About us

A consulting firm built for environments where failure is physical

Blackharbor exists because generic security advice breaks down in the places that matter most: a hospital that cannot pause care, a plant that cannot be rebooted, a colocation floor carrying everyone else's uptime, and an AI system that now makes decisions faster than anyone reviews them.

Headquarters
Toronto, Canada
Clients
Advising operators and builders worldwide

Our mission

To make strong security achievable for the organisations whose systems other people depend on — without pretending that clinical reality, process safety or release velocity can be redesigned around a control framework.

We combine consulting depth with engineering delivery. That means we can tell you what your risk actually is, then work alongside your teams to reduce it: hardening, segmentation, testing, guardrails and reporting you can show to an auditor, a customer or a board.

Headquartered in Toronto, Canada, we work across regions and time zones, aligning programmes to NIST CSF, the NIST AI RMF, ISO 27001 and 42001, IEC 62443, HIPAA and GDPR depending on where and how you operate.

Request a consultation
Data center aisle blended with industrial pipework under cool cyan light

How we work

Consequence over checklists

Findings are ranked by what would actually happen — to patients, to a process, to a facility, to a customer — not by a scanner's default severity.

Engineers, not questionnaire readers

The people who assess your environment can also help fix it: network, cloud, control-system and AI engineering in the same team.

AI treated as infrastructure

We secure models, pipelines and agents with the same discipline applied to networks and identity, because that is now what they are.

Plain answers

A clear statement of where you stand, what it takes to improve, and what we would do first if it were our budget.