Skip to main content

Security and Governance

Security and governance that hold up under questioning

Most security programmes stall for two reasons. Findings arrive faster than anyone can act on them, and the people who could fix things were never told which items mattered. We start by establishing which exposures are real in your environment, remediate those in priority order, then build the identity controls, guardrails and evidence trails that keep the next assessment from becoming a two-week scramble. The work runs on Azure, on AWS or across both, using the entitlements you already hold before anything new is purchased.

Also called: Cloud security posture management (CSPM) · Identity and access management (IAM) · Essential Eight uplift and maturity assessment · Zero trust architecture · Security operations and SIEM · Privileged access management · Cyber security uplift

Choose your platform

Business outcomes

Close the ways in, know exactly who can do what, and answer an auditor or a client questionnaire from current evidence rather than memory.

What changes for the business, and how we agree to measure it before work starts.

A smaller attack surface
Exposed management ports, forgotten public endpoints, dormant accounts and unencrypted storage are closed in priority order rather than all at once. Progress is reported to the same audience each month, so the trend matters more than any single snapshot.Agreed measure: Count of critical and high findings still open past an age you agree with us before work starts.
Identity you can account for
Every administrator, service identity and third party ends up with a named owner, a written justification and an expiry date. The IT manager gets a recertification cycle that runs on a schedule instead of a spreadsheet somebody abandons in week three.Agreed measure: Number of standing privileged assignments, counted at handover and again at each monthly review.
Data that is not reachable from outside
Public object storage, anonymous sharing links and unencrypted data stores are closed and the encryption keys move under your control. This is the exposure half of the problem; classification, cataloguing and loss prevention are a separate discipline and we scope them as one.Agreed measure: Proportion of internet-reachable data stores with public access blocked and encryption under keys you hold.
One honest view of cloud posture
Security leaders stop reconciling four consoles and a spreadsheet. Posture, misconfiguration and vulnerability findings land in a single prioritised queue with a named owner per workload, so the monthly conversation is about what changed rather than what is true.Agreed measure: Whether every open finding has a named owner who accepts it, sampled at handover.
Assurance responses measured in hours
Control descriptions, configuration evidence and exception records are maintained as the environment changes instead of being reconstructed under deadline. We help you prepare for and align to frameworks such as the Essential Eight, ISO 27001 and SOC 2. We do not certify, audit or attest, and the assessor stays independent of us.Agreed measure: Elapsed time to answer a named client security questionnaire, baselined on the last one you completed unaided.
AI adoption with controls around it
Before an assistant reaches staff, we set the identity boundary it inherits, the data it may retrieve, the logging that records what it did and the point at which a person must approve an action. Executives get a written position on AI data handling they can put in front of a client.Agreed measure: Whether each AI system has a recorded data boundary, retrieval logging and a named human approval point, agreed before release.

Common client problems

What we usually hear first.

These are the sentences that start most engagements, and what we do about each one.

  • Nobody can tell me who actually has admin rights, and the last access review was a spreadsheet that someone gave up on halfway through.

    We inventory every privileged assignment across your tenants and accounts, including service identities, pipeline credentials and guest access, then attach an owner and a justification to each one. Standing access is replaced with time-bound elevation that requires an approval and leaves a record you can point at later. The uncomfortable part is usually the service identities: they have no manager to ask, and deciding whether one is still needed means reading logs rather than sending an email.

  • We bought the security tooling, it is switched on, and nobody looks at it.

    We turn the noise down first, suppressing findings that genuinely do not apply and routing what remains to the team that can fix it. Then we agree a short triage routine with severity thresholds and named owners, so a finding has a path to closure rather than a dashboard to sit on. If the honest answer is that nobody has capacity to act on detections, we would rather reduce the tooling than pretend a queue is a control.

  • I am fairly sure we have client data in places it should not be, but I cannot prove it either way.

    There are two questions inside that one and they need different work. Whether the data is reachable, unencrypted or shared with an anonymous link is a posture question we answer in the assessment. Whether it is correctly classified, catalogued and covered by loss prevention is a data governance programme with its own budget and its own business owners, and we scope it separately rather than pretend a posture scan is the same thing.

