A security seat at your table, without the full-time hire.
Fractional security leadership for Australian businesses, delivered Australia-wide by Brisbane practitioners who build and run production systems in regulated industries.
Most Australian businesses do not need a full-time CISO. They need someone accountable: a named person who owns the security strategy, keeps the risk register honest, briefs the board in plain English, and picks up the phone when something goes wrong. That is what a vCISO engagement gives you. Black Shard provides fractional security leadership on a standing cadence, sized to the business you run, delivered Australia-wide from our Brisbane head office.
We design, build, and operate production software, for client firms GRM LAW and Stone Leaf Capital, and through our own ventures Aurii, Bold Property Group, and Restart Recruitment. The person setting your security direction carries the same obligations you do, in systems that are live today.
What a vCISO engagement includes
A vCISO is a fractional chief information security officer: a named senior practitioner who owns your security programme for an agreed share of their time, on a regular cadence. Not a helpdesk, not a rotating bench of consultants, and not a report that arrives once and gathers dust. One person, accountable, who knows your systems and your obligations and turns up every month with the register updated and the next decisions framed.
The engagement covers the work a CISO would own if you had one.
- Security strategy: a written plan with owners and dates, reviewed as the business changes
- Policies drafted for how your organisation actually operates, kept current rather than filed
- A living risk register: what could hurt you, how likely, and what is being done about it
- Board reporting in plain English your directors can question and act on
- Incident readiness: a response plan your team can run, pressure-tested in a tabletop exercise
- A named security lead on a regular cadence, so accountability has a face and a calendar
Who needs a vCISO
The pattern is consistent. The business has grown past the point where security can live in the IT manager's spare hours, but not to the point where a full-time executive salary makes sense. Somebody owns the firewall; nobody owns the risk.
Four situations bring businesses to us. A board or insurer has started asking pointed questions about cyber risk and nobody owns the answer. A large customer has sent a security questionnaire that an honest response would fail. The business operates in a regulated industry, health, legal, financial services, where the obligations are real and personal. Or an incident, yours or a competitor's, has made the gap impossible to ignore.
We work in those industries ourselves. Black Shard builds and operates the compliance portal GRM LAW runs on, the operations platform behind Stone Leaf Capital, and our own clinical-software venture, Aurii. The obligations your board is asking about are ones we carry in production.
vCISO or full-time hire
A full-time CISO is the right call at a certain scale: a security team to lead, a threat profile that shifts weekly, an executive table with a permanent seat to fill. Below that scale the economics fail. The salary is significant, the market for good ones is thin, and the hiring search itself is time spent exposed rather than fixing anything.
A vCISO gives you the judgement without the payroll event. You get a senior practitioner immediately, for a defined fraction of the cost, with the breadth that comes from working across more than one environment. And the seat is backed by a whole firm rather than one person's calendar: penetration testers, Azure security reviewers, and engineers who ship remediations.
The honest boundary: if you grow into needing a full-time hire, a good vCISO engagement is the best possible predecessor. The strategy, the register, the policies, and the board relationship are all built and documented for the incoming executive to inherit.
How an engagement starts
The usual way in is a security posture assessment: a structured gap analysis against the ASD Essential Eight and the CIS Controls. It establishes where you actually stand, mapped to recognised controls, what is exposed, and what to fix first. The findings become the first version of your roadmap, prioritised and costed by effort, so the retainer begins with a plan rather than a discovery phase that never ends.
From there, the retainer builds the working machinery of the programme.
- A posture assessment report: where you stand today, mapped to the Essential Eight and CIS Controls
- A prioritised remediation roadmap, costed by effort, with quick wins separated from projects
- A risk register stood up and reviewed with the people who own each risk
- A policy baseline drafted for how the business actually operates
- An incident response plan your team can run without us in the room
- The first board report, in plain English, with the cadence set for the ones that follow
Why take security leadership from a firm that builds software?
Most security advisory comes from people who do not operate systems of their own. Our vCISO practice sits inside a firm that designs, builds, and runs production software in regulated settings: multi-tenant data layers with row-level security, append-only audit trails enforced on every state change, secrets kept out of code, deployments on Azure in Australian regions. When your vCISO recommends a control, it is one we operate, not one we read about.
The same honesty applies to our own posture. Black Shard holds SMB1001:2026 Gold, independently issued and verifiable on the public CyberCert registry, and self-assesses against the ASD Essential Eight and the Australian Privacy Principles. We label what we hold and what we self-assess, and we hold clients to the same discipline. The full picture is on our trust page; how we run an engagement is on our approach page.
It also means the seat is never a dead end. Findings that need engineering get engineered. If the roadmap calls for a penetration test, a secure code review, or a review of your Azure tenancy, the same firm delivers it, under the same named lead, accountable for the result.
What does a vCISO cost?
We do not publish figures because honest pricing is scoped, not listed. The standing shape is an ongoing monthly retainer, and a one-off posture assessment is the usual way in: the smallest sensible first step, rather than asking you to commit to standing leadership unseen.
The variables that move the number are the ones you would expect: the size and complexity of the business, the regulatory frame you operate under, the reporting cadence your board needs, and how much of the groundwork, the policies, the register, the response plan, already exists. Name those in your brief and the quote comes back faster.
Every engagement includes
A director on the work
A director reads the brief, scopes the engagement, and stays accountable for the result.
A defined retainer, priced first
Cadence, scope, and fee are agreed before the engagement starts, and reviewed as the business changes.
Reporting your board can question
Plain-English reporting prepared on your board's calendar.
A named lead, on a cadence
One senior practitioner owns the seat, month after month.
Least-privilege access
We take only the access the work requires, and client data sits in Australian regions.
A report that is yours
Written for your engineers and your board, and kept confidential.
Questions, answered
- How often will we actually see our vCISO?
- On the cadence agreed at the start of the engagement. The standing shape is a monthly retainer: a working session, the risk register reviewed, the roadmap moved forward, and reporting prepared on your board's calendar. Between sessions, the strategy, the policies, and the register are kept current.
- Do we need a separate firm for penetration testing?
- No. Offensive testing is Black Shard's other security practice: penetration testing, red teaming, and phishing simulation, with every finding validated by hand and a re-test to confirm the fixes landed. When the vCISO roadmap calls for a test, the same accountable firm runs it.
- Do you only work with Brisbane businesses?
- No. Black Shard is a national firm and delivers Australia-wide from its Brisbane head office. Security leadership travels well: the cadence, the reporting, and the reviews do not depend on being in the same room.
- What frameworks do you work against?
- The ASD Essential Eight, the CIS Controls, SMB1001, ISO 27001, and the Australian Privacy Principles. Black Shard holds SMB1001:2026 Gold itself, verifiable on the public CyberCert registry. The rest are methodologies we work against, never credentials we claim.
- What happens if we have an incident?
- You run the response plan we built together, and your vCISO helps run it: containment decisions, communication, and the notification obligations under the Privacy Act's Notifiable Data Breaches scheme. Incident readiness is built early in the engagement precisely so the plan exists before it is needed.
- What access do you need to our systems?
- Only the access the work requires, and no more. That is the same least-privilege discipline we run on our own systems: administrative privilege granted deliberately, never by default, and access reviewed as the engagement changes.
- How do we start?
- Send a brief to info@blackshard.com.au. The usual first step is a security posture assessment: it gives both sides an honest picture before a retainer is scoped.
Related reading
The full practice: Security advisory & vCISO.
Your security seat, filled.
Australia-wide, from our Brisbane head office. Someone will contact you as soon as possible.