Cyber security services for Australian organisations.
Offensive testing, security advisory, compliance readiness, incident response and secure software builds, delivered nationally from our Brisbane head office.
Black Shard is an Australian software engineering and cybersecurity firm. The security practices cover offensive testing, defensive advisory, breach remediation, compliance readiness and secure software builds, and every one of them is delivered nationally. The firm also designs, builds and operates production software, so a finding that needs engineering can be engineered rather than handed back as a recommendation.
Most organisations arrive with one question rather than a programme: whether an application would survive an attack, whether the Essential Eight position is defensible, what to put in front of an insurer or a customer's security questionnaire, or what to do about an incident already underway. An engagement starts at that question and widens only if the answer warrants it.
Practices
Five security practices sit alongside the engineering practice that builds the fix. Offensive testing establishes what is exploitable. Defensive advisory owns the risk register and board reporting between tests. Breach remediation contains an incident and closes what allowed it. Compliance readiness prepares the evidence customers, insurers and auditors ask for. Secure builds apply the same review to new systems before they ship.
- Offensive testing: penetration testing, red teaming, phishing simulation
- Defensive advisory: vCISO services, posture assessments, Azure and Entra ID security reviews, attack surface monitoring
- Breach remediation: incident response, root-cause remediation, Notifiable Data Breaches support
- Compliance readiness: Essential Eight uplift, SMB1001 certification readiness, ISO 27001 groundwork, Privacy Act uplift
- Secure builds: secure code review, threat modelling, security architecture
- Software engineering: custom builds and the production systems the firm operates
Where an engagement usually starts
Penetration testing suits an organisation that needs to know whether a specific application, API or network is exploitable, and wants that answered with evidence rather than assertion. A posture assessment against the Essential Eight and CIS Controls suits one that needs to know where it stands overall before committing a budget. A vCISO retainer suits one that has to keep a security programme moving without hiring a full-time CISO.
Where a customer questionnaire, an insurer or a tender is driving the work, compliance readiness is usually the shorter path: the gap is identified against the framework in question and closed with the evidence attached. Where something has already happened, incident response takes precedence over all of it.
Offensive testing and defensive advisory
Offensive work runs against OWASP and ASD guidance. Web applications, APIs, networks and cloud environments are tested manually, with automated tooling used for coverage rather than for conclusions. Every finding is reproduced by a tester before it is written up, each carries the technical detail required to remediate it, and a re-test of agreed fixes is included on fixed-scope offensive work. Red teaming runs against a defined objective, and phishing simulation measures how staff respond to a controlled campaign.
Defensive advisory covers a vCISO on an agreed cadence who owns the risk register and briefs the board in business risk terms, posture assessment against the Essential Eight and CIS Controls, Azure and Entra ID security review of the tenancy, and attack surface monitoring of what changes between tests. Exposure monitoring runs scheduled external scans through Assay, our own scanning platform, and every result is reviewed by an engineer before it reaches a report.
Compliance readiness and breach remediation
Compliance readiness covers Essential Eight uplift, SMB1001 certification readiness, ISO 27001 groundwork and Privacy Act uplift. Black Shard prepares the evidence and closes the gaps. The certification or the audit itself sits with the accredited body, and that is said before the work starts rather than after.
Breach remediation covers containment and triage, root-cause analysis of the code, configuration or infrastructure behind the incident, the remediation itself, a re-test of the remediated surface, and support with the Notifiable Data Breaches assessment under the Privacy Act 1988. Black Shard does not give legal advice; the notification decision sits with your legal advisers.
Systems we build and operate
Black Shard designs, builds and operates production software in regulated industries, which is where the security positions on this site come from. GRM LAW runs on an operations and compliance portal in which every state change is written to an append-only audit ledger. Stone Leaf Capital operates a staff portal Black Shard built, with a sealed compliance audit log structured around the firm's AFSL perimeter. Aurii, clinical software Black Shard built and operates, isolates tenant data with PostgreSQL row-level security on Azure in Australia. Black Shard is also a Xero developer partner, listed on the Xero App Store.
Black Shard holds SMB1001:2026 Gold, independently issued and verifiable on the public CyberCert registry. OWASP, the ASD Essential Eight and the frameworks above are methodologies we test and build against, not certifications we claim. The trust page sets out the full position, and the approach page describes how an engagement runs.
Delivery across Australia
Every practice is delivered Australia-wide. Scoping, testing, board briefings and debriefs run by video call and secure access wherever you operate, and the report and the re-test are the same ones an organisation down the road receives. The head office is on Eagle Street in Brisbane, and for organisations in that city scoping, internal network testing and debriefs can also run in person, described on the cyber security company in Brisbane page.
What do cyber security services cost?
There is no rate card, because the practices cover different shapes of work: a fixed-scope penetration test, a standing vCISO retainer, a milestone-driven compliance programme, an incident that cannot be sized until it is triaged. Cost is driven by the practice, the attack surface or system count in scope, and the framework involved.
Send a brief to info@blackshard.com.au with whichever of those you know, and scoping starts from there.
Questions, answered
- Where should we start if we have never had a security assessment?
- With whichever question you actually have. A posture assessment against the Essential Eight and CIS Controls establishes where the organisation stands overall. A penetration test answers whether one specific system is exploitable. If a customer questionnaire or an insurer is driving it, compliance readiness against that framework is the shorter path.
- Do you deliver outside Brisbane?
- Yes. Black Shard is an Australian firm headquartered in Brisbane, and every practice is delivered Australia-wide by video call and secure access. Brisbane organisations have the additional option of in-person scoping, on-site internal testing and an in-person debrief.
- Can you certify us against ISO 27001 or SMB1001?
- No. Black Shard prepares the evidence and closes the gaps; the certification or audit itself sits with the accredited body. Black Shard holds SMB1001:2026 Gold in its own right, independently issued and verifiable on the public CyberCert registry.
- If a test finds a problem, can you remediate it, or do we need another vendor?
- Black Shard can remediate it. The firm designs, builds and operates production software as well as testing it, so the fix for a finding it reported can be engineered and shipped by the same firm, then re-tested.
- What do you need from us to scope an engagement?
- Whatever you have: the systems in question, the framework or customer requirement driving the work, and any deadline attached to it. Send that to info@blackshard.com.au and scoping starts from the detail available.
Tell us what you need built, reviewed or secured.
Brisbane head office. Work delivered across Australia.