Industries · Government & suppliers
For the public sector, and everyone who supplies it.
Councils and government suppliers get asked the same hard questions. We get you ready to answer them with evidence.
This page is different from the five beside it, and says so plainly: we have no named government client to show you. What we bring is capability (Essential Eight uplift, penetration testing, a standing vCISO seat, and secure builds) and a set of procurement facts you can verify before you ever talk to us.
The audience is twofold. Councils and local government bodies carry serious security expectations without enterprise security teams. And businesses supplying government inherit those expectations through tender questionnaires: Essential Eight maturity, incident readiness, and evidence for every claim.
What you carry, and what we do about it.
Essential Eight maturity is the default yardstick: agencies are assessed against it, and suppliers are increasingly asked for it.
An Essential Eight uplift: your current maturity rating across all eight strategies, an uplift plan to the target level, and an evidence trail for each mitigation.
Essential Eight upliftTender security questionnaires demand specific answers with evidence, and a blank row can cost the bid.
A posture assessment maps where you stand against recognised controls, and a vCISO gives you a named security lead to stand behind the answers.
vCISO & posture assessmentIncident reporting expectations: government buyers want a response path that has actually been rehearsed.
A review of your logging and alerting coverage, an incident response playbook your team can run, and a tabletop exercise to pressure-test it.
Detection & response advisoryLegacy systems predate the expectations now applied to them, and they still run the service.
We penetration-test what you actually run and hand back a ranked fix list. Where a system cannot be defended, we design and build its replacement secure by design.
Penetration testing & secure builds
The obligations in play
- ASD Essential Eight
- The baseline mitigation strategies Australian government bodies are assessed against, and increasingly expect their suppliers to address.
- ASD Information Security Manual
- The control framework for systems handling government information; we design to it where it applies.
- Privacy regimes
- Councils sit under state information-privacy statutes; suppliers handle personal information under the Privacy Act 1988.
- Procurement security requirements
- Tenders carry their own mandated controls, insurances, and evidence obligations, set contract by contract.
This list orients the engineering work. It is not legal advice; your advisers own the interpretation.
What procurement asks, answered.
The facts a tender evaluation actually checks, stated here so you can verify them before the first conversation.
- Legal entity
- Black Shard Pty Ltd · ABN 66 696 910 773
- Certification
- SMB1001:2026 Gold (Level 3), independently issued by CyberCert and listed on the public registry.Verify on the CyberCert registry ↗
- Insurance
- Professional indemnity, public liability, and cyber insurance held. Certificates of currency on request.
- Ownership
- Australian-owned and operated, headquartered in Brisbane, Queensland.
- Delivery
- Senior-only. The people you meet do the work.
- Capability statement
- Ready for your evaluation pack.Download the capability statement (PDF) ↓
If your requirement needs an IRAP assessment or a panel arrangement we do not hold, we will say so up front and point you at the right door.
Who you'll work with.
Kane Roberts
Founder
Kane founded Black Shard to run software engineering and security as one discipline. He builds and operates the firm’s systems in regulated industries (clinical, legal, capital markets) on Azure in Australia, and he is the practitioner who scopes the engagement, delivers it, and answers for it afterwards.
The services behind this page.
Compliance readiness
Get audit-ready against the frameworks Australian businesses are actually asked for.
Read more
Offensive testing
We attack your systems the way a real adversary would, then hand you a ranked fix list.
Read more
Defensive & advisory
Ongoing security leadership and review, without hiring a full-time CISO.
Read more
Ready for the questions procurement actually asks.
Australia-wide, from our Brisbane head office. Someone will contact you as soon as possible.

