Australia’s critical infrastructure supports the essential services on which communities, businesses and government depend. As these services become more digitally connected and reliant on third parties, a cyber incident affecting one organisation or supplier can cause disruption across a much wider network.
The Security of Critical Infrastructure Act 2018, known as the SOCI Act, establishes a framework for managing these risks. For organisations within scope, compliance requires more than documenting internal cyber controls. It calls for an ongoing understanding of operational dependencies, material risks and the organisations that support the delivery of essential services.
What is the SOCI Act?
The SOCI Act sets legal obligations for entities that own, operate or hold direct interests in specified critical infrastructure assets. It also provides measures through which the Australian Government may assist in responding to serious cyber incidents.
The Act covers 11 sectors:
- Communications
- Financial services and markets
- Data storage or processing
- Defense industry
- Higher education and research
- Energy
- Food and grocery
- Healthcare and medical
- Space technology
- Transport
- Water and sewerage.
The obligations applying to an organisation depend on its role, asset class and the relevant rules. Organisations should confirm their position using current Cyber and Infrastructure Security Centre guidance and seek legal advice where appropriate.
What are the main SOCI Act obligations?
The SOCI framework contains several obligations designed to embed risk management, preparedness and resilience into normal business operations.
1. Register of Critical Infrastructure Assets
Responsible entities and direct interest holders may need to provide operational and ownership information for the Register of Critical Infrastructure Assets. Accurate records help the Australian Government understand who owns and controls critical assets and how those assets operate.
Organisations need clear internal ownership of submissions and processes for updating information when relevant circumstances change. Accurate records help the Australian Government understand how critical assets are owned, controlled and operated.
2. Mandatory cyber incident reporting
Responsible entities must report certain cyber security incidents affecting critical infrastructure assets to the Australian Signals Directorate’s Australian Cyber Security Centre.
A cyber incident that has a significant impact on the availability of a critical infrastructure asset must generally be reported within 12 hours of the organisation becoming aware of it. Other incidents that have, are having or are likely to have a relevant impact must generally be reported within 72 hours. CISC provides further guidance on these reporting obligations.
Meeting these timeframes requires documented escalation routes, clear decision-making authority and reliable information about affected systems and third parties. Supplier contracts and incident response procedures should support prompt notification when an incident originates outside the organisation’s own environment.
3. Critical Infrastructure Risk Management Program
Where the obligation applies, a responsible entity must adopt, maintain and comply with a written Critical Infrastructure Risk Management Program, or CIRMP.
The program must identify material risks that could have a relevant impact on the asset and describe how those risks will be minimized or eliminated so far as reasonably practicable.
The risk domains include:
- cyber and information security
- supply-chain hazards
- personnel hazards
- physical security hazards and natural hazards.
A CIRMP must remain current and be supported by appropriate governance, review and reporting. This places supply chain risk within the same resilience framework as cyber security, personnel and physical security.
4. Enhanced Cyber Security Obligations
Critical infrastructure assets declared to be Systems of National Significance may be subject to Enhanced Cyber Security Obligations
These obligations may include:
- Developing cyber security incident response plans
- Undertaking cyber security exercises
- Conducting vulnerability assessments
- Providing system information to support a near real-time threat picture
These requirements are intended to improve preparedness for assets whose disruption could have serious consequences for Australia.
5. Notification of data service providers
Responsible entities must notify external data service providers when those providers store or process business-critical data relating to a critical infrastructure asset. This helps providers understand the importance and sensitivity of the information they manage, as well as any obligations that may apply to them.
Why cyber resilience depends on supply-chain resilience
An organisation can have mature internal cyber controls and still be exposed through a technology provider, contractor, logistics partner or specialist service provider.
Suppliers may have privileged access to systems, process sensitive information, support operational technology or provide services that are difficult to replace. In each case, their cyber resilience becomes part of yours.
The Critical Infrastructure Security Centre (CISC) highlights the interconnected nature of critical infrastructure: disruption in one area can have consequences across others. Supplier networks create a similar dependency. A cyber weakness several tiers away can quickly become your operational problem when that supplier supports a critical process, system or asset.
Managing supplier cyber risk increasingly requires a joined-up view across procurement, cyber security and operations. Organisations need to understand where critical dependencies lie, identify changes in supplier risk early and focus deeper assurance where the potential impact is greatest. The goal is not simply to assess whether a supplier meets cyber requirements, but to understand what that supplier means to the resilience of the wider business.
Why point-in-time supplier assessments are not enough
Questionnaires and onboarding checks remain valuable, but they reflect a supplier’s position at a particular moment. Between assessments, new vulnerabilities may emerge, ownership can change, financial pressure may affect controls or adverse information may indicate a developing concern.
- A more resilient approach combines assessment, continuous supplier risk monitoring and remediation:
- Map suppliers to critical assets, services and data.
- Segment suppliers according to their potential operational impact and access and replaceability.
- Assess higher-risk suppliers using proportionate due diligence and independent evidence.
- Monitor relevant cyber, financial, sanctions, adverse media and ESG risk indicators.
- Investigate alerts in context rather than treating every signal as equal.
- Agree remediation plans with accountable owners, actions and review dates.
- Collaborate with suppliers to improve controls and test incident response arrangements.
- Maintain evidence for governance reviews, assurance and regulatory reporting.
Continuous monitoring does not replace engagement. Its value lies in identifying change early enough for the organisation and supplier to respond together. When an issue is identified, a documented remediation plan should define the risk, required improvements, responsible parties, agreed timeframes and evidence needed for closure.
How Achilles can support SOCI compliance
Achilles helps organisations improve visibility and manage risk across complex supplier networks. Achilles Cyber Risk is provided in partnership with Orpheus Cyber, a UK Government-accredited cyber threat intelligence provider offering cyber risk ratings and threat intelligence services.
Achilles can support SOCI readiness and the ongoing delivery of a CIRMP by helping organisations:
- Establish consistent supplier prequalification and due diligence processes
- Assess cyber, financial, operational, ESG and compliance indicators
- Apply continuous risk screening across a broader supplier population
- Conduct independent desktop and onsite audits where deeper assurance is required
- Maintain traceable records of assessments, findings and improvement activity
- Produce management information for governance and risk reviews
Achilles does not replace an organisation’s legal interpretation, incident response capability or accountability under the SOCI Act. It provides supplier intelligence, assurance processes and a collaborative framework that can make supply chain risk management more consistent, current and actionable.
To learn how Achilles can help strengthen supplier visibility, cyber risk management and supply chain resilience, speak with our team or register for our upcoming session, Meeting SOCI Obligations in a Rising Threat Environment, featuring experts from Hall & Wilcox and Orpheus Cyber.