Black Shard

A security seat at your table.

Ongoing security leadership and review, without hiring a full-time CISO.

Most businesses do not need a full-time CISO; they need someone accountable who knows the terrain. We provide that: strategy, review, and a steady hand on your security posture.

Security posture assessment

A structured gap analysis against the Essential Eight and CIS Controls.

What you get

  • Where you stand today, mapped to recognised controls
  • What is exposed, and what to fix first
  • A prioritised roadmap, costed by effort

vCISO: fractional security leadership

Strategy, policy, board reporting, and incident readiness, sized to you.

What you get

  • A named security lead on a regular cadence
  • Security strategy, policies, and a risk register kept current
  • Plain-English reporting your board can act on

Azure cloud security review

We run on Azure and secure it daily. We review yours the same way.

What you get

  • Identity, network, secrets, and logging review of your tenant
  • Misconfiguration and over-privilege findings
  • A remediation plan tied to Azure-native controls

Entra ID & Microsoft 365 identity security

Identity is the perimeter now. We review and harden the tenant your business signs in to, the way we run our own.

What you get

  • Conditional access and MFA coverage review, including break-glass accounts
  • Privileged-role and app-consent audit across the tenant
  • Offboarding hygiene and recovery readiness, so a lost admin never locks the business out

Managed exposure monitoring

Scheduled external scans of your internet-facing systems by Assay, our own scanner, read by a senior engineer rather than forwarded raw.

What you get

  • Assay scans of your external footprint on a standing schedule, with every change diffed against the last run
  • A written position each month: what changed, what matters, and what we would fix first
  • Evidence you can hand to an insurer or customer, and remediation by us when you want the findings closed

Detection & response advisory

Make sure you would actually see an attack, and know what to do.

What you get

  • A review of your logging and alerting coverage
  • An incident response playbook your team can run
  • A tabletop exercise to pressure-test it

How it is shaped

An ongoing monthly retainer, or a one-off assessment to start.

Every engagement includes

  • A director on the work

    A director reads the brief, scopes the engagement, and stays accountable for the result.

  • A named lead, on a cadence

    One senior practitioner owns the seat, so accountability has a face and a calendar.

  • Mapped to recognised controls

    Your posture measured against the Essential Eight and CIS Controls, and a prioritised path to fix it.

  • Reporting your board can question

    Plain-English reporting prepared on your board's calendar.

  • Least-privilege access

    We take only the access the work requires, and client data sits in Australian regions.

  • A report that is yours

    Written for your engineers and your board, and kept confidential.

Questions, answered

Who does the advisory work?
Engineers who design, build, and run production software. Black Shard builds and secures software: Aurii, plus the compliance and operations portal GRM LAW runs on and the staff portal Stone Leaf Capital operates from. The person reviewing your Azure tenant secures the same platform daily, and the person writing your incident response playbook is one of the engineers who would triage an incident in our own systems. The advice comes from people who carry production responsibility, not from a methodology binder.
How do you handle our data and access during an engagement?
Least privilege, from day one. We ask for the minimum access the work requires and nothing more. The practices we publish on our trust page apply to client material as much as our own: encryption in transit and at rest, a deliberately small set of third parties, Australian regions for the services that host client data, and a defined incident handling path that meets the Privacy Act's notification obligations. An Azure cloud security review reads your identity, network, secrets, and logging configuration; the same least-privilege rule sets the access we ask for to run it.
What do we get at the end?
A plain-English document you can act on. A posture assessment comes back with where you stand mapped to the Essential Eight and CIS Controls, what is exposed, what to fix first, and a prioritised roadmap costed by effort. An Azure review lands the same way, with misconfiguration and over-privilege findings tied to the Azure-native controls that close them. Every finding is validated by hand before it reaches the page; we do not forward raw scanner output. It is written so your board can act on it, not just your engineers.
Do you verify that fixes actually landed?
On advisory work, verification is built into the cadence rather than bolted onto the end. Under a vCISO retainer a named security lead keeps strategy, policies, and the risk register current, and reports progress to the board in plain English. Where an engagement includes fixed-scope offensive testing, a re-test of the fixed findings is included, so closure is demonstrated rather than assumed. A one-off assessment gives you the roadmap; an ongoing retainer is how it keeps getting worked.
How is a posture assessment different from a penetration test?
A posture assessment is a structured gap analysis: your controls measured against the Essential Eight and CIS Controls, with a prioritised roadmap out the other side. A penetration test is an attack: we probe applications, networks, and people the way an adversary would and prove what is exploitable. They answer different questions. The assessment tells you where your security program is weak; the test tells you what an attacker can do today. The natural sequence is to start with the assessment to set direction, then commission testing on the surfaces the roadmap flags. Both run from one team; our offensive testing page covers the second.
Do you work with organisations outside Brisbane?
Yes. Black Shard is a national firm with its head office in Brisbane, and delivers Australia-wide. Advisory work suits remote delivery: a posture assessment, an Azure tenant review, board reporting, and a tabletop exercise all run without anyone on a plane. Client data stays in Australian regions on the services that host it, and the Privacy Act obligations that govern it are the same ones we design to ourselves. The engineers reviewing your environment are the engineers running ours.
How much does a security assessment or vCISO retainer cost?
We do not publish prices, because cost is driven by scope. What we can tell you is the shape of the engagement: a posture assessment runs as a one-off, advisory continues as an ongoing monthly retainer, and offensive testing is a fixed-scope engagement with a defined target and timeframe, plus a re-test. Compliance work runs as a defined program with milestones toward your certification or audit date. If you want a figure, send the brief.
What happens after the report is delivered?
The roadmap becomes the plan. You can take the report and run remediation in-house; the findings come with concrete fixes, so that is a legitimate path. Or move to an ongoing retainer, where a named security lead on a regular cadence keeps strategy, policies, and the risk register current, with plain-English reporting your board can act on. Detection and response advisory closes the loop the same way: the incident response playbook we write is pressure-tested in a tabletop exercise with your team, not filed. Our approach page describes the full arc: read the real risk, test like an adversary, fix like an engineer.

Put a security lead at your table.

Australia-wide, from our Brisbane head office. Someone will contact you as soon as possible.

Open a brief[email protected]