Black Shard

Technical incident response and remediation.

If you have suffered or suspect a security incident, the first priority is establishing what happened and containing any continuing access.

Talk to us about an incident

Black Shard investigates the affected systems, determines the likely entry point and scope, and works with your team on containment. Once the incident is understood, we can remediate the underlying application, infrastructure or configuration issues and verify the affected surface afterwards. Where the incident may involve obligations under the Notifiable Data Breaches scheme, we can prepare the technical record required by management and legal advisers. We do not provide legal advice.

Incident containment & triage

Establish what happened, what was reached, and contain any continuing access.

What you get

  • Triage of the compromise: the entry point, the scope and the data touched
  • Containment actions agreed with you before they are taken
  • A written account of what is known and what is not yet known

Root-cause analysis & remediation engineering

Remediation of the application, infrastructure or configuration issue behind the incident.

What you get

  • Root-cause analysis tracing the incident to the underlying weakness
  • Remediation engineered and deployed, with adjacent gaps hardened
  • Verification of the affected surface after remediation

Notifiable Data Breaches support

Technical support for the assessment and notification obligations under the Notifiable Data Breaches scheme.

What you get

  • Support with the Notifiable Data Breaches assessment; we do not give legal advice
  • A factual incident record for your board, insurer or legal advisers
  • Changes that make the next assessment simpler to run

Incident readiness

The response plan, the practice run and a verified backup restore, prepared before an incident.

What you get

  • An incident response plan written for your team and systems
  • A tabletop exercise run against a realistic scenario
  • Backup and recovery verified against a completed restore

How it is shaped

A fixed-scope engagement: investigation and containment first, then remediation and verification of the affected surface.

Questions, answered

Who does the remediation work?
Engineers who build and run production software in regulated industries. Black Shard operates its own systems, and the same team runs the firm's offensive testing practice. That combination is the point of the service: the person who traces your incident to root cause is someone who ships and attacks systems like yours, so the fix is engineered and shipped rather than described in a recommendation.
How do we reach you when an incident starts?
Contact is by email to info@blackshard.com.au; a director reads every brief and replies as soon as possible. What we offer is depth once engaged: containment, root-cause analysis, remediation engineering, and a re-test, done properly.
We think we have been breached but are not sure. Is that enough to start?
Yes. A suspected incident is a legitimate brief, and triage is the first phase of the engagement either way: establishing what happened, what was reached, and whether the compromise is still live. If the triage shows no incident, you get that finding in writing, along with whatever weaknesses the investigation surfaced.
How is your incident data handled?
Under the same practices we apply to our own estate. Access is least-privilege: we take only what the engagement requires, and containment actions are agreed with you before they are taken. Engagement material is encrypted in transit and at rest, the set of third parties that touch it is kept deliberately small, and the services that host client data sit in Australian regions. Incident material is among the most sensitive a firm can hold, and it is treated that way.
Can you help with our Notifiable Data Breaches obligations?
Yes, with a clear boundary. We support the assessment the Privacy Act's Notifiable Data Breaches scheme requires: establishing the facts of what was accessed, who is affected, and what remediation has been done, and producing the factual record the assessment and any notification rest on. We are engineers, and we do not give legal advice; where the judgement is legal, your legal advisers make it, working from the record we build.
How is this different from a penetration test?
A penetration test finds the holes before an attacker does. Breach remediation is for after: the incident has happened, or you suspect it has, and the work is containment, root cause, and the engineering fix. The two share the same discipline, and a remediation engagement ends the way our offensive work does, with a re-test of the fixed surface to confirm the holes are closed.
Do you work outside Brisbane?
Yes. A national firm, head office in Brisbane, delivering Australia-wide. Containment, root-cause analysis, and remediation run against your systems wherever they are hosted, the same way our testing and build work does.
How is the cost set?
By scope, like the firm's other security work. Breach remediation runs as a fixed-scope engagement: triage and containment first, then remediation scoped against what the triage found. The drivers are the size of the affected surface, the state of the systems involved, and whether we are also supporting a Notifiable Data Breaches assessment. We do not publish prices, because a number without a scope misleads in both directions.

Tell us what you have found.

Brisbane head office. Work delivered across Australia.

Open a briefinfo@blackshard.com.au