How a structured advisory engagement delivered regulatory compliance alongside measurable security uplift for an energy sector operator subject to SOCI Act risk management programme obligations — within a hard regulatory deadline.
The Security of Critical Infrastructure Act's risk management programme obligations came into full effect for this energy distribution operator with less notice than the organisation had anticipated. The 2021–22 SOCI Act amendments had significantly expanded the definition of critical infrastructure — bringing energy distribution within scope and imposing mandatory CIRMP obligations, asset registration requirements and a 12-hour incident notification capability.
The operator had engaged with the legislation but had not translated that engagement into a compliant programme. When a scheduled ASD engagement was confirmed, the gap between their current state and the CIRMP Rules requirements became the immediate operational priority. They had 90 days.
Context: The SOCI Act's CIRMP obligations require responsible entities to identify and manage material risks to their critical infrastructure assets across four hazard categories — cyber, physical, personnel and supply chain. The Critical Infrastructure Risk Management Programme Rules set out minimum requirements for each category. Non-compliant entities face directed remediation, civil penalties and in serious cases government step-in powers.
Three factors made this engagement materially more complex than a standard compliance programme design. First, the operator's environment included legacy OT systems with significant patching and network visibility constraints that could not be addressed through standard IT security approaches. Second, the two-state asset footprint created inconsistent control implementations across locations with different operational teams. Third, the ASD deadline meant that any recommended control that could not be implemented within the 90-day window needed a documented compensating control and risk acceptance — otherwise the CIRMP would not accurately reflect the operator's actual posture.
Every control recommendation had to be assessed against a binary question: can this be implemented and evidenced within 90 days, or does it require a longer uplift programme? Controls that required procurement, major configuration changes or operational maintenance windows beyond the deadline were documented as exceptions with compensating controls — not omitted from the CIRMP. APRA-style regulators reward transparency about what is not yet in place more than they reward optimistic claims that cannot be evidenced.
Regulators reward transparency about what is not yet in place more than they reward optimistic claims that cannot be evidenced. A CIRMP that accurately documents exceptions with compensating controls is more credible than one that claims full compliance without the evidence to support it.
The engagement was structured in four sequential phases — each with discrete deliverables that could stand alone if the timeline was disrupted. This sequencing meant that at any point within the 90 days, the operator had a documentable set of completed work rather than a partially built programme that could not be submitted.
Confirmed the asset boundary for CIRMP purposes — which systems, OT components, cloud services and third-party connections were in scope. Mapped the operator's existing control documentation against the four CIRMP hazard categories: cyber, physical, personnel and supply chain.
This phase produced the asset register and risk identification documentation that underpins the entire CIRMP. Getting the boundary right at this stage prevented scope creep and assessment surprises in later phases.
Conducted a non-intrusive OT security assessment across the operator's industrial control systems — using passive network monitoring rather than active scanning to avoid operational disruption. This established the OT network visibility baseline and identified the segmentation gaps that represented the highest-consequence cyber risks under the CIRMP Rules.
For each gap identified, the team assessed whether remediation was achievable within the 90-day window. Controls that required extended maintenance windows or vendor involvement were documented as time-bound exceptions with compensating controls.
Drafted the complete Critical Infrastructure Risk Management Programme document — covering all four hazard categories, the risk assessment methodology, the controls implemented against each risk, the exception register and the governance arrangements including board oversight and annual review commitments.
In parallel, designed and documented the 12-hour incident notification framework — decision trees, escalation contacts, notification templates, ACSC engagement procedures and the criteria for determining whether an incident meets the "significant impact" threshold. Then ran a two-hour tabletop exercise to test whether the framework could produce a notification within the 12-hour window under simulated incident conditions.
Finalised the CIRMP document and submitted to the ACSC. Prepared the ASD engagement briefing pack — a board-level summary of the programme, the risk decisions made, the exceptions documented and the uplift roadmap for controls outside the 90-day window. Delivered a structured handover to the operator's internal team with maintenance procedures, annual review requirements and the documentation needed for future CIRMP updates.
