- Who does the remediation work?
- Engineers who build and run production software in regulated industries. Black Shard operates its own systems, and the same team runs the firm's offensive testing practice. That combination is the point of the service: the person who traces your incident to root cause is someone who ships and attacks systems like yours, so the fix is engineered and shipped rather than described in a recommendation.
- Are you a 24/7 incident response hotline?
- No, and we do not pretend to be. Black Shard is a small, senior, director-led firm with no security operations centre. Contact is by email to info@blackshard.com.au; a director reads every brief and replies as soon as possible. What we offer is depth once engaged: containment, root-cause analysis, remediation engineering, and a re-test, done properly.
- We think we have been breached but are not sure. Is that enough to start?
- Yes. A suspected incident is a legitimate brief, and triage is the first phase of the engagement either way: establishing what happened, what was reached, and whether the compromise is still live. If the triage shows no incident, you get that finding in writing, along with whatever weaknesses the investigation surfaced.
- How is your incident data handled?
- Under the same practices we publish on our trust page. Access is least-privilege: we take only what the engagement requires, and containment actions are agreed with you before they are taken. Engagement material is encrypted in transit and at rest, the set of third parties that touch it is kept deliberately small, and the services that host client data sit in Australian regions. Incident material is among the most sensitive a firm can hold, and it is treated that way.
- Can you help with our Notifiable Data Breaches obligations?
- Yes, with a clear boundary. We support the assessment the Privacy Act's Notifiable Data Breaches scheme requires: establishing the facts of what was accessed, who is affected, and what remediation has been done, and producing the factual record the assessment and any notification rest on. We are engineers, not lawyers, so we do not give legal advice; where the judgement is legal, your legal advisers make it, working from the record we build.
- How is this different from a penetration test?
- A penetration test finds the holes before an attacker does. Breach remediation is for after: the incident has happened, or you suspect it has, and the work is containment, root cause, and the engineering fix. The two share the same discipline, and a remediation engagement ends the way our offensive work does, with a re-test of the fixed surface to confirm the holes are closed.
- Do you work outside Brisbane?
- Yes. A national firm, head office in Brisbane, delivering Australia-wide. Containment, root-cause analysis, and remediation run against your systems wherever they are hosted, the same way our testing and build work does.
- How is the cost set?
- By scope, like the firm's other security work. Breach remediation runs as a fixed-scope engagement: triage and containment first, then remediation scoped against what the triage found. The drivers are the size of the affected surface, the state of the systems involved, and whether we are also supporting a Notifiable Data Breaches assessment. We do not publish prices, because a number without a scope misleads in both directions.