Critical Infrastructure Cyber Security: Meeting Australia SOCI Act Requirements – ThreatDefence
Skip to content

Critical Infrastructure Cyber Security: Meeting Australia SOCI Act Requirements

Cybersecurity

Anton Guzhevskiy
Anton Guzhevskiy July 14, 2026 31 min read
Principal Product Researcher

Critical infrastructure cyber security in Australia is governed primarily by the Security of Critical Infrastructure Act 2018, commonly known as the SOCI Act. The Act applies to defined assets across 11 sectors and can require asset registration, a Critical Infrastructure Risk Management Program, mandatory cyber incident reporting, and enhanced obligations for Systems of National Significance. Meeting these requirements depends on continuous visibility, fast incident classification, structured evidence collection, and coordinated monitoring across IT, cloud and operational technology environments.

Introduction

Most organisations don't find out they're covered by the SOCI Act from a compliance memo. They find out when a customer, insurer or auditor asks a question they can't answer.

Critical infrastructure cyber security obligations in Australia have expanded significantly since 2018, and the practical burden isn't the paperwork. It's building the detection and evidence capability the paperwork assumes you already have.

This guide explains what the SOCI Act requires, which sectors it applies to, why meeting the reporting timeframes is harder than it sounds, and how to build a practical critical infrastructure cyber security program that supports both regulatory compliance and operational resilience.

What Is the SOCI Act?

The Security of Critical Infrastructure Act 2018 (Cth), commonly known as the SOCI Act, is Australia's primary legislation for protecting the systems and assets considered essential to the economy, national security and society.

Following reforms introduced during 2021 and 2022, the Act now applies across 11 critical infrastructure sectors and creates several distinct obligations.

These can include:

  • Registering critical infrastructure assets
  • Maintaining a documented Critical Infrastructure Risk Management Program
  • Reporting certain cyber security incidents within strict timeframes
  • Meeting enhanced cyber security obligations for the highest-risk assets
  • Cooperating with government assistance measures in serious circumstances

The Act does not prescribe one specific cyber security technology stack or operating model. Instead, it places responsibility on operators to manage risk effectively and demonstrate that risk management is happening in practice.

Regulators therefore expect more than a policy document. They expect evidence of monitoring, detection, escalation, remediation and ongoing review.

Which Sectors Does the SOCI Act Cover?

The SOCI Act applies across a broad range of industries, not only sectors traditionally associated with national infrastructure.

Sector Typical Examples
Communications Telecommunications providers, internet service providers and broadcasters
Data Storage and Processing Data centres, cloud providers and managed service providers
Defence Industry Defence contractors, manufacturers and supply-chain organisations
Education and Research Universities, research institutions and specialist facilities
Energy Electricity generators, gas pipelines, fuel storage and distribution
Financial Services and Markets Banks, superannuation funds, payment systems and market infrastructure
Food and Grocery Distribution centres, warehousing and cold-chain logistics
Health Care and Medical Hospitals, pathology services and pharmaceutical supply
Space Technology Satellite infrastructure, launch services and ground stations
Transport Ports, airports, rail networks, freight and logistics
Water and Sewerage Water utilities, desalination plants and wastewater systems

If an organisation owns, operates or holds a direct interest in an asset within one of these sectors, it may have binding obligations under the Act.

Sector membership alone does not always determine coverage. The specific asset definitions, ownership arrangements and class rules must also be considered.

The Core SOCI Act Obligations

The SOCI Act creates several obligations that can apply depending on the type and significance of the asset.

  • Asset registration responsible entities may need to register critical infrastructure assets with the Cyber and Infrastructure Security Centre
  • Critical Infrastructure Risk Management Program relevant organisations must maintain a written program covering cyber, personnel, supply-chain, physical and natural hazard risks
  • Mandatory cyber incident reporting certain cyber incidents must be reported to ASD within defined timeframes
  • Enhanced obligations Systems of National Significance can be subject to additional monitoring, incident response and exercise requirements
  • Government assistance powers these may be used as a last resort where a serious cyber attack threatens national interests

Asset Registration

Responsible entities may be required to provide information about their critical infrastructure assets to the Cyber and Infrastructure Security Centre.

This information can include:

  • The identity of the responsible entity
  • The asset's location and operational function
  • Ownership and control details
  • Direct interest holders
  • Relevant operational contacts

Registration information must generally be kept accurate and updated when material changes occur.

Critical Infrastructure Risk Management Program

A Critical Infrastructure Risk Management Program, commonly referred to as a CIRMP, is a documented and operational program for identifying and managing material risks to a critical infrastructure asset.

The program generally covers four hazard categories:

Hazard Area What It Covers
Cyber and information security Cyber attacks, system compromise, data loss and technology failure
Personnel Insider threats, staff suitability, access management and workforce risks
Supply chain Vendor dependencies, third-party access and service-provider exposure
Physical and natural hazards Physical intrusion, fire, flood, severe weather and other disruptions

A CIRMP should not be treated as a static policy written once for compliance purposes. It should reflect how the organisation actively identifies, assesses, mitigates and reviews risk.

