Black Shard

Fractional CISO services for Australian businesses.

A Black Shard vCISO acts as the named owner of your organisation's security program without a full-time executive hire.

A Black Shard vCISO acts as the named owner of the organisation's security program without requiring a full-time executive hire. The engagement can include strategy, risk management, board reporting, policies, incident readiness, supplier assurance and oversight of security projects. The scope and meeting cadence are agreed at the start and adjusted as the organisation changes.

Black Shard is an Australian software engineering and cybersecurity firm headquartered in Brisbane. The firm builds and operates production systems in regulated settings, including the operations and compliance portal GRM LAW runs on, where every state change lands in an append-only audit ledger, and Aurii, a clinical software platform with tenant health data isolated by PostgreSQL row-level security. The controls a vCISO recommends are drawn from that operating work.

What a vCISO engagement includes

A vCISO is a fractional chief information security officer: a senior practitioner who owns the security program for an agreed share of their time, on a regular cadence. The engagement covers the work a CISO would own if the organisation employed one.

  • Security strategy: a written plan with owners and dates, reviewed as the business changes
  • Risk management: a risk register maintained with the people who own each risk
  • Board reporting on the board's calendar, written for directors to question and act on
  • Policies drafted for how the organisation operates and kept current
  • Incident readiness: a response plan the team can run, tested in a tabletop exercise
  • Supplier assurance: customer and supplier security questionnaires handled as they arrive
  • Oversight of security projects, including penetration tests, Azure reviews and remediation work

When a vCISO fits

The usual position is an organisation that has grown past security living in the IT manager's spare hours and has not reached the scale where a full-time executive salary is justified. Common triggers: a board or insurer has started asking about cyber risk and nobody owns the answer; a large customer has sent a security questionnaire; the business operates in a regulated industry such as health, legal or financial services; or an incident has exposed the gap.

A full-time CISO fits at a certain scale: a security team to lead, a threat profile that shifts weekly, a permanent executive seat. Where an organisation grows into that, the strategy, register, policies and board relationship built under the vCISO engagement are documented for the incoming executive to inherit.

How an engagement starts

The usual first step is a security posture assessment: a gap analysis against the ASD Essential Eight and the CIS Controls. It records where the organisation stands, mapped to recognised controls, and what to fix first. The findings become the first version of the roadmap, prioritised and costed by effort, so the retainer starts with a plan.

From there the retainer stands up the working parts of the program: the risk register, a policy baseline, an incident response plan and the first board report, with the reporting cadence set for those that follow.

How the retainer runs

The standard shape is a monthly retainer. Each session works the same agenda: the risk register reviewed against what has changed, the roadmap moved forward by what was committed last time, and reporting prepared on the board's calendar. The agenda produces a record a director or auditor can follow month over month.

Between sessions the vCISO handles what arrives outside the cycle: a supplier questionnaire, a board question, an alert that needs a decision. Where the roadmap calls for a penetration test, a secure code review or an Azure tenant review, Black Shard scopes and delivers it as a separate piece of work under the vCISO's oversight.

Our own position

Black Shard holds SMB1001:2026 Gold, issued by CyberCert and verifiable on its public registry, and self-assesses against the ASD Essential Eight at Maturity Level 2 and against the Australian Privacy Principles. What is held and what is self-assessed is labelled as such, and the same labelling is applied to client positions in board reporting and questionnaire responses.

What does a vCISO cost?

Pricing is scoped and no rate card is published. The standing shape is a monthly retainer, and a one-off posture assessment is the usual first step.

The variables are the size and complexity of the business, the regulatory frame it operates under, the reporting cadence the board needs, and how much of the groundwork (policies, register, response plan) already exists. Send a brief to info@blackshard.com.au.

Questions, answered

What is a CISO services retainer?
The standing arrangement a vCISO engagement runs on: an agreed share of a senior practitioner's time on a regular cadence, covering strategy, policy, the risk register and board reporting, kept current between sessions.
How is a vCISO retainer different from hiring a CISO?
A full-time CISO is a salaried executive hire. A vCISO retainer provides the same ownership of the security program for a defined fraction of the cost, with the firm's penetration testing, Azure review and engineering capability behind it. An organisation that grows into the full-time role inherits a strategy, register and policy set already built.
How often will we see our vCISO?
On the cadence agreed at the start of the engagement, typically monthly. Between sessions the strategy, policies and register are kept current, and matters that cannot wait for the next session are handled as they arise.
Do we need a separate firm for penetration testing?
No. Black Shard runs penetration testing, red teaming and phishing simulation as separately scoped engagements. When the vCISO roadmap calls for a test, the firm scopes and delivers it.
Do you only work with Brisbane businesses?
No. Black Shard is an Australian firm headquartered in Brisbane and delivers vCISO engagements Australia-wide. The cadence, reporting and reviews run remotely.
What frameworks do you work against?
The ASD Essential Eight, the CIS Controls, SMB1001, ISO 27001 and the Australian Privacy Principles. Black Shard holds SMB1001:2026 Gold, verifiable on the CyberCert public registry. The others are frameworks the firm works against.
What happens if we have an incident?
The response plan built during the engagement is run, with the vCISO involved in containment decisions, communication and the notification obligations under the Privacy Act's Notifiable Data Breaches scheme. Incident readiness is built early in the engagement so the plan exists before it is needed.
What access do you need to our systems?
The access the work requires and no more: administrative privilege granted deliberately, reviewed as the engagement changes and removed when it ends.
How do we start?
Send a brief to info@blackshard.com.au. The usual first step is a security posture assessment, which gives both sides a documented position before a retainer is scoped.

Tell us what you need built, reviewed or secured.

Brisbane head office. Work delivered across Australia.

Open a briefinfo@blackshard.com.au