Australian owned · Operating since 2014 · Sydney, NSW Support & SLAs 24×7 incident line

Home/Industries/Government & GovTech

Industries — Government & GovTech

Assessment-ready, not assessment-hopeful.

Selling to or operating within Australian government means your controls get read by somebody whose job is to disbelieve them. We build for that reader.

IRAP readiness

What we do, and what we deliberately do not

Seacow prepares systems for IRAP assessment. We are not a registered IRAP assessor, and we would not want to be for a system we built — an assessor marking their own homework is worth nothing to you or to the agency reading the report.

  • Gap assessment against the Information Security Manual controls in scope
  • Control implementation and configuration hardening across the estate
  • System security plan input and architecture documentation
  • Evidence automation so control operation is demonstrable continuously
  • Sitting alongside your assessor through the assessment, answering technical questions
  • Remediation of findings, tracked to closure with re-evidence

Assessment and any authorisation decision rest with your registered assessor and the accrediting authority. We will introduce you to assessors we have worked with, and we have no commercial arrangement with any of them.

Data residency

Two Australian AWS regions are available, and for many government workloads the choice matters for both latency and policy:

  • ap-southeast-2 — Sydney, our primary region
  • ap-southeast-4 — Melbourne, for in-country secondary and DR

Backups, logs and support tooling stay in-country. Our sub-processor register lists every location, and changes come with notice rather than appearing in a quarterly update.

On protective marking

Our experience is with OFFICIAL and OFFICIAL: Sensitive workloads. We do not claim capability above that, and if your requirement is PROTECTED or higher we will say so at the first meeting rather than at contract.

Essential Eight

The four that actually apply to a cloud estate

Half the Essential Eight mitigation strategies are desktop-oriented. On a cloud-native platform with no managed fleet in scope, the meaningful work concentrates in four — and clarifying that early saves a great deal of budget.

Mitigation strategyCloud relevanceHow we implement it
Patch applicationsHighAmazon Inspector plus pipeline image scanning, patch SLA by severity, exceptions registered with expiry
Patch operating systemsHighSystems Manager patch baselines per environment, coverage reported monthly, immutable AMI pipeline where possible
Multi-factor authenticationHighIAM Identity Center federation with MFA enforced, SCP denying long-lived key creation
Restrict admin privilegesHighPermission boundaries, just-in-time elevation, session logging, no standing production admin
Regular backupsHighAWS Backup policy per workload, immutability via Vault Lock, restore tested on a schedule
Application controlPartialContainer admission policy and signed artefacts; legacy EC2 hosts assessed individually
Configure macro settingsUsually out of scopeApplies to a desktop fleet, not to the cloud platform
User application hardeningUsually out of scopeApplies to a desktop fleet, not to the cloud platform

Scope boundaries must be agreed with your assessor. This table reflects how the strategies typically map, not a determination for your system. Longer write-up →

Procurement

Documentation shaped for the process you are in

Government procurement fails engineering teams less often than it fails their paperwork. We produce the artefacts in the form the process expects, rather than a beautifully written document in the wrong shape.

  • System security plan input and control implementation statements
  • Architecture and data flow diagrams kept current, not redrawn per tender
  • Sub-processor register with hosting locations and change notice terms
  • Incident response and notification path aligned to agency requirements
  • Insurance certificates, personnel screening policy, and confidentiality terms
  • Exit plan and handover documentation, because continuity gets assessed too

Related case study

A SaaS platform needed demonstrable controls for a government tender. The platform was well built; the evidence was informal — screenshots, tribal knowledge, and a policy nobody had read since 2023.

Ten weeks later: IRAP assessment commenced with no blocking findings, Essential Eight maturity lifted from Level 1 to Level 2, and 63 long-lived IAM keys reduced to zero.

Read the case study

Find the gaps before your assessor does

A gap assessment against the Essential Eight or the ISM controls in scope, with a prioritised remediation plan you own.