Financial Services·Superannuation·Government·Health·Education·Data Centre Providers·Care Services·Critical Infrastructure Operators·Growing Businesses
What we do · Critical infrastructure
Essential systems. Defensible position.

Critical infrastructure

Design, secure, and operate essential services across digital and operational systems. From scoping to live program, with safety before security, evidence and resilience together, and operator knowledge leading the controls.

The critical infrastructure moment

Essential services are now under a sharpening lens.

The rules for protecting critical infrastructure have changed the conversation. What was once technical is now board and shareholder business. Annual sign-offs, asset registers, hazard classes, and evidence packs are no longer optional. Threats against operational systems are rising. The controls haven't always kept pace. The gap between framework and reality is where the work lives.

Lumaris brings digital and operational systems under one roof. Safety before security. Evidence and resilience together. A risk-management plan designed to operate, not just to sign off. We start in the control room. We design controls operators will actually use.

The adversary doesn't care which framework you aligned to. Your board, the rules, and the citizens you serve do.
The CI portfolio

Four capabilities. One integrated CI practice.

Each capability stands alone. Together they take a responsible entity from first scoping to a mature risk-management plan. Digital and operational systems designed together.

— 01

Strategy & Advisory

Strategy, operating plans, policy frameworks, standards, and technology advice, tuned to the realities of essential services under regulation.

— 02

Security & Compliance

Risk-management plan work, hosting alignment, privacy, threat modelling, and the evidence pack that makes annual sign-off a routine rather than a crisis.

— 03

Systems Integration

Architecture across digital and operational systems. Operational technology services, infrastructure, networking, and integrated monitoring, designed to operate together.

— 04

Operations & Enablement

Project delivery, change, monitoring, knowledge, testing, and procurement support, the operating layer that keeps the risk plan alive.

The rules we work to

The critical infrastructure rules we work to.

We work to the major Australian and international rules for critical infrastructure. The SOCI Act sets the requirements. The CIRMP defines what responsible entities must do. IEC 62443 covers industrial control system security. The Essential Eight is the cyber baseline. ISO 27001 covers information security. The Australian hosting framework (ASD HCF) applies to sensitive workloads. Sector rules add their own layer for energy, water, telco, transport, and data storage. See the glossary for what each one covers and when it bites.
Outcomes, not deliverables

Outcomes you can take to a board.

Every engagement closes with artefacts a board or auditor can read on its own.

  • SOCI scope determination with hazard classes mapped to assets
  • Risk-management plan designed to operate: roles, cadence, accountability, and evidence
  • Digital and operational systems separation design, aligned to industrial security standards and operational safety
  • Operational systems readiness baseline with prioritised uplift, sized to risk and program
  • Annual sign-off evidence pack, refreshed quarterly, ready when asked
  • Crisis exercise outcomes with operator-led runbook updates
  • Sector-rule and government security gap closure plan
  • Board-ready closing brief and 90-day roadmap
Three ways to engage

Three ways to engage. Sized to where you are today.

— 01Start with a question

A focused 4–8 week review

Scope review, risk-plan readiness, or operational systems baseline. Fixed scope, price, end date.

  • Best when you know something needs to happen but aren't yet certain what
  • Board-ready closing brief
  • Prioritised fix-list and roadmap
  • Defined scope, fixed fee
— 02Start with a programme

A defined 8–16 week implementation

Risk-plan stand-up. Operational systems security uplift. Digital and operational systems brought together. Sign-off readiness.

  • Best when the answer is clear and the work is to make it real
  • Reference architecture and runbooks
  • Operator-led control design
  • Hand-over with continued support
— 03Start with advice

A principal advisor on retainer

Senior counsel for boards and executives working through the rules, the risk plan, and operational systems decisions. Monthly, quarterly, or to your cadence.

  • Best when you need a trusted hand over time
  • Board-ready risk briefings
  • Independent platform and vendor reviews
  • CI lead, fractional
Packaged CI engagements

Ten ways we scope the work.

Standardised forms our critical infrastructure work takes. Each is scoped and sized to deliver measurable outcomes, designed as a complete engagement in its own right and a natural step into deeper support where needed.

01

Critical Infrastructure Readiness Review

A clear, defensible picture of where you stand against the rules.

4–6 wks
02

Crisis Exercise & Tabletop Programme

Test your risk plan under load, safely, with the right people.

4–8 wks
03

Risk-Plan Assessment

Know exactly where you stand against the SOCI Act and your risk-management plan.

6–10 wks
04

Digital and Operational Systems Integration

Where to bring digital and operational systems together, and where safety says keep them apart.

6–16 wks
05

Risk-Plan Stand-up

From a documented risk plan to one that actually operates: people, cadence, accountability.

8–12 wks
06

Operational Systems Security Uplift

Raise the bar on operational systems security without taking essential services off-line.

8–16 wks
07

Operational Systems Security Pilot

Take a designed control from architecture into production at one site.

10–14 wks
08

Strategic Advisory Retainer

A trusted CI principal in your corner, sized to your cadence.

Rolling
09

Annual Risk-Plan Sign-off Support

Turn the annual sign-off from a scramble into a routine.

Rolling
10

CI Continuous Assurance

Standing evidence as a steady operating cadence rather than an annual scramble.

Rolling

Every packaged engagement is fixed-fee on a scoping call. Talk to us about your context and we will price it specifically.

The other four offerings

One framework. Five places to start.

Talk to us about your CI programme.

Tell us about your environment and we will be in touch within one business day.

Rise with confidence.