Security of Critical Infrastructure Act

Your CIRMP Assumesyou know what is reachable.

A Critical Infrastructure Risk Management Program is assembled from what you believe you operate. We establish what actually answers on the public internet — independently, passively, and without touching operational technology.

12 hoursTo report a critical incident to ASD
90 daysTo report your CIRMP, board-approved
4Hazard vectors your program must cover
3 monthsIsolation capability ASD now expects

Passive only — no systems, networks or accounts are accessed at any point.

A CIRMP Is Not a Document. It Is a Program.

The Security of Critical Infrastructure Act 2018 places its central requirement on the Critical Infrastructure Risk Management Program. A responsible entity must identify and manage material risks across four hazard vectors, have the program approved by its board or governing body, and report on it to the relevant regulator within 90 days of the end of the Australian financial year.

The four vectors:

Cyber and information security

The vector most operators assess, and the one where the evidence is thinnest. Identifying material risks to availability, integrity, reliability and confidentiality requires knowing what is reachable — which is an external question.

Supply chain

Your suppliers, their access, and the systems they hold on your behalf. From 4 April 2025 business critical data and the secondary systems holding it came into scope, which pulled a large number of providers into other organisations’ programs.

Personnel

Insider risk, vetting and access management. Not assessable from outside, and we say so rather than implying coverage we do not have.

Physical and natural hazards

Site security, environmental and natural hazard risk. Also outside the scope of a passive external assessment.

The clocksCritical cyber security incidents having a significant impact on the availability of the asset must be reported to the Australian Signals Directorate within 12 hours of becoming aware. Other reportable incidents, within 72 hours. The clock starts when you become aware — not when the investigation concludes. An asset you did not know was internet-facing is an asset you will become aware of late.

Programs Are Written From the Inside

A CIRMP is assembled from what the organisation believes it operates. Asset registers, architecture diagrams, system owner interviews, supplier contracts. Every one of those records intent. None records what actually answers on the public internet.

That gap is not theoretical. Across 2026, ASD issued advisory after advisory in which the operative instruction was the same: establish what is reachable from the internet, and reduce it. Internet-facing networking devices targeted by state actors since at least 2015. Management interfaces at service providers leading to customer compromise. Content management systems on forgotten domains. Almost none of it turned on a zero-day.

In July 2026 the point was made bluntly elsewhere: an attacker used valid credentials to enter Romania’s national land registry, mapped the network, attempted extortion, and when refused, deleted the database and its backups. Property transactions stopped nationwide. The agency had spent roughly 0.2 per cent of two decades of digitalisation investment on cyber security.

CI Fortify raises the bar againASD’s guidance released in late July 2026, aligned with a CISA initiative and following roughly twelve months of industry consultation, asks critical infrastructure operators to be capable of running essential services in complete isolation for three months. Its list of coupling points is the useful part: shared routing and switching, common virtualisation and storage, Active Directory, DNS, DHCP, certificate services — and Network Time Protocol. Dependencies that appear on no architecture diagram, and which quietly determine whether isolation is achievable at all.

What a BlackFlag Advisory SOCI Assessment Covers

  • External asset discovery — every hostname, subdomain and internet-facing service attributable to your entities, drawn from certificate transparency, passive DNS and public source aggregation, including assets that appear on no register
  • Internet-facing management and administrative interfaces — the specific asset class named repeatedly in ASD’s 2026 advisories
  • Network edge exposure — routers, firewalls, VPN gateways and SD-WAN controllers, the equipment targeted by the state actors named in the July 2026 joint advisory
  • Technology and version fingerprinting, triaged with the CISA Known Exploited Vulnerabilities catalogue, EPSS and SSVC decision points so findings arrive as decisions rather than a severity count
  • Credential exposure where your identities, or your suppliers’, appear in published breach and infostealer corpora
  • Supply chain surface — the providers holding your business critical data, assessed from outside and without their cooperation
  • Hazard vector mapping to the two vectors an external assessment can honestly evidence, with an explicit statement of the two it cannot
Passive Only — No Systems AccessedEvery BlackFlag Advisory assessment uses exclusively passive OSINT techniques against publicly available sources. No systems, networks or accounts are accessed, probed or tested at any point. Nothing we do can reach operational technology. No change window, no authorisation to test, and no operational risk.

Who This Is For

Energy, water and sewerage operators

Among the first asset classes brought into the CIRMP obligation, and the sectors where an outage is measured in public consequence rather than revenue.

Transport, ports and freight

Captured by asset definition rather than by size. Several operators carry obligations without having registered the fact.

Food and grocery

A SOCI sector since the 2021 reforms. Two Mackay sugar mills halted operations after a cyber incident in June 2026 — production stopping, not data leaving, was the damage.