Mandatory Cyber Incident Reporting

Certain cyber incidents affecting critical infrastructure assets must be reported to the Australian Signals Directorate within defined timeframes.

  • Significant cyber security incidents may need to be reported within 12 hours of the organisation becoming aware of the incident
  • Other reportable cyber security incidents may need to be reported within 72 hours

The reporting clock begins when the organisation becomes aware of the incident, not when the investigation is complete.

This makes rapid detection, classification and escalation essential.

Systems of National Significance

Systems of National Significance are critical infrastructure assets considered especially important because their disruption could have serious consequences across multiple sectors, regions or essential services.

Entities responsible for these assets may face Enhanced Cyber Security Obligations, including:

  • More detailed cyber security reporting
  • Incident response planning and exercises
  • Vulnerability assessments
  • Proactive threat monitoring
  • Additional information-sharing requirements

These obligations sit on top of the baseline requirements that may already apply under the SOCI Act.

Why Critical Infrastructure Cyber Security Is Genuinely Difficult

Meeting SOCI Act requirements is not simply a matter of completing forms. Organisations must build the operational capability needed to detect incidents, assess their impact and produce reliable evidence.

Visibility Gaps

Operational technology and information technology environments are often managed separately.

Legacy industrial systems may not support traditional endpoint agents or modern security tools, creating blind spots across equipment, controllers, engineering workstations and remote-access systems.

These visibility gaps can make it difficult to identify whether suspicious activity is isolated, widespread or affecting essential operations.

Reporting Speed

A 12-hour reporting window leaves very little time for manual investigation.

An organisation must be able to:

  • Detect suspicious behaviour
  • Confirm which asset is affected
  • Assess operational impact
  • Determine whether the reporting threshold is met
  • Escalate internally
  • Prepare and submit the initial report

If those steps depend on someone manually reviewing logs during business hours, consistently meeting the deadline becomes difficult.

Evidence Requirements

Annual reporting, audits and regulator inquiries require structured and retrievable evidence.

Useful evidence may include:

  • Alert records
  • Investigation notes
  • Incident timelines
  • System logs
  • Remediation actions
  • Risk acceptance decisions
  • Exercise results
  • Vendor assessments

Ad hoc screenshots and disconnected spreadsheets are rarely sufficient for demonstrating a mature risk-management process.

Limited Internal Resources

Many critical infrastructure operators have small security teams responsible for large, complex environments.

They may lack the internal capacity for:

  • Continuous monitoring
  • OT-specific threat detection
  • After-hours escalation
  • Threat hunting
  • Incident classification
  • Regulatory reporting support

Supply-Chain Exposure

The CIRMP specifically includes supply-chain hazards.

This means that risks introduced by cloud providers, managed service providers, software vendors, maintenance contractors and other third parties remain part of the responsible entity's risk-management obligations.

Outsourcing a service does not automatically outsource accountability.

A Practical Approach to Meeting SOCI Act Requirements

  1. Confirm whether your organisation is captured review current asset definitions, class rules, ownership arrangements and CISC guidance rather than relying only on sector membership
  2. Register relevant assets confirm whether required information has been submitted and whether existing records remain accurate
  3. Build or update the CIRMP cover cyber, personnel, supply-chain, physical and natural hazards as an operational program
  4. Establish continuous monitoring gain appropriate visibility across IT, cloud, OT and industrial control environments
  5. Define incident classification criteria document how the organisation distinguishes significant incidents from other reportable incidents
  6. Create an escalation workflow identify who must be contacted, what information they need and who has authority to report
  7. Structure evidence collection retain monitoring records, investigation notes, remediation evidence and management decisions
  8. Test the process run tabletop exercises, technical simulations and reporting drills
  9. Review the program regularly update controls and procedures when assets, suppliers, threats or legal requirements change

Building an Incident Classification Process

A documented classification process helps teams determine whether an incident meets a reporting threshold.

The process should consider:

  • Whether the incident affected a critical infrastructure asset
  • Whether availability, integrity, reliability or confidentiality was impacted
  • Whether essential services were disrupted or at risk
  • Whether the attacker gained unauthorised access
  • Whether data was altered, destroyed, accessed or exfiltrated
  • Whether the incident is ongoing
  • Whether other organisations or dependent services could be affected

The organisation should also define who has authority to make the final classification decision.

Monitoring IT and OT Environments

Critical infrastructure environments often combine traditional corporate systems with operational technology.

Environment Typical Monitoring Focus
IT systems Endpoints, identity, email, servers, cloud platforms and business applications
OT systems Industrial protocols, controllers, engineering workstations and production systems
Network infrastructure Segmentation, remote access, unusual traffic and command-and-control activity
Cloud environments Identity changes, exposed storage, configuration changes and privileged access
Third-party connections Vendor access, remote maintenance and managed service activity

The monitoring approach must account for the operational sensitivity of industrial environments.

Security tools should not disrupt production systems, interfere with safety controls or create unacceptable performance risks.

