What Australian Security Leaders Are Prioritising as SOCI Act Obligations Mature
As SOCI Act risk management programme obligations mature, Australian critical infrastructure boards and CISOs are moving from tick-box Essential Eight uptake towards risk-based maturity and demonstrable governance.
Direct answer
Australian security leaders are moving past initial SOCI Act compliance and into a harder second phase: proving that their risk management programmes actually work, not just that they exist on paper. Boards and CISOs are prioritising risk-weighted Essential Eight uptake, defensible evidence trails, and board-level accountability over generic maturity scores. Procurement and risk teams are, in turn, asking providers to demonstrate ongoing assurance rather than a single point-in-time assessment.
What regulators and frameworks expect
The regulatory expectation in Australia has shifted from "adopt a framework" to "run a programme and evidence it continuously." This is visible across the four areas most critical infrastructure entities now have to satisfy.
SOCI Act risk management programme obligations
There are three positive security obligations that can apply to all critical infrastructure assets, depending on their asset class: providing operational and ownership information to the Register of Critical Infrastructure Assets, reporting cyber incidents which impact the delivery of essential services to the Australian Cyber Security Centre, and adopting, maintaining and complying with a written risk management programme. The risk management programme obligation is the one occupying the most board time now, because Part 2A of the SOCI Act provides that a responsible entity for one or more of the specified critical infrastructure assets must have, and must comply with, a written CIRMP, unless an exemption applies.
Critically, this is not a document exercise. In its CIRMP, the responsible entity must identify material risks — each hazard where there is a material risk that the occurrence of a hazard could have a relevant impact on the asset — and minimise and eliminate that material risk, so far as is reasonably practicable. The scope is also broader than most technical teams initially assume: CIRMP requirements extend beyond cyber to include personnel, supply chain, and physical security risks, requiring a coordinated and continuously updated risk management approach aligned to recognised frameworks.
The obligation is ongoing by design. These are all ongoing obligations, so compliance is not achieved through a one-time assessment but through continuous risk governance and operational oversight. That single point is why so many programmes built for the initial compliance deadline are now being reworked — a static risk register and a one-off framework mapping do not satisfy a requirement built around continuous review.
Essential Eight: from baseline to risk-weighted maturity
The Essential Eight remains the most commonly referenced technical baseline for Australian organisations, but its role in a mature SOCI programme is narrower than many boards assume. The Australian Cyber Security Centre has developed prioritised mitigation strategies, in the form of the Strategies to Mitigate Cyber Security Incidents, to help organisations mitigate cyber security incidents caused by various cyber threats, and the most effective of these are known as the Essential Eight. The ACSC recommends all Australian organisations implement the Essential Eight mitigation strategies as a baseline.
Each strategy is assessed against a defined maturity model. The maturity levels are defined as: Maturity Level Zero, meaning minimally aligned with the intent of the mitigation strategy; Maturity Level One, partly aligned; Maturity Level Two, mostly aligned; and Maturity Level Three, fully aligned with the intent of the mitigation strategy. Originally built for federal agencies, the Essential Eight has since become widely adopted by private-sector organisations as a practical, technically focused baseline to defend against common threats, especially ransomware, malware, and unauthorised access.
The tick-box failure mode is uneven maturity: strong controls in one or two areas masking weak coverage elsewhere. Assessors and boards are increasingly alert to this. Achieving genuine maturity across the Essential Eight requires consistent implementation across all eight strategies — gaps in even a single area weaken the overall security posture. A mature security leader treats the Essential Eight as one input into a risk-based programme, not the programme itself — the target maturity level for each strategy should be set by the criticality of the asset it protects, not by a blanket organisation-wide target.
APRA CPS 234, where it applies
For entities that are also APRA-regulated — banks, insurers, superannuation trustees, and related critical infrastructure operators in the financial sector — Prudential Standard CPS 234 sits alongside SOCI obligations and reinforces the same direction of travel: from control existence to demonstrated capability. The standard requires senior management to establish and maintain a comprehensive security policy framework, manage cyber risk, implement robust security controls, and define clear accountability for security roles and responsibilities. Third-party risk is explicit in the standard: entities are expected to assess whether their third parties have the resources, skills, and controls needed to protect the information assets they manage. Regular testing and independent verification of controls for information technology assets are also a key requirement under CPS 234 to ensure ongoing compliance.
