ThreatDefence is the only SecOps as a Service company providing broad coverage across your entire technology stack with evidence-based security.
We provide security teams with full-stack SecOps infrastructure – you get deep visibility from day one, gain control over your security data, and get access to a comprehensive set of ready-to-use tools, detections, workflows, playbooks and scenarios.
24×7 managed detection and response across endpoint, network, cloud, identity, and log sources
Eyes-on-glass SOC and continuous threat hunting
Protect your entire technology stack and build your SecOps on your own pace
Launch your SOC business without any upfront investment
Get ultimate assurance that your environment is free from threat actors
Quickly recover from cyber attacks and breaches
24×7 SOC, Continuous Monitoring, Threat Containment and Incident Response
Visibility and actionable insights for all IT assets
Leverage our Cyber Range to train defenders based on real-world scenarios and simulations
OT and industrial cyber security services for critical infrastructure
Cloud-based SIEM platform providing visibility across all your data sources
Manage your external footprint, publicly available data, and Dark Web leaks
Quick alert triage and integrated SOC metrics
Fully featured distrubuted NDR for on-premises and public cloud environments
Deploy honeypots and honeytokens and stay ahead of threat actors
Quick investigations and Threat Hunting with our cyber AI
Integrated endpoint agent providing deep visibility, response and forensics
Log management and threat detection across any of your log sources
A SecOps platform purpose-built for industrial and OT environments
ThreatDefence puts security and compliance at the heart of our service, keeping your data protected at all times.
See how we keep your data secure.
Read what our customers say about us
Solution briefs and datasheets
Technical support and knowledge base
Essential Eight monitoring, reporting, and evidence for ongoing compliance
Privacy Act reform impacts, obligations, and practical security considerations
Monitoring and compliance support for critical infrastructure environments
A practical guide to Incident Response and Digital Forensics
Read how cyber range helps to train cyber defenders
A practical guide to securing critical infrastructure with continuous monitoring
A practical buyer’s guide for schools evaluating SIEM and SOC services
A practical guide to selecting the right SIEM and SOC service for local government
We provide end-to-end SecOps solutions for Managed Security Service Providers (MSSPs), Managed Service Providers (MSPs), and Value-Added Resellers (VARs).
Find out how you can become a ThreatDefence partner.
AI SOC hyperautomation transforms cybersecurity ops by autonomously detecting, analyzing, and remediating threats.
Honored to Support the Launch of the University of Technology Sydney Cybersecurity Precinct!
ThreatDefence Cyber had the privilege of meeting with Honeywell Dubai’s Digital City leadership to explore synergies in OT/SCADA and…
Read More
Equinox to support companies with ready to use, end-to-end SecOps infrastructure, including a full stack platform able to capture and…
ThreatDefence had an amazing time at AISA CyberCon 2024, connecting with industry leaders and advancing cyber security conversations.
Critical infrastructure cyber security in Australia is governed primarily by the Security of Critical Infrastructure Act 2018, commonly known as the SOCI Act. The Act applies to defined assets across 11 sectors and can require asset registration, a Critical Infrastructure Risk Management Program, mandatory cyber incident reporting, and enhanced obligations for Systems of National Significance. Meeting these requirements depends on continuous visibility, fast incident classification, structured evidence collection, and coordinated monitoring across IT, cloud and operational technology environments.
Most organisations don't find out they're covered by the SOCI Act from a compliance memo. They find out when a customer, insurer or auditor asks a question they can't answer.
Critical infrastructure cyber security obligations in Australia have expanded significantly since 2018, and the practical burden isn't the paperwork. It's building the detection and evidence capability the paperwork assumes you already have.
This guide explains what the SOCI Act requires, which sectors it applies to, why meeting the reporting timeframes is harder than it sounds, and how to build a practical critical infrastructure cyber security program that supports both regulatory compliance and operational resilience.
The Security of Critical Infrastructure Act 2018 (Cth), commonly known as the SOCI Act, is Australia's primary legislation for protecting the systems and assets considered essential to the economy, national security and society.
Following reforms introduced during 2021 and 2022, the Act now applies across 11 critical infrastructure sectors and creates several distinct obligations.
These can include:
The Act does not prescribe one specific cyber security technology stack or operating model. Instead, it places responsibility on operators to manage risk effectively and demonstrate that risk management is happening in practice.
Regulators therefore expect more than a policy document. They expect evidence of monitoring, detection, escalation, remediation and ongoing review.
The SOCI Act applies across a broad range of industries, not only sectors traditionally associated with national infrastructure.
If an organisation owns, operates or holds a direct interest in an asset within one of these sectors, it may have binding obligations under the Act.
Sector membership alone does not always determine coverage. The specific asset definitions, ownership arrangements and class rules must also be considered.
The SOCI Act creates several obligations that can apply depending on the type and significance of the asset.
Responsible entities may be required to provide information about their critical infrastructure assets to the Cyber and Infrastructure Security Centre.
This information can include:
Registration information must generally be kept accurate and updated when material changes occur.
A Critical Infrastructure Risk Management Program, commonly referred to as a CIRMP, is a documented and operational program for identifying and managing material risks to a critical infrastructure asset.
The program generally covers four hazard categories:
A CIRMP should not be treated as a static policy written once for compliance purposes. It should reflect how the organisation actively identifies, assesses, mitigates and reviews risk.
