- Who does the AI security work?
- Black Shard engineers. The same team that builds and operates Aurii, our clinical software built on Azure AI Speech recognition with production speech-to-text and OCR pipelines, multi-tenant Postgres and row-level security enforcing tenant separation, tests and secures the AI other businesses run. Delivery is Australia-wide from our Brisbane head office.
- How do you handle our data and access during an AI security engagement?
- Least privilege, from day one. We ask for the minimum access the work requires and nothing more: read access to the application, tenant or environment in scope, with administrative privilege granted only where the work demands it. The practices we publish on our trust page apply to AI security work the same as everything else: encryption in transit and at rest, a deliberately small set of third parties, Australian regions for the services that host client data, and a defined incident handling path that meets the Privacy Act's notification obligations.
- What AI security services does Black Shard provide?
- Six, covering AI adoption end to end. AI security assessment: shadow AI discovery, an AI usage policy and access boundaries for the tools already in use. AI penetration testing: manual testing of LLM-backed applications, chatbots and AI agents against the OWASP Top 10 for Large Language Model Applications. Microsoft Copilot security review: a pre-rollout review of what Copilot can see and who can reach it, covering SharePoint and Teams permissions and conditional access. AI governance and ISO 42001 readiness: gap analysis and management-system groundwork toward ISO 42001, plus a Voluntary AI Safety Standard assessment. Defence against AI-enabled attacks: verification workflows, awareness testing and an incident playbook for phishing, deepfake and voice-clone fraud. Secure AI engineering: guardrails, audit trails and tenant isolation built into an AI feature from the first line of code. If a brief names something else, ask.
- What can you do about AI-generated phishing and deepfake fraud?
- Controls that catch an AI-enabled attempt before money or credentials move. Verification workflows for payment and credential requests, designed to hold even when a voice or a face on the call is a clone. Awareness testing using AI-generated phishing and pretext scenarios, reported per team without identifying individuals. An incident playbook for a suspected AI-enabled fraud attempt, written and ready before the call comes in. This extends our existing phishing-simulation and incident-response practice to attacks built with AI.
- Do you work outside Brisbane?
- Yes. Black Shard is a national firm with its head office in Brisbane, and delivers Australia-wide. AI security work runs against your applications, tenant and documentation, so scoping, testing and the debrief all run by video call the same way in every state.
- How is the cost set?
- We do not publish prices, because cost is driven by scope. An AI penetration test or a Copilot security review runs as a fixed-scope engagement with a defined target and timeframe, plus a retest of agreed fixes. AI governance and ISO 42001 readiness runs as a defined program with milestones toward the assessment date. Send a brief with the AI systems or tools in scope.
- What happens after the engagement or report is delivered?
- The findings and the roadmap become the plan. A penetration test or Copilot review report comes with fixes your engineers can apply directly, and a retest of agreed fixes is included in the fixed scope. AI governance readiness ends at the audit, the same way our other compliance work does; what holds the position afterward is the AI management-system documentation and evidence trail the engagement built. Where AI features are still being built, our secure AI engineering service carries the same guardrails into the next release.