A cyber security company in Brisbane.
Offensive testing, security advisory, compliance readiness, incident response and secure software builds, from one engineering and security firm.
- Brisbane head office
- Eagle Street
- Plus the engineering that builds the fix
- Five practices
- CyberCert public registry
- SMB1001:2026 Gold
Black Shard is an Australian software engineering and cybersecurity firm with its head office on Eagle Street in Brisbane. Five security practices run alongside the engineering practice that builds the fix, so a finding and the work that closes it stay with one firm.
Where engagements start
The firm also designs, builds and operates production software for clients.
Engagements usually start with one practice: a penetration test, a posture assessment, a compliance gap review. Where a finding requires engineering, Black Shard can build the fix.
Practices
Five security practices, alongside the engineering practice that builds the fix.
- Offensive testing: penetration testing, red teaming, phishing simulation
- Defensive advisory: vCISO services, posture assessments, Azure and Entra ID security reviews, attack surface monitoring
- Breach remediation: incident response, root-cause remediation, Notifiable Data Breaches support
- Compliance readiness: Essential Eight uplift, SMB1001 certification readiness, ISO 27001 groundwork, Privacy Act uplift
- Secure builds: secure code review, threat modelling, security architecture
- Software engineering: custom builds and the production systems the firm operates
What each practice does
Offensive testing establishes what is exploitable. Defensive advisory maintains the risk register and board reporting between tests. Breach remediation contains an incident and fixes what allowed it. Compliance readiness prepares evidence for the frameworks customers and insurers ask about.
Secure builds apply the same review to new systems before they ship, and the engineering practice underneath builds the fix where one is needed.
Offensive testing and defensive advisory
The offensive practice delivers penetration testing in Brisbane and Australia-wide, run against OWASP and ASD guidance. Red teaming runs against a defined objective, and social engineering testing covers phishing, vishing and physical pretexting and measures how staff respond to a controlled campaign.
Findings and re-tests
Findings are reproduced before they are reported, each carries remediation detail, and a re-test is included on fixed-scope offensive work.
Defensive advisory
Defensive advisory covers a vCISO on a regular cadence who owns the risk register and briefs the board, posture assessment against the Essential Eight and CIS Controls, an Azure security review and Entra ID security review of the tenancy, and attack surface monitoring of what changes between tests.
Compliance readiness, breach remediation and secure builds
Compliance readiness covers Essential Eight uplift against the ASD's maturity model, SMB1001 certification readiness, ISO 27001 readiness and Privacy Act uplift. Black Shard prepares the evidence and closes the gaps; the certification or audit itself sits with the accredited body.
Breach remediation
Breach remediation covers incident response: containment and triage, root-cause analysis of the code, configuration or infrastructure behind the incident, remediation, a re-test of the remediated surface, and support with the Notifiable Data Breaches assessment under the Privacy Act.
Secure builds
Secure builds apply the same review to a new system before it ships. Secure code review sits with the same engineering practice that builds and operates Black Shard's own production systems.
Systems we build and operate
Black Shard designs, builds and operates production software. GRM LAW, a Brisbane law firm, runs on an operations and compliance portal in which every state change is written to an append-only audit ledger.
Stone Leaf Capital, Aurii and certification
Stone Leaf Capital operates a staff portal Black Shard built, with a sealed compliance audit log structured around the firm's AFSL perimeter. Aurii, clinical software Black Shard built and operates, isolates tenant data with PostgreSQL row-level security on Azure in Australia. Black Shard is also a Xero developer partner, listed on the Xero App Store.
Black Shard holds SMB1001:2026 Gold, independently issued and verifiable on the public CyberCert registry. OWASP, the ASD Essential Eight and the frameworks above are methodologies we test and build against.
In person in Brisbane
Black Shard's head office is on Eagle Street in Brisbane. Parts of an engagement benefit from being local: internal network testing and scoping on a penetration test, physical pretexting on a social engineering test, and a board briefing on a vCISO retainer.
