirely. This page is written for Brisbane buyers because the physical component works best where we can be in the building, but the phishing and vishing channels are delivered identically nationwide.
Scoping and the debrief run remotely for organisations outside Brisbane, with the same hand-built pretexts, the same per-team reporting, and the same rule against naming individuals. Where a physical component is part of the brief, it is scheduled and travelled to, and priced as part of the fixed scope rather than discovered later.
Every engagement includes
A director on the work
A director reads the brief, scopes the engagement, and stays accountable for the result.
Fixed scope, quoted first
Scope, timeframe, and price are agreed before work starts.
Findings validated by hand
Every finding is checked by a human, written in plain English, and paired with a concrete fix. Raw scanner output is never forwarded.
A re-test to prove it
Fixed-scope offensive work includes a re-test, so fixes are confirmed closed rather than assumed.
Least-privilege access
We take only the access the work requires, and client data sits in Australian regions.
A report that is yours
Written for your engineers and your board, and kept confidential.
Questions, answered
- Is phishing simulation the same as a social engineering test?
- No. Phishing simulation is one channel. A full social engineering test can also cover vishing and physical pretexting, scoped together or run as a single channel on its own, depending on the question you are asking.
- Do you tell us who clicked, who answered the call, or who let someone in?
- No. Results come back as per-team numbers with the gaps named, never a list of individuals to discipline. Naming people damages trust internally and tells you less than the aggregate numbers already do.
- Can physical pretexting run outside Brisbane?
- Yes. It is scheduled and travelled to as part of the fixed scope, wherever your premises are. Phishing and vishing channels run identically nationwide from our Brisbane head office.
- How does this map to our security awareness training?
- The report names the specific verification step that was missing or skipped under pressure, not a generic reminder to be careful. That becomes a targeted awareness follow-up aimed at the actual gap, and where training addresses it, a second wave measures whether it held.
- Will the test disrupt our staff or our operations?
- Rules of engagement are agreed in writing before anything runs: which channels, which topics are off-limits, and what happens if something goes further than intended. Where a phishing lure leads to a login page, nothing typed into it is a real credential.
- What if someone reports the phishing email or the call instead of acting on it?
- That is a result worth reporting on its own. A staff member who reports a lure instead of acting on it is the outcome the training is for, and the report captures that alongside the click-through numbers, not just the failures.
Related reading
The full practice: Penetration testing & red teaming.
Know where your people would fall, before an attacker finds out.
Australia-wide, from our Brisbane head office. Someone will contact you as soon as possible.