Black Shard

We build software. Then we break it before attackers do.

An Australian software engineering and cybersecurity firm. We build and run software in regulated industries, then attack it the way an adversary would. Penetration testing, red teaming, advisory, compliance, breach remediation, secure-by-design builds.

scroll

Two practices. One team.

Software that ships fast and stands up to attack, from one team accountable for both. We build it, then break it the way an adversary will, so weaknesses are closed before production finds them.

  • Software engineering

    Product and platform builds on Azure: web, native mobile, portals, and the operations systems underneath. We run what we ship.

  • Offensive testing

    Penetration testing, red teaming, phishing simulation. An adversary's attack, then a ranked fix list.

  • Defensive & advisory

    Posture assessments, vCISO, Azure security reviews. A security seat at your table, without the full-time hire.

  • Breach remediation

    Containment, root cause, and remediation after an incident. We fix what let it happen, then re-test.

  • Compliance readiness

    Essential Eight, SMB1001, ISO 27001, and Privacy Act uplift. Audit-ready, with the evidence to prove it.

  • Secure development

    Secure code review, threat modelling, and security architecture at the level attacks actually happen: the code.

  • Assay, our scanner

    Continuous external scanning, mapped to the Essential Eight and SMB1001. Live, from $349 a month.

Some of the brands we've worked for and secure.

Every name here has trusted us with real work: systems we build and run, and systems we test and secure.

Clients

Platform partners

  • Microsoft Azure
  • Microsoft 365
  • Cloudflare
  • Stripe
  • Docusign
  • Twilio
  • Xero
  • Tyro
  • InfoTrack
  • Medical Objects
Open the case studies

What can be shown publicly is here. The rest runs privately.

Assay

Our scanner, pointed at your business.

Assay scans your internet-facing systems, maps every finding to the Essential Eight and SMB1001, and gives you evidence you can hand to your insurer, your board, and your customers.

Every plan includes the whole product. From $349 a month, flat AUD.

Every finding lands as one of four verdicts, and a check that could not run is never dressed up as a pass.

  • OK

    The scan verified it. Nothing else in the report uses this green.

  • AT RISK

    The scan found a gap: exploitable software, a missing control, an exposed service.

  • NOT ASSESSED

    A scanner could not complete, so Assay claims nothing. Never treated as a pass.

  • NOT OBSERVABLE

    Cannot be seen from outside. Assay says so instead of guessing.

Technology you can trust with the work your organisation relies on.

We build under the obligations our clients are held to. The one credential here is independently issued and verifiable on a public registry. Beside it, the platforms we build with in production every day.

We test and build against ASD Essential Eight, OWASP, MITRE ATT&CK, CISA KEV, SMB1001:2026, ISO 27001, and the Australian Privacy Principles.

Three steps. One commitment.

  1. Read the real risk

    We learn the system before we test it: the attack surface, the data that matters, the obligations you carry.

  2. Test like an adversary

    We attack applications, networks, and people against the OWASP and ASD playbooks. We test for the objective an attacker is actually after.

  3. Fix like an engineer

    Plain-English findings, concrete fixes, and a re-test to prove the holes are closed.

info@blackshard.com.au

Australia-wide, from our Brisbane head office. Someone will contact you as soon as possible.