Home Insights SOCI Act Compliance in 90 Days
⚡ Anonymised Case Study · Energy Sector · Critical Infrastructure

Critical Infrastructure Operator Achieves SOCI Act Compliance in 90 Days

How a structured advisory engagement delivered regulatory compliance alongside measurable security uplift for an energy sector operator subject to SOCI Act risk management programme obligations — within a hard regulatory deadline.

90Days to full compliance
2States of operation
1stCIRMP submission accepted
12 hrNotification capability verified

The starting position

The Security of Critical Infrastructure Act's risk management programme obligations came into full effect for this energy distribution operator with less notice than the organisation had anticipated. The 2021–22 SOCI Act amendments had significantly expanded the definition of critical infrastructure — bringing energy distribution within scope and imposing mandatory CIRMP obligations, asset registration requirements and a 12-hour incident notification capability.

The operator had engaged with the legislation but had not translated that engagement into a compliant programme. When a scheduled ASD engagement was confirmed, the gap between their current state and the CIRMP Rules requirements became the immediate operational priority. They had 90 days.

Client profile
Energy distribution operator with assets across two states, hybrid OT/IT environment, regulated under the SOCI Act as a critical infrastructure asset responsible entity.
Starting state
Assets registered but no compliant CIRMP. Limited OT network visibility. No documented 12-hour notification capability. Third-party risk across OT vendors not assessed.
Deadline
90 days to CIRMP submission and ASD engagement — driven by a scheduled regulatory review, not an incident.
Primary outcome
CIRMP accepted by the ACSC on first submission. 12-hour notification capability tested and verified. OT network visibility uplift delivered without operational disruption.

Context: The SOCI Act's CIRMP obligations require responsible entities to identify and manage material risks to their critical infrastructure assets across four hazard categories — cyber, physical, personnel and supply chain. The Critical Infrastructure Risk Management Programme Rules set out minimum requirements for each category. Non-compliant entities face directed remediation, civil penalties and in serious cases government step-in powers.

What made this engagement complex

Three factors made this engagement materially more complex than a standard compliance programme design. First, the operator's environment included legacy OT systems with significant patching and network visibility constraints that could not be addressed through standard IT security approaches. Second, the two-state asset footprint created inconsistent control implementations across locations with different operational teams. Third, the ASD deadline meant that any recommended control that could not be implemented within the 90-day window needed a documented compensating control and risk acceptance — otherwise the CIRMP would not accurately reflect the operator's actual posture.

⏱️
The 90-day constraint shaped every decision

Every control recommendation had to be assessed against a binary question: can this be implemented and evidenced within 90 days, or does it require a longer uplift programme? Controls that required procurement, major configuration changes or operational maintenance windows beyond the deadline were documented as exceptions with compensating controls — not omitted from the CIRMP. APRA-style regulators reward transparency about what is not yet in place more than they reward optimistic claims that cannot be evidenced.

Regulators reward transparency about what is not yet in place more than they reward optimistic claims that cannot be evidenced. A CIRMP that accurately documents exceptions with compensating controls is more credible than one that claims full compliance without the evidence to support it.

How we structured the 90-day engagement

The engagement was structured in four sequential phases — each with discrete deliverables that could stand alone if the timeline was disrupted. This sequencing meant that at any point within the 90 days, the operator had a documentable set of completed work rather than a partially built programme that could not be submitted.

Weeks1–2
Phase 1 — Asset Boundary and Risk Identification

Confirmed the asset boundary for CIRMP purposes — which systems, OT components, cloud services and third-party connections were in scope. Mapped the operator's existing control documentation against the four CIRMP hazard categories: cyber, physical, personnel and supply chain.

This phase produced the asset register and risk identification documentation that underpins the entire CIRMP. Getting the boundary right at this stage prevented scope creep and assessment surprises in later phases.

Weeks3–6
Phase 2 — OT Security Assessment and Control Gap Analysis

Conducted a non-intrusive OT security assessment across the operator's industrial control systems — using passive network monitoring rather than active scanning to avoid operational disruption. This established the OT network visibility baseline and identified the segmentation gaps that represented the highest-consequence cyber risks under the CIRMP Rules.

For each gap identified, the team assessed whether remediation was achievable within the 90-day window. Controls that required extended maintenance windows or vendor involvement were documented as time-bound exceptions with compensating controls.

Weeks7–10
Phase 3 — CIRMP Design, Drafting and Notification Framework

Drafted the complete Critical Infrastructure Risk Management Programme document — covering all four hazard categories, the risk assessment methodology, the controls implemented against each risk, the exception register and the governance arrangements including board oversight and annual review commitments.

In parallel, designed and documented the 12-hour incident notification framework — decision trees, escalation contacts, notification templates, ACSC engagement procedures and the criteria for determining whether an incident meets the "significant impact" threshold. Then ran a two-hour tabletop exercise to test whether the framework could produce a notification within the 12-hour window under simulated incident conditions.

Weeks11–13
Phase 4 — ACSC Submission, ASD Briefing Preparation and Handover

Finalised the CIRMP document and submitted to the ACSC. Prepared the ASD engagement briefing pack — a board-level summary of the programme, the risk decisions made, the exceptions documented and the uplift roadmap for controls outside the 90-day window. Delivered a structured handover to the operator's internal team with maintenance procedures, annual review requirements and the documentation needed for future CIRMP updates.

