About us
A consulting firm built for environments where failure is physical
Blackharbor exists because generic security advice breaks down in the places that matter most: a hospital that cannot pause care, a plant that cannot be rebooted, a colocation floor carrying everyone else's uptime, and an AI system that now makes decisions faster than anyone reviews them.
- Headquarters
- Toronto, Canada
- Clients
- Advising operators and builders worldwide
Our mission
To make strong security achievable for the organisations whose systems other people depend on — without pretending that clinical reality, process safety or release velocity can be redesigned around a control framework.
We combine consulting depth with engineering delivery. That means we can tell you what your risk actually is, then work alongside your teams to reduce it: hardening, segmentation, testing, guardrails and reporting you can show to an auditor, a customer or a board.
Headquartered in Toronto, Canada, we work across regions and time zones, aligning programmes to NIST CSF, the NIST AI RMF, ISO 27001 and 42001, IEC 62443, HIPAA and GDPR depending on where and how you operate.
Request a consultation
How we work
Consequence over checklists
Findings are ranked by what would actually happen — to patients, to a process, to a facility, to a customer — not by a scanner's default severity.
Engineers, not questionnaire readers
The people who assess your environment can also help fix it: network, cloud, control-system and AI engineering in the same team.
AI treated as infrastructure
We secure models, pipelines and agents with the same discipline applied to networks and identity, because that is now what they are.
Plain answers
A clear statement of where you stand, what it takes to improve, and what we would do first if it were our budget.