"Persistence engineering. Hardware to intelligence."
Twenty years of security engineering — from SCADA control rooms to silicon. Blackfish advises organizations where trust in the platform itself is non-negotiable: healthcare, legal, financial, and critical infrastructure. Hardware-level assessment. AI-augmented defense. Every engagement scoped, bounded, and accountable to a licensed professional.
The same principles that keep a firmware hook alive across an OS reinstall apply to every system we defend.
Mike Haddock founded Blackfish Security on a simple observation: the systems that fail catastrophically are usually the ones nobody understood at the lowest level. His career began in water treatment operations — running SCADA systems, managing industrial control networks, and learning what it costs when critical infrastructure goes down.
That operational grounding became hardware security engineering at the firmware and silicon level: FPGA development, PCIe/DMA security assessment, UEFI/SMM modification, and low-level penetration testing. The through-line is persistence — how systems retain state, identity, and capability across every change of substrate.
"Anyone can audit the application layer. We work where the trust actually lives — the platform underneath it."
Today, Blackfish applies that lens where it matters most: healthcare providers, legal firms, financial services, and critical infrastructure operators — pairing hardware-level security expertise with AI-augmented operations that run under licensed human oversight. The result is a small firm with an unusual depth of field: silicon to intelligence, one accountable chain.
Low-level security assessment and engineering for organizations where trust in the platform itself is non-negotiable. We work at the layers most firms cannot reach — and document everything in language your counsel and your board can read.
Capabilities
Healthcare organizations face a unique threat profile: HIPAA-mandated data protection, high-value patient records, clinical trial data, and staff who are overworked and undertrained in security. We provide layered defense — from infrastructure to inbox.
Managed Infrastructure
We design and deploy centralized workstation environments that eliminate the attack surface at the endpoint. Staff operate from lightweight mini-PCs connected to virtual machines on a secured, on-premises server. Every session is sandboxed, patched, and monitored.
Active Defense
Phishing is the #1 attack vector against healthcare organizations. We deploy AI-augmented email analysis that catches what rule-based filters miss — and we train your staff to catch what the filters don't.
Continuous Protection
Attacks don't stop at 5 PM. Neither do we. Our AI-augmented monitoring watches your infrastructure around the clock — business hours, after hours, weekends, and holidays.
Specialized Practice
Some data carries weight beyond HIPAA. Clinical trial data, research protocols, and proprietary medical research require security that understands the stakes.
Blackfish integrates large-scale AI capability into security workflows under strict operational controls. Every AI-augmented engagement is scoped, bounded, and supervised by a licensed security professional. No autonomous action. No unbounded access. Every output attributable.
Every AI-augmented task operates within a defined scope. Access is granted per-engagement, per-role, and per-dataset. No ambient access. No scope creep. The boundary is contractual, not aspirational.
Contract-DefinedOur systems maintain relevant operational history across sessions — threat intelligence, vulnerability assessments, client environment specifics — without re-briefing. Context persists within engagement scope, not beyond it.
Session-to-SessionEvery AI-augmented output is reviewed and attested by a licensed security professional. The AI provides analysis, correlation, and drafting. The human provides judgment, authorization, and accountability.
Human-AttestedAI-augmented analysis of threat feeds, vulnerability databases, and adversary TTPs. Cross-referenced against client environment specifics to produce actionable, prioritized intelligence.
OSINT + InternalAI-assisted review of security configurations, access controls, and architectural decisions. Rapid identification of misconfigurations, policy gaps, and attack surface anomalies.
Rapid TriagePersistent documentation of security decisions, incident responses, and environmental changes. New team members inherit full operational context without tribal knowledge loss.
Zero Knowledge LossBlackfish publishes original research on persistence engineering, AI-integrated security operations, and the structural analysis of the AI industry itself.
The formal framework behind the practice: how identity, state, and capability survive substrate change — in firmware, in organizations, and in machine intelligence.
Ongoing public analysis: AI industry structure, hardware security, and regulatory dynamics. Where the firm thinks out loud.
Long-horizon research into human–AI operational collaboration — the groundwork behind Blackfish's AI-integrated practice.
Blackfish Security is not a product company. It is a specialist advisory practice serving healthcare providers, legal firms, financial services, and critical infrastructure operators.
For engagements, assessments, or AI-integrated security service inquiries. Initial consultations are confidential and without obligation.