Software, ICT and cybersecurity.
We design, build, run and secure the technology organisations depend on.
The same engineers build the systems and secure them.
- Software engineering
Any software, from first design to production.
- Offensive security
Testing of any system, network, application or team.
- Security advisory
Security leadership, strategy and review across your whole environment.
- Incident response
Investigation, containment and recovery from any security incident.
- Compliance
Readiness and assurance against any security or privacy framework.
- Secure development
Security built into software from design to release.
- AI cyber defence
Testing and governance for any AI you build or adopt.
Work in production
Businesses we build and secure software for, and the platforms underneath.
Clients
Platforms in our builds
Assay · External attack surface monitoring
External attack surface monitoring.
Assay scans your internet-facing systems for exposed services, vulnerable software and configuration changes. Findings are mapped to the Essential Eight and SMB1001.
From $349 AUD a month. All plans run the same checks.
- Attack-surface discovery
- Vulnerability checks
- Email authentication
- Exploited-in-the-wild ranking
- Attack paths
- Change tracking
- OK
- AT RISK
- NOT ASSESSED
- NOT OBSERVABLE
Every platform here is live in a system we ship.
Builds also run on AWS, Google Cloud or client-run infrastructure when an engagement calls for it.
- SMB1001:2026 GoldLEVEL 3 · CYBERCERT · PUBLIC REGISTRYVerify ↗Black Shard’s certification on the CyberCert public registry, opens in a new tab
Microsoft Azure


- Docusign
- Stripe

- Xero
- Microsoft 365
Frameworks we work against: ASD Essential Eight, OWASP, MITRE ATT&CK, CISA KEV, SMB1001:2026, ISO 27001, and the Australian Privacy Principles.
How we work
Scope
The system, its data and its obligations, scoped first.
Test and review
We test the paths that reach data, money and admin access.
Verify
Where remediation is included, fixes are verified before close.






