Know the moment your attack surface changes.
Scheduled external scans of your internet-facing systems, read by a senior engineer every month at our Eagle Street office, not forwarded to you raw.
Black Shard is an Australian software engineering and cybersecurity firm with its head office on Eagle Street in Brisbane. Attack-surface monitoring is how we keep a standing watch on what your business exposes to the internet between the engagements that dig deeper: penetration tests, Azure tenant reviews, Entra ID reviews. Systems drift. A subdomain goes up for a campaign and never comes down. A certificate expires. A port opens during a migration and stays open. Monitoring exists to catch that drift the week it happens, not the year someone finally looks.
The scans run on Assay, the exposure-monitoring platform we built and operate ourselves. What makes the service different from a login and a dashboard is what happens after the scan: a senior engineer in this office reads every result, decides what actually matters, and writes you a position in plain English. We do not forward scanner output and call it a report.
What attack-surface monitoring involves
Assay runs a standing schedule of scans against your internet-facing systems: every exposed host and service catalogued, with remote-access and database ports flagged the moment they appear. Findings are checked against known CVEs, misconfigurations, default logins, and TLS problems, and ranked against CISA's Known Exploited Vulnerabilities catalogue and EPSS exploit probabilities, so you know which gaps attackers are actually using right now rather than a theoretical severity score. Email authentication is checked over DNS too: SPF and DMARC, including the softfail and p=none configurations that quietly leave a domain open to spoofing.
Every scan is diffed against the one before it, so a change to your footprint shows up as a change, not as a fresh report you have to compare by eye. When a gap matters, we can show the attack path an adversary could take to reach it, expressed in MITRE ATT&CK technique terms, and each finding carries one of four honest verdicts: confirmed OK, confirmed at risk, not assessed because a scan could not complete, or not observable from outside. None of the last three is ever treated as a pass.
- Scheduled scans of your external footprint, on a standing cadence rather than a single point-in-time report
- Every finding ranked against real-world exploitation data, not a generic severity label
- Change tracking that diffs each scan against the last, so drift shows up the week it happens
- A written monthly position from a senior engineer: what changed, what matters, what we would fix first
- Evidence you can hand to an insurer or a customer's security questionnaire
- Remediation by us when you want a finding closed, not just reported
Why a single scan is out of date the day it's issued
A point-in-time report describes your attack surface on the day it was run. The subdomain someone spun up for a marketing campaign three weeks later, the database port a contractor opened for a one-off job and forgot to close, the certificate that quietly expired: none of it is in a report from January if the incident happens in April. Attack surfaces do not hold still, and most businesses only find out theirs moved once something has already gone wrong with it.
Monitoring turns that into a standing position instead of a stale snapshot. Because every scan is compared against the last one, the report you get is never 'here is everything', it is 'here is what changed and why it matters', which is the version your team can actually act on without re-reading the whole thing.
Built on Assay, read by an engineer
Assay is the scanning platform behind this service, built by Black Shard. It exists because raw scanner output is close to useless to most businesses: a long list of severities with no judgement about which ones are real, which are noise, and which one actually needs a phone call today. Assay is opinionated about honesty instead: a finding is marked OK only once the scan has verified it, and where a scan cannot see a system or cannot complete against it, Assay says so rather than guessing at a pass.
For a managed engagement, that output is the starting point, not the deliverable. A senior engineer in this office reads the month's results against what your business actually does, separates the finding that is genuinely urgent from the one that can wait, and writes the position in plain English. If something needs fixing, the same firm can do the fixing, because monitoring, penetration testing, and remediation engineering all sit under one roof.
Why read it from Brisbane?
The monthly position can go out by email, and often does. But the office is on Eagle Street in Brisbane, and for businesses that want it, the review can happen across a table: the engineer who read the scan walks you through what changed, answers the question a written report cannot anticipate, and, where a finding needs deeper work, brings in the penetration testing or remediation team from the same building the same week.
That proximity matters most the moment something looks genuinely wrong. A verdict that flips from OK to at risk on a system that actually matters is not something you want sitting in an inbox until someone gets to it. Being local means the follow-up conversation can happen fast, with a person who already knows your environment.
Who reads the scans
The same engineers who run the rest of Black Shard's security practice: people who also perform penetration tests, review Azure tenants, and do the remediation engineering when an incident happens. That matters because reading a scan well takes more than the scan; it takes knowing what a finding on a login page usually turns into, and what to actually worry about versus what a checklist worries about by default.
Our own posture is on the same public record we would point a customer to: SMB1001:2026 Gold, verifiable on CyberCert's registry, and a self-assessment against the ASD Essential Eight, labelled exactly that. The trust page sets out the full picture, including what we deliberately do not claim.
What does attack-surface monitoring cost?
We do not publish a figure, because the honest answer depends on what is in scope: how many domains and hosts make up your footprint, how many environments you run, and whether you want the engagement to stop at reporting or extend to remediation when something needs fixing.
Send a brief to info@blackshard.com.au with a rough shape of what you want watched, and the reply comes back with the questions that let us scope it properly.
Do you only monitor Brisbane businesses?
No. The same monitoring service runs Australia-wide, with the position delivered by email and video call. This page is for Brisbane buyers, where the monthly attack-surface review can run face to face if you want it to.
If you are outside Brisbane, our attack-surface monitoring, Australia-wide page covers the national service.
Every engagement includes
A director on the work
A director reads the brief, scopes the engagement, and stays accountable for the result.
Fixed scope, quoted first
Scope, timeframe, and price are agreed before work starts.
Findings validated by hand
Every finding is checked by a human, written in plain English, and paired with a concrete fix. Raw scanner output is never forwarded.
A re-test to prove it
Fixed-scope offensive work includes a re-test, so fixes are confirmed closed rather than assumed.
Least-privilege access
We take only the access the work requires, and client data sits in Australian regions.
A report that is yours
Written for your engineers and your board, and kept confidential.
Questions, answered
- How is this different from a penetration test?
- A penetration test proves what an attacker can do with your systems in a defined, bounded engagement. Monitoring is the standing watch in between: scheduled scans that catch drift and known exploitable weaknesses as they appear. Most businesses run both, a test to prove the depth of a specific system, and monitoring to know when the picture changes.
- How often do the scans run?
- On a standing schedule agreed at scoping, with change tracking that compares every scan against the one before it. The exact cadence depends on how much of your footprint changes and how quickly you need to know.
- Will you contact us before the monthly report if something urgent shows up?
- Yes. The monthly written position is the standing rhythm, but a finding that genuinely cannot wait does not sit in a queue until the report is due.
- Can you fix what the scans find?
- Yes. Where a finding needs closing, the same firm can engineer the fix, because monitoring, penetration testing, and remediation engineering sit under one roof rather than three separate vendors.
- What does a 'not observable' or 'not assessed' verdict mean?
- That the scan could not see the system from outside, or could not complete against it. Neither is treated as a pass. We say so instead of guessing, because a false OK is worse than an honest gap in coverage.
- Do you only work with Brisbane businesses?
- No. The monitoring service runs Australia-wide from our Brisbane head office. Brisbane buyers get the option of a face-to-face monthly review; everyone else gets the same standard by email and video call.
Related reading
The full practice: Security advisory & vCISO.
See your exposure the moment it changes.
Australia-wide, from our Brisbane head office. Someone will contact you as soon as possible.