How a Brisbane MedTech SaaS company replaced ad-hoc incidents, inconsistent patching and scramble-for-evidence audits with a repeatable operating cadence its own team now runs.
Service catalogue and SLAs · identity lifecycle · patch and vulnerability cycles · tested restores
A Brisbane-based MedTech startup building a cloud-native SaaS product on AWS. A small, technically strong team with real product momentum, selling into health-sector customers who ask pointed questions about how patient and clinical data is handled. Growing fast, cloud-reliant for everything, and heading towards ISO 27001-aligned assurance because their buyers will eventually demand it.
Like most companies at this stage, security lived in the heads of a few people rather than in documented, repeatable practice — and there was no one whose job it was to own it.
Sector: MedTech SaaS · Location: Brisbane · Stage: early-stage, scaling · Platform: AWS, Microsoft 365 · Engagement: Oct 2024 – ongoing
Incidents and requests were handled ad hoc. Patching, backup and the access lifecycle were inconsistent, and the evidence customers asked for in audits was hard to assemble. The company needed a repeatable operations model that balanced speed, cost and assurance — one a small team could actually sustain.
We designed the operating model and then embedded the security hygiene into it:
The model is run by the client’s own team, which is the only version of an operating model that lasts.
Privacy by design in logs and diagnostics, explicit consent for access, clear separation of duties, and transparent reporting — failures and risks surfaced, discussed and owned, not hidden. On-call guardrails protected staff wellbeing; automation removed low-value toil. Vendor-neutral by design, with cloud-native controls before any third-party tooling and the trade-offs written down rather than buried. Least-privilege access for our own staff, no secondary use of client data, and change approvals logged. Skills transfer through paired delivery and runbooks, so the client’s people run the result — the point is to reduce their future spend on us, not to create it.
Auditors and enterprise customers ask the same things: who has access, when was it last reviewed, when did you last patch, when did you last restore a backup. A business with an operating cadence answers from its records. A business without one answers from memory, and memory does not pass audits.
Related: the same company’s vCISO engagement and AWS landing zone
Start with the free Obligations Check: one 30-minute conversation and a one-page read on what genuinely applies to your business. If a full assessment is the right next step, we’ll say so — and if it isn’t, we’ll say that too.