Black Shard

Security for the AI your business has already adopted.

We test AI-backed applications and Microsoft Copilot rollouts, assess AI governance against ISO 42001 and the Voluntary AI Safety Standard, and defend against AI-enabled attacks such as phishing and deepfake fraud.

Staff and teams adopt AI tools faster than most security or IT policies can track them, from chatbots plugged into business data to AI features built into products the business ships. We assess what is already in use, test AI-backed applications and Microsoft Copilot rollouts for the class of flaws OWASP catalogues for large language model applications, and prepare AI governance against ISO 42001 and the Voluntary AI Safety Standard. We also defend against the attacks AI now makes easier: phishing written by a model, and fraud attempted with a cloned voice or a deepfake video call. Where the requirement is a feature the business is building rather than adopting, our engineering practice designs the guardrails, audit trails and tenant isolation in from the start.

AI security work applies the firm's existing testing and advisory discipline to systems that use AI: the same verified findings, the same framework mapping and the same evidence trail as every other engagement.

What the engagement covers

  • Findings verified by an engineer before they are reported, the same standard applied to every offensive and advisory engagement
  • Testing and reviews mapped to recognised frameworks: OWASP guidance and the ASD Essential Eight, extended here to the OWASP Top 10 for Large Language Model Applications
  • Delivered by engineers who build and operate the firm's own production AI systems, including Aurii's Azure AI Speech recognition, speech-to-text and OCR pipelines
  • Evidence recorded as controls are implemented, ready for a certifying assessor
  • Delivered Australia-wide from the Brisbane head office, the same as every other Black Shard engagement

AI security assessment

A review of the AI tools already in use across the business, the data they can reach and the policy that should govern them.

What you get

  • Shadow AI discovery through tenant, network and app-consent review, the same methods used in our Entra ID reviews
  • An AI usage policy setting out what is and is not approved for use with business data
  • Access boundaries defined for each AI tool in scope, so a chatbot or plugin cannot reach data it should not

AI penetration testing

Manual testing of LLM-backed applications, chatbots and AI agents against the OWASP Top 10 for Large Language Model Applications.

What you get

  • Prompt injection and jailbreak testing against the application's actual configuration
  • Findings mapped to the OWASP LLM Top 10, with severity, impact and reproduction steps
  • Remediation guidance written for the engineers who built the feature, with retest of agreed fixes included in the fixed scope

Microsoft Copilot security review

A pre-rollout review of Microsoft 365 Copilot: what it can see, who can reach it and what needs tightening before it goes live.

What you get

  • SharePoint and Teams permission and oversharing review across the content Copilot can surface
  • Conditional access and app-consent review specific to the Copilot rollout
  • A remediation list ordered so the highest-exposure items close before rollout

AI governance & ISO 42001 readiness

Gap analysis and AI management-system groundwork toward ISO 42001, delivered by a certified ISO/IEC 27001:2022 Lead Auditor applying management-system audit discipline to the AI standard.

What you get

  • A gap analysis against ISO 42001 and a Voluntary AI Safety Standard assessment against its guardrails
  • AI management-system documentation: policies, roles and a risk register scoped to how the business actually uses AI
  • Evidence recorded as controls are implemented, ready for a certifying assessor

Defence against AI-enabled attacks

Controls and staff readiness against AI-generated phishing, deepfake and voice-clone fraud attempts, built on the firm's phishing-simulation and incident-response practice.

What you get

  • Verification workflows for payment and credential requests, designed to hold even when a voice or a face on the call is a clone
  • Awareness testing using AI-generated phishing and pretext scenarios, reported per team without identifying individuals
  • An incident playbook for a suspected AI-enabled fraud attempt, written and ready before the call comes in

Secure AI engineering

Design and build of AI features with guardrails, audit trails and tenant isolation in place from the first line of code, drawn from running Aurii's own AI pipelines in production.

What you get

  • Guardrails and input and output controls built around each AI feature before it ships
  • Audit trails recording what an AI feature did and why, for every automated action
  • Tenant isolation for AI features handling multi-tenant data, enforced at the database layer

How it is shaped

Testing and reviews run as fixed-scope engagements with a defined target. Governance readiness runs as a defined program with milestones toward the assessment date.

Questions, answered

Who does the AI security work?
Black Shard engineers. The same team that builds and operates Aurii, our clinical software built on Azure AI Speech recognition with production speech-to-text and OCR pipelines, multi-tenant Postgres and row-level security enforcing tenant separation, tests and secures the AI other businesses run. Delivery is Australia-wide from our Brisbane head office.
How do you handle our data and access during an AI security engagement?
Least privilege, from day one. We ask for the minimum access the work requires and nothing more: read access to the application, tenant or environment in scope, with administrative privilege granted only where the work demands it. The practices we publish on our trust page apply to AI security work the same as everything else: encryption in transit and at rest, a deliberately small set of third parties, Australian regions for the services that host client data, and a defined incident handling path that meets the Privacy Act's notification obligations.
What AI security services does Black Shard provide?
Six, covering AI adoption end to end. AI security assessment: shadow AI discovery, an AI usage policy and access boundaries for the tools already in use. AI penetration testing: manual testing of LLM-backed applications, chatbots and AI agents against the OWASP Top 10 for Large Language Model Applications. Microsoft Copilot security review: a pre-rollout review of what Copilot can see and who can reach it, covering SharePoint and Teams permissions and conditional access. AI governance and ISO 42001 readiness: gap analysis and management-system groundwork toward ISO 42001, plus a Voluntary AI Safety Standard assessment. Defence against AI-enabled attacks: verification workflows, awareness testing and an incident playbook for phishing, deepfake and voice-clone fraud. Secure AI engineering: guardrails, audit trails and tenant isolation built into an AI feature from the first line of code. If a brief names something else, ask.
What can you do about AI-generated phishing and deepfake fraud?
Controls that catch an AI-enabled attempt before money or credentials move. Verification workflows for payment and credential requests, designed to hold even when a voice or a face on the call is a clone. Awareness testing using AI-generated phishing and pretext scenarios, reported per team without identifying individuals. An incident playbook for a suspected AI-enabled fraud attempt, written and ready before the call comes in. This extends our existing phishing-simulation and incident-response practice to attacks built with AI.
Do you work outside Brisbane?
Yes. Black Shard is a national firm with its head office in Brisbane, and delivers Australia-wide. AI security work runs against your applications, tenant and documentation, so scoping, testing and the debrief all run by video call the same way in every state.
How is the cost set?
We do not publish prices, because cost is driven by scope. An AI penetration test or a Copilot security review runs as a fixed-scope engagement with a defined target and timeframe, plus a retest of agreed fixes. AI governance and ISO 42001 readiness runs as a defined program with milestones toward the assessment date. Send a brief with the AI systems or tools in scope.
What happens after the engagement or report is delivered?
The findings and the roadmap become the plan. A penetration test or Copilot review report comes with fixes your engineers can apply directly, and a retest of agreed fixes is included in the fixed scope. AI governance readiness ends at the audit, the same way our other compliance work does; what holds the position afterward is the AI management-system documentation and evidence trail the engagement built. Where AI features are still being built, our secure AI engineering service carries the same guardrails into the next release.

Tell us what AI you need secured.

Brisbane head office. Work delivered across Australia.

Open a brief[email protected]