Certain cyber incidents affecting critical infrastructure assets must be reported to the Australian Signals Directorate within defined timeframes.
The reporting clock begins when the organisation becomes aware of the incident, not when the investigation is complete.
This makes rapid detection, classification and escalation essential.
Systems of National Significance are critical infrastructure assets considered especially important because their disruption could have serious consequences across multiple sectors, regions or essential services.
Entities responsible for these assets may face Enhanced Cyber Security Obligations, including:
These obligations sit on top of the baseline requirements that may already apply under the SOCI Act.
Meeting SOCI Act requirements is not simply a matter of completing forms. Organisations must build the operational capability needed to detect incidents, assess their impact and produce reliable evidence.
Operational technology and information technology environments are often managed separately.
Legacy industrial systems may not support traditional endpoint agents or modern security tools, creating blind spots across equipment, controllers, engineering workstations and remote-access systems.
These visibility gaps can make it difficult to identify whether suspicious activity is isolated, widespread or affecting essential operations.
A 12-hour reporting window leaves very little time for manual investigation.
An organisation must be able to:
If those steps depend on someone manually reviewing logs during business hours, consistently meeting the deadline becomes difficult.
Annual reporting, audits and regulator inquiries require structured and retrievable evidence.
Useful evidence may include:
Ad hoc screenshots and disconnected spreadsheets are rarely sufficient for demonstrating a mature risk-management process.
Many critical infrastructure operators have small security teams responsible for large, complex environments.
They may lack the internal capacity for:
The CIRMP specifically includes supply-chain hazards.
This means that risks introduced by cloud providers, managed service providers, software vendors, maintenance contractors and other third parties remain part of the responsible entity's risk-management obligations.
Outsourcing a service does not automatically outsource accountability.
A documented classification process helps teams determine whether an incident meets a reporting threshold.
The process should consider:
The organisation should also define who has authority to make the final classification decision.
Critical infrastructure environments often combine traditional corporate systems with operational technology.
The monitoring approach must account for the operational sensitivity of industrial environments.
Security tools should not disrupt production systems, interfere with safety controls or create unacceptable performance risks.
Does the SOCI Act apply to my organisation?
If your organisation owns, operates or holds a direct interest in an asset within one of the 11 regulated sectors, it may have obligations. Coverage depends on the specific asset definition, class rules and ownership structure.
What should we do first if we're unsure whether we're covered?
Review the current CISC asset definitions and class rules, map your assets and ownership arrangements, and conduct a formal gap assessment.
What happens if we miss the 12-hour reporting deadline?
Civil penalties may apply for failing to meet mandatory reporting obligations. The practical ability to meet the deadline depends heavily on how quickly the organisation detects, classifies and escalates an incident.
What is the difference between the 12-hour and 72-hour reporting requirements?
More serious cyber security incidents may require notification within 12 hours of awareness, while other reportable incidents may have a 72-hour reporting window.
When does the reporting clock start?
The reporting period generally begins when the organisation becomes aware that a reportable incident has occurred, not when the full investigation is complete.
What does a CIRMP require?
A CIRMP is a written and operational program for identifying and managing material risks across cyber and information security, personnel, supply chain, and physical and natural hazards.
Do we need a 24×7 SOC to comply?
The SOCI Act does not explicitly require every organisation to operate a 24×7 SOC. However, continuous monitoring and after-hours escalation are often the most practical ways to meet strict reporting timeframes.
What is a responsible entity?
A responsible entity generally owns or operates a critical infrastructure asset and carries the primary obligations associated with that asset.
What is a direct interest holder?
A direct interest holder is an entity that holds a relevant ownership or control interest in a critical infrastructure asset. The exact definition depends on the applicable provisions and ownership arrangements.
What are Systems of National Significance?
They are critical infrastructure assets considered especially important because disruption could create serious national or cascading impacts. These assets can be subject to Enhanced Cyber Security Obligations.
Is OT cyber security different from standard IT security?
The risk-management obligations are related, but the operational challenge is different. OT environments often contain legacy systems, proprietary protocols and production equipment that cannot safely run conventional endpoint agents.
Can a managed service provider handle SOCI monitoring for us?
A qualified provider can support monitoring, detection and reporting workflows. However, the responsible entity generally retains accountability for meeting its legal and risk-management obligations.
How often should the CIRMP be reviewed?
It should be reviewed regularly and whenever material changes occur, including changes to assets, suppliers, technology, threats, ownership or operational dependencies.
The SOCI Act does not prescribe exactly how every critical infrastructure operator must secure its environment. It holds organisations accountable for managing risk and demonstrating that the required capability exists in practice.
For most operators, the most important question is straightforward: could your organisation detect a significant incident, classify it correctly and report it within 12 hours today?
If the answer is uncertain, that is the most important gap to address first.
ThreatDefence helps Australian critical infrastructure operators build the continuous monitoring, evidence and reporting capabilities needed to support SOCI Act obligations across IT, cloud and OT environments. Learn more about our critical infrastructure security monitoring or get in touch to scope a gap assessment against your specific environment and obligations.
Get insider access to ThreatDefence tradecraft, killer events, and the freshest blog updates.
By submitting this form, you accept our Terms of Service & Privacy Policy
You have subscribed successfully!