How a rapidly scaling Australian HR-technology SaaS business cut its egress and lateral-movement exposure, got full visibility of its critical networks, and became evidence-ready for customer audits — without customer-visible downtime.
AWS Network Firewall · Transit Gateway · infrastructure-as-code · ISM / Essential Eight mapping
An Australian HR-technology company whose recruitment and onboarding SaaS platform is used by large employers to hire and manage people at scale. That means holding candidate and employee data for organisations that take security assessments seriously: enterprise procurement teams and government buyers who send long questionnaires and expect evidence, not assurances.
The platform runs across multiple AWS accounts. The internal team is small and product-focused, with limited specialist depth in database and network security, and it was scaling faster than its operating practices.
Sector: HR-technology SaaS (recruitment and onboarding) · Customers: large employers, enterprise and government · Platform: multi-account AWS · Engagement: Jul – Oct 2025
Network patterns across the AWS accounts had grown organically. Logging, rulesets and change control were inconsistent, unrestricted egress and lateral pathways existed between workloads, and customer audits had started flagging the gaps. The business needed to strengthen lateral-movement resistance and egress control across the whole estate, and to be able to show it had — without taking the product down to do it.
We started with an architecture baseline and threat model, documented the non-functional requirements, and mapped the risks to the ISM and Essential Eight. Then we designed and implemented:
Questions that used to take days to answer now get an evidence pack.
Vendor-neutral by design, with cloud-native controls before any third-party tooling and the trade-offs written down rather than buried. Least-privilege access for our own staff, no secondary use of client data, and change approvals logged. Skills transfer through paired delivery and runbooks, so the client’s people run the result — the point is to reduce their future spend on us, not to create it. Right-sized resources, consolidated appliances and tuned log retention meant the bill went down along with the risk.
SaaS providers selling to enterprise and government get the same security questionnaire in slightly different clothes, over and over. Most of the questions have one honest answer: show me it’s designed, documented and logged. The businesses that struggle aren’t insecure — they have nothing they can point to. Architecture decision records, control mappings and audit trails are what turn a two-week scramble into a same-day reply.
Start with the free Obligations Check: one 30-minute conversation and a one-page read on what genuinely applies to your business. If a full assessment is the right next step, we’ll say so — and if it isn’t, we’ll say that too.