Common Mistakes

  • Treating the CIRMP as a one-off compliance document rather than a living operational program
  • Assuming the SOCI Act applies only to obvious sectors such as energy and water
  • Overlooking sectors such as data storage, education, logistics and food distribution
  • Depending on manual detection and triage for strict reporting deadlines
  • Monitoring IT and OT environments as disconnected programs
  • Failing to document incident classification criteria
  • Treating supply-chain security as the vendor's responsibility alone
  • Collecting evidence only when the annual report or audit is due
  • Failing to test incident reporting and escalation procedures
  • Assuming outsourced monitoring removes internal accountability

Best Practices

  • Build incident classification criteria before an incident occurs
  • Define 12-hour and 72-hour reporting workflows in advance
  • Extend visibility to OT and industrial control networks
  • Use monitoring approaches appropriate for legacy and production-sensitive systems
  • Maintain structured, exportable evidence throughout the year
  • Review third-party and supply-chain access regularly
  • Test escalation procedures outside normal business hours
  • Align the broader security program with recognised frameworks such as the Essential Eight and Information Security Manual
  • Run incident response exercises involving security, IT, operations, legal and leadership teams
  • Treat continuous monitoring as the foundation that makes the other obligations achievable

Frequently Asked Questions

Does the SOCI Act apply to my organisation?

If your organisation owns, operates or holds a direct interest in an asset within one of the 11 regulated sectors, it may have obligations. Coverage depends on the specific asset definition, class rules and ownership structure.

What should we do first if we're unsure whether we're covered?

Review the current CISC asset definitions and class rules, map your assets and ownership arrangements, and conduct a formal gap assessment.

What happens if we miss the 12-hour reporting deadline?

Civil penalties may apply for failing to meet mandatory reporting obligations. The practical ability to meet the deadline depends heavily on how quickly the organisation detects, classifies and escalates an incident.

What is the difference between the 12-hour and 72-hour reporting requirements?

More serious cyber security incidents may require notification within 12 hours of awareness, while other reportable incidents may have a 72-hour reporting window.

When does the reporting clock start?

The reporting period generally begins when the organisation becomes aware that a reportable incident has occurred, not when the full investigation is complete.

What does a CIRMP require?

A CIRMP is a written and operational program for identifying and managing material risks across cyber and information security, personnel, supply chain, and physical and natural hazards.

Do we need a 24×7 SOC to comply?

The SOCI Act does not explicitly require every organisation to operate a 24×7 SOC. However, continuous monitoring and after-hours escalation are often the most practical ways to meet strict reporting timeframes.

What is a responsible entity?

A responsible entity generally owns or operates a critical infrastructure asset and carries the primary obligations associated with that asset.

What is a direct interest holder?

A direct interest holder is an entity that holds a relevant ownership or control interest in a critical infrastructure asset. The exact definition depends on the applicable provisions and ownership arrangements.

What are Systems of National Significance?

They are critical infrastructure assets considered especially important because disruption could create serious national or cascading impacts. These assets can be subject to Enhanced Cyber Security Obligations.

Is OT cyber security different from standard IT security?

The risk-management obligations are related, but the operational challenge is different. OT environments often contain legacy systems, proprietary protocols and production equipment that cannot safely run conventional endpoint agents.

Can a managed service provider handle SOCI monitoring for us?

A qualified provider can support monitoring, detection and reporting workflows. However, the responsible entity generally retains accountability for meeting its legal and risk-management obligations.

How often should the CIRMP be reviewed?

It should be reviewed regularly and whenever material changes occur, including changes to assets, suppliers, technology, threats, ownership or operational dependencies.

Key Takeaways

  • Critical infrastructure cyber security in Australia is governed primarily by the SOCI Act
  • The Act applies across 11 sectors, including several sectors that organisations may overlook
  • Core obligations can include asset registration, a CIRMP, mandatory incident reporting and enhanced requirements for Systems of National Significance
  • Meeting 12-hour and 72-hour reporting windows requires fast detection, classification and escalation
  • Regulators expect structured evidence of active risk management, not policy documents alone
  • OT visibility, supply-chain risk and limited internal resources are common implementation challenges
  • Continuous monitoring across IT, cloud and OT environments supports nearly every practical SOCI obligation

Conclusion

The SOCI Act does not prescribe exactly how every critical infrastructure operator must secure its environment. It holds organisations accountable for managing risk and demonstrating that the required capability exists in practice.

For most operators, the most important question is straightforward: could your organisation detect a significant incident, classify it correctly and report it within 12 hours today?

If the answer is uncertain, that is the most important gap to address first.

ThreatDefence helps Australian critical infrastructure operators build the continuous monitoring, evidence and reporting capabilities needed to support SOCI Act obligations across IT, cloud and OT environments. Learn more about our critical infrastructure security monitoring or get in touch to scope a gap assessment against your specific environment and obligations.

Sign Up for ThreatDefence Updates

Get insider access to ThreatDefence tradecraft, killer events, and the freshest blog updates.

By submitting this form, you accept our Terms of Service & Privacy Policy