Contain it. Then fix what let it in.
Containment and triage, root-cause remediation, and Notifiable Data Breaches support from engineers who build and secure production systems, at our Eagle Street office.
Black Shard is an Australian software engineering and cybersecurity firm with its head office in Brisbane. If you suspect a breach right now, the first-hour steps that do not depend on us are on our breach page: isolate without destroying evidence, preserve records, contain accounts, engage your insurer, and know your notification clock. This page is about the engagement that follows: bringing in the team that contains the incident properly, finds what let it happen, and engineers the fix.
A breach is an engineering problem as much as a security one. We contain the compromise, trace it to root cause, and fix the code, configuration, or infrastructure that let it happen, then re-test to prove the fix closed. The same engineers who build and attack production systems do the remediation, from the Eagle Street office.
What incident response with Black Shard involves
Containment and triage come first: establishing what happened, what an attacker actually reached, and stopping it getting worse. That means a triage of the compromise, entry point, scope, and the data touched, with containment actions agreed with you before they are taken rather than assumed. You get a plain-English account of what is known and, just as importantly, what is not yet known.
Once the incident is contained, the work moves to root cause. We trace the compromise back to the flaw behind it, whether that is code, configuration, or infrastructure, engineer the fix, and harden the adjacent gaps the same weakness usually sits next to. Then we re-test the fixed surface to confirm the holes are actually closed, not just patched on paper.
- Triage of the compromise: entry point, scope, and data touched
- Containment actions agreed with you before they are taken
- Root-cause analysis tracing the incident back to the weakness behind it
- Remediation engineered and shipped, with adjacent gaps hardened
- A re-test of the fixed surface to confirm the holes are closed
- Support with the Notifiable Data Breaches assessment under the Privacy Act
In the middle of an incident right now?
Start with the first-hour steps on our breach page, none of which depend on us replying: isolate affected machines without wiping them, preserve logs and anything that looks wrong, contain accounts from a known-clean device, and do not negotiate with an attacker alone. If personal information is likely involved, the Privacy Act's Notifiable Data Breaches scheme may require a prompt assessment.
Then reach us. This page and its Australia-wide sibling describe the engagement that follows those first steps: the team that takes over containment properly, finds what let the incident happen, and fixes it.
Notifiable Data Breaches support
Where personal information is likely involved, the Privacy Act 1988's Notifiable Data Breaches scheme requires a prompt assessment of whether the breach is likely to result in serious harm, and notification if it is. We support that assessment: we do not give legal advice, and we keep that line clear the same way we keep every claim on this site clear.
What we provide is a factual incident record your board, insurer, or legal advisers can actually work from, built from the containment and root-cause work rather than reconstructed after the fact, plus the practical changes that make the same assessment easier if it is ever needed again.
Why bring incident response in from Brisbane?
An incident is not a document exchange; it is a live situation where the questions change by the hour. Our office is on Eagle Street in Brisbane, and where it helps, containment and the debrief can run face to face: your team and ours in the same room, working the timeline together instead of over an email thread.
The proximity also means the handoff to remediation is instant. The engineers doing containment and triage are the same firm's engineers who do root-cause remediation, penetration testing, and Azure and Entra ID reviews, so nothing gets lost between 'here is what happened' and 'here is the fix', and no second vendor needs re-briefing from scratch.
Build the response before you need it
The best incident response is the one you never fully need, because the plan and the practice already exist. Incident readiness builds that ahead of time: a response plan written for your actual team and systems rather than adapted from a template, a tabletop exercise that pressure-tests the plan against a realistic scenario, and backup and recovery verification against a real restore, not a checkbox.
It is the same work our vCISO clients build into their standing engagement, and it is available as a stand-alone piece for businesses that just want the plan and the drill done properly once.
What does incident response cost?
There is no published figure, because incident work is scoped to what actually happened: the systems affected, how far the compromise reached, and whether the engagement is containment only or extends through root-cause remediation and re-testing.
If you are mid-incident, email info@blackshard.com.au directly rather than waiting to scope it precisely; the engagement starts with containment and the detail gets filled in as the picture clears.
Do you only respond to Brisbane incidents?
No. Incident response runs Australia-wide from our Brisbane head office, with containment and the debrief run remotely when on-site does not add anything.
If you are outside Brisbane, our incident response, Australia-wide page covers the national service.
Every engagement includes
A director on the work
A director reads the brief, scopes the engagement, and stays accountable for the result.
Fixed scope, quoted first
Scope, timeframe, and price are agreed before work starts.
Findings validated by hand
Every finding is checked by a human, written in plain English, and paired with a concrete fix. Raw scanner output is never forwarded.
A re-test to prove it
Fixed-scope offensive work includes a re-test, so fixes are confirmed closed rather than assumed.
Least-privilege access
We take only the access the work requires, and client data sits in Australian regions.
A report that is yours
Written for your engineers and your board, and kept confidential.
Questions, answered
- What's the difference between this page and the breach page?
- The breach page is the first-hour checklist: what to do before anyone has replied, none of it dependent on us. This page is the engagement that follows: bringing in the team for containment, root-cause analysis, remediation, and Notifiable Data Breaches support.
- How fast can you start?
- Email info@blackshard.com.au directly if you are mid-incident. Containment does not wait for a fully scoped engagement; the detail gets filled in as the picture clears.
- Do you give legal advice on our notification obligations?
- No. We support the Notifiable Data Breaches assessment under the Privacy Act with a factual incident record and practical analysis; the legal call sits with your legal advisers. We keep that boundary clear rather than overstate what we do.
- Do you only fix the immediate compromise, or the underlying flaw too?
- Both, if that is what you want. Containment stops the immediate damage; root-cause analysis and remediation engineering fix the code, configuration, or infrastructure that let it happen, with a re-test to confirm the fix closed.
- Do you only respond to Brisbane businesses?
- No. We are a national firm and respond Australia-wide from our Brisbane head office. Brisbane businesses get on-site containment and a face-to-face debrief; the same standard applies remotely everywhere else.
- Can you help us get ready before an incident happens?
- Yes. Incident readiness builds the response plan, runs a tabletop exercise against a realistic scenario, and verifies your backups against a real restore, so the plan exists and has been tested before you need it.
Related reading
The full practice: Breach remediation & incident response.
Contain it, then fix what let it in.
Australia-wide, from our Brisbane head office. Someone will contact you as soon as possible.