// case study · cloud network security

Network segmentation and egress control across a multi-account AWS estate

How a rapidly scaling Australian HR-technology SaaS business cut its egress and lateral-movement exposure, got full visibility of its critical networks, and became evidence-ready for customer audits — without customer-visible downtime.

AWS Network Firewall  ·  Transit Gateway  ·  infrastructure-as-code  ·  ISM / Essential Eight mapping

// the business

A recruitment platform trusted with other people’s candidates

An Australian HR-technology company whose recruitment and onboarding SaaS platform is used by large employers to hire and manage people at scale. That means holding candidate and employee data for organisations that take security assessments seriously: enterprise procurement teams and government buyers who send long questionnaires and expect evidence, not assurances.

The platform runs across multiple AWS accounts. The internal team is small and product-focused, with limited specialist depth in database and network security, and it was scaling faster than its operating practices.

Sector: HR-technology SaaS (recruitment and onboarding)  ·  Customers: large employers, enterprise and government  ·  Platform: multi-account AWS  ·  Engagement: Jul – Oct 2025

// the situation

Growth had outrun the network, and audits had noticed

Network patterns across the AWS accounts had grown organically. Logging, rulesets and change control were inconsistent, unrestricted egress and lateral pathways existed between workloads, and customer audits had started flagging the gaps. The business needed to strengthen lateral-movement resistance and egress control across the whole estate, and to be able to show it had — without taking the product down to do it.

// what we did

Baseline, threat model, target state, then a staged cutover

We started with an architecture baseline and threat model, documented the non-functional requirements, and mapped the risks to the ISM and Essential Eight. Then we designed and implemented:

  • a Transit Gateway hub-and-spoke network with centralised egress, a shared-services VPC and AWS Network Firewall at the boundaries that matter
  • a rule-group strategy (stateless and stateful, domain lists, TLS-inspection scope), logging and alerting to a central SIEM, and change governance with architecture decision records
  • infrastructure-as-code for VPCs, routing, firewall policies, logs and metric alarms; pre-prod and prod environments with CI/CD checks
  • runbooks for rule lifecycle, break-glass and incident triage; engineer training; a tuning backlog
  • a staged migration with rollback plans, freeze windows and stakeholder communications
// outcome

Smaller attack surface, full visibility, and evidence customers can see

  • unrestricted egress and lateral pathways reduced; baseline misconfigurations dropped to tolerable residual risk with documented exceptions
  • complete flow and log visibility for critical VPCs; incidents triaged faster with actionable alerts
  • audit readiness improved — control mappings, decision records and change records are evidence-ready, cutting time to respond to customer assessments
  • performance and availability met requirements, with no customer-visible downtime during cutover

Questions that used to take days to answer now get an evidence pack.

// how we worked

Independent, evidence-led, and built to hand over

Vendor-neutral by design, with cloud-native controls before any third-party tooling and the trade-offs written down rather than buried. Least-privilege access for our own staff, no secondary use of client data, and change approvals logged. Skills transfer through paired delivery and runbooks, so the client’s people run the result — the point is to reduce their future spend on us, not to create it. Right-sized resources, consolidated appliances and tuned log retention meant the bill went down along with the risk.

// why it matters

The questionnaire is only hard when nothing is written down

SaaS providers selling to enterprise and government get the same security questionnaire in slightly different clothes, over and over. Most of the questions have one honest answer: show me it’s designed, documented and logged. The businesses that struggle aren’t insecure — they have nothing they can point to. Architecture decision records, control mappings and audit trails are what turn a two-week scramble into a same-day reply.

// next step

Not sure which obligations actually bind you?

Start with the free Obligations Check: one 30-minute conversation and a one-page read on what genuinely applies to your business. If a full assessment is the right next step, we’ll say so — and if it isn’t, we’ll say that too.