Health care and medical

Carrying SOCI obligations alongside Privacy Act and My Health Record obligations, with three regulators interested in the same estate.

Data storage or processing providers

Business critical data and the secondary systems holding it came into CIRMP scope from 4 April 2025. If you hold data for a responsible entity, their obligation reaches you.

Systems of National Significance

Where enhanced cyber security obligations apply on top of the CIRMP, including vulnerability assessment requirements.

How the Engagement Runs

Five steps. The only ones that require your time are the first and the last.

1. Confirm what is in scope

We agree the entities, domains and internet-facing estate to be assessed, and which of your asset classes the findings should be mapped against.

2. Passive collection

We observe what your organisation exposes using publicly available sources only. No systems, networks or accounts are accessed. Nothing touches operational technology, so no change window is required.

3. Hazard vector mapping

Findings are mapped to the two CIRMP hazard vectors an external assessment can honestly evidence — cyber and information security, and supply chain. We state plainly what we did not assess.

4. Board-ready output

Your CIRMP report must be approved by the board or governing body. The report is written so the evidence behind that approval is legible to the people signing it.

5. Delivery and walkthrough

A dual-audience report and a walkthrough. We remain available for the questions that follow, including from your regulator.

Frequently Asked Questions

The questions we are asked most often by responsible entities, their risk leads and their boards.

Which assets are captured by the SOCI Act?

The Security of Critical Infrastructure Act 2018 covers eleven sectors including energy, water and sewerage, transport, food and grocery, health care and medical, communications, financial services and markets, data storage or processing, defence industry, higher education and research, and space technology. Capture depends on the specific asset definition rather than the sector alone, and many operators are captured without having registered the fact.

What does a CIRMP have to cover?

A Critical Infrastructure Risk Management Program must identify and manage material risks across four hazard vectors: cyber and information security, personnel, supply chain, and physical and natural hazards. It must be written, operational rather than templated, approved by the board or governing body, and reported to the relevant regulator within 90 days of the end of the Australian financial year.

What are the incident reporting timeframes?

Critical cyber security incidents having a significant impact on the availability of the asset must be reported to the Australian Signals Directorate within 12 hours of becoming aware. Other reportable cyber security incidents must be reported within 72 hours. The clock starts when you become aware, not when the investigation concludes.

Does this replace a CIRMP or an AESCSF assessment?

No. A passive external assessment produces evidence for two of the four hazard vectors — cyber and information security, and supply chain — from outside your organisation. It does not assess personnel or physical and natural hazards, and it does not write your CIRMP. It is designed to sit underneath the program as independent evidence.

Do you need access to our OT or control systems?

No, and that is the point. BlackFlag Advisory assessments are passive only. No systems, networks or accounts are accessed, probed or tested at any point. Nothing we do can touch operational technology, so no change window, no authorisation to test, and no operational risk.

Packages and pricing are set out on the assessment packages page. To scope an engagement against your asset classes, book a short call.

Assessed Against the Obligation
You Actually Carry

Every engagement is the same passive methodology. What changes is the framework the findings are mapped to, and the audience the report is written for.

AI Governance
AI Governance Assessment

Find the AI you are running, not the AI you declared — exposed model endpoints, MCP servers and shadow deployments, mapped to ISO/IEC 42001.

View Assessment →
APRA CPS 234
CPS 234 Assessment

Independent external exposure evidence mapped clause by clause to the APRA prudential standard — for your Board and internal audit function.

View Assessment →
ASD Essential Eight
Essential Eight Assessment

Externally verified evidence against the mitigation strategies that can honestly be assessed from outside — and an explicit statement of those that cannot.

View Assessment →
Privacy Act & APPs
Privacy Act & APP 11 Assessment

What your organisation exposes, mapped to the Australian Privacy Principles — including tracking, consent sequencing and overseas disclosure.

View Assessment →
Supply Chain
Third-Party Risk Assessment

What your suppliers actually expose, observed from outside without their cooperation. Evidence rather than questionnaires.

View Assessment →
AML/CTF Tranche 2
Tranche 2 Cyber Assessment

For law firms, accountants, conveyancers and agencies now holding seven years of client identity documents under obligations that commenced 1 July 2026.

View Assessment →

Your Program Assumes
You Know What Is Reachable.

A BlackFlag Advisory assessment gives your board the independent external evidence a CIRMP assumes but rarely contains — without a single system being accessed.

Request an Assessment →
Assessments
AI Governance CPS 234 Essential Eight Privacy Act & APP 11 Third-Party Risk Tranche 2 Cyber Obligation Tool →
Intelligence
All briefings Romania land registry Tranche 2 commenced ASD advisories, 2026
Practice
GRC Partnerships Pricing Privacy
Start
Threat Scan Enquire Sample report