Local AI infrastructure
Models run on hardware we own and operate. Your source code, credentials, documents and findings never reach a third-party AI provider, because there is no third-party AI provider in the path.
Joe Black Security is a boutique offensive security consultancy. We stay deliberately small, because the work we do well does not scale by adding junior staff to it.
Most security testing has quietly become a compliance exercise. A scanner runs, a template fills in, a PDF arrives, a box gets ticked. Everybody is satisfied and nobody is any safer.
We do the other thing. We treat your organization the way somebody who genuinely wanted your data would: patiently, creatively, and without much regard for which systems you had planned to have tested. Then we show you every step of how we did it.
That means the judgement stays human. The findings that end organizations are chains of small, individually harmless things: a forgotten subdomain, a password pattern, an over-trusted service account, a helpdesk that wants to be helpful. Recognising that a chain exists is experience, and no tool supplies it.
What has changed is how much ground we can cover before applying that judgement. Every engagement is now AI-assisted, running on infrastructure we own, and it has made a genuine difference: work that used to mean sampling a codebase or skimming a log set can now be read in full. We find more, and we find it sooner.
We are also direct with you about what you need. If a focused penetration test would serve you better than a full red team operation, we will say so before you sign anything, even though it is the smaller engagement. Selling someone the wrong test is a good way to take their money and leave them no safer than before.
Everything happens with written authorization and agreed rules of engagement. You always know who to call, and during an operation you always have a live channel telling you what is us and what is not.
Global average cost of a data breach
Mean time to identify and contain one
Of breaches start with stolen credentials
Median handoff from access broker to attacker
IBM Cost of a Data Breach 2025, Verizon DBIR 2025, Mandiant M-Trends 2026.
Every engagement we run is AI-assisted, and every model runs on hardware we own and operate. Nothing you hand us is sent to a third-party AI service - not your source, not your logs, not your findings.
Models run on hardware we own and operate. Your source code, credentials, documents and findings never reach a third-party AI provider, because there is no third-party AI provider in the path.
Decades of hands-on offensive security experience decide what to attack and what a finding means. AI removes the grind - the reading, the correlating, the cross-referencing - so more of the engagement is spent on the work that genuinely needs a person.
Ground that used to be sampled can now be covered in full. The time saved goes into breadth and depth. It does not come off your invoice, and we would rather be straight with you about that.
Nothing reaches your report because a model asserted it. Findings are verified by hand, and anything we could not confirm is reported as unconfirmed rather than quietly dropped or dressed up.
AI-assisted, on local infrastructure we own - your data never reaches a third-party AI service.
Founder · Red Team Lead
Joe has spent more than two decades in offensive security, covering network intrusion from initial foothold to full domain compromise, application and API testing, wireless, physical intrusion and social engineering. His own focus is network infiltration, post-exploitation and human hacking: the parts of an operation where patience matters more than tooling.
Before founding Joe Black Security he worked as an information security engineer in Cisco's Center of Excellence red team, across both Cisco Israel and Cisco Korea. Prior to that he held positions as a security consultant to the South Korean government, as red team lead at boutique security firms, and as assistant director of MIS at a Las Vegas casino.
He has led diverse teams across multi-cultural environments, and takes the view that an engagement has failed if the client's own people have not learned something from it.
For operations that need more hands than one, we bring in vetted specialists we have worked with directly and can vouch for personally. You are told who is on your engagement and what they are doing before they start. No unfamiliar names turning up on a report.
A short call is usually enough to work out what you actually need.