🏭
The OT constraint that shaped every recommendation

Operational technology environments cannot be treated like corporate IT networks. A vulnerability scanner that would complete in minutes on a corporate network can cause process failures on an ICS. Every assessment activity, every control recommendation and every network change was assessed for operational impact before being proposed. The engagement delivered security uplift without a single unplanned operational disruption — which was a stated requirement from the outset.

The four CIRMP hazard categories — what each required

Each of the four mandatory hazard categories in the CIRMP Rules required a different approach to risk identification and control documentation.

🔒
Cyber Hazards

The most extensive category — covering IT and OT network security, access controls, vulnerability management, incident detection and the 12-hour notification capability. Required the OT assessment to establish an accurate risk baseline.

🏗️
Physical Hazards

Physical security of critical operational sites, access control systems, CCTV, personnel access procedures and the physical security of OT equipment. Cross-referenced with existing physical security documentation and site inspection records.

👥
Personnel Hazards

Insider threat controls, pre-employment screening, ongoing personnel security obligations for critical roles, separation procedures and the controls governing third-party personnel with access to critical systems.

🔗
Supply Chain Hazards

Third-party vendor security assessments, contractual security requirements for OT equipment suppliers, technology vendors with remote access to critical systems and the operator's procurement security requirements.

"The engagement delivered security uplift without a single unplanned operational disruption. In an OT environment, that constraint is not optional — it is the primary design requirement."

What was delivered — and what changed for the operator

The 90-day programme delivered four material outcomes: a CIRMP accepted by the ACSC on first submission, a verified 12-hour notification capability, baseline OT network visibility, and a structured handover enabling the operator's internal team to maintain the programme going forward.

90

Days from engagement start to ACSC-accepted CIRMP submission

1st

Submission — CIRMP accepted by ACSC without resubmission or directed remediation

12 hr

Notification capability verified capable of meeting the SOCI Act deadline under simulated conditions

Zero

Unplanned operational disruptions during OT assessment and network segmentation work

CIRMP accepted by ACSC on first submission

The CIRMP document was submitted within the 90-day window and accepted by the ACSC without requiring resubmission, clarification or directed remediation. This outcome requires both a technically sound programme and a document that communicates it in the format ACSC reviewers expect — both of which were built into the engagement design from the outset.

🔔
12-hour notification capability designed, documented and tested

The notification framework was documented as a set of decision trees, escalation contacts and notification templates — then tested in a tabletop exercise that simulated a ransomware event affecting one of the operator's substations. The exercise confirmed the framework could produce a compliant ACSC notification within the 12-hour window under realistic incident conditions.

🏭
OT network baseline visibility established

Passive OT network monitoring was deployed across the operator's primary ICS environments — providing the first comprehensive asset inventory and traffic baseline the operator's security team had seen. This baseline directly supported the CIRMP's cyber hazard risk assessment and created a detection capability that did not exist before the engagement.

📋
Structured programme handover — maintenance and annual review ready

The operator's internal team received a structured handover package covering CIRMP maintenance procedures, annual review requirements, the exception register with uplift timelines, and the documentation needed for future CIRMP updates. The programme was designed to be maintained by the internal team — not to require ongoing external engagement to remain compliant.

📊
ASD engagement briefing pack prepared

The ASD engagement — which had been the 90-day driver — was supported by a board-level briefing pack covering the programme structure, the risk decisions made, the exception register with compensating controls, and the uplift roadmap for controls that required longer implementation timelines. This pack gave the operator's board and security leadership a clear, defensible position going into the engagement.

We had 90 days to go from non-compliant to ACSC-accepted. GadgetAccess understood both the OT constraints we were working with and the regulatory expectations we had to meet. That combination is genuinely rare — most advisors are strong on one or the other, not both.

— Head of Operational Technology Security, Australian Energy Distributor

The most important outcome was not the CIRMP submission. It was the operator's internal team having a programme they understood, could maintain, and could defend to regulators without external support.

Regulatory Framework References
  • Security of Critical Infrastructure Act 2018 (Cth) as amended — SOCI Act 2022 amendments.
  • Security of Critical Infrastructure (Critical Infrastructure Risk Management Programme) Rules (LIN 23/006) 2023.
  • Department of Home Affairs. SOCI Act sector security plans — energy sector guidance.
  • Australian Cyber Security Centre. Critical infrastructure uplift guidance. cyber.gov.au
  • Note: Client profile is anonymised. Non-material identifying details have been withheld while the engagement structure and outcome metrics are presented for practical learning.
📄

Download the Full Case Study — PDF

Critical Infrastructure Operator Achieves SOCI Act Compliance in 90 Days · GadgetAccess · March 2026 · Anonymised Case Study

⬇ Download PDF
Related Insights

Facing a SOCI Act deadline or needing your CIRMP strengthened?

Our advisors have delivered CIRMP programmes, OT security assessments and incident notification frameworks for critical infrastructure operators across energy, transport and water sectors. We understand both the regulatory requirements and the OT operational constraints.