// case study · vciso and managed security

Standing up a security function for a fast-growing MedTech startup

How a Brisbane MedTech SaaS company went from inconsistent policies and ad-hoc incident response to board-level governance, hardened cloud controls and customer security reviews passed with no major findings.

vCISO  ·  ISO 27001-aligned ISMS  ·  AWS guardrails  ·  incident response

// the business

A MedTech product with momentum, and nobody owning security

A Brisbane-based MedTech startup building a cloud-native SaaS product on AWS. A small, technically strong team with real product momentum, selling into health-sector customers who ask pointed questions about how patient and clinical data is handled. Growing fast, cloud-reliant for everything, and heading towards ISO 27001-aligned assurance because their buyers will eventually demand it.

Like most companies at this stage, security lived in the heads of a few people rather than in documented, repeatable practice — and there was no one whose job it was to own it.

Sector: MedTech SaaS  ·  Location: Brisbane  ·  Stage: early-stage, scaling  ·  Platform: AWS, Microsoft 365  ·  Engagement: Oct 2024 – ongoing

// the situation

The board wanted a vCISO, not another tool

Policies were inconsistent, incident response was ad hoc, and cloud controls varied from account to account. The board asked for a partner to act as vCISO and operational lead: uplift governance, reduce risk, and meet the security expectations of the customers doing due diligence on them.

// what we did

Governance first, then the controls to back it

We took the vCISO role and built the function around it:

  • established the vCISO function: risk register, policy suite, key risk indicators and quarterly board reporting
  • built an ISO 27001-aligned security management system — asset inventory, statement of applicability, risk treatment plans
  • implemented cloud security improvements: AWS Organizations guardrails, IAM least-privilege patterns, AWS Network Firewall where it earned its place, centralised logging and monitoring, backup and DR runbooks
  • defined incident response playbooks and ran tabletop exercises
  • instituted vendor-risk and change-management gates; integrated service-desk workflows and SLAs
  • delivered staff security awareness training and phishing simulations
// outcome

Customer reviews passed, risk owned by the board, evidence on hand

  • multiple customer security reviews passed with no major findings
  • critical misconfigurations from the baseline scans reduced to board-accepted residual risk with documented treatment plans
  • faster security operations: standard change windows and incident triage with a clear RACI improved time to resolve
  • a predictable governance cadence — quarterly board packs and an audit-ready evidence library

The business gained a security function at exactly the stage where security usually becomes fragmented or reactive.

// how we worked

Independent, evidence-led, and built to hand over

Transparent prioritisation by business risk, not tool preference. We declined optional scope where the cost outweighed the risk reduction and documented why. Vendor-neutral by design, with cloud-native controls before any third-party tooling and the trade-offs written down rather than buried. Least-privilege access for our own staff, no secondary use of client data, and change approvals logged. Skills transfer through paired delivery and runbooks, so the client’s people run the result — the point is to reduce their future spend on us, not to create it.

// why it matters

Early-stage companies do not need more tools. They need an owner.

Startups and scale-ups usually have capable technical people and strong product momentum, but no one whose job is security: cloud tools with weak governance, admin access managed informally, no operating rhythm, and compliance ambitions without the structure to support them. A vCISO who also runs the operational uplift closes that gap without a full-time hire.

// next step

Not sure which obligations actually bind you?

Start with the free Obligations Check: one 30-minute conversation and a one-page read on what genuinely applies to your business. If a full assessment is the right next step, we’ll say so — and if it isn’t, we’ll say that too.