emPOWER Security

Summary

emPOWER Security is blueAPACHE's integrated security operating model. Rather than a single product, it is four pillars run together, each answering a different question, with reporting that feeds compliance evidence.

The design premise is that security failures rarely have one cause. An incident usually involves a person who was targeted, a weakness that was already known, a detection that did or did not fire, and a governance process that either produced evidence or did not. Running those four capabilities separately, under different providers, is what creates the gaps between them.

The four pillars

Pillar Question it answers Service
Detect & Respond What is happening now, and how do we contain it? Managed Detection and Response
Human Risk Who is being targeted, and how do they behave? Human Risk Management
Threat Exposure Where are we weak, and what matters most? Exposure Management
Governance, Risk & Compliance Can we evidence this to an auditor or board? Governance, Risk and Compliance

Detect & Respond

Continuous monitoring, managed detection, threat investigation and incident response — 24/7 alert notification, triage and remediation across the IT environment and security stack, combining EDR, ITDR, SIEM and threat intelligence.

Human Risk

Awareness training, phishing simulation and behavioural insight, on the premise that 82% of cyber breaches start with human behaviour. Also covers email threat detection, user-reported phishing response, and insider risk and data exposure monitoring.

Threat Exposure

Continuous visibility across vulnerabilities, misconfigurations, cloud services, identities and attack surface, prioritised by likely business impact rather than raw severity.

Governance, Risk & Compliance

Frameworks to manage risk, improve controls and align security investment — producing auditable reporting as an output of the services rather than as a separate exercise.

Security is embedded, not bolted on

blueAPACHE's stated position is that security is built into each service pillar rather than delivered as a siloed practice. In practice that shows up as:

Certification and framework alignment

Alignment is not attestation. blueAPACHE claims no SOC 2 report anywhere in its published material, and the ISO certificate covers the management system rather than the products.

Customer Zero

blueAPACHE states it runs the same security architecture and controls on its own environment before deploying them to customers. Its published blueAPACHE Security case study describes strengthening its own posture with CyberArk, adding enterprise-level identity controls across its business and managed services.

That is a reasonable thing to probe in evaluation: ask which controls blueAPACHE runs internally that it does not yet offer as a service, and vice versa.

What is not published

These are the questions that separate a security service you can hold to account from one you cannot. Put them in writing.

Integration with other emPOWER services

The four pillars are designed to be bought together, and each also reaches into the rest of the portfolio:

Typical engagement

Onboarding. As with other emPOWER services, Transition In Services begin immediately after the Service Commencement Date: due diligence to catalogue the environment and existing security tooling, configuration of monitoring where applicable, documentation on how to engage blueAPACHE's teams, and an agreed reporting cadence. Because security engagements typically bring one or more of the four pillars together, scoping which pillars are included — and which existing tools they integrate with rather than replace — is the substantive part of transition.

Steady state. Coverage runs 24/7 for alert notification, triage and remediation under Detect & Respond, with the other three pillars running on their own cadences — continuous exposure visibility, ongoing human risk training and phishing simulation, and periodic governance and compliance reporting.

Term, renewal and exit. Security services follow the same 36-month Minimum Service Period default as the rest of emPOWER, with the same holdover consequences for late notice. At exit, security tooling configuration and any customer data held within it are deleted from blueAPACHE's environment at no cost; the customer is responsible for exporting anything it needs — audit evidence, incident history, training records — beforehand.

Choosing security components deliberately

Use this portfolio page to decide which functions to purchase rather than treating it as one all-inclusive service. Exposure management prioritises risk; MDR addresses detection and response; GRC addresses governance; Human Risk Management addresses people-related risk. Record the interfaces and work retained by the customer, including who implements remediation and approves incident actions. A common brand does not establish that every platform or advisory activity is included.

Which document defines the commitment

The published General Terms v3.6 give the Service Order precedence over the General Terms, followed by the Schedules and then the Acceptable Use Policy (clause 2.3). Record the agreed scope, exclusions and negotiated departures in that document set. A brochure or a procurement discussion does not, by itself, define the customer-specific commitment. Keep the versions supplied at signing with the executed order and signed variations. Two offers with the same service name can cover different systems, operating hours or responsibilities.

