New The Black Shard capability statement: every service, one document. Download it Design preview · live site: blackshard.com.au

Australian software engineering and cybersecurity

We build software.
Then we break it before attackers do.

One Australian team across the whole surface. The engineers who design, build and run your platform are the same people who attack it, harden it and answer for it in production.

  • SMB1001:2026 Gold certified
  • ISO/IEC 27001:2022 certified lead auditor
  • Essential Eight ML2 self-assessed

Trusted by the brands we build for and secure

Aurii GRM LAW Fox Valuations Restart Recruitment Bold Property Group InfoTrack Medical Objects Tyro

0

controls certified under SMB1001:2026 Gold, on the public registry

ML0

Essential Eight maturity, self-assessed and built to daily

0

product platforms designed, built and run by this team

0

service families, delivered by one accountable team

The Black Shard platform

One team. Every layer. Zero handoffs.

Security products bolt on. We build it in. Six service families around a single accountable team, so the people who write your software are the people who defend it.

Think like the adversary

The best defence is a rehearsed attack

Every Black Shard build faces its own red team before it faces the internet. We attack our work with the same tradecraft we bring to engagements: reconnaissance, exploitation, persistence, and a written path to remediation.

Scope an engagement

Assay · our scanner · live

Your attack surface, watched like we own it

Assay scans your internet-facing systems, maps every finding to the Essential Eight and SMB1001, and gives you evidence you can hand to your insurer, your board and your customers.

  • Attack-surface discoveryEvery exposed host and service catalogued, remote-access and database ports flagged.
  • Exploited-in-the-wild rankingFindings ranked with CISA's Known Exploited Vulnerabilities catalogue and EPSS.
  • Attack pathsThe route an attacker could take, expressed in MITRE ATT&CK techniques.
  • Change trackingEvery assessment diffed against the last, so you see the moment something gets worse.

Monitor

$349/mo

or $3,840 a year

One business, the whole product.

  • Daily scans and change alerts
  • Attack paths on every gap
  • Insurance evidence pack
Start monitoring

Group

$549/mo

or $6,040 a year

Three businesses under one account.

  • Everything in Monitor
  • Three entities, one view
  • Consolidated reporting
Start monitoring

Portfolio

$999/mo

or $10,990 a year

Ten businesses, built for IT providers and groups.

  • Everything in Group
  • Ten entities under one account
  • Per-client evidence packs
Start monitoring

Most complete

Fully managed

Assay, plus the team behind it

Findings triaged, fixed and verified by the people who found them.

  • Everything in Portfolio
  • Remediation by our engineers
  • Direct line to the red team
Talk to the team

Where do we start?

Four doors into the same team

Proof, not promises

Checked by people whose job is to doubt us

We test and build against  ASD Essential Eight · OWASP · MITRE ATT&CK · CISA KEV · Australian Privacy Principles

See what an attacker sees.

A discovery call takes 30 minutes. You leave with a straight answer either way.