Black Shard

Contain the breach. Then fix what let it in.

Containment, root-cause remediation, and Notifiable Data Breaches support for Australian organisations, delivered nationally from our Brisbane head office.

Black Shard is an Australian software engineering and cybersecurity firm. If you suspect a breach right now, the first-hour steps that do not depend on us are on our breach page: isolate without destroying evidence, preserve records, contain accounts, engage your insurer, and know your notification clock. This page covers what happens next: engaging the team that takes containment further, finds what let the incident happen, and fixes it.

A breach is an engineering problem as much as a security one. We contain the compromise, trace it to root cause, fix the code, configuration, or infrastructure behind it, and re-test to prove the fix closed. The team doing the remediation is the same one that builds and attacks production systems for organisations across the country.

What incident response with Black Shard covers

Containment and triage establish what happened: the entry point, what an attacker actually reached, and what stops it getting worse right now. Containment actions are agreed with you before they are taken, and you get a plain-English account of what is known, and what is not yet known, rather than a confident-sounding guess.

From there the work traces to root cause: the code, configuration, or infrastructure weakness that let the incident happen, engineered into a fix with the adjacent gaps hardened at the same time. A re-test of the fixed surface confirms the holes are actually closed before we call the engagement done.

  • Triage of the compromise: entry point, scope, and data touched
  • Containment actions agreed with you before they are taken
  • Root-cause analysis tracing the incident back to the weakness behind it
  • Remediation engineered and shipped, with adjacent gaps hardened
  • A re-test of the fixed surface to confirm the holes are closed
  • Support with the Notifiable Data Breaches assessment under the Privacy Act

In the middle of an incident right now?

Start with the first-hour steps on our breach page, none of which wait on a reply from us: isolate affected machines without wiping them, preserve logs and anything that looks wrong, contain accounts from a known-clean device, and do not negotiate with an attacker alone. Where personal information is likely involved, the Privacy Act's Notifiable Data Breaches scheme may require a prompt assessment.

Then reach the team. This page describes the engagement that follows those first steps, delivered wherever in Australia you operate.

Notifiable Data Breaches support

Where personal information is likely involved, the Privacy Act 1988's Notifiable Data Breaches scheme requires a prompt assessment of whether the breach is likely to cause serious harm, and notification if it is. We support that assessment; we do not give legal advice, and we keep that boundary explicit rather than blur it.

What we build is a factual incident record your board, insurer, or legal advisers can work from, drawn directly from the containment and root-cause work, plus the practical changes that make the same assessment faster if it is ever needed again.

Delivered Australia-wide from our Brisbane head office

Incident response does not require us in your building. It requires fast containment decisions, a clear read on scope, and engineers who can move from triage straight into remediation without a handover to a second vendor. Scoping, containment coordination, and the debrief run by phone, video, and secure access, the same way regardless of which state you are in.

Where a Brisbane business wants the team on-site for containment or the debrief, that option exists too: our incident response, Brisbane page covers the same service with the local option made explicit.

Build the response before you need it

The best incident response is the one a business barely needs, because the plan and the practice already exist. Incident readiness builds that in advance: a response plan written for your actual team and systems, a tabletop exercise that pressure-tests it against a realistic scenario, and backup and recovery verification against a real restore rather than a checkbox.

It is standard groundwork inside a vCISO engagement, and available on its own for organisations that want the plan and the drill done properly without a standing retainer.

What does incident response cost?

There is no published figure, because incident work is scoped to what actually happened: the systems affected, how far the compromise reached, and whether the engagement stops at containment or extends through root-cause remediation and re-testing.

If you are mid-incident, email info@blackshard.com.au directly rather than waiting to scope it precisely; containment starts and the detail is filled in as the picture clears.

Every engagement includes

  • A director on the work

    A director reads the brief, scopes the engagement, and stays accountable for the result.

  • Fixed scope, quoted first

    Scope, timeframe, and price are agreed before work starts.

  • Findings validated by hand

    Every finding is checked by a human, written in plain English, and paired with a concrete fix. Raw scanner output is never forwarded.

  • A re-test to prove it

    Fixed-scope offensive work includes a re-test, so fixes are confirmed closed rather than assumed.

  • Least-privilege access

    We take only the access the work requires, and client data sits in Australian regions.

  • A report that is yours

    Written for your engineers and your board, and kept confidential.

Questions, answered

What's the difference between this page and the breach page?
The breach page is the first-hour checklist: what to do before anyone has replied, none of it dependent on us. This page is the engagement that follows: bringing in the team for containment, root-cause analysis, remediation, and Notifiable Data Breaches support.
How fast can you start?
Email info@blackshard.com.au directly if you are mid-incident. Containment does not wait for a fully scoped engagement; the detail gets filled in as the picture clears.
Do you give legal advice on our notification obligations?
No. We support the Notifiable Data Breaches assessment under the Privacy Act with a factual incident record and practical analysis; the legal call sits with your legal advisers. We keep that boundary clear rather than overstate what we do.
Do you fix the underlying flaw as well as containing the incident?
Yes, if that is what you want. Containment stops the immediate damage; root-cause analysis and remediation engineering fix the code, configuration, or infrastructure that let it happen, with a re-test to confirm the fix closed.
Do you work with organisations outside Brisbane?
Yes. Black Shard is a national firm and responds Australia-wide; scoping, containment coordination, and the debrief all run remotely as standard. Brisbane organisations that want the team on-site have that option too.
Can you help us get ready before an incident happens?
Yes. Incident readiness builds the response plan, runs a tabletop exercise against a realistic scenario, and verifies your backups against a real restore, so the plan exists and has been tested before you need it.

Close the breach, and the flaw behind it.

Australia-wide, from our Brisbane head office. Someone will contact you as soon as possible.

Open a briefinfo@blackshard.com.au