Boutique Security Advisory · Est. 2019

Blackfish Security

"Persistence engineering. Hardware to intelligence."

Twenty years of security engineering — from SCADA control rooms to silicon. Blackfish advises organizations where trust in the platform itself is non-negotiable: healthcare, legal, financial, and critical infrastructure. Hardware-level assessment. AI-augmented defense. Every engagement scoped, bounded, and accountable to a licensed professional.

Practice Domains

  • Firmware & Boot ChainUEFI · SMM · pre-boot
  • Bus-Level SecurityPCIe · DMA · TLP engines
  • Custom SiliconFPGA · SystemVerilog
  • Industrial ControlSCADA · OT hardening
  • AI-Integrated Defenseaugmented · supervised
  • Persistent Contextsession-to-session

The same principles that keep a firmware hook alive across an OS reinstall apply to every system we defend.

01 · About

The firm

Mike Haddock founded Blackfish Security on a simple observation: the systems that fail catastrophically are usually the ones nobody understood at the lowest level. His career began in water treatment operations — running SCADA systems, managing industrial control networks, and learning what it costs when critical infrastructure goes down.

That operational grounding became hardware security engineering at the firmware and silicon level: FPGA development, PCIe/DMA security assessment, UEFI/SMM modification, and low-level penetration testing. The through-line is persistence — how systems retain state, identity, and capability across every change of substrate.

"Anyone can audit the application layer. We work where the trust actually lives — the platform underneath it."

Today, Blackfish applies that lens where it matters most: healthcare providers, legal firms, financial services, and critical infrastructure operators — pairing hardware-level security expertise with AI-augmented operations that run under licensed human oversight. The result is a small firm with an unusual depth of field: silicon to intelligence, one accountable chain.

02 · Core Practice

Hardware Security

Low-level security assessment and engineering for organizations where trust in the platform itself is non-negotiable. We work at the layers most firms cannot reach — and document everything in language your counsel and your board can read.

Capabilities

Silicon to Operating System

  • FPGA Firmware Development — Xilinx Artix-7, SystemVerilog, custom logic for security-critical applications.
  • PCIe / DMA Security Assessment — TLP engine analysis, endpoint emulation, and bus-level attack surface review.
  • UEFI / SMM Modification — Pre-boot persistence design, firmware-level defense, and boot-chain integrity.
  • SCADA / OT Security — Industrial control assessment, network segmentation, and operational technology hardening for critical infrastructure.
  • Hardware Penetration Testing — IOMMU/VT-d bypass, memory controller manipulation, and physical-layer exploitation.
  • Adversarial Firmware Review — Detection and analysis of implants, hooks, and supply-chain modifications below the OS.
03 · Healthcare Security Practice

Protecting patient data. Stopping attacks before they land.

Healthcare organizations face a unique threat profile: HIPAA-mandated data protection, high-value patient records, clinical trial data, and staff who are overworked and undertrained in security. We provide layered defense — from infrastructure to inbox.

Managed Infrastructure

Secure Workstation Architecture

We design and deploy centralized workstation environments that eliminate the attack surface at the endpoint. Staff operate from lightweight mini-PCs connected to virtual machines on a secured, on-premises server. Every session is sandboxed, patched, and monitored.

  • Thin-client deployment — Staff mini-PCs are stateless terminals. No local data. No local attack surface. Compromised hardware is a non-event.
  • Centralized VM management — All workstations run as VMs on a secured local server. Patches, updates, and security policies are applied once, everywhere.
  • Remote management — We manage the server infrastructure remotely. Your office gets enterprise-grade IT without enterprise-grade headcount.
  • HIPAA-aligned architecture — Data stays on-premises. Access is logged. Sessions are auditable. The compliance trail is built in, not bolted on.

Active Defense

Phishing & Social Engineering Protection

Phishing is the #1 attack vector against healthcare organizations. We deploy AI-augmented email analysis that catches what rule-based filters miss — and we train your staff to catch what the filters don't.

