KNOW THE RISK.
OWN THE RESPONSE.
Know your risk. Test your defenses. Respond with confidence.
When a security incident, assessment, compliance requirement, or high-risk decision puts your organization under pressure, Black Spear Security gives you experienced practitioners you can call. We help you determine what happened, uncover weaknesses before attackers exploit them, validate whether your defenses actually work, and build a practical path toward stronger security and compliance.
Security expertise you can put to work.
You need more than a report full of findings. You need clear answers, defensible evidence, practical recommendations, and people who can help your team move from identifying risk to reducing it.
Whether you are dealing with an active incident, trying to understand where your environment is exposed, preparing for an audit, or testing how your organization would withstand a real attack, we tailor the engagement to the decisions you need to make.
We are technology-agnostic by design. We start with your risks, objectives, people, and operating environment—not a product we want to sell you. You leave with findings you can defend, priorities your team can act on, and a clearer understanding of what to do next.
The expertise you need when security matters most.
Digital Forensics & Incident Response
When something goes wrong, we help you establish what happened, what was affected, how the attacker operated, and what you should do next. Our DFIR work includes incident triage, forensic collection and analysis, scoping, containment guidance, root-cause investigation, and clear post-incident reporting.
Security Assessments & Consulting
Get an independent view of your security posture before an attacker, auditor, customer, or insurer finds the gaps for you. We assess technical and programmatic controls, identify material risk, and turn findings into a prioritized remediation plan your team can realistically execute.
Red Team Operations
Find out how your defenses perform against a determined adversary. We conduct authorized testing across technical, physical, and human attack surfaces to identify exploitable paths and evaluate prevention, detection, escalation, and response under realistic conditions.
Compliance & Readiness
Turn security and compliance requirements into an achievable program. We help you identify control gaps, map requirements, develop policies and procedures, prepare evidence, and prioritize remediation so you can approach reviews, audits, and customer requirements with confidence.
Clear answers. Actionable findings. No shelfware.
Our work is designed to answer the questions your leadership and technical teams actually have: What happened? Where are we exposed? Can our controls withstand a real attack? What should we fix first? And can we demonstrate that our security program works?
Incident Triage & Scoping
Quickly establish what happened, what systems or data may be affected, and what actions should be taken next while preserving critical evidence.
Digital Forensics
Reconstruct activity using endpoint, log, identity, network, and other artifacts so you can make decisions based on evidence rather than assumptions.
Compromise & Root-Cause Analysis
Understand how an attacker gained access, what they did, how far they got, and which control failures allowed the incident to occur.
Security Assessments
Identify weaknesses across architecture, configuration, identity, network, endpoint, cloud, and operational controls before they become incidents.
Penetration Testing & Red Team
See how exploitable weaknesses combine in practice and how effectively your people and controls prevent, detect, escalate, and respond to adversary activity.
Security Consulting & Remediation
Turn technical findings into a prioritized security roadmap that accounts for your actual risk, resources, operational constraints, and business objectives.
Compliance Gap Analysis
Understand where your current controls and evidence fall short of applicable requirements and what you need to do to close those gaps.
Policy, Procedure & Readiness
Build policies, procedures, incident response processes, evidence practices, and repeatable controls your team can actually maintain—and demonstrate when asked.
Experienced practitioners. Direct access. Practical guidance.
Your engagement is led by practitioners—not handed off to a generic delivery team. We bring hands-on experience across offensive and defensive security, digital forensics, infrastructure, compliance, risk, and emerging technology. We also know that lasting security depends on people, so we help your technical teams, leaders, and employees understand the why behind the controls and build security habits that continue after the engagement ends.
-
Cybersecurity practitioner and veteran of the U.S. Marine Corps with a background spanning security operations, red team leadership, IT administration, infrastructure defense, incident response, compliance, and technical instruction. Anthony brings an adversary-minded, mission-focused perspective to Black Spear’s assessments and consulting, combining hands-on defensive engineering with experience leading offensive security work. A longtime instructor and team leader, he is equally focused on making security understandable — helping organizations turn technical controls into repeatable practices and a stronger security culture.
-
Gerges brings deep expertise across enterprise infrastructure, network engineering, systems administration, architecture, and the configurations that security ultimately depends on. He also has substantial hands-on experience with artificial intelligence and emerging AI technologies. For clients evaluating infrastructure, architecture, or AI adoption, he brings a systems-level perspective that connects security requirements to how technology actually operates. He is particularly effective at making complex technical issues understandable to the people responsible for acting on them.
-
Adrian brings experience across ethical hacking, digital forensics, AI-driven security research, risk, and technology leadership. He helps clients connect technical findings to business risk, remediation priorities, and better security decisions. His combination of offensive, forensic, and advisory experience is especially valuable when an organization needs to understand not only what is technically possible, but what matters most and how to communicate it to leadership and technical teams.
Tell us what you need to solve.
You do not need to know exactly which service to ask for. Tell us what happened, what you are concerned about, what requirement you are facing, or what you want tested. We will help you define the problem, determine the right scope, and give you a clear path forward.