Operational technology environments cannot be treated like corporate IT networks. A vulnerability scanner that would complete in minutes on a corporate network can cause process failures on an ICS. Every assessment activity, every control recommendation and every network change was assessed for operational impact before being proposed. The engagement delivered security uplift without a single unplanned operational disruption — which was a stated requirement from the outset.
Each of the four mandatory hazard categories in the CIRMP Rules required a different approach to risk identification and control documentation.
The most extensive category — covering IT and OT network security, access controls, vulnerability management, incident detection and the 12-hour notification capability. Required the OT assessment to establish an accurate risk baseline.
Physical security of critical operational sites, access control systems, CCTV, personnel access procedures and the physical security of OT equipment. Cross-referenced with existing physical security documentation and site inspection records.
Insider threat controls, pre-employment screening, ongoing personnel security obligations for critical roles, separation procedures and the controls governing third-party personnel with access to critical systems.
Third-party vendor security assessments, contractual security requirements for OT equipment suppliers, technology vendors with remote access to critical systems and the operator's procurement security requirements.
"The engagement delivered security uplift without a single unplanned operational disruption. In an OT environment, that constraint is not optional — it is the primary design requirement."
The 90-day programme delivered four material outcomes: a CIRMP accepted by the ACSC on first submission, a verified 12-hour notification capability, baseline OT network visibility, and a structured handover enabling the operator's internal team to maintain the programme going forward.
Days from engagement start to ACSC-accepted CIRMP submission
Submission — CIRMP accepted by ACSC without resubmission or directed remediation
Notification capability verified capable of meeting the SOCI Act deadline under simulated conditions
Unplanned operational disruptions during OT assessment and network segmentation work
The CIRMP document was submitted within the 90-day window and accepted by the ACSC without requiring resubmission, clarification or directed remediation. This outcome requires both a technically sound programme and a document that communicates it in the format ACSC reviewers expect — both of which were built into the engagement design from the outset.
The notification framework was documented as a set of decision trees, escalation contacts and notification templates — then tested in a tabletop exercise that simulated a ransomware event affecting one of the operator's substations. The exercise confirmed the framework could produce a compliant ACSC notification within the 12-hour window under realistic incident conditions.
Passive OT network monitoring was deployed across the operator's primary ICS environments — providing the first comprehensive asset inventory and traffic baseline the operator's security team had seen. This baseline directly supported the CIRMP's cyber hazard risk assessment and created a detection capability that did not exist before the engagement.
The operator's internal team received a structured handover package covering CIRMP maintenance procedures, annual review requirements, the exception register with uplift timelines, and the documentation needed for future CIRMP updates. The programme was designed to be maintained by the internal team — not to require ongoing external engagement to remain compliant.
The ASD engagement — which had been the 90-day driver — was supported by a board-level briefing pack covering the programme structure, the risk decisions made, the exception register with compensating controls, and the uplift roadmap for controls that required longer implementation timelines. This pack gave the operator's board and security leadership a clear, defensible position going into the engagement.
We had 90 days to go from non-compliant to ACSC-accepted. GadgetAccess understood both the OT constraints we were working with and the regulatory expectations we had to meet. That combination is genuinely rare — most advisors are strong on one or the other, not both.
— Head of Operational Technology Security, Australian Energy DistributorThe most important outcome was not the CIRMP submission. It was the operator's internal team having a programme they understood, could maintain, and could defend to regulators without external support.
Critical Infrastructure Operator Achieves SOCI Act Compliance in 90 Days · GadgetAccess · March 2026 · Anonymised Case Study
What APRA scrutinises in supervised reviews — and how to prepare.
Research Brief · May 2026How Australian security teams are absorbing hidden operational tax.
Sector AdvisorySOCI Act CIRMP design, OT security assessment and incident notification frameworks.
Our advisors have delivered CIRMP programmes, OT security assessments and incident notification frameworks for critical infrastructure operators across energy, transport and water sectors. We understand both the regulatory requirements and the OT operational constraints.