Critical infrastructure resilience - SOCI compliance
Practical approaches to achieving strategic and operational outcomes through strong risk, resilience and compliance management that goes beyond compliance for critical infrastructure operators
Thales supports critical infrastructure achieve positive business outcomes beyond compliance through tailored cyber advisory, risk management and compliance solutions.
What do you need to know about SOCI?
-
Check asset status
Review your current asset portfolio relative to the SOCI requirements and Cyber and Infrastructure Security Centre (CISC) guidance, consider if anything has changed over the last 12 months.
-
Identify critical assets
The Cyber and Infrastructure Security Centre will not engage with you directly to advise entities that they are critical infrastructure in most cases. You need to review the critical infrastructure asset rules to see if any of your assets are critical.
-
Prepare for attestation
Consider your timeframe for attestation and whether you have reviewed your assets, updated your risk management plan and have prepared your Board for attestation by 28th September 2025.
Annual attestation - Knowing your obligations
The Security of Critical Infrastructure Act 2018 (SOCI Act) imposes security and risk management obligations on entities in designated critical infrastructure sectors. Regulated entities must adopt an “all hazards” approach and manage material risks across four domains: personnel, cyber, physical and supply chain.
Entities must also complete an annual attestation on the adequacy of their Critical Infrastructure Risk Management Program (CIRMP). The next attestation is 28 September 2026; preparation should include reviewing CIRMP design and operating effectiveness and confirming Board oversight to support timely completion.
Understanding Australia’s security of critical infrastructure requirements
Practical approaches to performing positive security obligations
Meeting the requirements of the SOCI Act - including Positive Security Obligations (PSOs) and Enhanced Security Obligations (ESOs) - can be complex, especially given how deeply these rules impact the entire organisation.
A successful approach starts with clear stakeholder mapping and strong executive sponsorship to align security and business priorities. Understanding who the obligations apply to - from technical teams to business leaders - is key to building an effective, compliant security program.
SOCI data amendments
The Security of Critical Infrastructure Act 2018 (Cth) (SOCI) was amended in late 2024 to capture the data storage systems that hold business critical data of those organisations captured under the Critical Infrastructure regime. In practice, this will also require entities to consider the risks to those data storage systems that are holding business critical data as part of their CIRMP, according to guidance from the Cyber and Infrastructure Security Centre this must occur before 28 May 2025.
Obligation under SOCI Act | Practice Performance | Key Stakeholders |
|---|---|---|
Asset Registration (Part 2) | The asset registration process requires details of the assets’ ownership, location and operation to be lodged with the regulator through a web portal. Changes to ownership or operation require the portal record to be re-submitted within 6 months of the change. | GRC Site/Facility managers *Asset details should be identified to the SOC to support them in determining which assets are critical assets that have been registered to support cyber notification processes. |
Protected Information (Part 2) and Business critical data | Entity information security policy and information classification requirements should describe a process for defining, determining and managing protected information and business critical data and for engaging SOCI stakeholders if either data set is affected in an incident. For less mature organisations a definition of what constitutes these information types will be of value if policy does not already provide a table for information classification specifically covering these. | CISO/CIO |
Data provider notifications (12F((3)) | Business critical information to be defined. GRC to notify data centres that they hold critical infrastructure asset data/business critical information. | GRC |
High level guidance
The Security of Critical Infrastructure Act 2018 (Cth) (SOCI) was amended in late 2024 to capture the data storage systems that hold business critical data of those organisations captured under the Critical Infrastructure regime. In practice, this will also require entities to consider the risks to those data storage systems that are holding business critical data as part of their CIRMP, according to guidance from the Cyber and Infrastructure Security Centre this must occur before 28 May 2025.
-
Data storage systems
Review data storage systems to understand which systems are business critical, undertaking a gap analysis between your existing requirements and amended SOCI requirements and SOCI to understand any uplift requirements.
-
Business-critical systems
Review the risk environment surrounding your business-critical systems, including recent incidents, control testing and assurance reports, risk registers and outcomes of BCP testing, uplifting through risk workshops as required.
-
Business-critical data
Adopt a low compliance risk appetite approach and develop or redevelop your CIRMP, aligning with better practice across CI entities. Review your current definition and application of ‘Business Critical Data’ against the legislative definition found in Section 5 of SOCI.
Thales is a sovereign critical infrastructure entity with a long-standing record of delivering national security outcomes for Australia and, through the legacy of Australian Defence Industries, has supported sovereign capability for the ADF for more than 100 years; under the Deed, Thales and the Commonwealth share responsibility for sustaining industrial capability, strategic facilities and the secure handling of critical intellectual property in support of Australia’s defence and national security, positioning Thales to advise on tailored, outcomes-focused SOCI solutions that protect value without unnecessarily constraining value creation.
Our solutions to meet SOCI obligations