Security

SOCI Act CIRMP: AI for Critical Infrastructure

SOCI Act CIRMP: AI for Critical Infrastructure

Abstract visualisation of interconnected critical infrastructure assets monitored by security shields and data flows

Australia's approach to protecting critical infrastructure has shifted decisively from a tick-box annual exercise toward continuous, evidence-driven risk management. Under the Security of Critical Infrastructure Act 2018 (the SOCI Act), responsible entities for regulated critical infrastructure assets have been required to adopt and maintain a Critical Infrastructure Risk Management Program (CIRMP) since 2023, with the cyber hazard requirement switched on from 17 August 2024.

The direction of travel is now clear. In December 2025 the Department of Home Affairs released a consultation paper on enhancements to the CIRMP Rules, and an Exposure Draft of the amended Rules followed on 25 March 2026 for a second round of consultation. The proposed changes make expectations around material risks more explicit and more prescriptive across cyber, supply chain, and personnel security. The underlying message to operators in energy, water, transport, data storage and processing, health care, and food and grocery is that an annual attestation is no longer the goal. Demonstrable, ongoing control is.

For the CISO or risk officer at a midsize operator, this raises a hard operational question. How do you produce continuous, defensible evidence across four hazard domains without expanding the security team faster than the budget allows? This is precisely the gap where AI, applied carefully and with humans accountable, does real work.

What the CIRMP actually requires

A CIRMP is a documented program that requires a responsible entity to identify and manage the material risks of "hazards" that could affect the availability, integrity, reliability, or confidentiality of a critical infrastructure asset. The Rules group those hazards into four domains:

  • Cyber and information security hazards
  • Personnel hazards (the trusted insider risk)
  • Supply chain hazards
  • Physical security and natural hazards

For the cyber domain, responsible entities subject to the requirement must apply one of a set of recognised cyber security frameworks. The Rules point to established standards such as the Australian Energy Sector Cyber Security Framework (AESCSF), ISO/IEC 27001, the NIST Cybersecurity Framework, and the Australian Cyber Security Centre's Essential Eight, or an equivalent framework. The point is alignment to a recognised baseline, not a bespoke invention.

On top of the CIRMP itself, the SOCI Act imposes mandatory cyber incident reporting: critical incidents must be reported to the Australian Signals Directorate within short, legislated timeframes, with a longer window for other reportable incidents. A board-approved annual report on the CIRMP must also be submitted to the regulator. Miss any of these and you are exposed not just to penalties but to the operational consequences of an incident you were not watching for.

If your organisation has built its security posture around the general cyber security requirements for Australian businesses, the SOCI Act adds a higher, asset-specific bar, with a regulator, the Cyber and Infrastructure Security Centre, that expects evidence rather than intent.

Are you a responsible entity?

The first task is establishing whether you hold a regulated critical infrastructure asset and are therefore a responsible entity. The asset classes are defined by sector. The guide below is a starting filter only; confirm against current CISC guidance and legal advice.

SOCI Act Applicability Check

Does your organisation operate assets in a regulated sector?
Electricity, gas, liquid fuels, energy market operation
→ Likely a responsible entity: CIRMP obligations apply
Water, sewerage, transport, ports, aviation
→ Likely a responsible entity: assess each asset
Data storage or processing for government or critical sectors
→ Potentially in scope: check the asset definition
Health care, food and grocery, communications
→ Potentially in scope: confirm thresholds
No regulated assets, but you supply one
→ Out of direct scope, but expect supply chain due diligence

The last row matters for a large set of midsize businesses. Even if you are not a responsible entity, your customers who are will increasingly push SOCI-driven supply chain requirements onto you. Being able to demonstrate strong controls becomes a commercial qualifier, not just a compliance one.

From annual attestation to continuous assurance

The hardest part of the new direction is not writing the CIRMP. It is keeping the evidence behind it live all year. Most operators can produce a credible document. Far fewer can show, on any given day, that the controls described in that document are actually operating.