Steps that can run at your premises
For a Brisbane organisation, those steps can run at Eagle Street or at your premises instead of by video call. Everything else, scoping, the report and the re-test, runs the same way it does for a client anywhere else in the country.
Choosing a cyber security company by what it can evidence
A cyber security company's claims are hard to check from a website alone. Three things can be checked directly: a certification listed on the issuing body's own public registry, a credential held by a named individual, and whether the team reporting a finding is the same one that fixes it.
Black Shard holds SMB1001:2026 Gold, Level 3, issued by CyberCert and active to 17 June 2027, listed on CyberCert's public registry. The firm's own estate runs at Essential Eight Maturity Level 3.
The credential, the stack and what to check
A director holds the Exemplar Global Certified Lead Auditor credential for ISO/IEC 27001:2022, certificate C-560291, valid to 25 August 2027, an individually held credential. Delivery runs on Microsoft 365, Azure in Australian regions and Cloudflare, the stack the engineering practice builds and operates for clients.
None of that substitutes for the scope of an engagement. It is what to check before agreeing one: whether the certification is listed publicly, whether the credential names a person, and whether the team that reports a finding is the one that fixes it.
What does cyber security cost?
There is no rate card, because the practices cover different shapes of work: a fixed-scope penetration test, a standing vCISO retainer, a milestone-driven compliance programme, an incident that cannot be sized until it is triaged.
What drives the cost
Cost is driven by the practice, the attack surface or system count in scope, the framework involved, and whether on-site work in Brisbane is included.
Send a brief to info@blackshard.com.au with whichever of those you know, and scoping starts from there.
Recent work of this kind
PowerSync
External attack-surface monitoring on Assay, with per-subject report delivery by email.
About AssayClient confidential
Authenticated application and cloud-configuration penetration test of a Queensland financial-services platform, under signed authority, retested to closure.
Client confidential
Essential Eight assessment and uplift: authentication, patching, privilege, backups, the same program our own estate runs at Maturity Level 3.
Questions, answered
How do we choose a cyber security company?
Ask what the deliverable is, whether findings are reproduced before they are reported, whether a fix and a re-test are included, whether the firm operates production systems of its own, and whether the certifications claimed are held by the legal entity and verifiable.
What does a cyber security engagement cost?
There is no published figure. Cost follows scope, driven by the practice, the attack surface or system count, the framework involved, and whether on-site delivery in Brisbane is included. Send a brief to info@blackshard.com.au and scoping starts from the detail you have.
What does an engagement look like, day to day?
Scoping first, so both sides agree what is in and out before anything is touched; then the work, whether a test, a review or a build; then a report or briefing with remediation detail for each finding; and, where it applies, a re-test. Standing engagements such as a vCISO retainer run on an agreed cadence.
Do you only work with Brisbane businesses?
No. Black Shard is an Australian firm headquartered in Brisbane, and every practice is delivered Australia-wide. Brisbane organisations have the option of in-person scoping, on-site testing and an in-person debrief.
If a security review finds a problem, do you also fix it?
Yes, where that is what you want. Black Shard designs, builds and operates production software, and can engineer the fix for a finding it reported.
Does Black Shard hold SMB1001 Gold?
Black Shard holds SMB1001:2026 Gold, Level 3, issued by CyberCert and active to 17 June 2027. Any firm's claim can be checked the same way: CyberCert's public registry lists who holds a certificate, at what tier, and until when.
Do you work on site in Brisbane?
Yes. Scoping, internal network testing, physical social engineering testing, board briefings and debriefs can run at our Eagle Street head office or at your premises. Every practice is also delivered the same way, by video call and secure access, for a business anywhere else in Australia.
What does a Brisbane cyber security engagement start with?
A brief to info@blackshard.com.au covering the systems or question involved, the framework or deadline driving it, and whether Brisbane on-site delivery matters to you. Scoping follows from that, in person at Eagle Street or by video call, and agrees what is in and out before anything is touched.
Related reading
The full practice: Security advisory & vCISO.
Tell us what you need built, reviewed or secured.
Brisbane head office.