Black Shard

We build software. Then we break it before attackers do.

Black Shard builds production software and secures the systems businesses already rely on. We design and operate web applications, mobile apps, internal platforms and cloud infrastructure. Our security work covers penetration testing, red teaming, cloud and identity reviews, compliance, secure code review and incident remediation. The firm is based in Brisbane and works across Australia.

Engineering and security under one roof

Software engineering and security work, delivered by one firm.

  • Software engineering

    Web applications, mobile apps, internal platforms and integrations. We can take a product from design through to production, or work inside an existing engineering team.

  • Offensive security

    Penetration testing, red teaming and social-engineering assessments across applications, APIs, networks and people.

  • Security advisory

    Security assessments, vCISO engagements, Azure and Microsoft 365 reviews, and ongoing exposure monitoring.

  • Incident response

    Technical investigation, containment and remediation when a compromise has occurred or is suspected.

  • Compliance

    Essential Eight, SMB1001, ISO 27001 and Australian Privacy Principle readiness, including the technical work and evidence needed to support the assessment.

  • Secure development

    Code review, threat modelling and security architecture for software already in production or still being designed.

Work in production

Black Shard has delivered software and security work across legal, clinical, property, recruitment and financial-services environments. The public case studies show the systems, the problem each one solves and the security controls behind it.

Clients

Platforms we use

40+ systems and engagements on the public register alone

Open the work register

The marks shown are the ones that can be shown publicly.

Assay

External security monitoring without the noise.

Assay monitors your internet-facing systems for exposed services, vulnerable software and configuration changes. Results are mapped to the Essential Eight and SMB1001, with a clear distinction between what has been verified, what presents a risk, and what the scanner cannot determine.

Every plan includes the whole product. Plans start at $349 AUD per month.

Every finding is reported as one of four verdicts. A check the scanner could not complete is reported as such.

  • OK

    The scan verified it. Nothing else in the report uses this green.

  • AT RISK

    The scan found a gap: exploitable software, a missing control, an exposed service.

  • NOT ASSESSED

    A scanner could not complete, so Assay claims nothing. Never treated as a pass.

  • NOT OBSERVABLE

    Cannot be seen from outside. Assay reports that as the result.

What we hold and what we build on

The certification below is independently issued and can be checked on CyberCert's public registry. The platforms beside it are what our production systems run on. We also build on AWS, Google Cloud and client-run infrastructure when needed.

Frameworks we work against: ASD Essential Eight, OWASP, MITRE ATT&CK, CISA KEV, SMB1001:2026, ISO 27001, and the Australian Privacy Principles.

How we work

  1. Scope

    We scope the system first, including the information it holds, the way it is used and the obligations around it.

  2. Test and review

    Testing and review then focus on the paths that could produce meaningful impact.

  3. Verify

    Where remediation is included, fixes are verified before the engagement is closed.

[email protected]

Tell us what you need built, reviewed or secured. 1800 370 270. Our head office is in Brisbane, and we deliver work across Australia.