Who the Act covers
The Act started in 2018 with a narrow scope and was expanded twice, in 2021 and 2022, to eleven sectors: communications, data storage and processing, defence industry, energy, financial services and markets, food and grocery, health care and medical, higher education and research, space technology, transport, and water and sewerage.
Within those sectors the Act defines asset classes. If you own or operate one of them you are a responsible entity, and a set of obligations follows. Mining is not a listed sector, though a mine's port, rail or power assets can be.
The four obligations that touch OT
- Register of critical infrastructure assets: ownership and operational information about the asset, kept current with the Cyber and Infrastructure Security Centre.
- Mandatory cyber incident reporting: a cyber incident with a significant impact on the availability of the asset must be reported within 12 hours of becoming aware of it; an incident with a relevant impact within 72 hours. The report goes to the Australian Signals Directorate.
- Critical Infrastructure Risk Management Program (CIRMP): for the asset classes the rules name, a written program that identifies and manages material risks across four hazard domains, including cyber and information security, with an annual report approved by the board.
- Enhanced cyber security obligations: for assets declared systems of national significance, additional duties such as incident response planning, cyber security exercises and vulnerability assessments on request.
What CIRMP asks for, in practice
The cyber and information security hazard is where OT comes in. The rules require the entity to identify material risks to the asset, minimise or eliminate them so far as is reasonably practicable, and mitigate their impact. The program has to be more than a policy: it needs to name the risks, the controls and the owners.
The rules also require a recognised cyber security framework to be established and maintained. The list includes the Australian Energy Sector Cyber Security Framework at Security Profile 1, the Essential Eight at Maturity Level One, ISO/IEC 27001, the NIST Cybersecurity Framework and the C2M2 at Maturity Indicator Level 1, or an equivalent framework. For energy entities, AESCSF SP-1 is the natural choice because it was written for their operating environment.
What an assessor looks for
- An asset inventory that includes the OT: controllers, HMIs, engineering workstations, network gear and the protocols between them, not just the corporate fleet.
- A network that is segmented in fact, with the IT/OT boundary enforced and proven, not drawn on a diagram.
- Remote access that is controlled: who, from where, for how long, with multi-factor authentication and a record.
- Monitoring that would actually notice a change in the control network, and someone who would act on it.
- An incident response plan that covers the plant, with the 12-hour and 72-hour clocks built into it, and evidence it has been exercised.
- A board that has seen the material risks and signed the annual report knowing what it says.
Where to start
If the program does not yet exist, start with a risk assessment against the framework you intend to adopt and an honest asset inventory. If it does exist, test it: run a tabletop exercise on a control-system scenario and see whether the reporting clock, the vendor call and the safe-shutdown decision are actually in the plan.
The reforms are still moving. The Act was amended again in 2024, and the rules and guidance are updated periodically, so check the current text before relying on a clause.
- Security of Critical Infrastructure Act 2018 (Cth), as amended
- Security of Critical Infrastructure (Critical infrastructure risk management program) Rules
- Cyber and Infrastructure Security Centre guidance





