Black Shard

If something is wrong, start here.

This page is the first hour of a suspected breach, in order, then how to reach us. Every step on it works before anyone has replied to you.

The first hour.

In this order. None of it waits on a reply from us, and all of it makes whoever responds faster and your position stronger.

  1. Isolate, don't destroy.

    Disconnect affected machines from the network: pull the cable, drop the Wi-Fi, pause the VM. Do not wipe, reinstall, or "clean up". The evidence of how they got in is what gets you safely out.

  2. Preserve what you can.

    Keep logs, screenshots, ransom notes, odd emails, anything that looks wrong. Note times as you go: a plain timeline of what you saw and when is the most useful document you can hand a responder.

  3. Contain accounts.

    From a known-clean device, reset credentials for admin and email accounts, revoke active sessions, and turn on multi-factor authentication where it is missing. A compromised machine cannot be trusted to change its own locks.

  4. Don't pay, don't reply, don't negotiate alone.

    Engage your insurer early: cyber policies often require notification before action is taken. Get help before communicating with an attacker in any form.

  5. Know your notification clock.

    If personal information is likely involved, the Privacy Act's Notifiable Data Breaches scheme may apply, and the assessment it requires has to be prompt. We support that assessment; we do not give legal advice.

Then reach us.

Email info@blackshard.com.au with URGENT in the subject, or use the contact form on the breach track. Someone will get back to you as soon as possible.

Who answers: senior engineers who do containment, root-cause analysis, and remediation engineering, the same people who build and attack production systems. Not a call centre, not a ticket queue.

The full service: breach remediation & incident response

If it turns out to be nothing

Good. A false alarm costs an email; an unexamined incident can cost a business. And if you would rather this page never be relevant to you again, incident readiness builds the plan, the practice run, and the tested recovery before you need any of it.

Contain the breach. Then fix what let it in.

Australia-wide, from our Brisbane head office. Someone will contact you as soon as possible.

Open a briefinfo@blackshard.com.au