Point-in-Time vs Continuous Assurance

Metric
Annual Attestation
Continuous Assurance
Improvement
Control evidenceGathered once a yearCaptured continuouslyAlways current
Risk visibilitySnapshotLiveReal-time
Audit preparationWeeks of scrambleQuery the systemMajor
Time to detect driftMonthsDaysMaterial
Board reporting confidenceBest estimateEvidence-backedDefensible

The figures above describe the typical difference in posture, not a specific measured result. The shift the regulator is signalling, away from periodic snapshots and toward continuous, evidence-driven management, is exactly the gap that automation closes.

Where AI does real work across the four hazard domains

AI is not a control framework, and it does not replace the accountable executive who signs the annual CIRMP report. What it does well is the high-volume, exception-driven monitoring and evidence work that humans cannot sustain manually across four domains and dozens of controls. Four applications stand out.

1. Continuous cyber control monitoring

The cyber domain generates enormous volumes of signal: configuration states, patch levels, access events, alerts. AI is well suited to continuously checking the actual state of controls against the framework baseline you have adopted, whether that is the Essential Eight, ISO/IEC 27001, or the AESCSF, and flagging drift the moment a control slips out of its expected state.

AI-Assisted Continuous Control Monitoring

Ingest
Pull control state from across systems
Assess
Compare against the framework baseline
Detect
Flag drift and emerging anomalies
Escalate
Route material risks to the right owner
Evidence
Log a timestamped, auditable trail

The evidence step is the quiet hero. When the regulator asks how you know a control was operating in March, the answer is a query, not an archaeology project. This is the same continuous, auditable approach we describe for automated compliance reporting.

2. Supply chain risk monitoring

Supply chain is one of the domains the proposed amendments target most directly, and it is the hardest to manage manually because the risk lives outside your perimeter. AI helps maintain a live view of your material suppliers: monitoring for adverse signals, tracking the security posture attested by vendors, and flagging concentration risk where too many critical functions depend on a single provider. This extends the discipline of structured AI vendor onboarding into ongoing, year-round oversight rather than a one-time questionnaire.

3. Personnel and insider risk signals

The personnel domain covers the trusted insider. AI can support, never replace, human judgement here by correlating access patterns and behavioural signals to surface anomalies for review by a human investigator. The governance bar is high: this is sensitive employee data, and any system touching it must respect the Privacy Act and clear human-override controls, exactly as set out in our AI governance framework.

4. Evidence assembly and the annual report

Pulling the annual CIRMP report together is a major effort: collating evidence across four domains, summarising material risks, and producing a document the board can approve with confidence. AI can draft the narrative and assemble the supporting evidence from the monitoring trail, leaving security leaders to verify and exercise judgement. The accountable executive still signs; the assembly burden shrinks.

The roadmap to continuous assurance

Operators do not get to continuous assurance in one step. A staged roadmap keeps the program credible while you build capability.

Path to Continuous CIRMP Assurance

1
Stage 1
Baseline
Map assets, adopt a recognised cyber framework, document the CIRMP across all four hazard domains
2
Stage 2
Instrument
Connect control data sources so evidence can be collected automatically
3
Stage 3
Monitor
Layer AI-assisted continuous monitoring and drift detection on the instrumented controls
4
Stage 4
Assure
Generate evidence-backed board and regulator reporting on demand

Most midsize operators are somewhere between Stage 1 and Stage 2. The good news is that the instrumentation work in Stage 2, connecting your existing systems so control data flows into one place, is largely a system integration exercise that pays for itself well beyond compliance.

The cost and risk picture

The economics of continuous assurance are driven less by software cost and more by avoided incidents and avoided audit scramble. For an operator running critical assets, the downside of a control failure is measured in outage, safety, and regulatory exposure, not just remediation hours.

