Home/Services/Security & Compliance
Service 04 — Security & ComplianceGuardrails, not gates.
Preventive controls that stop the mistake, detective controls that catch what slips through, and the evidence trail your auditor will ask for — produced continuously rather than reconstructed the week before an audit.
Four layers, each doing a different job
Most estates we inherit are strong on detection and weak on prevention — which means the security team spends its week triaging findings that a service control policy should have made impossible.
Make the mistake impossible
- AWS Control Tower landing zone with account factory
- Service control policies: region restriction, root usage, public-access denial
- Permission boundaries so delegated admin cannot escalate
- IAM Identity Center federation — no long-lived keys
- KMS key strategy with encryption enforced by policy
Catch what still gets through
- GuardDuty across all accounts and regions, findings triaged by our team
- Security Hub with a curated standard set — not every control switched on
- AWS Config rules for drift on the controls that matter
- CloudTrail organisation trail to immutable, separately-owned log storage
- Amazon Inspector plus image scanning in the build pipeline
Know what to do at 2am
- Documented incident response plan mapped to your obligations
- Tested containment playbooks — credential compromise, exposed bucket, crypto-mining
- Forensics-ready logging and snapshot procedure
- Notifiable Data Breach assessment path defined in advance
- Post-incident reports written for engineers and executives
Prove it, repeatedly
- Control mapping maintained against your chosen frameworks
- Automated evidence collection with timestamps and scope
- Quarterly control effectiveness review
- Architecture diagrams kept current, not redrawn for each audit
- Standard response pack for customer security questionnaires
Seacow provides security engineering and readiness services. We are not an IRAP assessor, a penetration testing firm or a certification body — formal certification is issued by accredited third parties, and we will introduce you to ones we trust.
The obligations Australian organisations actually face
| Framework | Who it applies to | What we do |
|---|---|---|
| ACSC Essential Eight | Commonwealth entities and their suppliers; increasingly demanded in private-sector tenders | Maturity assessment, uplift plan and AWS-native control mapping to Level 2 or 3 |
| ISO/IEC 27001 | Anyone selling to enterprise or government | Annex A gap assessment, technical control implementation, evidence for certification audit |
| SOC 2 Type II | SaaS platforms with North American customers | Trust Services Criteria mapping, continuous evidence, auditor liaison |
| IRAP | Systems handling Australian government data | Readiness preparation, control implementation and assessor support — the assessment itself is done by a registered assessor |
| APRA CPS 234 / CPS 230 | Regulated financial entities and their material service providers | Information security capability evidence, incident notification path, service provider documentation |
| Privacy Act & NDB scheme | Almost every organisation over $3M turnover | Data flow mapping, retention policy, breach assessment procedure |
| PCI DSS | Anyone touching cardholder data | Scope reduction architecture, segmentation and evidence for the assessed environment |
This table is a summary, not legal advice. Your obligations depend on your sector, turnover, contracts and the data you hold.
The difference between passing an audit and surviving one
Most organisations can pass an audit by reconstructing evidence in the fortnight before it. That works exactly once, costs a fortnight of engineering time each year, and tells you nothing about whether the control was operating in month seven.
We automate collection so control operation is demonstrable at any point in time, timestamped and scoped. It turns audit prep from a project into a download.
- Config conformance packs mapped to your framework of choice
- Scheduled evidence snapshots to immutable storage with retention
- Control owner and test frequency recorded against each item
- Exceptions register with expiry dates, so temporary is actually temporary
Related case study
A SaaS platform went from informal controls to a signed evidence pack in ten weeks, then commenced IRAP assessment with no blocking findings.
Read the case studyRehearsed, not just documented
Prepare
Response plan mapped to your regulatory notification obligations, contact tree tested, forensic tooling pre-staged, and legal and communications contacts identified before you need them.
Detect & triage
Findings correlated and assessed by our team against your environment, so you receive an assessed incident rather than a raw alert feed to interpret yourselves.
Contain
Tested playbooks for the scenarios that actually happen: compromised credentials, exposed storage, crypto-mining, and third-party breach with blast radius into your estate.
Recover & report
Restoration from tested backups, root cause analysis, and a report that satisfies both your engineers and your board — plus control changes tracked to closure.
An untested DR plan is a document, not a capability
Almost every organisation we assess has a recovery plan. Far fewer have run it. The gap between the two is usually discovered on the worst possible day.
- RTO and RPO agreed per workload with the business, not assumed by IT
- Backup and cross-region strategy rebuilt to match the agreed targets
- AWS Resilience Hub assessment and continuous drift detection
- A live failover exercise with a written, timed result
- Scheduled re-tests inside the managed service — annual, or semi-annual on Enterprise
The most common finding
Backups that complete successfully and cannot be restored — because nobody has ever tried, or because the restore depends on a credential, network path or licence that only exists in the environment being recovered.
Security questions
Can you get us ISO 27001 certified?
We can get you ready and support you through the audit, but we cannot certify you — certification is issued by an accredited certification body, and any provider claiming otherwise is misdescribing the process. We do the gap assessment, the technical implementation and the evidence, and we sit in the audit with you.
Do you do penetration testing?
No. We deliberately do not test our own configurations — an independent tester is worth more to you than a convenient one. We scope the engagement, introduce you to firms we trust, and remediate what they find.
How long does Essential Eight uplift take?
For a cloud-native estate with no desktop fleet in scope, Level 2 is typically eight to fourteen weeks. Four of the eight mitigation strategies are desktop oriented and often out of scope — which is exactly the kind of thing the assessment clarifies before you commit budget.
Will guardrails slow our developers down?
Badly designed ones will. We deploy preventive controls in report mode first, measure what they would have blocked, fix the false positives, and only then enforce. Anything that blocks a legitimate workflow more than occasionally gets redesigned rather than exception-listed.
Do you provide a SOC as a service?
We provide security operations for AWS estates we manage — triage, containment and response within that boundary. We are not a general-purpose managed detection and response provider for endpoints, email and corporate networks, and we will say so rather than stretch the definition.
Find the gaps before an assessor does
A gap assessment against Essential Eight, ISO 27001 or SOC 2 — fixed price from $14,000, with a prioritised remediation plan you own.