Penetration testing for regulated Australian firms.
Fixed-scope penetration testing, delivered Australia-wide from our Brisbane head office, with every finding validated by hand and a re-test included.
Black Shard is an Australian software engineering and cybersecurity firm. We test web applications, APIs, and networks against the OWASP and ASD playbooks for organisations across the country. The work runs from our Brisbane head office; a penetration test does not need us in your building: it needs a defined scope, provisioned access, and a team that knows what an adversary would do with your systems.
What separates us is that we build and operate production software ourselves. We know what a matter register, a clinical record, and an AFSL obligation look like from the inside, because we ship systems that carry them. That changes how we test: we work toward the objective an attacker is actually after, not a checklist.
What a Black Shard penetration test includes
Web applications, APIs, and networks, tested against the OWASP and ASD playbooks. Those are methodologies we work against, not accreditations we hold. The test starts with reconnaissance done in the open, with you: we map the attack surface, identify the data that matters, and name the obligations you carry before anything is touched.
Then we attack. Human testers work the target the way an adversary would, chaining small findings into the path that matters. Automation has a place in coverage, but nothing reaches the report until a human has proven it works. Where the brief calls for more than an application test, the same team runs red-team exercises and phishing simulation, so one engagement can cover people and process as well as technology.
- Web application and API penetration testing
- Network penetration testing
- Phishing and social-engineering simulation
- Red teaming: a goal-driven, multi-vector exercise against a scoped objective
A test proves what a scan can only list
A scan enumerates known weaknesses; a penetration test proves what an attacker can do with them. Reformatted scanner output will tell you a library is outdated. It will not tell you that the outdated library, chained with a permissive CORS policy and a forgotten staging subdomain, hands over your customer database. That chain is the finding that matters, and only a human tester finds it.
We use scanners where they add coverage, and we never forward their raw output. Each one is proven by a tester, ranked by real impact, and written up so your engineers can replay it. If you are weighing the two, the short version is this: a scan is a data feed, a test is a judgement.
Test material stays under Australian law
A penetration test generates sensitive material: credentials, configuration detail, evidence of exactly how your systems fail. Where that material sits, and whose law governs it, is not a detail. Black Shard is an Australian company. The Privacy Act 1988 and the Notifiable Data Breaches scheme apply to us directly, and the platforms that host client data run in Australian regions on Microsoft Azure.
The testing itself is delivered from our head office in Brisbane. During an engagement we operate on least-privilege access, taking only what the scope requires, and engagement data is encrypted in transit and at rest. Our own posture is documented on our trust page, down to the one certification we hold: SMB1001:2026 Gold, verifiable on the CyberCert public registry.
Built and operated in the industries we test
We build and operate regulated systems as well as test them. In legal, Black Shard built and runs the operations and compliance portal that GRM LAW, a Brisbane law firm, works from: intake, conflicts checks, a matter register, and an append-only audit ledger. In health, our clinical-software venture Aurii runs on Azure in the Australia East region, with tenant health data isolated by PostgreSQL row-level security and tamper-evident audit trails. In capital markets, we built the staff portal Stone Leaf Capital operates on, with a compliance audit log structured around the firm's AFSL perimeter.
That depth changes the test. A tester who has shipped a multi-tenant clinical data layer knows where tenant isolation breaks. A tester who has built an AFSL-shaped audit log knows which records a regulator will ask for and which gaps an attacker will exploit first. When we test a firm in one of these industries, findings are ranked by severity and by what they would actually cost you, read against the obligations you carry.
- Legal: the compliance and operations portal GRM LAW runs on
- Health: Aurii, clinical software for Australian private-hospital specialists
- Capital markets: the operations platform behind Stone Leaf Capital
What does a penetration testing engagement look like?
Every penetration test is a fixed-scope engagement: a defined target, a defined timeframe, and a defined deliverable, agreed before work starts. You know what is being tested, when, and what you will get back before anything begins. A re-test is included on fixed-scope offensive work, so the engagement ends when the holes are confirmed closed, not when the report is emailed. The method behind it is documented on our approach page: read the real risk, test like an adversary, fix like an engineer, then prove it.
The engagement ends with a ranked fix list in your hands. Findings arrive ordered by severity and impact, each with the steps to reproduce it and a concrete, plain-English fix. We write for two audiences at once: enough technical detail for the engineer applying the fix, and enough clarity for the director signing off on it.
How much does penetration testing cost?
We will not publish a number, because an honest one does not exist without scope. The price of a penetration test is driven by attack surface, the number of environments in scope, and tenancy count: a single marketing site and a multi-tenant platform spanning production and staging are different jobs. What we commit to is the shape: scope fixed and drivers named up front, so both sides know exactly what is being tested.
Scoping starts with a conversation. Describe the system, and a director replies with the questions that set the price.
Every engagement includes
A director on the work
A director reads the brief, scopes the engagement, and stays accountable for the result.
Fixed scope, quoted first
A defined target, a defined timeframe, and a defined price, in writing before testing begins.
Findings validated by hand
Every finding is checked by a human, written in plain English, and paired with a concrete fix. Raw scanner output is never forwarded.
A re-test to prove it
Fixed-scope offensive work ends when the re-test confirms the holes closed, not at report delivery.
Least-privilege access
We take only the access the work requires, and client data sits in Australian regions.
A report that is yours
Yours to hand to your board or insurer, and kept confidential.
Questions, answered
- Can you test an organisation outside Brisbane?
- Yes. We deliver Australia-wide, remotely from our Brisbane head office. A penetration test targets your applications and networks over the same paths an attacker would use, so your location is a scoping detail, not a constraint.
- What methodologies do you test against?
- OWASP guidance for applications and APIs, and the ASD playbooks, including the Essential Eight mitigation strategies, for the surrounding environment. These are methodologies we work against, not credentials we claim. The one certification we hold is SMB1001:2026 Gold, verifiable on the CyberCert public registry.
- Is a re-test included?
- Yes, on fixed-scope offensive work. Once you have applied the fixes, we re-test the findings and confirm the holes are closed. The engagement is not finished at report delivery.
- Do you just run a scanner?
- No. We use automated tooling where it adds coverage, but every finding in the report comes with the reproduction steps a human used to prove it. We do not forward raw scanner output.
- Can I share the report with my board or insurer?
- The report is written to be handed on. Findings come in plain English with reproduction steps and a concrete fix for each one, so a director can act on it and your engineers can apply the fixes without us in the room.
- How long does a penetration test take?
- The timeframe is fixed at scoping and depends on the attack surface, the environments in scope, and tenancy count. You have it in writing before testing begins.
- What access do you need?
- Only what the scope requires. We operate on least-privilege access during engagements, and the access model is agreed at scoping along with the targets and the timeframe.
Related reading
The full practice: Penetration testing & red teaming.
The adversary's view of your systems, in writing.
Australia-wide, from our Brisbane head office. Someone will contact you as soon as possible.