  • Every customer security questionnaire costs us two weeks and pulls three senior people off billable work.

    We build a control library that maps your real configuration to the questions buyers keep asking, with evidence references kept current as the environment changes. Most of the next questionnaire then becomes assembly rather than investigation, and the exceptions are already written down. What it will not do is make an unfavourable answer favourable: if a control is not there, the library says so.

  • Our developers have permanent production access because that is how it has always been done here.

    We separate the build path from the run path so changes reach production through a pipeline identity rather than a human one. Where people still need production access it becomes requested, time-boxed, approved and logged, with break-glass accounts documented and rehearsed. This one is cultural as much as technical: if requesting access is slower than the old habit, the old habit wins, so the request path has to be genuinely quick.

  • Staff have started pasting things into AI tools and I have no visibility of what is going where.

    We identify which AI services are in use, who is using them and which data classes are reaching them, then put a sanctioned and governed alternative in front of people so the unmanaged route stops being the easy one. Policy is paired with a technical control, because a policy on its own does not change behaviour. Blocking alone tends to move the activity onto personal devices where you cannot see it at all.

Capabilities

What this domain covers.

  • Identity and privileged access review
  • Joiner, mover and leaver automation
  • Conditional access and phishing-resistant authentication
  • Zero trust access design
  • Cloud security posture management
  • Threat detection engineering and triage
  • SIEM design, tuning and ingestion cost control
  • Landing zone guardrails and policy as code
  • Key, certificate and secrets management
  • Data exposure and encryption key control
  • Edge, WAF and denial-of-service protection
  • Endpoint, patching and device compliance
  • Essential Eight and ISO 27001 alignment
  • Audit and customer assurance readiness
  • AI security and responsible-AI controls

How we deliver

From assessment through to the day we are still operating it.

  1. 01

    Assessment and advisory

    We start with a fixed-scope review that produces a defensible picture of current exposure rather than a generic maturity chart. Every rating is tied to a specific piece of configuration evidence you can re-check yourself.

    • Privileged access inventory. Every privileged role holder, service identity, guest account and long-lived credential across all tenants, subscriptions, accounts and organizational units.
    • Essential Eight maturity rating. The environment assessed against the ASD Essential Eight maturity model and the control themes an ISO 27001 or SOC 2 assessor will raise, with the evidence behind each rating recorded so the gap list survives challenge.
    • Exposure mapped from outside in. Internet-reachable endpoints, exposed management ports, anonymous sharing links and public object storage listed with what each one can reach behind it.
    • Licence entitlement audit. Current entitlements and enabled service plans checked against the controls the design needs, so unused entitlement is separated from a genuine product gap before anyone proposes a purchase.
    • Remediation backlog by effort. Findings ordered by exposure reduction per unit of effort, with dependencies, residual risk and a named owner recorded against each item.
    • Measures agreed before delivery. The two or three numbers the programme will be judged on, chosen up front, for example critical findings open past 30 days or the count of standing privileged assignments.
  2. 02

    Architecture and implementation

    Controls are implemented as code and reviewed like code, so any guardrail can be traced to a commit, explained to an assessor and rolled back if it breaks a workload.

    • Boundaries that contain a compromise. Tenant, subscription, account and organizational unit structure designed so a compromised credential is contained by a boundary rather than by a naming convention someone has to maintain.
    • Access policy in report-only first. The sign-in policy set run in report-only mode with documented break-glass accounts that are monitored and tested, then enforced in waves ordered by user population.
    • Standing admin rights removed. Permanent administrative assignments replaced with time-bound, approval-gated elevation, and the request trail kept as evidence for later review.
    • Guardrails deployed as policy code. Preventative policy promoted through the same pipeline as infrastructure, peer reviewed, versioned and tested in a non-production scope before it reaches anything that matters.
    • Secrets out of repositories. Keys, certificates and application secrets centralised behind managed identities or roles, credentials stripped from pipeline variables, and rotation scheduled rather than aspirational.
    • Logging designed to a cost ceiling. Named sources, retention tiers and a monthly ceiling agreed at design time, so the detection you want is still affordable to run 12 months later.
  3. 03

    Governance, risk and assurance

    Governance earns its place when it makes decisions faster. We keep the artefacts small enough that people maintain them and specific enough that an external assessor can use them without a workshop. Data classification, cataloguing and loss prevention sit with our data governance and compliance work rather than here.