Confidential information and access

Clause 16 provides mutual confidentiality protection. It covers information marked confidential, information identified orally and confirmed in writing within 30 days, and information that should reasonably be understood to be confidential. Customer Data, Customer Records and Customer Software are included; blueAPACHE’s agreement and fees are also confidential. Permitted disclosures include appropriately bound personnel on a need-to-know basis and specified professional advisers, with other exceptions in the clause. Identify who may receive operational reports, configuration details and commercial information. Access to information to deliver the service is not a general permission to circulate it.

Responsibility across the delivery chain

The published terms allow blueAPACHE to subcontract all or part of the Service Agreement without customer consent or a notification requirement. Clause 27.5 nevertheless makes blueAPACHE liable for its subcontractors’ acts and omissions to the same extent as for its employees. This differs from a third-party supplier contracted directly by the customer. Identify which arrangement applies to each dependency in the design. Where supplier identity, delivery location or change notification matters, request a documented supplier list and put any agreed notification or approval requirement in the Service Order; the general clause does not supply that visibility automatically.

Evidence available during the engagement

The General Terms provide standard monthly performance reports within five Business Days of month end and a formal service review every six months. Performance Records must be kept through the term and for seven years afterwards. The customer audit provisions allow access to relevant Records, premises for audit purposes and personnel interviews, with five Business Days’ notice normally or one Business Day where a regulator requires the audit. This records obligation is not a seven-year backup-retention promise for customer workloads. Agree additional report formats and audit-cost arrangements before depending on them; the general audit clause does not clearly allocate every audit cost.

How liability differs from service performance

Clause 19 separates performance obligations from financial liability. The general cap per claim is the greater of the fees paid in the preceding three months or $25,000, with exclusions and specific categories governed separately. Confidentiality, information security, privacy and the IP indemnity have a $1 million per-event and $2 million aggregate cap. Data-loss liability depends on whether blueAPACHE had, and breached, a contracted backup or disaster recovery obligation; the relevant measure is restoration cost to the applicable recovery point, not the value of every business consequence. Read these provisions alongside the negotiated Service Order and Schedule; an availability statement does not describe the liability regime.

Sources and scope

The contractual detail above summarises the published General Terms and Conditions v3.6, using the KB documents on service agreement formation and document precedence; confidentiality; subcontracting and assignment; reporting review and audit rights; liability and indemnity. The customer’s Service Order, Schedules and agreed variations determine the specific engagement. See the terms and conditions guide and Service Agreement.

Frequently asked questions

Is emPOWER Security one product or several?

Four pillars run as one operating model: detection and response, human risk, threat exposure, and governance risk and compliance. They can be bought individually but are designed to work together.

What response time does blueAPACHE commit to?

None published. Coverage is 24/7 for alert notification, triage and remediation, but MTTD, MTTR and response targets are not stated publicly — source them from your Service Description.

Do we have to replace our existing security tools?

No. MDR integrates Microsoft Security, Microsoft Identity, Microsoft Sentinel, CrowdStrike and other third-party tooling.

Is blueAPACHE certified?

ISO/IEC 27001:2022, certificate 202507-118, covering ten named services. It states Essential Eight Maturity Level 3, APRA CPS 234 and NIST compliance. No SOC 2 report is claimed.

Which pillar should we start with?

It depends on the gap. If you have tooling but no one watching it, start with Detect & Respond. If your incidents start with phishing, start with Human Risk. If you cannot answer an auditor, start with GRC. If you have a backlog of findings you cannot prioritise, start with Threat Exposure.

Is security included in managed services?

Proactive security management and Security Gap Analysis audits are within managed services scope. Dedicated 24/7 detection and response, human risk and exposure management are sold through this pillar — confirm inclusion on the Service Order.

Does blueAPACHE use its own services internally?

It states it does, as Customer Zero, and its published security case study describes deploying CyberArk identity controls across its own business and managed services.

What is the contract term for emPOWER Security?

The standard 36-month Minimum Service Period applies, as it does across emPOWER, unless a different term is stated in the Service Description for a specific pillar.