  • AI-augmented email filtering — Real-time analysis of incoming email for phishing indicators, social engineering patterns, and payload anomalies. Catches zero-day phishing that signature-based filters miss.
  • Real-time threat response — Detected threats are quarantined, the security team is alerted, and the incident is logged for compliance reporting.
  • Staff security training — Regular phishing simulation and training programs. Your staff becomes the second line of defense, not the weakest link.
  • Incident documentation — Every blocked attack is documented with full forensic detail. HIPAA breach notification requirements are met with evidence, not guesswork.

Continuous Protection

24/7 AI-Augmented Monitoring

Attacks don't stop at 5 PM. Neither do we. Our AI-augmented monitoring watches your infrastructure around the clock — business hours, after hours, weekends, and holidays.

  • Business-hours active defense — During operations, our systems monitor for phishing attempts, unauthorized access, and anomalous behavior in real time. Threats are stopped as they're attempted.
  • After-hours vigilance — When the office is empty, monitoring continues. Automated patching, log analysis, and anomaly detection run continuously. You wake up to a report, not a breach.
  • Penetration testing — Regular authorized penetration testing of your infrastructure. We find the gaps before the attackers do.
  • Compliance reporting — Continuous documentation of security posture, incident response, and remediation. HIPAA audit preparation is a byproduct, not a project.

Specialized Practice

High-Risk Data Environments

Some data carries weight beyond HIPAA. Clinical trial data, research protocols, and proprietary medical research require security that understands the stakes.

  • Clinical trial data protection — Security for research data subject to FDA, IRB, and sponsor requirements. Data integrity, access control, and audit trails designed for regulatory scrutiny.
  • Multi-site coordination — Secure infrastructure for organizations operating across multiple locations. Centralized management with site-specific access controls.
  • Vendor risk management — Assessment and monitoring of third-party vendors with access to your systems or data. The supply chain is part of the attack surface.
04 · AI-Integrated Practice

AI-Augmented Security Services

Blackfish integrates large-scale AI capability into security workflows under strict operational controls. Every AI-augmented engagement is scoped, bounded, and supervised by a licensed security professional. No autonomous action. No unbounded access. Every output attributable.

Scoped

Bounded Engagement

Every AI-augmented task operates within a defined scope. Access is granted per-engagement, per-role, and per-dataset. No ambient access. No scope creep. The boundary is contractual, not aspirational.

Contract-Defined

Advanced

Persistent Operational Context

Our systems maintain relevant operational history across sessions — threat intelligence, vulnerability assessments, client environment specifics — without re-briefing. Context persists within engagement scope, not beyond it.

Session-to-Session

Safe

Licensed Oversight

Every AI-augmented output is reviewed and attested by a licensed security professional. The AI provides analysis, correlation, and drafting. The human provides judgment, authorization, and accountability.

Human-Attested

Threat Intelligence

Multi-Source Correlation

AI-augmented analysis of threat feeds, vulnerability databases, and adversary TTPs. Cross-referenced against client environment specifics to produce actionable, prioritized intelligence.

OSINT + Internal

Security Assessment

Augmented Analysis

AI-assisted review of security configurations, access controls, and architectural decisions. Rapid identification of misconfigurations, policy gaps, and attack surface anomalies.

Rapid Triage

Operational Continuity

Institutional Memory

Persistent documentation of security decisions, incident responses, and environmental changes. New team members inherit full operational context without tribal knowledge loss.

Zero Knowledge Loss
Methodology & research →
05 · Research & Analysis

Published work

Blackfish publishes original research on persistence engineering, AI-integrated security operations, and the structural analysis of the AI industry itself.

06 · Credentials

Why Blackfish

Blackfish Security is not a product company. It is a specialist advisory practice serving healthcare providers, legal firms, financial services, and critical infrastructure operators.

20+
Years security engineering
Healthcare
HIPAA compliance
Legal
Privileged data protection
Financial
GLBA & SOX expertise
Infrastructure
SCADA & OT security
24/7
AI-augmented monitoring
Blackfish Security LLC · Founded 2019 Florida, United States
07 · Contact

Start a conversation

For engagements, assessments, or AI-integrated security service inquiries. Initial consultations are confidential and without obligation.