OAIC and the privacy overlay
Where a security incident also involves personal information, the Notifiable Data Breaches scheme applies independently of SOCI reporting. Under the Notifiable Data Breaches scheme, any organisation or agency the Privacy Act 1988 covers must notify affected individuals and the OAIC when a data breach is likely to result in serious harm to an individual whose personal information is involved. Entities have a defined window to make that call: organisations must conduct a reasonable and expeditious assessment of a suspected eligible data breach, taking all reasonable steps to ensure that the assessment is completed within 30 days. Mature programmes now map SOCI incident reporting and Notifiable Data Breaches obligations together, rather than treating them as separate compliance tracks triggered by different teams.
How to prepare: what security leaders are actually doing
Across the boards and risk committees we work with, the shift from tick-box compliance to genuine maturity tends to show up in the same set of changes.
← Swipe to compare →
| Focus area | Tick-box compliance (early SOCI adoption) | Risk-based maturity (current expectation) |
|---|---|---|
| Essential Eight target | One organisation-wide maturity target applied uniformly | Maturity target set per asset, weighted to criticality and exposure |
| CIRMP evidence | A written programme document, reviewed annually | Continuously updated risk register with logged decisions and remediation dates |
| Board reporting | A compliance status slide, pass or fail | Trend data, residual risk, and named accountability for open items |
| Third-party assurance | Signed vendor questionnaire at onboarding | Ongoing evidence review aligned to CPS 234-style third-party expectations |
| Incident reporting readiness | Contact details on file for ACSC reporting | Rehearsed workflow linking SOCI, Notifiable Data Breaches, and internal escalation |
In practical terms, that translates into a small number of concrete actions for a security lead:
- Re-baseline the CIRMP against actual asset criticality rather than a generic template, so material risks are identified per asset class as the SOCI Act requires.
- Set differentiated Essential Eight maturity targets, reserving the highest maturity levels for the systems that genuinely warrant them, and document the rationale.
- Build a single evidence pack that a board member, an APRA examiner, or an ACSC liaison could all read without translation — consistent risk language, dated remediation actions, and named owners.
- Rehearse the incident notification pathway end to end, including where SOCI cyber incident reporting to the ACSC and Notifiable Data Breaches obligations to the OAIC intersect.
- Extend third-party assurance beyond onboarding, with periodic evidence reviews of supplier controls rather than a one-off attestation.
Questions procurement and risk leaders should be asking providers now
- Can you show evidence of continuous CIRMP review, not just the original document?
- How do you determine which Essential Eight maturity level is appropriate for a given asset, and can you justify that decision to a regulator?
- What does your third-party assurance process look like after the initial engagement — is it periodic or one-off?
- How is board reporting structured, and does it show trend and remediation status, or only a current-state score?
- Is your incident reporting workflow integrated across SOCI and privacy obligations, or handled by separate teams with separate triggers?
A CIRMP that only exists to satisfy an annual reporting deadline will not hold up under sustained regulatory scrutiny — the obligation is designed to be lived, not filed.
How Infracom helps
Infracom Consultancy Integration Pte Ltd is an ISO 27001-certified cybersecurity consultancy that helps critical infrastructure operators and their suppliers build risk management programmes that hold up to regulatory scrutiny, not just internal sign-off. Our governance, risk and compliance work covers CIRMP evidence structuring, Essential Eight maturity assessments weighted to asset criticality, and board reporting design aligned to how regulators such as the ACSC and OAIC actually assess maturity. Read more on our governance, risk and compliance services page.
Sources (7)
- Critical infrastructure
- Federal Register of Legislation
- Office of the Australian Information Commissioner
- Australian Prudential Regulation Authority
- SOCI Act regulatory obligations
- Specified responsible entities must become compliant with the risk management program obligation
- Information security requirements for all APRA-regulated entities
Get Infracom Insights by email
Practical cybersecurity governance and regulatory updates for Singapore and Australia. No more than a few emails a month; unsubscribe any time.
