// case study · security operations

An operations model that keeps a MedTech platform audit-ready

How a Brisbane MedTech SaaS company replaced ad-hoc incidents, inconsistent patching and scramble-for-evidence audits with a repeatable operating cadence its own team now runs.

Service catalogue and SLAs  ·  identity lifecycle  ·  patch and vulnerability cycles  ·  tested restores

// the business

Growth had outpaced operations

A Brisbane-based MedTech startup building a cloud-native SaaS product on AWS. A small, technically strong team with real product momentum, selling into health-sector customers who ask pointed questions about how patient and clinical data is handled. Growing fast, cloud-reliant for everything, and heading towards ISO 27001-aligned assurance because their buyers will eventually demand it.

Like most companies at this stage, security lived in the heads of a few people rather than in documented, repeatable practice — and there was no one whose job it was to own it.

Sector: MedTech SaaS  ·  Location: Brisbane  ·  Stage: early-stage, scaling  ·  Platform: AWS, Microsoft 365  ·  Engagement: Oct 2024 – ongoing

// the situation

Every incident was handled from scratch

Incidents and requests were handled ad hoc. Patching, backup and the access lifecycle were inconsistent, and the evidence customers asked for in audits was hard to assemble. The company needed a repeatable operations model that balanced speed, cost and assurance — one a small team could actually sustain.

// what we did

A catalogue, a cadence, and the hygiene underneath

We designed the operating model and then embedded the security hygiene into it:

  • service model and governance: a service catalogue and RACI, SLAs and OLAs, dashboards and a weekly cadence for incident, change and problem management
  • service desk: triage workflows, queues and escalation paths; knowledge articles and a known-error database; request templates for common changes
  • observability: centralised logs and metrics, alert thresholds and routing; runbooks for triage, containment and rollback; post-incident reviews with tracked actions
  • secure operations: joiner-mover-leaver identity lifecycle, MFA and key rotation, least-privilege roles; patch cycles and vulnerability management integrated with change windows; immutable backups with restore tests
  • resilience: documented recovery objectives, exercised restore and failover scenarios, evidence recorded
  • enablement: paired delivery with the client’s engineers, on-call with equitable rostering and fatigue rules, training in runbooks and communications
// outcome

Predictable support, stronger hygiene, evidence as a by-product

  • predictable support: tickets flow through standard queues with visible SLAs; incidents triaged quickly and communicated consistently
  • stronger security hygiene: identity lifecycle, patching, vulnerability management and backup tests create clear audit trails and reduce risk
  • faster delivery: standard change patterns and templated requests cut lead time for routine work
  • better reliability: monitoring and playbooks reduced repeat incidents; service owners have clear KPIs
  • costs stabilised through right-sizing, lifecycle policies and environment scheduling

The model is run by the client’s own team, which is the only version of an operating model that lasts.

// how we worked

Independent, evidence-led, and built to hand over

Privacy by design in logs and diagnostics, explicit consent for access, clear separation of duties, and transparent reporting — failures and risks surfaced, discussed and owned, not hidden. On-call guardrails protected staff wellbeing; automation removed low-value toil. Vendor-neutral by design, with cloud-native controls before any third-party tooling and the trade-offs written down rather than buried. Least-privilege access for our own staff, no secondary use of client data, and change approvals logged. Skills transfer through paired delivery and runbooks, so the client’s people run the result — the point is to reduce their future spend on us, not to create it.

// why it matters

Evidence is a by-product of good operations, or it is a scramble

Auditors and enterprise customers ask the same things: who has access, when was it last reviewed, when did you last patch, when did you last restore a backup. A business with an operating cadence answers from its records. A business without one answers from memory, and memory does not pass audits.

// next step

Not sure which obligations actually bind you?

Start with the free Obligations Check: one 30-minute conversation and a one-page read on what genuinely applies to your business. If a full assessment is the right next step, we’ll say so — and if it isn’t, we’ll say that too.