- Who performs the testing?
- Black Shard engineers. The same team that designs, builds, and runs production software performs the offensive work: one team, accountable for both practices. That matters because the person probing your API or reading your authentication flow has shipped and operated systems like it, so findings come back as engineering problems with engineering fixes. Every finding is validated by hand before it reaches the report.
- How are our data and access handled during an engagement?
- Least privilege, for the duration of the work and no longer. We take only the access the engagement requires, against a defined scope agreed before testing starts. Data is encrypted in transit and at rest, the set of third parties that touch client data is kept deliberately small, and the services that host it run in Australian regions. Anything sensitive an engagement surfaces is handled under the same incident and Privacy Act obligations we hold ourselves to. Our trust page sets these practices out in full, alongside the one certification we hold, SMB1001:2026 Gold.
- What do we get at the end?
- A ranked findings report. Each finding carries severity, impact, reproduction steps, and a concrete fix, ranked by what it would cost you rather than by scanner score. Red team engagements add an attack narrative showing how far we got and how. The report is written in plain English for the people who will act on it, so leadership and the engineers fixing the issues read the same document. Nothing in it is pasted from a scanner; every finding was proven by a person.
- Is a re-test included?
- Yes. Fixed-scope offensive work includes a re-test. Once your team has remediated, we re-run the reproduction steps for each finding and confirm the holes are actually closed. The re-test covers the findings from the original engagement; new surface or new features are a new scope, and we say so plainly rather than blur the line. A test that ends at the PDF proves nothing changed. The engagement is finished when the fixes are verified, which is the commitment our approach page describes: fix like an engineer, then prove it.
- Do you work outside Brisbane?
- Yes. A national firm, head office in Brisbane, delivering Australia-wide. Offensive testing runs against your systems wherever they are hosted: applications, APIs, networks, and people can all be tested remotely under a controlled scope. Scoping, reporting, and the re-test work identically for a client in Perth or Melbourne as for one across town.
- What happens after the report lands?
- Remediation starts the day it arrives, because each finding already carries a concrete fix. Work the list in ranked order. When the fixes are in, we re-test and confirm they landed. Where findings point at deeper design problems rather than one-line patches, that is where our secure development and advisory work picks up: threat modelling, line-level code review, or a standing security seat at your table.
- How is the cost set?
- By scope. Offensive work runs as a fixed-scope engagement: a defined target, a defined timeframe, and a re-test. Scoping names what is actually in play, the applications, APIs, networks, and people to be tested, so the price follows the work rather than a rate card. We do not publish indicative prices because a number without a scope misleads in both directions. If the target needs to grow mid-engagement, we re-scope in the open rather than quietly absorb it. A scoped brief gets you a real number.
- How do we get started?
- Send a brief to info@blackshard.com.au or through the contact page: what the system is, roughly what it holds, and what prompted the test. It does not need to be polished; naming the target and the concern is enough. From there we scope a fixed-target, fixed-timeframe engagement with the re-test built in, and the scope is agreed before any testing starts.