Black Spear Security mark Black Spear Security
Black Spear Security, Inc.

KNOW THE RISK.
OWN THE RESPONSE.

Know your risk. Test your defenses. Respond with confidence.

When a security incident, assessment, compliance requirement, or high-risk decision puts your organization under pressure, Black Spear Security gives you experienced practitioners you can call. We help you determine what happened, uncover weaknesses before attackers exploit them, validate whether your defenses actually work, and build a practical path toward stronger security and compliance.

Black Spear Security mark
Approach

Security expertise you can put to work.

You need more than a report full of findings. You need clear answers, defensible evidence, practical recommendations, and people who can help your team move from identifying risk to reducing it.

50+
Years combined experience
Human
Security culture & training
4
Core security disciplines

Whether you are dealing with an active incident, trying to understand where your environment is exposed, preparing for an audit, or testing how your organization would withstand a real attack, we tailor the engagement to the decisions you need to make.

We are technology-agnostic by design. We start with your risks, objectives, people, and operating environment—not a product we want to sell you. You leave with findings you can defend, priorities your team can act on, and a clearer understanding of what to do next.

Services

The expertise you need when security matters most.

DFIR

Digital Forensics & Incident Response

When something goes wrong, we help you establish what happened, what was affected, how the attacker operated, and what you should do next. Our DFIR work includes incident triage, forensic collection and analysis, scoping, containment guidance, root-cause investigation, and clear post-incident reporting.

Assess

Security Assessments & Consulting

Get an independent view of your security posture before an attacker, auditor, customer, or insurer finds the gaps for you. We assess technical and programmatic controls, identify material risk, and turn findings into a prioritized remediation plan your team can realistically execute.

Adversary

Red Team Operations

Find out how your defenses perform against a determined adversary. We conduct authorized testing across technical, physical, and human attack surfaces to identify exploitable paths and evaluate prevention, detection, escalation, and response under realistic conditions.

Govern

Compliance & Readiness

Turn security and compliance requirements into an achievable program. We help you identify control gaps, map requirements, develop policies and procedures, prepare evidence, and prioritize remediation so you can approach reviews, audits, and customer requirements with confidence.

Expertise

Clear answers. Actionable findings. No shelfware.

Our work is designed to answer the questions your leadership and technical teams actually have: What happened? Where are we exposed? Can our controls withstand a real attack? What should we fix first? And can we demonstrate that our security program works?

01

Incident Triage & Scoping

Quickly establish what happened, what systems or data may be affected, and what actions should be taken next while preserving critical evidence.

02

Digital Forensics

Reconstruct activity using endpoint, log, identity, network, and other artifacts so you can make decisions based on evidence rather than assumptions.

03

Compromise & Root-Cause Analysis

Understand how an attacker gained access, what they did, how far they got, and which control failures allowed the incident to occur.

04

Security Assessments

Identify weaknesses across architecture, configuration, identity, network, endpoint, cloud, and operational controls before they become incidents.

05

Penetration Testing & Red Team

See how exploitable weaknesses combine in practice and how effectively your people and controls prevent, detect, escalate, and respond to adversary activity.

06

Security Consulting & Remediation

Turn technical findings into a prioritized security roadmap that accounts for your actual risk, resources, operational constraints, and business objectives.

07

Compliance Gap Analysis

Understand where your current controls and evidence fall short of applicable requirements and what you need to do to close those gaps.

08

Policy, Procedure & Readiness

Build policies, procedures, incident response processes, evidence practices, and repeatable controls your team can actually maintain—and demonstrate when asked.

Team

Experienced practitioners. Direct access. Practical guidance.

Your engagement is led by practitioners—not handed off to a generic delivery team. We bring hands-on experience across offensive and defensive security, digital forensics, infrastructure, compliance, risk, and emerging technology. We also know that lasting security depends on people, so we help your technical teams, leaders, and employees understand the why behind the controls and build security habits that continue after the engagement ends.

  • Cybersecurity practitioner and veteran of the U.S. Marine Corps with a background spanning security operations, red team leadership, IT administration, infrastructure defense, incident response, compliance, and technical instruction. Anthony brings an adversary-minded, mission-focused perspective to Black Spear’s assessments and consulting, combining hands-on defensive engineering with experience leading offensive security work. A longtime instructor and team leader, he is equally focused on making security understandable — helping organizations turn technical controls into repeatable practices and a stronger security culture.

  • Gerges brings deep expertise across enterprise infrastructure, network engineering, systems administration, architecture, and the configurations that security ultimately depends on. He also has substantial hands-on experience with artificial intelligence and emerging AI technologies. For clients evaluating infrastructure, architecture, or AI adoption, he brings a systems-level perspective that connects security requirements to how technology actually operates. He is particularly effective at making complex technical issues understandable to the people responsible for acting on them.

  • Adrian brings experience across ethical hacking, digital forensics, AI-driven security research, risk, and technology leadership. He helps clients connect technical findings to business risk, remediation priorities, and better security decisions. His combination of offensive, forensic, and advisory experience is especially valuable when an organization needs to understand not only what is technically possible, but what matters most and how to communicate it to leadership and technical teams.

Contact

Tell us what you need to solve.

You do not need to know exactly which service to ask for. Tell us what happened, what you are concerned about, what requirement you are facing, or what you want tested. We will help you define the problem, determine the right scope, and give you a clear path forward.