Night harbor with silhouetted cranes and a distant lighthouse beam across black water

Cybersecurity consulting for high-consequence systems

Safe harbour for the systems that cannot be allowed to fail

Blackharbor secures healthcare and OT environments, data centers, cloud platforms and the applications on top of them — with AI security as the practice the rest of the market is still catching up to.

Headquarters
Toronto, Canada
Coverage
Global delivery
Flagship
Secure AI & AI security

Secure AI

Your models read internal data and take actions. Who has tested that?

We threat model the whole AI stack — prompts, retrieval, embeddings, tools and autonomy — then evaluate it against real attacker behaviour and stand up the guardrails, monitoring and governance that make production defensible.

  • Prompt injection & tool abuse evaluation
  • Agent blast-radius design
  • RAG tenancy & data leakage review
  • NIST AI RMF / ISO 42001 governance
See the AI security practice

Practices

One standard of engineering rigour, from vCISO to managed detection

A specialist bench covering security leadership, risk analysis, GRC and compliance, third-party risk, security engineering, data protection, and managed detection and response.

All services

Programmes aligned to the frameworks you are measured against

  • NIST CSF 2.0
  • NIST AI RMF
  • ISO/IEC 27001
  • ISO/IEC 42001
  • IEC 62443
  • HIPAA Security Rule
  • SOC 2
  • HITRUST CSF
  • GDPR
  • CIS Benchmarks
  • OWASP ASVS
  • OWASP Top 10 for LLMs

Who we serve

Consequence, not company size, decides how we work

A hospital network, a substation, a colocation floor and an AI platform fail in very different ways. Our teams are organised around those failure modes.

What makes us different

Specialists in the environments most firms treat as an exception

  • Built for high-consequence environments

    Clinical floors, plant networks, colocation halls and AI platforms

    We work where downtime is measured in patient harm, physical process or contractual penalty — so scoping, testing windows and change control are designed around operations, never imposed on them.

  • AI security as a first-class practice

    Not a checklist bolted onto a legacy assessment

    Prompt injection, retrieval tenancy, tool and agent blast radius, model supply chain and AI governance are treated as their own discipline, mapped to NIST AI RMF and ISO 42001.

  • Risk stated in decision-ready terms

    Quantified exposure, not a colour-coded spreadsheet

    Findings are tied to the asset, the business consequence and the cost of fixing or accepting them, so boards and budget owners can act on the first read.

  • Engineers, not report writers

    Recommendations we are willing to implement ourselves

    The same consultants who assess your environment can design, build and operate the controls — architecture, cloud, identity, data protection and detection engineering.

Ways to work with us

From a single assessment to a fully managed programme

See the full bench
  1. 01

    Assessment & risk analysis

    A bounded review of an environment, product or AI system, ending with a prioritised, quantified remediation plan.

  2. 02

    Project & engineering delivery

    A defined build: segmentation, cloud hardening, identity, data protection, detection content or a compliance programme.

  3. 03

    Fractional leadership

    A virtual CISO embedded in your governance cadence, owning strategy, reporting and audit readiness.

  4. 04

    Managed programme

    Ongoing managed detection and response with continuous risk, vendor and compliance oversight.

Our approach

Chart, quantify, harden, sustain

  1. 01

    Chart

    We map data flows, systems, models, vendors and obligations before recommending a single control.

  2. 02

    Quantify

    Risk is scored at the asset and component level, so investment goes where real-world consequence is highest.

  3. 03

    Harden

    We deliver a sequenced roadmap and, where you want it, execute the engineering work alongside your teams.

  4. 04

    Sustain

    Testing, monitoring, evaluation and reporting continue on a cadence you can show to auditors, customers and boards.

Start with a conversation, not a quote

Tell us what you run, what you are accountable for and what would hurt most if it stopped. We will tell you honestly where to start.