    • Control library mapped to clauses. Each implemented control mapped to the framework clauses it supports, with a configuration reference an assessor can verify independently rather than take on trust.
    • Exceptions with an owner and expiry. Every accepted risk carries an owner, an expiry date and a review trigger, because a temporary exception with no end date is how a control gets quietly switched off.
    • Identity lifecycle as the control. Joiner, mover and leaver events drive entitlement, so access changes with employment status rather than with a service desk ticket somebody has to remember to raise.
    • AI use register maintained. Which systems process which data classes, what a human must approve, and how prompts and responses are retained and reviewed.
    • Alignment, never certification. We prepare the environment and the evidence for external assessment. Certification, attestation and audit opinions are issued by an independent party, not by us, and we hold none of them ourselves.
    • One page to the executive monthly. Exposure trend, the top three risks, exceptions expiring, and the single decision the group actually needs to make.
  4. 04

    Adoption and enablement

    A control that people route around has made things worse, not better. We sequence rollouts so users have a working path before the old one closes, and we measure the friction rather than assume it away.

    • Piloted with one willing department. Each identity change trialled with a single team, the support tickets it generates counted, and the friction fixed before the organisation-wide wave.
    • Service desk trained before users. Elevation, enrolment and access request flows walked through on the real screens rather than a slide deck, with a one-page decision guide left behind.
    • Break-glass rehearsed with real people. Emergency access and a lost-device scenario tested with the staff who would genuinely be on the call, and the runbook updated from what the rehearsal exposed.
    • A sanctioned AI path. A published position naming the data classes staff must not put into unsanctioned tools, paired with a governed tool that does the job well enough to be chosen.
    • Findings handed to the owning team. Application owners given scoped access to their own posture findings with a short guide to which classes are mandatory, so remediation is not bottlenecked in one central team.
    • Monthly forum with a fixed agenda. New exceptions, expiring exceptions, overdue findings and one decision that needs the group in the room. Anything else is a status update, not governance.
  5. 05

    Managed security operations

    Security posture decays without maintenance, and the decay is invisible until something goes wrong. Our managed continuation keeps controls current, noise low and evidence collected, during agreed support hours and through an escalation path you have seen and approved in advance. We are not a round-the-clock monitoring service, and if that is what your risk profile requires we will say so.

    • Posture drift reported monthly. What changed, what regressed and what remains open past its agreed age, reported to the same audience each month so the trend is visible.
    • Alerts triaged to a named playbook. Triage against an agreed severity model, escalating through a playbook that names the person, the channel and the fallback contact.
    • Quarterly access recertification. Assignments nobody re-justifies are removed rather than rolled over, and the removals are recorded for the next assurance cycle.
    • Detection coverage reviewed quarterly. Coverage compared against the techniques relevant to your sector, then rules written or tuned to close the gaps we find.
    • Policy and detections in version control. Policy code, detection content and runbooks held in a repository, with every change tested in a non-production scope before promotion.
    • Log spend held to the ceiling. Ingestion and service cost reviewed monthly, with high-volume low-value sources re-tiered so spend stays inside the ceiling set at design time.

Questions we get asked

The things people ask before they commit.

Including the awkward ones. If the honest answer is that this is not right for you, that is the answer you will get.

  • What does cloud security consulting actually cost in Australia?

    The assessment is the part we can scope tightly, because its inputs are your tenant and account count rather than your ambition, and we quote it as a fixed fee. Remediation is the variable half, and it is variable because the backlog is unknown until we have looked. What we will not do is quote a remediation programme before the assessment, because the honest number depends on how much unpicking your identity estate needs. Expect the running cost of log ingestion and posture tooling to be a separate, ongoing line that grows with the estate.

  • Can we just do this in-house with the tools we already pay for?

