Security posture assessment
A structured gap analysis against the Essential Eight and CIS Controls.
What you get
- Current position mapped to recognised controls
- Exposures identified and ordered by priority
- A remediation roadmap with effort estimates
Ongoing security leadership for organisations that need somebody to own cyber risk but do not require a full-time CISO.
A vCISO engagement covers security strategy, risk management, policies, board reporting, incident preparation and oversight of technical remediation. We also conduct standalone security posture assessments, Azure reviews, Entra ID reviews and incident-readiness exercises.
We establish where the organisation stands, set the order of work and keep the security program moving.
A structured gap analysis against the Essential Eight and CIS Controls.
What you get
Security strategy, policy, board reporting and incident readiness on a defined cadence.
What you get
A review of identity, network, secrets and logging configuration across your Azure tenant.
What you get
Review and hardening of the Entra ID and Microsoft 365 tenant your business signs in to.
What you get
Scheduled external scans of your internet-facing systems using Assay, our scanning platform, with each result reviewed by an engineer before it is reported.
What you get
A review of whether an attack would be detected, and what the response would be.
What you get
How it is shaped
An ongoing monthly retainer, or a one-off assessment to start.
PowerSync
External attack-surface monitoring on Assay, with per-subject report delivery by email.
About AssayClient confidential
Continuous security review of running estates, with perimeter scanning between audits.
Engineers who design, build and run production software, including Aurii, the compliance and operations portal GRM LAW runs on, and the staff portal Stone Leaf Capital operates from. The person reviewing your Azure tenant secures the same platform daily, and the person writing your incident response playbook would triage an incident in our own systems.
Least privilege from day one: the minimum access the work requires. Client material gets the same practices as our own: encryption in transit and at rest, few third parties, Australian regions for hosted client data, and an incident path that meets the Privacy Act's notification obligations. An Azure review reads identity, network, secrets and logging configuration under the same rule.
A written document you can act on. A posture assessment maps where you stand against the Essential Eight and CIS Controls, what is exposed, what to fix first, and a roadmap costed by effort. An Azure review ties each misconfiguration and over-privilege finding to the Azure control that closes it. An engineer confirms every finding.
On advisory work, verification runs through the cadence. Under a vCISO retainer a named security lead keeps strategy, policies and the risk register current and reports progress to the board. Where an engagement includes fixed-scope offensive testing, a re-test of the fixed findings is included. A one-off assessment gives you the roadmap; a retainer keeps it worked.
A posture assessment is a gap analysis: your controls measured against the Essential Eight and CIS Controls, with a prioritised roadmap. A penetration test is an attack that proves what is exploitable today. The usual sequence is the assessment first to set direction, then testing on the surfaces the roadmap flags. Black Shard runs both.
Yes. A posture assessment, an Azure tenant review, board reporting and a tabletop exercise all run remotely. Client data stays in Australian regions on the services that host it, under the same Privacy Act obligations we design to ourselves.
We do not publish prices, because cost is driven by scope. A posture assessment runs as a one-off, advisory as a monthly retainer, and offensive testing as a fixed-scope engagement with a re-test. Compliance work runs as a program with milestones toward your certification or audit date. Send the brief for a figure.
The roadmap becomes the plan. Run remediation in-house, since the findings come with fixes, or move to a retainer where a named security lead keeps strategy, policies and the risk register current, with reporting your board can act on. The incident response playbook we write is pressure-tested in a tabletop exercise with your team.
Further reading