Indicative Annual Impact of Continuous Assurance

Audit and report preparation time saved~200-400 hours
Faster detection of control driftMonths to days
Avoided cost of a preventable incidentSignificant
Lower regulatory and penalty exposureMaterially reduced

Treat these as a planning framework rather than a promise. The defensible business case for SOCI investment is rarely "save hours". It is "reduce the probability and cost of the incident that takes a critical asset offline", with the efficiency gains as a welcome second order benefit.

The traps to avoid

Three failure modes recur when operators bolt AI onto critical infrastructure security.

Sending sensitive control data offshore. Critical infrastructure telemetry, vulnerability data, and personnel signals are among the most sensitive data your organisation holds. Routing them through public AI services hosted overseas can create both a sovereignty problem and a fresh attack surface. The defensible pattern is to keep this data onshore in private AI infrastructure you control, which is the central argument of our data sovereignty guide.

Treating AI output as a determination. AI can detect drift and draft reports, but the accountable executive owns the CIRMP and signs the annual report. Any workflow that lets AI silently close a risk, or auto-approve a control state, removes the human accountability the SOCI Act assumes. Keep AI in an advisory, evidence-producing role with humans deciding.

Automating an immature program. Layering continuous monitoring on top of poorly defined controls just produces faster noise. Get the framework baseline and the documented CIRMP right first, then instrument and automate. The order matters.

If you are scoping tools, the structured approach in our 50-point AI security checklist maps neatly onto the diligence a SOCI-regulated operator needs before deploying any AI system in a security-critical role.

Meeting the incident reporting clock

The CIRMP is only half of the SOCI obligation. The Act also requires mandatory reporting of cyber security incidents affecting critical infrastructure assets, with critical incidents reportable within a short legislated window and other significant incidents within a longer one. For most operators, the practical problem is not the decision to report. It is detecting the incident, triaging its severity, and assembling the facts fast enough to meet the clock.

This is where continuous monitoring and incident reporting reinforce each other. An operator that already collects control state and telemetry continuously is far better placed to detect an incident early, classify it against the reporting threshold, and pull together the chronology a report requires. AI assists by correlating signals across systems, flagging the events that may cross the reporting threshold, and drafting the factual timeline for a human to verify before lodging. The accountable security leader still decides whether and what to report; the system removes the scramble that causes late filings.

Operators should rehearse this. A tabletop exercise that runs a simulated incident through detection, classification, and reporting against the legislated timeframes exposes the gaps long before a real incident does. The monitoring instrumentation you build for the CIRMP is the same foundation that makes the incident reporting clock achievable.

What the board needs to see

Because the annual CIRMP report must be approved at board or governing-body level, the program ultimately has to translate into something a non-specialist director can understand and sign with confidence. Directors are increasingly aware that they carry personal accountability for the organisation's risk posture, and they are no longer satisfied with a green dashboard and a verbal assurance.

What works is a concise, evidence-backed view: the material risks across the four hazard domains, the controls in place, where those controls are operating as designed, and where there is drift or an accepted residual risk with a remediation plan. AI helps assemble this view from the underlying evidence, but the value to the board is precisely that the summary is traceable back to real, timestamped records rather than to optimistic self-assessment. A board that can see the evidence behind the assurance is a board that can sign the report without quietly carrying unquantified risk.

The bottom line

The SOCI Act and its evolving CIRMP Rules are steering critical infrastructure operators away from once-a-year attestation toward continuous, evidence-driven assurance across cyber, supply chain, personnel, and physical hazards. That is a higher bar, and for a midsize operator it is not realistically met by adding headcount alone. AI, kept in an advisory and evidence-producing role with sensitive data held onshore and humans accountable for every decision, is what makes continuous assurance affordable.

Build the program on a recognised framework first. Instrument your controls so evidence flows automatically. Then use AI to watch for drift, monitor your supply chain, and assemble the reporting that lets your board and the regulator see, at any moment, that your controls are actually working.


Related reading

Ready to move from annual attestation to continuous assurance? Explore our system integration services or learn how private AI infrastructure keeps critical infrastructure data onshore and under your control.