Black Shard

Security leadership without building an internal security function.

Ongoing security leadership for organisations that need somebody to own cyber risk but do not require a full-time CISO.

Talk to us about your security posture

A vCISO engagement covers security strategy, risk management, policies, board reporting, incident preparation and oversight of technical remediation. We also conduct standalone security posture assessments, Azure reviews, Entra ID reviews and incident-readiness exercises.

What the work is for

We establish where the organisation stands, set the order of work and keep the security program moving.

Security posture assessment

A structured gap analysis against the Essential Eight and CIS Controls.

What you get

  • Current position mapped to recognised controls
  • Exposures identified and ordered by priority
  • A remediation roadmap with effort estimates

vCISO: fractional security leadership

Security strategy, policy, board reporting and incident readiness on a defined cadence.

What you get

  • A security lead on a regular cadence
  • Security strategy, policies and a risk register kept current
  • Board reporting in business risk terms

Azure cloud security review

A review of identity, network, secrets and logging configuration across your Azure tenant.

What you get

  • Identity, network, secrets and logging review of the tenant
  • Misconfiguration and over-privilege findings
  • A remediation plan tied to Azure-native controls

Entra ID & Microsoft 365 identity security

Review and hardening of the Entra ID and Microsoft 365 tenant your business signs in to.

What you get

  • Conditional access and MFA coverage review, including break-glass accounts
  • Privileged-role and app-consent audit across the tenant
  • Offboarding and recovery review, so a lost admin account cannot lock the business out

Managed exposure monitoring

Scheduled external scans of your internet-facing systems using Assay, our scanning platform, with each result reviewed by an engineer before it is reported.

What you get

  • Assay scans of your external footprint on a standing schedule, each run diffed against the last
  • A written monthly position: what changed, what matters and what to fix first
  • Evidence suitable for an insurer or customer, and remediation by us where required

Detection & response advisory

A review of whether an attack would be detected, and what the response would be.

What you get

  • A review of logging and alerting coverage
  • An incident response playbook written for your team
  • A tabletop exercise to test it

How it is shaped

An ongoing monthly retainer, or a one-off assessment to start.

Recent work of this kind

  • PowerSync

    External attack-surface monitoring on Assay, with per-subject report delivery by email.

    About Assay
  • Client confidential

    Continuous security review of running estates, with perimeter scanning between audits.

Questions, answered

Who does the advisory work?

Engineers who design, build and run production software, including Aurii, the compliance and operations portal GRM LAW runs on, and the staff portal Stone Leaf Capital operates from. The person reviewing your Azure tenant secures the same platform daily, and the person writing your incident response playbook would triage an incident in our own systems.

How do you handle our data and access during an engagement?

Least privilege from day one: the minimum access the work requires. Client material gets the same practices as our own: encryption in transit and at rest, few third parties, Australian regions for hosted client data, and an incident path that meets the Privacy Act's notification obligations. An Azure review reads identity, network, secrets and logging configuration under the same rule.

What do we get at the end?

A written document you can act on. A posture assessment maps where you stand against the Essential Eight and CIS Controls, what is exposed, what to fix first, and a roadmap costed by effort. An Azure review ties each misconfiguration and over-privilege finding to the Azure control that closes it. An engineer confirms every finding.

Do you verify that fixes landed?

On advisory work, verification runs through the cadence. Under a vCISO retainer a named security lead keeps strategy, policies and the risk register current and reports progress to the board. Where an engagement includes fixed-scope offensive testing, a re-test of the fixed findings is included. A one-off assessment gives you the roadmap; a retainer keeps it worked.

How is a posture assessment different from a penetration test?

A posture assessment is a gap analysis: your controls measured against the Essential Eight and CIS Controls, with a prioritised roadmap. A penetration test is an attack that proves what is exploitable today. The usual sequence is the assessment first to set direction, then testing on the surfaces the roadmap flags. Black Shard runs both.

Do you work with organisations outside Brisbane?

Yes. A posture assessment, an Azure tenant review, board reporting and a tabletop exercise all run remotely. Client data stays in Australian regions on the services that host it, under the same Privacy Act obligations we design to ourselves.

How much does a security assessment or vCISO retainer cost?

We do not publish prices, because cost is driven by scope. A posture assessment runs as a one-off, advisory as a monthly retainer, and offensive testing as a fixed-scope engagement with a re-test. Compliance work runs as a program with milestones toward your certification or audit date. Send the brief for a figure.

What happens after the report is delivered?

The roadmap becomes the plan. Run remediation in-house, since the findings come with fixes, or move to a retainer where a named security lead keeps strategy, policies and the risk register current, with reporting your board can act on. The incident response playbook we write is pressure-tested in a tabletop exercise with your team.

Tell us where your security program stands.

Brisbane head office.

Open a briefinfo@blackshard.com.au