Black Shard

Know your exposure, wherever you operate.

Scheduled scans of your internet-facing systems, read by a senior engineer every month and delivered Australia-wide from our Brisbane head office.

Black Shard is an Australian software engineering and cybersecurity firm. Attack-surface monitoring is the standing watch we run between deeper engagements: penetration tests, Azure tenant reviews, Entra ID reviews. Systems drift on their own schedule, not yours. A subdomain from a campaign stays live after the campaign ends, a port opens during a migration and is never closed again, a certificate lapses quietly. Monitoring exists to catch that the week it happens.

The scans run on Assay, the exposure-monitoring platform Black Shard built and operates. The service is not a login and a dashboard: a senior engineer reads every month's results, separates what matters from what does not, and writes you a position in plain English, delivered wherever your business runs.

What attack-surface monitoring includes

Assay scans your internet-facing footprint on a standing schedule: every exposed host and service catalogued, remote-access and database ports flagged the moment they surface, and findings checked against known CVEs, misconfigurations, default logins, and TLS problems. Severity is not a generic label; findings are ranked against CISA's Known Exploited Vulnerabilities catalogue and EPSS exploit probabilities, so you know which gaps are being used against real targets right now. Email authentication is checked over DNS as well, catching the SPF and DMARC misconfigurations, including softfail and p=none policies, that leave a domain open to spoofing.

Each scan is diffed against the last one, so the report is a change list, not a fresh document to compare by eye. Where a gap matters, we can show the path an attacker could take to reach it in MITRE ATT&CK terms, and every finding carries one of four honest verdicts: confirmed OK, confirmed at risk, not assessed because a scan could not complete, or not observable from outside. Only the first is ever treated as a pass.

  • Scheduled scans of your external footprint, on a standing cadence rather than a single point-in-time report
  • Findings ranked against real-world exploitation data, not a generic severity label
  • Change tracking that diffs each scan against the last, so drift shows up the week it happens
  • A written monthly position from a senior engineer: what changed, what matters, what to fix first
  • Evidence you can hand to an insurer or a customer's security questionnaire
  • Remediation by us when a finding needs closing, not just reporting

Why a snapshot goes stale

A point-in-time report is accurate for exactly one day. The subdomain spun up for a campaign, the database port opened for a one-off job and never closed, the certificate that lapsed on a system nobody remembers standing up: none of it appears in a report from months earlier. Most businesses learn their attack surface has moved only once something has already gone wrong with it.

Monitoring turns the report into a standing position instead of a stale artefact. Because every scan is compared against the one before it, what lands in your inbox is the change, not the whole picture again, which is the version a busy team can actually act on.

Built on Assay, read by an engineer

Assay is the platform behind the service, and Black Shard built and operates it. It exists because raw scanner output is close to useless without judgement: a list of severities with no sense of which finding is real, which is noise, and which needs a phone call today. Assay is built to be honest instead: OK only once a scan has verified it, and where a scan cannot see or cannot complete against a system, it says so rather than guessing at a pass.

For a managed engagement, Assay's output is the starting point, not the deliverable. A senior engineer reads each month's results against what your business actually does, decides what genuinely matters, and writes the position in plain English. When something needs fixing, the same firm can engineer the fix, because monitoring, penetration testing, and remediation all sit under one roof.

Delivered Australia-wide from our Brisbane head office

The engagement runs the same way whether your business is in Perth, Melbourne, or the Brisbane office's own postcode. Scoping, the monthly review, and any follow-up conversation happen by email and video call, and the position you receive carries the same judgement either way: a senior engineer's read of what changed and what to do about it.

If your business is in Brisbane and you would rather sit across a table for the monthly review, that option exists too. Our attack-surface monitoring, Brisbane page covers the same service with the local option made explicit.

Who reads the scans

The same engineers who run the rest of Black Shard's security practice: people who also perform penetration tests, review Azure tenants and Entra ID, and do the remediation engineering when an incident happens. Reading a scan well is a judgement call built from doing the adjacent work, not just running the tool.

That posture is public where we would point a customer to it too: SMB1001:2026 Gold, verifiable on CyberCert's registry, and a self-assessment against the ASD Essential Eight, labelled exactly that on our trust page.

What does attack-surface monitoring cost?

We do not publish a figure. Cost follows what is actually in scope: the number of domains and hosts in your footprint, how many environments you run, and whether the engagement stops at reporting or extends to remediation when something needs fixing.

Send a brief to info@blackshard.com.au with a rough shape of what you want watched, and the reply comes back with the questions that let us scope it properly.

Every engagement includes

  • A director on the work

    A director reads the brief, scopes the engagement, and stays accountable for the result.

  • Fixed scope, quoted first

    Scope, timeframe, and price are agreed before work starts.

  • Findings validated by hand

    Every finding is checked by a human, written in plain English, and paired with a concrete fix. Raw scanner output is never forwarded.

  • A re-test to prove it

    Fixed-scope offensive work includes a re-test, so fixes are confirmed closed rather than assumed.

  • Least-privilege access

    We take only the access the work requires, and client data sits in Australian regions.

  • A report that is yours

    Written for your engineers and your board, and kept confidential.

Questions, answered

How is this different from a penetration test?
A penetration test proves what an attacker can do with your systems in a defined, bounded engagement. Monitoring is the standing watch in between: scheduled scans that catch drift and known exploitable weaknesses as they appear. Most businesses run both, a test to prove the depth of a specific system, and monitoring to know when the picture changes.
How often do the scans run?
On a standing schedule agreed at scoping, with change tracking that compares every scan against the one before it. The exact cadence depends on how much of your footprint changes and how quickly you need to know.
Will you contact us before the monthly report if something urgent comes up?
Yes. The monthly written position is the standing rhythm, but a finding that genuinely cannot wait does not sit in a queue until the report is due.
Can you fix what the scans find?
Yes. Where a finding needs closing, the same firm can engineer the fix, because monitoring, penetration testing, and remediation engineering sit under one roof rather than three separate vendors.
What does a 'not observable' or 'not assessed' verdict mean?
That the scan could not see the system from outside, or could not complete against it. Neither is treated as a pass. We say so instead of guessing, because a false OK is worse than an honest gap in coverage.
Do you deliver this outside Brisbane?
Yes. Black Shard is a national firm and delivers Australia-wide; the monitoring runs the same way regardless of where your business is based. If you are Brisbane-based and want the monthly review in person, that option exists on our Brisbane page.

See your exposure change, wherever you run.

Australia-wide, from our Brisbane head office. Someone will contact you as soon as possible.

Open a briefinfo@blackshard.com.au