Industries · Government & suppliers
For the public sector, and everyone who supplies it.
Councils and government suppliers get asked the same hard questions. We get you ready to answer them with evidence.
We bring Essential Eight uplift, penetration testing, a standing vCISO seat and secure builds, with procurement facts you can verify before the first conversation.
The audience is twofold. Councils and local government bodies carry serious security expectations without enterprise security teams. And businesses supplying government inherit those expectations through tender questionnaires: Essential Eight maturity, incident readiness, and evidence for every claim.
What you carry, and what we do about it.
Essential Eight maturity is the default yardstick: agencies are assessed against it, and suppliers are increasingly asked for it.
An Essential Eight uplift: your current maturity rating across all eight strategies, an uplift plan to the target level, and an evidence trail for each mitigation.
Essential Eight upliftTender security questionnaires demand specific answers with evidence, and a blank row can cost the bid.
A posture assessment maps where you stand against recognised controls, and a vCISO gives you a named security lead to stand behind the answers.
vCISO & posture assessmentIncident reporting expectations: government buyers want a response path that has been rehearsed.
A review of your logging and alerting coverage, an incident response playbook your team can run, and a tabletop exercise to pressure-test it.
Detection & response advisoryLegacy systems predate the expectations now applied to them, and they still run the service.
We penetration-test the systems you run and hand back a ranked fix list. Where a system cannot be defended, we design and build its replacement secure by design.
Penetration testing & secure builds
The obligations in play
- ASD Essential Eight
- The baseline mitigation strategies Australian government bodies are assessed against, and increasingly expect their suppliers to address.
- ASD Information Security Manual
- The control framework for systems handling government information; we design to it where it applies.
- Privacy regimes
- Councils sit under state information-privacy statutes; suppliers handle personal information under the Privacy Act 1988.
- Procurement security requirements
- Tenders carry their own mandated controls, insurances, and evidence obligations, set contract by contract.
Not legal advice; your advisers own the interpretation.
What procurement asks, answered.
The facts a tender evaluation checks, stated here so you can verify them before the first conversation.
- Legal entity
- Black Shard Pty Ltd · ABN 66 696 910 773
- Certification
- SMB1001:2026 Gold (Level 3), issued by CyberCert on director attestation and listed on the public registry.Verify on the CyberCert registry ↗
- Insurance
- Professional indemnity, public liability, and cyber insurance held. Certificates of currency on request.
- Ownership
- Australian-owned and operated, headquartered in Brisbane, Queensland.
- Capability statement
- Ready for your evaluation pack.Download the capability statement (PDF) ↓
If you are running procurement, ask for the capability statement; we answer security questionnaires as part of the job.
The services behind this work.
Compliance readiness
Black Shard works with organisations preparing for the Essential Eight, SMB1001 and ISO 27001, as well as businesses reviewing their obligations under the Australian Privacy Principles.
Read more
Offensive testing
We test applications, APIs, networks and cloud environments for vulnerabilities that can be reproduced and exploited.
Read more
Defensive & advisory
Ongoing security leadership for organisations that need somebody to own cyber risk but do not require a full-time CISO.
Read more
Ready for the questions procurement asks.
Brisbane head office. Work delivered across Australia.

