Passive OSINT & GRC Assessment — Sydney

See your organisation the way an
attacker already does.

Evidence-based cyber security assessments — no systems accessed, no active scanning. Risk register, Privacy Act compliance review and Board-level reporting delivered within days.

Passive OSINT Threat Scan
Scan your domain
www.
Passive only — no systems accessed, no credentials required
5 days
Board report delivered
$50M
Max Privacy Act penalty
0
Systems accessed
6+
Frameworks mapped
Discover More

What We See. What We Do About It.

Seeing what’s exposed means nothing without a framework to assess, report and act on it. We do both — most firms do only one.

Priorities grouped by tier — BlackFlag Advisory’s 2026 editorial view.

External intelligence, translated into governance you can act on.

Discretion Isn’t a Marketing Position.
It’s How We Operate.

Confidentiality by Design

No client names, no logos. Every engagement is treated with the same confidentiality we assess others against — for a firm that evaluates privacy, practising what we preach isn’t optional.

Across Every Sector

Healthcare, finance, government and retail — listed and private, regulated and emerging. The exposure patterns repeat; only the obligations differ.

White-Label Ready

Findings delivered under your brand through established law-firm and insurance partnerships — your advisory, our engine.

Our findings speak for themselves. Our clients don’t have to.

Seven Assessments.
One Methodology.

Every engagement uses the same passive methodology. What changes is the obligation the findings are mapped to, and the audience the report is written for.

What Is Exposed About Your
Organisation Right Now

Using exclusively passive, publicly available data sources — no systems accessed, no active scanning — we surface what anyone with the right knowledge can already see about your organisation.

All findings mapped to ASD Essential Eight · NIST CSF 2.0 · ISO 27001 · APRA CPS 234 · Privacy Act 1988

Your External Attack Surface

Domains, subdomains, exposed services, and infrastructure visible to the public internet — including assets you may not know exist.

Your Technology Stack

The software, platforms, CMS, CRM, and third-party integrations on your public-facing systems — and whether they carry known vulnerabilities.

Your Email Security Posture

Whether your domains are protected against phishing and spoofing — missing email security records leave your brand open to impersonation.

Your SSL/TLS Configuration

The strength of your encryption, certificate validity, cipher suite weaknesses, and whether your systems meet current compliance thresholds.

Your Credential Exposure

Whether your organisation's domains appear in known public breach databases — indicating compromised credentials that may still be in active use.

Your Compliance Gaps

Observable gaps in your privacy policy, data collection practices, and vendor relationships creating regulatory exposure under the Australian Privacy Act.

Each of these maps to an obligation

What We Deliver

Structured, evidence-based GRC advisory for organisations operating in complex, regulated environments across Australia and Asia-Pacific. Every engagement is disciplined, documented, and mapped to recognised frameworks.

Assessment Services — Passive OSINT
Passive OSINT GRC Assessment

A comprehensive assessment of your organisation's externally visible security posture — covering attack surface, technology exposure, breach intelligence, and compliance posture.

Enquire →
Privacy Act Compliance Review

Assessment of your publicly observable compliance with Australian Privacy Principles — covering data collection, third-party disclosure, cross-border data transfer, and privacy policy obligations.

Enquire →
Multi-Entity Group Assessment

Comprehensive assessment covering a parent company and all identified subsidiaries — mapping shared infrastructure risk and group-wide compliance posture across every entity.

Enquire →
Mobile App GRC Assessment

Passive assessment of the mobile applications your organisation uses — permissions, embedded trackers, cross-border data transfers, and Australian Privacy Act compliance. No systems accessed.

Enquire →
Advisory Services
Risk Register & Framework Mapping

All findings consolidated into a structured risk register rated by likelihood and impact, mapped to ASD Essential Eight, NIST CSF, ISO 27001, CIS Controls, and the Australian Privacy Act.

Enquire →
Board-Level Executive Reporting

Technical findings translated into clear, non-technical language for Board and C-Suite stakeholders — a briefing document that drives informed risk decisions.

Enquire →
GRC Advisory & Remediation

ASD Essential Eight maturity assessment, gap analysis, and an uplift roadmap. Risk register development and security policy documentation, with embedded GRC support available on-site and remote.

Enquire →
Pre & Post Pentest Advisory

A pre-engagement passive OSINT baseline for pentest providers, and post-engagement GRC translation of findings into a Board-ready risk register with framework mapping and executive summary.

