How we help · Critical Infrastructure Operators
For SOCI-regulated asset owners and operators

The asset is critical by law. The obligations follow the asset, not the intent.

Energy, water, transport, ports and communications operators sit inside the Security of Critical Infrastructure Act's positive security obligations whether or not security was ever the core business. A designated asset carries a risk-management programme requirement, mandatory cyber incident reporting, and, for the most significant assets, enhanced obligations that reach the board. Lumaris helps operators turn a legal designation into a workable, board-defensible security programme rather than a compliance exercise bolted onto operational technology that was never built for it.

Why this is on the agenda now

Three forces every asset owner is navigating at once.

— 01

The obligation follows the asset, not the sector you think you're in

The SOCI Act designates critical infrastructure assets across eleven sectors, from energy and water to ports and communications. An operator can be captured by the Act without ever having thought of itself as a security-first organisation.

— 02

Positive Security Obligations reach into operational technology

The Critical Infrastructure Risk Management Program obligation and mandatory cyber incident reporting apply to the systems that run the physical asset, not just the corporate network. Most OT environments were never designed for this level of assurance.

— 03

Systems of National Significance carry a materially higher bar

The most critical assets face Enhanced Cyber Security Obligations: incident response planning, cyber security exercises, vulnerability assessments and, in some cases, government-installed system information software. Board and executive accountability follows.

How we work with operators

Capabilities tuned to the physical-digital boundary.

OT data platforms and AI-assisted monitoring

Bringing SCADA, ICS and sensor telemetry into a single, queryable data platform, with AI-assisted anomaly detection layered on top so operational technology gets active monitoring, not just a compliance paper trail.

Critical Infrastructure Risk Management Program design

Risk-management programmes covering cyber, personnel, supply chain and physical/natural hazards, built to the SOCI rules and ready for regulator and board scrutiny.

Mandatory cyber incident reporting readiness

Detection, triage and reporting pathways designed to meet SOCI's incident notification timelines to the Australian Signals Directorate, tested before an incident forces the pace.

OT and IT convergence security

Segmentation, monitoring and access design for environments where operational technology, once air-gapped by assumption, now shares infrastructure with corporate and cloud systems.

Systems of National Significance readiness

Enhanced Cyber Security Obligation uplift: incident response planning, exercise programmes and vulnerability assessment for the assets carrying the highest designation.

Supply chain and third-party risk

Assurance programmes for the vendors, maintenance contractors and managed service providers with access to critical operational systems.

The landscape we read

Where operators get exposed.

The gaps that surface once an asset is designated and the obligations start to bite.

Operational technology

OT environments assured for uptime, not for the obligations now attached to them

Control systems, SCADA and industrial networks were built for reliability and safety, on the assumption of isolation. Positive Security Obligations now ask for cyber assurance across systems many operators have never formally assessed.

  • Legacy OT with limited native security or logging capability
  • IT/OT convergence points added faster than security controls kept pace
  • Incident detection tuned for safety events, not cyber events
Governance and accountability

Board-level obligations without board-level visibility

Risk-management programme obligations and, for the most critical assets, personal director accountability mean the board is now a stakeholder in operational technology risk it may never have reported into before.

  • No standing risk-management programme reporting cadence to the board
  • Unclear ownership between IT, OT and physical security functions
  • Incident response plans that have not been exercised against a realistic scenario
Supply chain

Third parties with deep access and shallow assurance

Maintenance contractors, equipment vendors and managed service providers frequently hold privileged access to operational systems, often with less scrutiny than the operator applies to its own staff.

  • Vendor remote access without consistent security baselines
  • Equipment and firmware supply chains difficult to assess for provenance
  • Managed service providers operating outside the operator's own monitoring
Proof points

Outcomes a board and a regulator will accept.

  • OT data platform with AI-assisted anomaly detection across SCADA and ICS telemetry.
  • Critical Infrastructure Risk Management Program approved by the board and mapped to the SOCI rules.
  • Mandatory cyber incident reporting pathway tested against realistic OT and IT scenarios.
  • OT/IT segmentation and monitoring design for converged operational environments.
  • Systems of National Significance readiness assessment against the Enhanced Cyber Security Obligations.
  • Third-party and supply chain assurance programme for critical operational access.
The rules we work to

The rules we work to.

We work to the Security of Critical Infrastructure Act 2018 (as amended by the SLACI and SLACIP Acts) and its Positive Security Obligations: the critical infrastructure asset register, the Critical Infrastructure Risk Management Program rules, and mandatory cyber incident reporting to the Australian Signals Directorate. For assets designated as Systems of National Significance, we work to the Enhanced Cyber Security Obligations that sit above the baseline. See the glossary for what each one covers and when it bites.
Latest insights

Recent articles for critical infrastructure operators.

All insights →
Where this sector usually starts

Service offerings most relevant to critical infrastructure operators.

Other sectors we work with

8 other sectors. Same converged practice.

Talk to us about your critical infrastructure asset.

Tell us about your environment and we will be in touch within one business day.

Rise with confidence.