Incident response in Brisbane.
Containment and triage, root-cause remediation, and support with the Notifiable Data Breaches assessment, from our Brisbane head office.
Black Shard provides incident response for organisations in Brisbane and across Australia: containment and triage, root-cause analysis, remediation of the code, configuration or infrastructure behind the incident, a re-test of the remediated surface, and support with the Notifiable Data Breaches assessment under the Privacy Act 1988.
If you suspect a breach now, the first-hour steps on our breach page do not depend on us: isolate affected machines without wiping them, preserve logs, contain accounts from a known-clean device, engage your insurer, and note your notification clock.
Stages of an engagement
Contact is by email to info@blackshard.com.au. A suspected incident is sufficient to begin triage; a confirmed breach is not required.
Containment actions are put to you before they are taken. Root-cause analysis traces the compromise to the flaw behind it, and remediation is engineered and shipped with the adjacent gaps the same weakness tends to sit beside. The remediated surface is re-tested before close-out.
- Contact and triage: entry point, scope, and data touched, established from what you can tell us
- Containment: actions agreed with you before they are taken, without destroying what root-cause analysis will need
- Root-cause analysis: the compromise traced to the code, configuration or infrastructure behind it
- Remediation and re-test: the fix engineered and shipped, then the remediated surface re-tested
- Close-out: an incident record for your board, insurer or legal advisers, and support with the Notifiable Data Breaches assessment where personal information is involved
Notifiable Data Breaches support
Where personal information is likely involved, the Privacy Act 1988's Notifiable Data Breaches scheme requires a prompt assessment of whether the breach is likely to result in serious harm, and notification if it is. Black Shard supports that assessment. We do not give legal advice; the legal decision sits with your legal advisers.
The support consists of a factual incident record drawn from the containment and root-cause work, and the changes that make the same assessment faster if it is needed again.
Delivery in Brisbane
Black Shard's head office is on Eagle Street in Brisbane, and incident response runs Australia-wide from it. For Brisbane organisations, containment and the debrief can run in person at Eagle Street or at your office. Elsewhere they run by phone, video and secure access.
Root-cause remediation, penetration testing, and Azure and Entra ID reviews are delivered by Black Shard, so remediation follows triage without a handover to another vendor.
Incident readiness
Incident readiness is available before an incident: a response plan written for your team and systems, a tabletop exercise that runs the plan against a scenario, and backup and recovery verification by performing a restore.
It is part of a vCISO engagement and is available on its own.
What does incident response cost?
There is no published figure. Incident work is scoped to what happened: the systems affected, how far the compromise reached, whether the engagement stops at containment or extends through root-cause remediation and re-testing, and whether a Notifiable Data Breaches assessment is being supported.
If you are mid-incident, email info@blackshard.com.au before scoping it precisely. Containment starts and the detail is filled in as the picture clears.
Questions, answered
- How fast can you start?
- Email info@blackshard.com.au. Triage begins on what you can tell us, and containment does not wait for a fully scoped engagement.
- Do you give legal advice on our notification obligations?
- No. We support the Notifiable Data Breaches assessment with a factual incident record and technical analysis. The legal decision sits with your legal advisers.
- Do you only fix the immediate compromise, or the underlying flaw too?
- Both, where that is what you want. Containment stops the immediate damage. Root-cause analysis and remediation fix the code, configuration or infrastructure that allowed it, and the remediated surface is re-tested.
- Do you only respond to Brisbane businesses?
- No. Incident response runs Australia-wide from the Brisbane head office. Brisbane organisations have the option of on-site containment and an in-person debrief.
- Can you help us get ready before an incident happens?
- Yes. Incident readiness produces the response plan, runs a tabletop exercise against a scenario, and verifies backups by performing a restore.
- What should we do right now if we think we have been compromised?
- Start on the breach page: isolate affected machines without wiping them, preserve logs and records, contain accounts from a known-clean device, engage your insurer, note your notification clock, and do not negotiate with an attacker alone. Then email info@blackshard.com.au. A suspected incident is sufficient to begin triage.
Contact Black Shard about an incident.
Brisbane head office. Work delivered across Australia.