Black Shard

Tested the way an adversary works. Fixed the way an engineer ships.

Penetration testing scoped face to face at our Eagle Street office, run by hand, reported in plain English, and re-tested to prove the fixes landed.

Black Shard is an Australian software engineering and cybersecurity firm with its head office on Eagle Street in Brisbane. We run penetration tests from that office for businesses in Brisbane and across the country: web applications, APIs, and networks, attacked the way an adversary works and reported in terms an engineer can act on.

The engineers who test your systems are the engineers who design, build, and run production software. That changes what comes back: every finding validated by hand, written in plain English with reproduction steps and a concrete fix, and a re-test included to confirm the holes are closed. We do not forward raw scanner output.

What a Black Shard penetration test involves

It starts with scoping, because a test is won or lost there. We learn the system before we touch it: the attack surface, the data that matters, the obligations you carry. The reconnaissance an attacker would do anyway, we do with you, in the open. Then we attack the agreed scope against the OWASP and ASD playbooks, aimed at the objective an attacker is actually after rather than a checklist of what a scanner can see.

What you get back is built to be acted on. Every finding is validated by hand and ranked by what it would cost you, not by what a tool guessed. The report is yours, and the engagement is fixed scope with a defined target and timeframe, so there is no meter running.

  • Scoping across a table: where your attack surface starts and stops, agreed before anything is touched
  • Testing against the OWASP and ASD playbooks, driven at the objective an attacker actually wants
  • A ranked findings report with severity, impact, and reproduction steps for every issue
  • A concrete, plain-English fix for each finding, not a generic advisory
  • A re-test inside the fixed scope to confirm the fixes landed
  • Least-privilege access for the duration of the engagement

What we test

Web applications and APIs, against the OWASP playbooks: authentication and session handling, access control, injection, and the ways an application's own logic can be turned against it. Multi-tenant systems get the tenant boundary tested specifically. We build multi-tenant data layers with row-level security in our own products, so we know where isolation tends to break.

Networks, external and internal, against ASD guidance. External testing measures what an internet attacker can reach; internal testing assumes a foothold and measures how far it goes. Internal testing can run on-site at your Brisbane office.

Where a test surfaces deeper problems, the adjacent work sits under the same roof: secure code review at the line level, red teaming when the question is whether an attacker can reach a specific objective, phishing simulation when the question is people, and an Azure cloud security review when the exposure is the tenant rather than the application.

Why scope face to face?

Scoping decides what a test is worth. Scope too narrow and it misses the systems that matter; scope through a discovery form and the nuance dies in a text field. At Eagle Street we scope across a table: your engineers, our engineers, and the real questions about where your attack surface starts and stops.

The debrief works the same way. A findings report lands differently when the person who wrote the exploit chain is in the room to walk your team through it, argue priority, and answer the hard questions. We debrief face to face at Eagle Street or at your office, and every finding comes back with the reproduction steps your team needs to check it themselves.

The local proof is a client we can name. GRM LAW, a Brisbane law firm, runs day to day on an operations and compliance portal Black Shard built and operates, with every state change landing in an append-only audit ledger. We build and we secure out of the same office, and each half of that work sharpens the other.

Who does the testing

The same engineers who design, build, and run production software. Aurii, our clinical-software venture, carries live tenant health data on Azure in Australia, and the isolation and audit engineering that protects it is ours. The GRM LAW portal carries a law firm's intake, conflicts checks, and matter register every working day. Engineers who have shipped and defended systems like these know where the bugs live, because they have written those bugs and fixed them.

The posture behind the work is published, not implied. We hold one certification, SMB1001:2026 Gold, held by the legal entity and verifiable on CyberCert's public registry. OWASP and the ASD Essential Eight are methodologies we test against, not credentials we claim, and we keep that line clear. The full picture, including what we deliberately do not claim, is on our trust page. The way we run every engagement is on our approach page: read the real risk, test like an adversary, fix like an engineer.

How much does a penetration test cost?

You get a fixed quote before any work starts. Cost follows scope, and scope has named drivers rather than a number pulled from the air. We would rather name the drivers than publish a range that turns out wrong for your systems.

The re-test is inside the fixed scope, not a second invoice for confirming your fixes worked. Send a brief to info@blackshard.com.au; scoping starts from whatever detail you have.

  • Attack surface: how many applications, APIs, and live hosts are in scope
  • Environments: production alone, or staging and development alongside it
  • Tenancy count: multi-tenant systems take longer to test properly
  • Delivery: whether internal on-site testing is part of the engagement

Do you only test in Brisbane?

No. The same team delivers penetration testing Australia-wide. This page is for Brisbane buyers, where a penetration test can run face to face end to end: scoping across a table, internal testing on your premises, an in-person debrief with the engineer who did the work.

Everywhere else the scoping and debrief run remotely, with the same hand validation, the same report, and the same re-test. If you are outside Brisbane, our penetration testing and red teaming page covers the national practice.

Every engagement includes

  • A director on the work

    A director reads the brief, scopes the engagement, and stays accountable for the result.

  • Fixed scope, quoted first

    Target, timeframe, and price are settled across a table before testing starts.

  • Findings validated by hand

    Every finding is checked by a human, written in plain English, and paired with a concrete fix. Raw scanner output is never forwarded.

  • A re-test to prove it

    Once your fixes ship, we re-run the reproduction steps and confirm each hole is closed.

  • Least-privilege access

    Only the access the scope names, for the duration of the work, with client data in Australian regions.

  • A report that is yours

    Written for your engineers and your board, and kept confidential.

Questions, answered

Is a vulnerability scan the same as a penetration test?
No. A scanner enumerates known issues; a penetration test validates what is exploitable and chains findings into a real attack path.
Can you test on-site in Brisbane?
Yes. Internal network testing can run from your Brisbane office, and scoping and debriefs can happen face to face at Eagle Street or at yours. Where on-site adds nothing, the same engagement runs remotely.
How long does a penetration test take?
The timeframe is fixed at scoping and depends on the attack surface, the environments in scope, and whether on-site internal testing is included. You have it in writing before work starts, and if on-site testing is in scope the schedule is agreed around your office and your team.
Will a penetration test disrupt production?
Rules of engagement are agreed at scoping: what is in bounds, when testing runs, and what happens if we find something critical mid-test. We learn the system before we touch anything and operate with least-privilege access for the duration.

Know where you stand before an attacker does.

Australia-wide, from our Brisbane head office. Someone will contact you as soon as possible.

Open a briefinfo@blackshard.com.au