A Brisbane cyber security company that also builds the software it secures.
Offensive testing, defensive advisory, compliance readiness, and breach remediation, from the same Eagle Street office and the same engineers who build and run production software, face to face in Brisbane and Australia-wide.
Black Shard is an Australian software engineering and cybersecurity firm with its head office on Eagle Street in Brisbane. We run six practices from that office: offensive testing, defensive advisory, breach remediation, compliance readiness, secure software builds, and the custom engineering work that sits underneath all of it. Businesses come to us for one of those six; most stay because the other five sit one phone call away, inside the same firm.
The difference is who does the work. The engineers who scope a penetration test, advise a board, or triage an incident are the same engineers who design, build, and run production software for GRM LAW and Stone Leaf Capital, and through our own ventures. They know where a system breaks because they have shipped systems like it, and when a finding needs fixing rather than just reporting, the same firm does that too.
What a cyber security company from Black Shard covers
Six practices, one accountable firm. Offensive testing finds what an attacker would find; defensive advisory keeps a board and a risk register honest between tests; breach remediation contains an incident and fixes what let it in; compliance readiness gets you ready for the frameworks your customers and insurers ask about; secure software builds put the same discipline into new systems before they ship; and the software engineering underneath all of it means the fix, when one is needed, is built by the firm that found the problem.
Most engagements start narrow: a single penetration test, a posture assessment, a compliance gap review. The breadth matters because security problems rarely stay narrow. A test surfaces a code-level flaw; a posture review turns up a gap the board needs briefed; an incident needs both containment and an engineered fix. One firm carries the whole chain, so nothing gets lost in a handoff to a second vendor who has to be re-briefed from scratch.
- Offensive testing: penetration testing, red teaming, phishing simulation
- Defensive advisory: vCISO services, posture assessments, Azure and Entra ID security reviews, attack surface monitoring
- Breach remediation: incident response, root-cause remediation, Notifiable Data Breaches support
- Compliance readiness: Essential Eight uplift, SMB1001 certification readiness, ISO 27001 groundwork, Privacy Act uplift
- Secure builds: secure code review, threat modelling, security architecture
- Software engineering: the custom builds and production systems the security practice is tested against
Offensive testing and defensive advisory
Offensive testing is the adversary's side of the work: penetration testing against the OWASP and ASD playbooks, red teaming aimed at a defined objective rather than a checklist, and phishing simulation that measures how people respond to a real attempt. Every finding is validated by hand and reported with a concrete fix, and a re-test is included to confirm the fix landed.
Defensive advisory is the standing side: a vCISO on a regular cadence who owns the risk register and briefs the board, a posture assessment against the Essential Eight and CIS Controls, an Azure or Entra ID security review of the tenancy itself, and attack surface monitoring that watches what changes between tests rather than waiting a year to look again.
Compliance readiness and breach remediation
Compliance readiness gets you ready for the frameworks Australian businesses are actually asked for: Essential Eight uplift, SMB1001 certification readiness, ISO 27001 groundwork, and Privacy Act uplift. Black Shard prepares the evidence and closes the gaps; the certification or audit itself sits with the accredited body, and we keep that line clear.
Breach remediation is the work nobody wants to need. Containment and triage first, then root-cause analysis that traces the incident back to the code, configuration, or infrastructure that let it happen, remediation engineered and shipped, a re-test to confirm the fix closed, and support with the Notifiable Data Breaches assessment under the Privacy Act.
Why a cyber security company that also builds software
Most security advisory comes from people who do not operate systems of their own. Black Shard designs, builds, and runs production software in regulated industries: the compliance portal GRM LAW runs on, the operations platform behind Stone Leaf Capital, and Aurii, our own clinical-software venture, which carries live tenant health data on Azure in Australia. We are also a Xero developer partner, listed on the Xero App Store, for integration work built to the same standard. A security engagement from Black Shard recommends controls we operate ourselves, in our own production systems.
The same honesty applies to what we claim. Black Shard holds SMB1001:2026 Gold, independently issued and verifiable on the public CyberCert registry. OWASP, the ASD Essential Eight, and the frameworks above are methodologies we test and build against, not credentials we hold, and we keep that distinction clear. The full picture is on our trust page; how we run an engagement is on our approach page.
Face to face in Brisbane, delivered Australia-wide
Our office is on Eagle Street in Brisbane, and for Brisbane businesses the whole engagement can run in person: scoping across a table, internal network testing on your premises, a board briefing in the room, a debrief with the engineer who did the work rather than an account manager relaying it.
Everywhere else the same practices run remotely, to the same standard: the same hand-validated findings, the same plain-English reporting, the same re-test. Distance changes the delivery channel, and nothing else.
What does cyber security cost?
We do not publish a rate card, because honest pricing follows scope and the practices span very different shapes of work: a fixed-scope penetration test, a standing vCISO retainer, a milestone-driven compliance programme, an incident that cannot be sized until it is triaged. What we can do is name what actually moves the number.
Send a brief to [email protected] with whichever of these you know, and scoping starts from there.
- Which practice: a fixed-scope test looks nothing like a standing retainer
- Attack surface or system count: how many applications, tenancies, or sites are in scope
- Framework: Essential Eight, SMB1001, ISO 27001, and Privacy Act readiness carry different evidence burdens
- Delivery: whether on-site work in Brisbane is part of the engagement
Every engagement includes
A director on the work
A director reads the brief, scopes the engagement, and stays accountable for the result.
Fixed scope, quoted first
Scope, timeframe, and price are agreed before work starts.
Findings validated by hand
Every finding is checked by a human, written in plain English, and paired with a concrete fix. Raw scanner output is never forwarded.
A re-test to prove it
Fixed-scope offensive work includes a re-test, so fixes are confirmed closed rather than assumed.
Least-privilege access
We take only the access the work requires, and client data sits in Australian regions.
A report that is yours
Written for your engineers and your board, and kept confidential.
Questions, answered
- How do we choose a cyber security company?
- Match the firm to the shape of the problem, not just the sales pitch. Check whether findings are validated by hand or forwarded straight from a scanner, whether a fix is included or just a report, whether the firm operates production systems of its own, and whether the certifications claimed are actually held rather than implied. Ask who the named practitioner on the engagement will be.
- What does a cyber security engagement cost?
- There is no published figure, because the practices cover very different shapes of work: a fixed-scope penetration test, a standing vCISO retainer, a milestone-driven compliance programme. Cost follows scope, driven by which practice, the attack surface or system count, the framework involved, and whether on-site delivery in Brisbane is part of it. Send a brief to [email protected] and scoping starts from whatever detail you have.
- What does an engagement actually look like, day to day?
- It depends on the practice, but the shape is consistent: scoping first, so both sides agree what is in and out before anything is touched; the work itself, whether that is an attack, a review, or a build; a plain-English report or briefing with a concrete fix for every finding; and, where it applies, a re-test to confirm the fix landed. Standing engagements like a vCISO retainer run on an agreed cadence rather than a single pass.
- Do you only work with Brisbane businesses?
- No. Black Shard is a national firm and delivers every practice Australia-wide from its Brisbane head office. Brisbane businesses get face-to-face scoping, on-site testing, and an in-person debrief; the same standard applies remotely everywhere else.
- If a security review finds a problem, do you also fix it?
- Yes, if that is what you want. The same firm that finds a problem engineers the fix, because the practitioners doing the security work are the engineers who design, build, and run production software day to day. Nothing has to be re-briefed to a second vendor.
Related reading
The full practice: Security advisory & vCISO.
Built, tested, and fixed under one roof.
Australia-wide, from our Brisbane head office. Someone will contact you as soon as possible.