Skip to main content

Compliance - Critical infrastructure risk management, done as a process

The SOCI Act asks responsible entities to run a risk management program across all hazards, maintain it, and report on it. Most programs we review are scoped around cyber alone and were written once. We help operators build the version that holds up.

The Enhanced CIRMP Rules commenced in June 2026, with staged deadlines in June 2027 and June 2028. Cyber security framework compliance falls in the later one — and the framework most operators nominated is being retired on roughly the same schedule.

How we work with responsible entities

Four engagements, depending on whether you are building a program, checking one, aligning it to a framework, or proving it works.

Risk management program development

We build a CIRMP that covers all five hazard vectors, not just cyber, and that reads as a live process rather than a document written once.

  • Asset and boundary scoping
  • Material risk identification across all hazards
  • Interdependency mapping
  • Review and maintenance cadence

Program review and gap analysis

You have a program already. We assess it against the obligations and tell you where the evidence would not hold up.

  • Coverage assessment across hazard vectors
  • Evidence and operating-effectiveness testing
  • Findings ranked by exposure, not by ease
  • Remediation plan with owners

Framework nomination and alignment

Choosing which framework to nominate, mapping your current controls onto it, and finding what the mapping does not cover.

  • Essential Eight retirement: what to nominate instead
  • AESCSF maturity assessment
  • IEC 62443 and NIST 800-82 for OT environments
  • AS 7770 for rail operators

Incident response readiness

Building and exercising the response capability that enhanced obligations expect, before a declaration makes it urgent.

  • Incident response plan development
  • Tabletop exercises against realistic scenarios
  • Black Swan cascading-failure simulation
  • Post-exercise findings and plan revision

Scope - Two tiers, and most entities only carry one

Knowing which obligations apply to your assets decides what your program has to demonstrate, and how much of it you need now rather than later.

  • Positive security obligation. The baseline. If you are a responsible entity for a critical infrastructure asset, you adopt and maintain a risk management program, review it, and report annually. Nobody has to tell you it applies.
  • Enhanced cyber security obligations. Attach only to assets declared as Systems of National Significance. The declaration is private and the evidence burden shifts from having a program to showing it works under pressure.
  • All hazards, not just cyber. Cyber, personnel, physical, natural, and supply chain. A program that names four of these and addresses one is the most common finding we report.
  • A framework that will still exist. Five frameworks sit on the nomination list. Until now the criteria were fit and effort. With the Essential Eight being withdrawn, durability is a third one.

Background reading - What we have written on this

Longer analysis of the obligations, the frameworks, and where programs tend to fall short.

Start your cybersecurity education

Our offices

  • Global Operations
    Remote-first, worldwide delivery

Sign up for our newsletter

Stay informed about the latest OT/IT security threats, vulnerability alerts, and industry best practices.

O/IT Cyber Logo O/IT Cyber

© O/IT Cyber 2026