// case study · cloud architecture

An AWS landing zone with guardrails for a cloud-native MedTech product

How a Brisbane MedTech startup replaced organically grown AWS accounts with a multi-account landing zone, single sign-on, central logging and tested restores — so engineers could ship faster with fewer defects and consistent controls.

AWS Organizations  ·  SSO and least privilege  ·  central logging  ·  infrastructure-as-code

// the business

A product outgrowing the accounts it was built in

A Brisbane-based MedTech startup building a cloud-native SaaS product on AWS. A small, technically strong team with real product momentum, selling into health-sector customers who ask pointed questions about how patient and clinical data is handled. Growing fast, cloud-reliant for everything, and heading towards ISO 27001-aligned assurance because their buyers will eventually demand it.

Like most companies at this stage, security lived in the heads of a few people rather than in documented, repeatable practice — and there was no one whose job it was to own it.

Sector: MedTech SaaS  ·  Location: Brisbane  ·  Stage: early-stage, scaling  ·  Platform: AWS, Microsoft 365  ·  Engagement: Oct 2024 – Dec 2025

// the situation

Growth needed guardrails, not gatekeepers

The business needed a scalable AWS landing zone with clear guardrails, stronger identity and access, centralised logging and monitoring, and resilience patterns that could keep pace with product growth — without slowing the engineers down. Environments were being provisioned by hand, controls varied between accounts, and recovery had never been tested.

// what we did

Make the secure path the default path

We designed and built the platform so that doing it right was the easy option:

  • a multi-account strategy (Organizations and OUs), baseline security services (GuardDuty, Config, Security Hub) and an account-vending workflow
  • identity patterns: SSO, role-based access, break-glass and automated least-privilege baselines
  • observability: centralised CloudTrail and application logs, alarms and dashboards; recovery objectives and backup standards
  • reference architectures for container and serverless workloads with encryption, secrets management and network segmentation
  • infrastructure-as-code modules for common components; pipeline gates (policy checks, unit tests) and architecture decision records for traceability
  • workshops and training for engineers; change and incident processes aligned to the new architecture
// outcome

Faster, safer delivery with consistent controls

  • faster, safer environment provisioning; consistent controls across accounts and workloads
  • reduced identity risk through SSO and least-privilege roles; improved detection and response via central logging and alerting
  • a clear resilience posture with tested restore runbooks and recovery objectives
  • engineering teams delivering new services on reusable patterns, cutting cycle time and defects

Securitribe retained no standing access after handover. The platform is theirs.

// how we worked

Independent, evidence-led, and built to hand over

Transparent cost and benefit on every option, no reseller incentives, and documented privacy boundaries and approval workflows for any diagnostic data. Right-sized defaults, autoscaling, scheduled non-production shutdowns and lifecycle policies kept the bill honest. Vendor-neutral by design, with cloud-native controls before any third-party tooling and the trade-offs written down rather than buried. Least-privilege access for our own staff, no secondary use of client data, and change approvals logged. Skills transfer through paired delivery and runbooks, so the client’s people run the result — the point is to reduce their future spend on us, not to create it.

// why it matters

Guardrails are cheaper than remediation

Cloud-native businesses rarely fail an audit because a control is missing; they fail because nobody can show it operating consistently across every account. A landing zone makes consistency structural. It is also what lets a small team answer ‘how do you control access to production?’ with a diagram and a log instead of a conversation.

// next step

Not sure which obligations actually bind you?

Start with the free Obligations Check: one 30-minute conversation and a one-page read on what genuinely applies to your business. If a full assessment is the right next step, we’ll say so — and if it isn’t, we’ll say that too.