Australian owned · Operating since 2014 · Sydney, NSW Support & SLAs 24×7 incident line

Home/Case Studies/Compliance evidence

SaaS Security IRAP readiness

From “we think we're compliant” to an evidence pack in ten weeks.

SaaS platform · IRAP readiness · ISO 27001 certification path · government tender deadline

10 weeksgap assessment to signed evidence pack
63 → 0long-lived IAM access keys
L1 → L2Essential Eight maturity
0blocking findings at assessment commencement

The situation

A government tender required demonstrable controls and a credible assessment pathway, with a submission date fourteen weeks out. The platform itself was well built — a competent engineering team, sensible architecture, no obvious weaknesses.

The evidence was another matter. Controls were real but informal: screenshots in a shared drive, knowledge held by two engineers, and an information security policy document last revised in 2023 that described a system architecture which no longer existed.

This is an extremely common position and it is not the same as being insecure. It is being unable to prove you are secure, to a reader whose job is to disbelieve you, within a deadline.

Gap assessment

Three weeks against the ACSC Essential Eight and ISO 27001 Annex A, in parallel rather than in sequence, because the overlap is substantial and running them separately wastes a fortnight.

Forty-one findings: nine high, nineteen medium, thirteen low. The nine high findings clustered into three themes, which is typical — problems in this space are rarely independent.

  • Identity. Sixty-three long-lived IAM access keys across eleven accounts, including four with administrator policies attached and no rotation in over two years.
  • Audit integrity. CloudTrail enabled but writing to a bucket in the same account it was auditing, with delete permissions available to the same roles it was meant to be watching.
  • Evidence. No mechanism to demonstrate that any control had been operating at a given point in the past — only that it was configured now.

Remediation, in priority order

Identity first

IAM Identity Center federation with the customer's existing identity provider, MFA enforced, and a service control policy denying access key creation entirely. Human access became role assumption with session logging; machine access became IAM roles for service accounts and OIDC federation from CI.

Sixty-three keys to zero in eleven days. The engineering team expected this to be disruptive. It was mildly annoying for four days and then invisible, which is the usual shape.

Guardrails before detection

AWS Control Tower with service control policies denying region use outside Australia, root account usage, public S3 access and CloudTrail modification. Deployed in report mode for a week first, so we could see exactly what would have broken before enforcing anything.

Two legitimate workflows would have broken. Both were redesigned rather than exception-listed — an exception granted during implementation is an exception that exists forever.

Audit integrity

Organisation trail to a dedicated log archive account with Object Lock and separate access control. Nobody with production access can alter the record of what they did in production, which is the entire point and was the finding an assessor would have opened with.

The part that mattered most

We automated evidence collection. Config conformance packs mapped to the framework controls, scheduled evidence snapshots to immutable storage with retention, and a register recording the owner and test frequency for each control.

This is the difference between passing an assessment and being able to survive one. Any organisation can reconstruct evidence in the fortnight before an audit. That works exactly once, costs a fortnight of engineering time every year, and tells the assessor — and you — nothing about whether the control was operating in month seven.

Where it landed

Ten weeks from gap assessment to a signed evidence pack, four weeks inside the tender deadline. IRAP assessment commenced with no blocking findings.

Mid-assessment the assessor requested evidence of a control operating over a specific historical period — something the customer would previously have been unable to produce at all. It was generated and mapped in four days.

ISO 27001 certification followed the next quarter, which was faster than the customer's own plan because the technical control work was already complete and evidenced.

“Our IRAP assessor asked for evidence we didn't have. Seacow had it produced and mapped in four days.”

Chief Information Security Officer, SaaS platform

What we did not do

We did not assess the system. Seacow is not a registered IRAP assessor and we would not want to be for a system we had just hardened — an assessor marking their own work is worth nothing to the agency reading the report.

We also did not penetration test. An independent tester was engaged separately on the customer's contract, with no referral arrangement, and we remediated what they found.

Certification was issued by an accredited certification body, not by us. Any provider telling you they will "certify you to ISO 27001" is describing the process incorrectly.

Find the gaps before an assessor does

A gap assessment against Essential Eight, ISO 27001 or SOC 2 — fixed price from $14,000, with a remediation plan you own.