Home/Industries/Government & GovTech
Industries — Government & GovTechAssessment-ready, not assessment-hopeful.
Selling to or operating within Australian government means your controls get read by somebody whose job is to disbelieve them. We build for that reader.
What we do, and what we deliberately do not
Seacow prepares systems for IRAP assessment. We are not a registered IRAP assessor, and we would not want to be for a system we built — an assessor marking their own homework is worth nothing to you or to the agency reading the report.
- Gap assessment against the Information Security Manual controls in scope
- Control implementation and configuration hardening across the estate
- System security plan input and architecture documentation
- Evidence automation so control operation is demonstrable continuously
- Sitting alongside your assessor through the assessment, answering technical questions
- Remediation of findings, tracked to closure with re-evidence
Assessment and any authorisation decision rest with your registered assessor and the accrediting authority. We will introduce you to assessors we have worked with, and we have no commercial arrangement with any of them.
Data residency
Two Australian AWS regions are available, and for many government workloads the choice matters for both latency and policy:
- ap-southeast-2 — Sydney, our primary region
- ap-southeast-4 — Melbourne, for in-country secondary and DR
Backups, logs and support tooling stay in-country. Our sub-processor register lists every location, and changes come with notice rather than appearing in a quarterly update.
On protective marking
Our experience is with OFFICIAL and OFFICIAL: Sensitive workloads. We do not claim capability above that, and if your requirement is PROTECTED or higher we will say so at the first meeting rather than at contract.
The four that actually apply to a cloud estate
Half the Essential Eight mitigation strategies are desktop-oriented. On a cloud-native platform with no managed fleet in scope, the meaningful work concentrates in four — and clarifying that early saves a great deal of budget.
| Mitigation strategy | Cloud relevance | How we implement it |
|---|---|---|
| Patch applications | High | Amazon Inspector plus pipeline image scanning, patch SLA by severity, exceptions registered with expiry |
| Patch operating systems | High | Systems Manager patch baselines per environment, coverage reported monthly, immutable AMI pipeline where possible |
| Multi-factor authentication | High | IAM Identity Center federation with MFA enforced, SCP denying long-lived key creation |
| Restrict admin privileges | High | Permission boundaries, just-in-time elevation, session logging, no standing production admin |
| Regular backups | High | AWS Backup policy per workload, immutability via Vault Lock, restore tested on a schedule |
| Application control | Partial | Container admission policy and signed artefacts; legacy EC2 hosts assessed individually |
| Configure macro settings | Usually out of scope | Applies to a desktop fleet, not to the cloud platform |
| User application hardening | Usually out of scope | Applies to a desktop fleet, not to the cloud platform |
Scope boundaries must be agreed with your assessor. This table reflects how the strategies typically map, not a determination for your system. Longer write-up →
Documentation shaped for the process you are in
Government procurement fails engineering teams less often than it fails their paperwork. We produce the artefacts in the form the process expects, rather than a beautifully written document in the wrong shape.
- System security plan input and control implementation statements
- Architecture and data flow diagrams kept current, not redrawn per tender
- Sub-processor register with hosting locations and change notice terms
- Incident response and notification path aligned to agency requirements
- Insurance certificates, personnel screening policy, and confidentiality terms
- Exit plan and handover documentation, because continuity gets assessed too
Related case study
A SaaS platform needed demonstrable controls for a government tender. The platform was well built; the evidence was informal — screenshots, tribal knowledge, and a policy nobody had read since 2023.
Ten weeks later: IRAP assessment commenced with no blocking findings, Essential Eight maturity lifted from Level 1 to Level 2, and 63 long-lived IAM keys reduced to zero.
Read the case studyFind the gaps before your assessor does
A gap assessment against the Essential Eight or the ISM controls in scope, with a prioritised remediation plan you own.