Black Shard

Attack surface monitoring in Brisbane.

Scheduled Assay scans of your internet-facing systems, with the changes that require action identified by Black Shard engineers at our Brisbane office.

Attack surfaces change between penetration tests. Assay monitors external systems for new hosts, exposed services, vulnerable software, TLS issues and other changes that alter your external security position. For managed engagements, Black Shard reviews the results and identifies the changes that require action rather than sending an unfiltered scanner report.

Black Shard is an Australian software engineering and cybersecurity firm headquartered on Eagle Street in Brisbane. Assay is our scanner, built and operated by the firm, and the managed service runs from the Brisbane office.

What the monitoring covers

Assay runs a standing schedule of scans against your internet-facing systems: every exposed host and service catalogued, with remote-access and database ports flagged when they appear. Findings are checked against known CVEs, misconfigurations, default logins and TLS problems, and ranked against CISA's Known Exploited Vulnerabilities catalogue and EPSS exploit probabilities. Email authentication is checked over DNS: SPF and DMARC, including softfail and p=none configurations that leave a domain open to spoofing.

Each scan is diffed against the one before it, so a change to the footprint appears as a change. Where a gap matters, the route an attacker could take to reach it is expressed in MITRE ATT&CK technique terms. Each finding carries one of four verdicts: OK, at risk, not assessed because a scan could not complete, or not observable from outside. Only the first is treated as a pass.

  • Scheduled scans of your external footprint on a standing cadence
  • Findings ranked against CISA KEV and EPSS exploitation data
  • Change tracking that diffs each scan against the last
  • A written monthly position: what changed, what matters, what to fix first
  • Evidence for an insurer or a customer's security questionnaire
  • Remediation by Black Shard where a finding needs closing

Monitoring compared with a point-in-time scan

A point-in-time report describes the attack surface on the day it ran. A subdomain stood up for a campaign and never taken down, a database port opened for a one-off job, a certificate that expired on a system nobody remembers building: none of it appears in a report from months earlier.

Monitoring compares every scan with the last one, so the report is the change since the previous period and what it means, which is the form a team can act on without re-reading the whole picture.

Assay and the managed review

Assay marks a finding OK only once the scan has verified it. Where a scan cannot see a system or cannot complete against it, the verdict says so and is never treated as a pass.

For a managed engagement, Black Shard engineers read each period's results against what the business runs, identify the changes that require action, and write the position. The engineers who read the scans also run the firm's penetration tests, Azure and Entra ID reviews and remediation work, so where a finding needs closing the fix can be scoped from the same office. Black Shard holds SMB1001:2026 Gold, verifiable on CyberCert's registry, and self-assesses against the ASD Essential Eight at Maturity Level 2.

The Brisbane option

The written position goes out by email. For Brisbane businesses the review can also run across a table at Eagle Street, with the engineer who read the scan walking through what changed and answering the questions a written report does not anticipate.

A verdict that moves from OK to at risk on a system that matters is followed up directly, and where deeper work is needed, penetration testing or remediation is scoped from the same office.

What does attack-surface monitoring cost?

No figure is published. Cost follows what is in scope: how many domains and hosts make up the footprint, how many environments are run, and whether the engagement stops at reporting or extends to remediation.

Send a brief to info@blackshard.com.au with a rough shape of what you want watched, and the reply comes back with the questions needed to scope it.

Do you only monitor Brisbane businesses?

No. The same monitoring service runs Australia-wide, with the position delivered by email and video call. In Brisbane the review can run in person.

Questions, answered

How is this different from a penetration test?
A penetration test establishes what an attacker can do with your systems in a defined, bounded engagement. Monitoring is the standing watch between tests: scheduled scans that catch drift and known exploitable weaknesses as they appear. Many businesses run both.
How often do the scans run?
On a schedule agreed at scoping, with change tracking that compares every scan against the one before it. The cadence depends on how much of the footprint changes and how quickly you need to know.
Will you contact us before the monthly report if something urgent shows up?
Yes. The monthly written position is the standing rhythm. A finding that cannot wait is raised when it is found.
Can you fix what the scans find?
Yes. Where a finding needs closing, Black Shard can engineer the fix. Monitoring, penetration testing and remediation engineering run from the same firm.
What does a 'not observable' or 'not assessed' verdict mean?
The scan could not see the system from outside, or could not complete against it. Neither is treated as a pass. The verdict records the gap in coverage instead of assuming the system is fine.
Do you only work with Brisbane businesses?
No. The monitoring service runs Australia-wide from the Brisbane head office. Brisbane businesses have the option of an in-person review; everyone else receives the same position by email and video call.

Tell us what you need built, reviewed or secured.

Brisbane head office. Work delivered across Australia.

Open a briefinfo@blackshard.com.au