    Often more of it than vendors would like you to think, and we will tell you when that is the case. If you have an engineer with genuine identity platform experience and the time to spend, the assessment plus a remediation backlog may be all you need from us. Where clients keep getting value from outside help is the sequencing and the arguments: which controls to enforce first, what to do when a control blocks a release, and having someone independent tell the executive that an accepted risk has expired.

  • How long does Essential Eight uplift take, and which maturity level should we target?

    For a mid-sized organisation, maturity level one across all eight strategies is usually a few months of focused work if patching and application control are already partly in place, and considerably longer if they are not. Level two is a step change rather than an increment, because it pushes into logging, monitoring and privileged access practices most organisations have not built. Pick the level your obligations or your largest customer actually require, not the highest one on the page, and be aware that application control is the strategy that most often stalls a programme.

  • Do you certify us against Essential Eight, ISO 27001 or SOC 2?

    No, and nobody should tell you they can do both halves. We assess against the framework, build the controls and maintain the evidence so an assessment is survivable. The assessment, the audit opinion and any certificate come from an independent party you engage separately, and keeping that separation is what makes the result worth having. Celestique holds no formal certification of its own, and we will not imply otherwise on a capability statement.

  • Is Azure or AWS more secure?

    Neither, and the question usually hides a different one about which platform your team can actually operate. Azure gives you more controls switched on by default and a policy engine that can repair configuration, at the cost of licensing complexity that is genuinely hard to reason about. AWS gives you harder isolation boundaries and a permission ceiling an account administrator cannot raise, at the cost of building more of the control set yourself. In practice, misconfiguration rather than platform capability is what causes exposure on both.

  • We already have a SIEM. Is replacing it worth the disruption?

    Frequently not, and it is worth being sceptical of anyone whose recommendation happens to match what they are best at deploying. Migrating a SIEM means rebuilding detections, retraining analysts and running two platforms during the transition, and the benefit has to be larger than that. The cases where it is genuinely worth it are where your log estate has already moved to one cloud, where the current licence model punishes the ingestion you need, or where nobody has maintained a detection in a year. We would rather tune what you have.

  • What happens when something goes wrong and you are the ones who built the controls?

    We work during agreed support hours through an escalation path you have reviewed before it is needed, and we do not promise a response time we cannot staff. If an incident needs specialist digital forensics or legal notification advice, that is a different capability and we will say so rather than improvise. Being direct about this before an engagement starts is deliberate: the worst version of this arrangement is a client who believes somebody is watching overnight when nobody is.

  • Where should we start if we can only fund one thing this year?

    Identity, almost always. Multi-factor authentication with no quiet exclusions, standing administrative access removed, and a leaver process that actually revokes access will close more real risk than any detection product you could buy with the same money. Detection is worth funding once somebody is resourced to act on it. Buying a SIEM before you have cleaned up privileged access is how organisations end up paying monthly to watch a problem they could have fixed once.

Related industries

  • Professional Services

    Governed enterprise search, document intelligence and secure copilots that respect matter confidentiality and conflict boundaries.

  • Healthcare and Community Services

    Administrative automation, policy search, workforce analytics and privacy uplift for healthcare and community providers, with clinical decisions left entirely to clinicians.

  • Construction and Property

    Tender intelligence, addenda tracking and project reporting that keep estimators and contract administrators ahead of the documents instead of buried in them.

Related services

  • Landing Zone and Platform Foundations

    The account structure, identity, network and policy baseline that every future workload inherits, deployed from code rather than assembled by hand.

  • Data Governance and Compliance

    Discovery, classification, access control and audit evidence over the data you already hold, designed against the obligations that actually apply to you.

  • Platform Engineering and Infrastructure as Code

    Deployments that repeat exactly, carry their own evidence and can be rebuilt from source, so releasing to production stops being an event.

  • Managed Services

    Your platform keeps earning its business case after go-live, with cost, security posture, reliability and adoption reviewed on an agreed cycle rather than left to drift.

Free discovery workshop

Start with a security and governance discovery workshop.

Bring one challenge in this area. We will map the opportunity, the readiness gaps and a recommended next step.