What happens if we let the term lapse without notice?

The service automatically extends three months at full list price with Service Levels switched off — a material gap for a security service, since coverage commitments are not contractual during that period either.

Can we terminate early if we are not satisfied?

Only on the termination grounds in the general terms, and early exit before the Minimum Service Period ends triggers an Early Termination Payment under the relevant Schedule.

What happens to our incident history and training records if we leave?

blueAPACHE deletes customer data from its environment at no cost on exit. The customer must take its own copy of audit evidence, incident history and training records beforehand — there is no published retention window after termination.

Does emPOWER Security cover data breach notification obligations?

The General Terms and Conditions require each party to notify the other of an eligible data breach within 24 hours of discovery. That is a contractual obligation on both parties, separate from, and in addition to, the technical detection and response this service provides.

What support window applies to a security incident?

Detect & Respond provides 24/7 alert notification, triage and remediation. No MTTD or MTTR target is published; agreed response handling should be documented in your Service Description.

Related

Security hub · Managed Detection and Response · Human Risk Management · Exposure Management · Governance, Risk and Compliance · Connectivity · emPOWER SASE · Cloud · Managed Services · Glossary · Contact

Source

Drawn from blueAPACHE's emPOWER Security page, the emPOWER Managed Detection and Response and Human Risk Management brochures, the emPOWER platform overview, Global Capabilities brochure, the ISO/IEC 27001:2022 certificate 202507-118, the General Terms and Conditions v3.6, and the published blueAPACHE Security case study. Response-time targets, platform vendors and inclusion status are not stated in blueAPACHE's published material and are not inferred here. Also drawn from the General Terms and Conditions v3.6 (service term, renewal and minimum service period; transition in and disengagement services; consequences of termination; data protection and privacy) and blueAPACHE's data sovereignty and residency statement.

Knowledge Base

What is emPOWER Security?

emPOWER Security is blueAPACHE's integrated security portfolio that combines managed detection and response, exposure management, governance, risk and compliance, and human risk management to strengthen cyber resilience for organisations.

What are the four components of the emPOWER Security portfolio?

The four components are Managed Detection & Response, Human Risk Management, Governance, Risk & Compliance, and Exposure Management.

Does emPOWER Security operate as a standalone security layer?

No, emPOWER Security is designed to work alongside blueAPACHE's managed services, cloud and connectivity offerings rather than operate as a disconnected security layer.

What benefits does emPOWER Security aim to deliver for organisations?

It aims to improve visibility, help organisations prioritise action, and build stronger cyber resilience by bringing together detection and response, governance, and human risk management across technology, process and people.

What certifications and maturity levels support blueAPACHE's emPOWER Security offering?

blueAPACHE delivers emPOWER Security as a combined MSP and MSSP, holds ISO/IEC 27001:2022 certification (certificate 202507-118), and states ASD Essential Eight Maturity Level 3, per the MDR brochure.

Who is the target audience for emPOWER Security?

The service targets mid-market, enterprise and government organisations, primarily within Australia.

What does the Managed Detection and Response (MDR) service within emPOWER Security include?

The MDR service provides 24/7 managed security monitoring and response, including alert notification, triage, and remediation across the full IT environment, Endpoint Detection and Response (EDR), IT Data Response (ITDR), Security Information and Event Management (SIEM), identity-focused threat detection, coverage for email-borne and identity-based compromise, ITIL-aligned incident management, ISO 27001 certification alignment, and ASD Essential Eight Level 3 maturity.

What does the Human Risk Management (HRM) service within emPOWER Security cover?

HRM is a managed security awareness service that includes ongoing security awareness education, regular phishing simulations aligned to current attack techniques, email threat detection and alerting, user-reported phishing response and investigation, insider risk and data exposure protection monitoring across endpoints, browsers, and cloud applications, and behavioral insights with remediation guidance.

How can someone contact blueAPACHE for support related to emPOWER Security?

Support options include calling 1300 135 548 (Australia) or +61 3 8696 9369 (international), emailing support@blueapache.com, using the Remote Access or Client Portal links, or speaking to the team via the contact page. The general contact number listed for the service is 1800 248 749.

Images on This Page