Australian software engineering and cybersecurity
We build software.
Then we break it before attackers do.
One Australian team across the whole surface. The engineers who design, build and run your platform are the same people who attack it, harden it and answer for it in production.
SMB1001:2026 Gold certified- ISO/IEC 27001:2022 certified lead auditor
- Essential Eight ML2 self-assessed
Trusted by the brands we build for and secure
0
controls certified under SMB1001:2026 Gold, on the public registry
ML0
Essential Eight maturity, self-assessed and built to daily
0
product platforms designed, built and run by this team
0
service families, delivered by one accountable team
The Black Shard platform
One team. Every layer. Zero handoffs.
Security products bolt on. We build it in. Six service families around a single accountable team, so the people who write your software are the people who defend it.
- Software engineeringWeb platforms, native mobile and the infrastructure underneath, shipped and run in production.
- Offensive testingPenetration testing, red teaming and phishing simulation, run like a real adversary.
- Defensive and advisoryvCISO, hardening and architecture that fits how your organisation operates.
- Breach remediationContainment, recovery and the engineering that stops the second breach.
- Compliance readinessEssential Eight, SMB1001, ISO 27001 readiness and the Privacy Act, from the first commit.
- Secure developmentSecure-by-design builds with the evidence to prove it.
Think like the adversary
The best defence is a rehearsed attack
Every Black Shard build faces its own red team before it faces the internet. We attack our work with the same tradecraft we bring to engagements: reconnaissance, exploitation, persistence, and a written path to remediation.
Scope an engagementAssay · our scanner · live
Your attack surface, watched like we own it
Assay scans your internet-facing systems, maps every finding to the Essential Eight and SMB1001, and gives you evidence you can hand to your insurer, your board and your customers.
Assay
Overview
Findings
Attack paths
Evidence pack
External posture
Daily scan · diffed against yesterday
1 change since last scan · exposed service closed
- Attack-surface discoveryEvery exposed host and service catalogued, remote-access and database ports flagged.
- Exploited-in-the-wild rankingFindings ranked with CISA's Known Exploited Vulnerabilities catalogue and EPSS.
- Attack pathsThe route an attacker could take, expressed in MITRE ATT&CK techniques.
- Change trackingEvery assessment diffed against the last, so you see the moment something gets worse.
Monitor
$349/mo
or $3,840 a year
One business, the whole product.
- Daily scans and change alerts
- Attack paths on every gap
- Insurance evidence pack
Group
$549/mo
or $6,040 a year
Three businesses under one account.
- Everything in Monitor
- Three entities, one view
- Consolidated reporting
Portfolio
$999/mo
or $10,990 a year
Ten businesses, built for IT providers and groups.
- Everything in Group
- Ten entities under one account
- Per-client evidence packs
Most complete
Fully managed
Assay, plus the team behind it
Findings triaged, fixed and verified by the people who found them.
- Everything in Portfolio
- Remediation by our engineers
- Direct line to the red team
Where do we start?
Four doors into the same team
Ship a platform
A web or mobile product built secure-by-design and run in production by the people who wrote it.
Software engineeringTest my defences
A penetration test, red team or phishing simulation that behaves like the adversary you actually face.
Offensive testingProve compliance
Essential Eight, SMB1001 or ISO 27001 readiness with evidence auditors and insurers accept.
Compliance readinessI have been breached
Containment and recovery now, then the engineering that makes sure there is no second time.
Breach remediationProof, not promises
Checked by people whose job is to doubt us
SMB1001:2026 Gold
Certified by CyberCert against all 27 controls of the standard.
View the public registryISO/IEC
27001:2022
Certified lead auditor
Exemplar Global credential held within the team.
Read the trust pagePI · PL
Cyber
Insured for the work
Professional indemnity, public liability and cyber cover current.
Certificates on request
The document
Capability statement, 2026
Every service, every credential and every platform we run, in one seven-page document you can hand to a board.
Download the PDFWe test and build against ASD Essential Eight · OWASP · MITRE ATT&CK · CISA KEV · Australian Privacy Principles
See what an attacker sees.
A discovery call takes 30 minutes. You leave with a straight answer either way.