The Australian frame you design against
The Privacy Act and the Australian Privacy Principles govern collection, use, storage and disclosure of personal information, and apply to many businesses that never saw themselves as handling sensitive data. The Notifiable Data Breaches scheme adds an assessment duty where an incident is likely to cause serious harm. Alongside it: larger customers send questionnaires asking how access is revoked, whether production data is used in testing, and where data resides.
Access control modelled on real job functions
Roles named after chart entries — Manager, Admin, User — do not match what people do, so everyone ends up with the most permissive role that lets them finish. Model permissions on functions instead: raise an order, approve to a value limit, view payroll for a cost centre, export a report containing personal information.
Access must be revocable the day someone changes role, which means it derives from a source of truth, and reviewable.
Audit trails that answer questions
An audit log is not a debugging console. Its job is to answer, months later, who changed a record, what it was before and under what authority — which means storing the previous value and retaining records for years, in storage the application role cannot overwrite.
Secrets, dependencies and patching
Credentials belong in a secrets manager with rotation, never in configuration files or history — and scan history before go-live, because deleting a secret from the tree does not remove it from history. Dependencies are the other half: libraries carry vulnerabilities on a predictable schedule, so scanning runs in CI with a policy for high-severity findings and a named owner. That ownership is much of what a maintenance and support engagement buys.
A backup you have never restored is a hypothesis, not a control.
Backups you have actually restored
The control is the restore: performed on a schedule, timed and reconciled. Untested restores fail for mundane reasons — a key held elsewhere, a permission changed during migration, a procedure that depended on someone who has left. Recovery and breach response are one capability, as argued in uptime definitions.
Least-privilege access to production
Production access should be exceptional, time-bound and logged. Where production data is needed to investigate, a sanitised extract is usually right, and test environments should never hold unmasked personal information. The risk is not malice; it is the wrong environment selected in a terminal.
Secure development practice
- Threat modelling at design time. An hour on what an attacker wants and where trust boundaries sit catches what no scanner will find.
- Code review by a second engineer, with authentication, authorisation and export given real attention.
- Automated scanning in CI.
SASTand dependency scanning on every build, triaged rather than accumulated. - Secure defaults in the framework — parameterised queries, output encoding, CSRF protection.
Data residency
Stating precisely where data is stored, processed, backed up and logged is now routine in Australian procurement, including for derived artefacts such as extracted text — the same constraint discussed in AI readiness.
Why bolt-on security fails
Security added in the weeks before launch is constrained by decisions already made. If the data model has no notion of scope, per-cost-centre access becomes a filter bolted onto every query; if the application never recorded who changed what, audit becomes reconstruction.
The evidence work in the compliance reporting automation case was straightforward because the model was designed with those controls in mind. We take the same approach in custom software development, and treat access, audit and recovery as remediation priorities on inherited platforms, particularly where a modernisation programme is already touching the core.
Pre-launch checklist
- Roles defined against job functions, with a scheduled access review.
- Audit trail covering create, update, delete, export and sign-in, storing previous values.
- Secrets in a managed store, rotated, with history scanned.
- Dependency and static analysis in CI, with a triage owner.
- Restore performed end to end, timed and reconciled.
Designing a system, or inheriting one?
We will review the access model, audit trail, secrets handling and restore capability, and say what needs fixing before launch.