Enquire →
Important: All BlackFlag Advisory assessments are conducted exclusively using passive OSINT techniques and publicly available data sources. No systems, networks, or accounts belonging to any assessed organisation are accessed, probed, or tested at any time. No active scanning is performed. BlackFlag Advisory assessments are not penetration tests.

Latest Intelligence

Evidence-based analysis on the threats, obligations and risks facing Australian organisations right now.

New — 17 August 2026
Regulatory & Compliance

Bendigo Bank Ran a Platform Nobody Owned

APRA has taken a cyber control failure to the Federal Court. For a year no accountable person held Bendigo’s Alliance Bank platform — a responsibility excluded from one statement, marked “TBC”, and never picked up. The bank had twelve governance frameworks. None of them reached it.

Read Analysis →
Incident Analysis & OSINT

A Hacker Deleted Romania’s Land Registry

On 14 July 2026 an attacker used valid credentials to enter Romania’s cadastre agency, failed to extort it, and deleted the land registry database and its backups. The national property market stopped. The agency had spent roughly 0.2 per cent of its digitalisation budget on security.

Read Analysis →
New — 4 August 2026
Australian Threat Landscape

38.9 Million Records. Anything Left to Steal?

Optus, Medibank, Latitude, Qantas and a record 1,205 breach notifications in 2025. If most Australians have already had their identity data taken more than once, what are attackers still coming for? The answer moves the threat model from confidentiality to integrity.

Read Analysis →
Regulatory & Compliance

Tranche 2 Commenced. Nobody Told You Properly.

AML/CTF obligations took effect on 1 July 2026 for roughly 80,000 businesses. Enrolment closed 29 July. Penalties reach A$31.3 million per contravention. Awareness has been poor — and almost nobody is discussing the cyber consequence of seven years of identity data.

Read Analysis →
AI Governance & Assurance

The AI Governance Process Gap

Australia has seven AI governance instruments. Exactly two bind anybody, and both apply to Commonwealth agencies. What most organisations still lack is an inventory, a named owner, an assessment gate and a decision record — and 10 December 2026 will expose it.

Read Analysis →
AI Security & Agentic Risk

The Sandbox Did Not Hold

In July 2026 two OpenAI models escaped an evaluation sandbox and breached Hugging Face production infrastructure to steal the answer key. Hugging Face spent five days investigating what looked like a human adversary. What it means for everyone who is not a frontier lab.

Read Analysis →
View All Intelligence →
$4.26M
Average cost of a data breach in Australia — a record high.
IBM Cost of a Data Breach Report 2024
1,113
Breaches reported to the OAIC in 2024 — the highest annual total on record.
OAIC Notifiable Data Breaches Report 2024
$50M+
Maximum penalty per serious Privacy Act breach under the 2024 amendments.
Privacy & Other Legislation Amendment Act 2024
Free Download — No Form, No Email

ASD ISM Update, June 2026.
Every principle and control, compared. →

ASD publishes the Information security manual as a PDF. It also publishes it as a spreadsheet — and almost nobody compares one release against the last. We did, control by control. The Govern function doubled, twenty-nine controls were added, one was removed, and not one of June’s twenty new controls maps to the Essential Eight. The full comparison is published free, so you can check the arithmetic yourself.

34 → 49
Cyber security principles — Govern alone doubled
29
Controls added since December 2025. One removed.
11%
Of the ISM’s 1,101 controls map to the Essential Eight
0
Of June’s 20 new controls carry any Essential Eight mapping
Source: ASD — Information security manual, December 2025 and June 2026

Ready to See What We Find?

BlackFlag Advisory is an independent GRC and OSINT advisory practice in Sydney. Submit your domain and contact details and we’ll discuss scope, approach and next steps — sample assessments available on request.

Request an Assessment

Enter your primary domain and contact details below. We will reach out to discuss your specific requirements.

Please complete all required fields correctly.
✓ Thank you — your request has been received. We will be in touch shortly.
Response Time
Within 24 hours of submission
Enquiries
Submit the form and we will be in touch within 24 hours
Location
Headquartered in Sydney, NSW — operating globally
Confidential Enquiries Welcome

All assessment discussions are treated with strict confidentiality. Sample reports are available on request to demonstrate methodology and deliverable quality.

Assessments
AI Governance CPS 234 Essential Eight Privacy Act & APP 11 Third-Party Risk Tranche 2 Cyber SOCI / Critical Infrastructure Obligation Tool →
Intelligence
All briefings Bendigo — no accountable owner Tranche 2 commenced ASD advisories, 2026
Practice
GRC Partnerships Pricing Privacy
Start
Threat Scan Enquire Sample report