Infrastructure and Cloud Security
Secure the infrastructure your organisation runs on — cloud, on-premises and everything in between.
Most infrastructure estates were never designed, they accumulated over time. A decade of projects, migrations and acquisitions leaves a hybrid of cloud platforms, on-premises systems and network paths that nobody holds a complete picture of, secured by controls that made sense for an estate that no longer exists.
The risk concentrates in the gaps: the unmanaged asset, the forgotten firewall rule, the flat network a single compromised device can cross. Avocado runs a deliberate sequence across cloud and on-premises estates to discover what actually exists, assess how well it is secured, then design the target state. It is then delivered by architects who have designed, built and automated infrastructure for regulated Australian enterprises for more than 20 years.
You'll recognise the situation
Nobody in your organisation holds a complete picture of the estate — a decade of projects, migrations and acquisitions has left a hybrid of cloud, on-premises, and network paths that accumulated rather than got designed.
Risk concentrates in gaps: the unmanaged asset, the forgotten firewall rule, the flat network a single compromised device can cross.
You're an eligible critical infrastructure entity that needs network segregation as an explicit, evidenced obligation under the enhanced CIRMP Rules.
You want a deliberate discover-assess-design sequence, not another point solution bought for an estate nobody has mapped.
Four capabilities, run as one sequence
Discovery
Map your estate — assets, topology, dependencies and the systems nobody remembers owning.
Cloud Security Assessment
Assess your cloud security posture and architecture across AWS, Azure and Google Cloud.
On-prem Security Assessment
Assess the security of your data centre, network and on-premises platforms.
Design and Architect
Design the secure target state — segmentation, hardening and controlled paths — that your teams can build and run.
How each capability works
Discovery
Every assessment and every design decision are only as good as the picture of the estate underneath it. In most organisations that picture is years out of date. We build it from evidence, not interviews alone: discovering what is actually on the network, how it actually connects, and what actually depends on what.
- Asset discovery and inventory across cloud, on-premises and network estates, including unmanaged assets, shadow IT and end-of-life systems.
- Network topology and dependency mapping — how systems actually connect, and what breaks what.
- Current-state findings report and estate baseline, feeding directly into assessment and design work.
Cloud Security Assessment
Cloud security failures are rarely sophisticated — they are architecture and identity decisions made quickly during migration and never revisited. We assess your cloud posture as architects, not auditors: not just whether a setting deviates from a benchmark, but whether the design it belongs to can be defended.
- Cloud architecture and landing zone review — account and subscription structure, guardrails, and workload isolation.
- Cloud identity and access review — privileged roles, service identities, federation and conditional access design.
- Network design review — exposure of services, private connectivity, and traffic control between environments.
- Data protection review — encryption, key management and storage exposure.
- Logging, monitoring and alerting coverage — whether you would see an attack in progress.
- Multi-cloud and hybrid posture review, with findings prioritised by exploitability and business impact.
On-prem Security Assessment
On-premises infrastructure carries the systems too critical or too old to move which makes it both the most important part of many estates and the least recently examined. We assess it with people who have run it: data centre, network, virtualisation and platform practitioners. Where an obligation applies, such as the network segregation requirements the Enhanced CIRMP Rules impose on eligible critical infrastructure entities, we assess against it explicitly.
- Network security assessment — segmentation and zoning, firewall rulebase review, and east-west traffic control.
- Remote access and perimeter review — VPN, vendor access and the paths in from outside.
- Server, virtualisation and storage platform security review.
- Backup and recovery infrastructure security — whether backups would survive the incident they exist for.
- Legacy and end-of-life system risk assessment, with compensating control recommendations.
- Findings consolidated with your cloud assessment into a single prioritised remediation view.
Design and Architect
Our architects are SABSA-certified and design to a method, so every control in the target state traces to a business risk rather than a product preference. Because Avocado's DNA is building and automating infrastructure, we design what can actually be built — patterns your engineers can implement, automate and operate. We stay accountable through delivery; the design is done when it is running, not when it is presented.
- Security architecture and target-state design using the SABSA methodology, traced to business risk.
- Network segmentation and zoning design, including segregation obligations where they apply.
- Zero trust network architecture: identity-aware access, least privilege paths and controlled lateral movement.
- Secure cloud platform and landing zone design across AWS, Azure and Google Cloud.
- Secure remote access and hybrid connectivity design, and platform hardening standards your teams can automate and reuse.
- Design assurance and implementation support through to a running target state.
Discover, assess, design — in that order
Discover
Map the estate: assets, topology, dependencies and the systems nobody remembers owning.
Assess
Assess cloud and on-premises security posture against recognised frameworks and baselines, prioritised by real-world risk.
Design
Design the secure target state: segmentation, hardening and controlled paths — using the SABSA methodology, traced to business risk.
Our architects are practitioners who have designed, built and automated infrastructure for regulated Australian enterprises for more than 20 years, so the target state we design is one your engineers can actually build and operate, not a diagram that dies in a drawer.
Book a discovery with our cyber team
Tell us what your estate looks like — or what you suspect it looks like — and we'll tell you where to start.
Benchmarked, not opinion-based
AWS, Azure and Google Cloud for cloud security assessment and landing zone design; the SABSA methodology for security architecture; zero trust network architecture principles for segmentation and access design. Assessments are benchmarked against recognised frameworks and baselines rather than consultant opinion, delivered by SABSA-certified architects alongside practitioners certified across CISM, CRISC and CISA.
What you walk away with
Hospitality Industry — Cybersecurity Uplift
Not sure whether you need discovery, assessment or design first? Talk to us about where your estate stands. Contact us for a tailored quote.
Common questions
Do we need to start with discovery, or can we go straight to assessment?
It depends how current your picture of the estate is. If it's more than a year or two old, discovery first ensures the assessment and design that follow are based on what actually exists, not what you think exists.
Does this cover multi-cloud environments?
Yes — cloud security assessment and design cover AWS, Azure and Google Cloud, individually or as a multi-cloud and hybrid posture review.
What's the difference between assessment and design services?
Assessment tells you where your current infrastructure stands against recognised benchmarks. Design and Architect builds the secure target state your teams can continue to build and operate. The two are often engaged together but are separate deliverables.
Does network segregation apply to our organisation?
Network segregation is an explicit obligation for eligible critical infrastructure entities under the enhanced CIRMP Rules. Outside that scope it remains strong practice. Talk to us about whether the obligation applies to you specifically.
Can you assess legacy on-premises systems we can't yet retire?
Yes — legacy and end-of-life system risk assessment includes compensating control recommendations for systems that can't be modernised immediately.
Where teams go next
Security Testing and Assurance
Want your infrastructure independently tested, not just assessed?Workforce Access Governance
Need identity and access controls designed in too?Cyber Strategy and Architecture
Want ongoing architecture leadership, not a one-off engagement?Build on infrastructure you can defend
Talk to our infrastructure security specialists about discovering, assessing and designing an estate you can stand behind.