Australian owned · Operating since 2014 · Sydney, NSW Support & SLAs 24×7 incident line

Home/Services/Security & Compliance

Service 04 — Security & Compliance

Guardrails, not gates.

Preventive controls that stop the mistake, detective controls that catch what slips through, and the evidence trail your auditor will ask for — produced continuously rather than reconstructed the week before an audit.

Control layers

Four layers, each doing a different job

Most estates we inherit are strong on detection and weak on prevention — which means the security team spends its week triaging findings that a service control policy should have made impossible.

LAYER 01 — PREVENTIVE

Make the mistake impossible

  • AWS Control Tower landing zone with account factory
  • Service control policies: region restriction, root usage, public-access denial
  • Permission boundaries so delegated admin cannot escalate
  • IAM Identity Center federation — no long-lived keys
  • KMS key strategy with encryption enforced by policy
LAYER 02 — DETECTIVE

Catch what still gets through

  • GuardDuty across all accounts and regions, findings triaged by our team
  • Security Hub with a curated standard set — not every control switched on
  • AWS Config rules for drift on the controls that matter
  • CloudTrail organisation trail to immutable, separately-owned log storage
  • Amazon Inspector plus image scanning in the build pipeline
LAYER 03 — RESPONSIVE

Know what to do at 2am

  • Documented incident response plan mapped to your obligations
  • Tested containment playbooks — credential compromise, exposed bucket, crypto-mining
  • Forensics-ready logging and snapshot procedure
  • Notifiable Data Breach assessment path defined in advance
  • Post-incident reports written for engineers and executives
LAYER 04 — ASSURANCE

Prove it, repeatedly

  • Control mapping maintained against your chosen frameworks
  • Automated evidence collection with timestamps and scope
  • Quarterly control effectiveness review
  • Architecture diagrams kept current, not redrawn for each audit
  • Standard response pack for customer security questionnaires

Seacow provides security engineering and readiness services. We are not an IRAP assessor, a penetration testing firm or a certification body — formal certification is issued by accredited third parties, and we will introduce you to ones we trust.

Frameworks

The obligations Australian organisations actually face

FrameworkWho it applies toWhat we do
ACSC Essential EightCommonwealth entities and their suppliers; increasingly demanded in private-sector tendersMaturity assessment, uplift plan and AWS-native control mapping to Level 2 or 3
ISO/IEC 27001Anyone selling to enterprise or governmentAnnex A gap assessment, technical control implementation, evidence for certification audit
SOC 2 Type IISaaS platforms with North American customersTrust Services Criteria mapping, continuous evidence, auditor liaison
IRAPSystems handling Australian government dataReadiness preparation, control implementation and assessor support — the assessment itself is done by a registered assessor
APRA CPS 234 / CPS 230Regulated financial entities and their material service providersInformation security capability evidence, incident notification path, service provider documentation
Privacy Act & NDB schemeAlmost every organisation over $3M turnoverData flow mapping, retention policy, breach assessment procedure
PCI DSSAnyone touching cardholder dataScope reduction architecture, segmentation and evidence for the assessed environment

This table is a summary, not legal advice. Your obligations depend on your sector, turnover, contracts and the data you hold.

Evidence automation

The difference between passing an audit and surviving one

Most organisations can pass an audit by reconstructing evidence in the fortnight before it. That works exactly once, costs a fortnight of engineering time each year, and tells you nothing about whether the control was operating in month seven.

We automate collection so control operation is demonstrable at any point in time, timestamped and scoped. It turns audit prep from a project into a download.

  • Config conformance packs mapped to your framework of choice
  • Scheduled evidence snapshots to immutable storage with retention
  • Control owner and test frequency recorded against each item
  • Exceptions register with expiry dates, so temporary is actually temporary
seacow · evidence pack · e8-l2
# generating evidence pack: essential-eight L2 Patch applications Inspector + SSM 14d SLA met Patch OS SSM baselines 100% coverage MFA IdC + SCP deny 0 exceptions Restrict admin privs perm boundaries JIT only Backups AWS Backup restore tested 07-22 App control partial 2 legacy hosts Macro settings n/a — no desktops User app hardening n/a — no desktops pack: e8-2026-08.zip signed, 214 artefacts

Related case study

A SaaS platform went from informal controls to a signed evidence pack in ten weeks, then commenced IRAP assessment with no blocking findings.

Read the case study
Incident response

Rehearsed, not just documented

Prepare

Response plan mapped to your regulatory notification obligations, contact tree tested, forensic tooling pre-staged, and legal and communications contacts identified before you need them.

Detect & triage

Findings correlated and assessed by our team against your environment, so you receive an assessed incident rather than a raw alert feed to interpret yourselves.

Contain

Tested playbooks for the scenarios that actually happen: compromised credentials, exposed storage, crypto-mining, and third-party breach with blast radius into your estate.

Recover & report

Restoration from tested backups, root cause analysis, and a report that satisfies both your engineers and your board — plus control changes tracked to closure.

Resilience & disaster recovery

An untested DR plan is a document, not a capability

Almost every organisation we assess has a recovery plan. Far fewer have run it. The gap between the two is usually discovered on the worst possible day.

  • RTO and RPO agreed per workload with the business, not assumed by IT
  • Backup and cross-region strategy rebuilt to match the agreed targets
  • AWS Resilience Hub assessment and continuous drift detection
  • A live failover exercise with a written, timed result
  • Scheduled re-tests inside the managed service — annual, or semi-annual on Enterprise
Timed Every DR exercise produces a written result with the actual clock time against the agreed RTO — including the ones that miss. That document is yours, and it is what an assessor will ask for.

The most common finding

Backups that complete successfully and cannot be restored — because nobody has ever tried, or because the restore depends on a credential, network path or licence that only exists in the environment being recovered.

FAQ

Security questions

Can you get us ISO 27001 certified?

We can get you ready and support you through the audit, but we cannot certify you — certification is issued by an accredited certification body, and any provider claiming otherwise is misdescribing the process. We do the gap assessment, the technical implementation and the evidence, and we sit in the audit with you.

Do you do penetration testing?

No. We deliberately do not test our own configurations — an independent tester is worth more to you than a convenient one. We scope the engagement, introduce you to firms we trust, and remediate what they find.

How long does Essential Eight uplift take?

For a cloud-native estate with no desktop fleet in scope, Level 2 is typically eight to fourteen weeks. Four of the eight mitigation strategies are desktop oriented and often out of scope — which is exactly the kind of thing the assessment clarifies before you commit budget.

Will guardrails slow our developers down?

Badly designed ones will. We deploy preventive controls in report mode first, measure what they would have blocked, fix the false positives, and only then enforce. Anything that blocks a legitimate workflow more than occasionally gets redesigned rather than exception-listed.

Do you provide a SOC as a service?

We provide security operations for AWS estates we manage — triage, containment and response within that boundary. We are not a general-purpose managed detection and response provider for endpoints, email and corporate networks, and we will say so rather than stretch the definition.

Find the gaps before an assessor does

A gap assessment against Essential Eight, ISO 27001 or SOC 2 — fixed price from $14,000, with a prioritised remediation plan you own.