BlackFlag Advisory — GRC Consulting

Governed by evidence.
Guided by experience.

Structured, evidence-based GRC advisory for organisations navigating complex, regulated environments — wherever they operate.

Cyber attacks attempted globally since you opened this page
0
Based on 1 attack every 39 seconds — University of Maryland Research
Get Started
Submit Your Domain

Enter your website domain. We will assess your external security posture and come back with findings and options.

www.
Passive assessment only — no systems accessed, no active scanning
✓ Thank you — your request has been received. We will be in touch shortly.
or
Speak First
Request a Callback

Prefer to talk through your requirements before committing? Leave your details and we will reach out at a time that suits you.

Please complete all required fields correctly.
✓ Thank you — we will be in touch shortly.
Confidential — no obligation
18-step
Framework
5
Phases
6+
Frameworks
0
Systems Accessed
Discover More

What Is Exposed About Your
Organisation Right Now

Using exclusively passive, publicly available data sources — no systems accessed, no active scanning — we surface what anyone with the right knowledge can already see about your organisation.

Your External Attack Surface

Domains, subdomains, exposed services, and infrastructure visible to the public internet — including assets you may not know exist.

Your Technology Stack

The software, platforms, CMS, CRM, and third-party integrations on your public-facing systems — and whether they carry known vulnerabilities.

Your Email Security Posture

Whether your domains are protected against phishing and spoofing — missing email security records leave your brand open to impersonation.

Your SSL/TLS Configuration

The strength of your encryption, certificate validity, cipher suite weaknesses, and whether your systems meet current compliance thresholds.

Your Credential Exposure

Whether your organisation's domains appear in known public breach databases — indicating compromised credentials that may still be in active use.

Your Compliance Gaps

Observable gaps in your privacy policy, data collection practices, and vendor relationships creating regulatory exposure under the Australian Privacy Act.

Simple to Start.
Thorough in Delivery.

Every engagement begins with your domain. What follows is a structured, evidence-based assessment that gives you a clear picture of your risk posture.

1
Submit Your Domain

Enter your primary domain and contact details. We identify all associated entities, subdomains, and publicly visible infrastructure before we begin.

2
We Assess

Our structured, 5-phase passive assessment framework is applied across your entire external footprint. Every finding is evidenced, sourced, and mapped to a recognised framework control.

3
You Receive a Report

A structured professional report — risk register, framework mapping, and a Board-level executive summary — that tells you exactly what was found and what to do about it.

What We Deliver

Structured, evidence-based GRC advisory for organisations operating in complex, regulated environments across Australia and Asia-Pacific. Every engagement is disciplined, documented, and mapped to recognised frameworks.

01
Passive OSINT GRC Assessment

A comprehensive assessment of your organisation's externally visible security posture — covering attack surface, technology exposure, breach intelligence, and compliance posture.

Enquire →
02
Risk Register & Framework Mapping

All findings consolidated into a structured risk register rated by likelihood and impact, mapped to ASD Essential Eight, NIST CSF, ISO 27001, CIS Controls, and the Australian Privacy Act.

Enquire →
03
Board-Level Executive Reporting

Technical findings translated into clear, non-technical language for Board and C-Suite stakeholders — a briefing document that drives informed risk decisions.

Enquire →
04
Multi-Entity Group Assessment

Comprehensive assessment covering a parent company and all identified subsidiaries — mapping shared infrastructure risk and group-wide compliance posture across every entity.

Enquire →
05
Privacy Act Compliance Review

Assessment of your publicly observable compliance with Australian Privacy Principles — covering data collection, third-party disclosure, cross-border data transfer, and privacy policy obligations.

Enquire →
06
Threat Intelligence Briefing

Your confirmed technology stack cross-referenced against current threat advisories and known exploited vulnerabilities — surfacing active threats in your specific environment.

Enquire →

A Structured, Repeatable
Assessment Framework

Every assessment follows the same disciplined process. No shortcuts. No guesswork. Every finding is evidenced and mapped to a recognised framework control.

01
Reconnaissance

Corporate entity mapping, subsidiary identification, domain and subdomain enumeration, and email security record analysis across all associated entities.

02
Infrastructure Analysis

Passive infrastructure review, certificate analysis, SSL/TLS configuration audit, and technology stack fingerprinting across all public-facing systems.

03
Breach Intelligence

Domain breach exposure analysis, indexed sensitive content discovery, historical footprint review, and credential exposure assessment.

04
Compliance Review

Privacy policy assessment against Australian Privacy Principles, current threat advisory cross-referencing, and third-party vendor risk identification.

05
Synthesis & Reporting

Risk register population, framework mapping, remediation roadmap development, and Board-level executive summary production.

What We Map To

All findings are mapped to recognised Australian and international cybersecurity and compliance frameworks.

ASD Essential Eight
NIST CSF 2.0
ISO 27001
CIS Controls v8
Australian Privacy Act 1988
Australian Privacy Principles
ACSC ISM
CISA Known Exploited Vulnerabilities
NVD / CVE Database
Important: All BlackFlag Advisory assessments are conducted exclusively using passive OSINT techniques and publicly available data sources. No systems, networks, or accounts belonging to any assessed organisation are accessed, probed, or tested at any time. No active scanning is performed. BlackFlag Advisory assessments are not penetration tests.

Current Cyber Threats
Australia & Global

Live intelligence updated each time this page loads. This is the threat landscape your organisation operates in.

Live Feed
Loading...
Fetching current threat intelligence...

Commercial Acumen.
Cybersecurity Expertise.

BlackFlag Advisory was founded by Cluny Archibald — a senior enterprise sales and business development leader with over 20 years of experience across technology, SaaS, government, financial services, and commercial property sectors across Australia and internationally.

After completing a Bachelor of Cyber Security with a GPA of 6.31/7.0 in 2025, Cluny brings a rare combination to GRC consulting: genuine commercial maturity, deep experience in regulated environments, and formal cybersecurity qualifications.

All findings are presented in structured, Board-ready reports that translate technical risk into business language accessible to non-technical decision-makers.

Bachelor of Cyber SecurityTorrens University Australia — GPA 6.31/7.0 — 2025
Certificate IV in Cyber SecurityTAFE NSW — 2025
20+ Years Enterprise Sales & Business DevelopmentGovernment, Financial Services, Technology, Construction

Most organisations assume their governance and compliance posture is adequate. Our assessments reveal what is actually visible to the outside world — before a threat actor, a regulator, or a competitor finds it first.

Cluny Archibald — Founder, BlackFlag Advisory

Ready to See What We Find?

Submit your domain and contact details. We will be in touch to discuss scope, approach, and next steps. Sample assessment reports available on request.

Request an Assessment

Enter your primary domain and contact details below. We will reach out to discuss your specific requirements.

Please complete all required fields correctly.
✓ Thank you — your request has been received. We will be in touch shortly.
Response Time
Within 24 hours of submission
Enquiries
Submit the form and we will be in touch within 24 hours
Location
Headquartered in Sydney, NSW — operating globally
Confidential Enquiries Welcome

All assessment discussions are treated with strict confidentiality. Sample reports are available on request to demonstrate methodology and deliverable quality.