Site icon GM Group Services

The 5 Shocking Truths About the Security of Critical Infrastructure Act 2018

The security of critical infrastructure act 2018 (SOCI Act) is a pivotal piece of Australian legislation designed to safeguard the essential services our country depends on. It's a comprehensive framework to protect these services from an array of modern threats, including sophisticated cyber-attacks, physical sabotage, and insider risks from personnel. In essence, the Act mandates that owners and operators of critical assets proactively manage security, report significant incidents swiftly, and maintain a register of their assets with the government. For many businesses, understanding and complying with the security of critical infrastructure act 2018 is no longer optional—it's a legal necessity.

Understanding the Security of Critical Infrastructure Act 2018

If you’re running events, managing large venues, or overseeing construction and retail sites, you might mistakenly believe the SOCI Act is something only major energy companies or telcos need to worry about. That's a common and risky assumption. This legislation has fundamentally reshaped how Australian businesses must approach risk, and its scope is far broader than most people realize. It's not a set of recommendations; it’s a direct legal requirement to protect the very systems our modern society is built on.

Originally, the Act was much narrower. But as our understanding of interconnected national security threats has grown, the legislation has expanded right alongside it. The fundamental goal is to make sure our essential services—everything from power and water to communications and transport—can withstand and recover from any hazard thrown at them.

The Big Shift to Proactive Security

One of the most significant changes the SOCI Act introduced was the Positive Security Obligations (PSOs). This might sound like legal jargon, but the concept is simple: it legally shifts the focus from a reactive mindset (waiting for something to go wrong and then fixing it) to a proactive one (actively preventing it from happening in the first place).

So, what does this mean in practice for a site manager or event organiser? It means you are now legally obligated to:

This forward-thinking approach is no longer just good practice. It’s a mandatory part of doing business if your operations touch any of Australia’s critical systems.

A Rapidly Expanding Net

When the SOCI Act was first passed in 2018, it only covered four key sectors. But things have changed—dramatically. To keep up with evolving threats, the government introduced major reforms.

Here's a quick look at how the Act grew.

SOCI Act Expansion at a Glance

Milestone Effective Year Key Change
Initial Act 2018 Focused on 4 sectors: electricity, gas, water, and ports.
Major Expansion 2022 The Security Legislation Amendment (Critical Infrastructure Protection) Act 2022 expanded the framework to cover 11 critical sectors and 22 asset classes.

This expansion was a game-changer. Suddenly, the net was cast wide enough to include data centres, major hospitals, food and grocery suppliers, and critical transport services. You can get a deeper understanding of Australia's critical infrastructure act reforms and their business impact on the official government site.

This massive expansion means thousands of businesses that were never on the regulatory radar before now have to get up to speed. Ignoring these obligations isn't an option, as the penalties for non-compliance are severe. It's now absolutely vital to work out exactly how these rules apply to you.

Determining If the SOCI Act Applies to You

The Security of Critical Infrastructure Act 2018 (SOCI Act) can feel overwhelming, but determining its applicability comes down to one core question: do you own, operate, or have a direct interest in an asset that Australia considers 'critical'? The definition is much wider than you might think, going far beyond just power stations and ports.

It’s not just about what you do, but also what you depend on.
Practical Example: A large shopping centre, on its own, might not seem like critical infrastructure. But because it houses a major supermarket, it is now considered a critical food and grocery asset and falls squarely under the Act.

The same logic applies to events. A major music festival relies on a steady power supply and robust communication networks for everything from ticketing to emergency services. This reliance on the energy and communications sectors can pull the event organiser under the SOCI Act's umbrella. It all comes back to the role an asset plays in keeping our community and economy running.

Understanding the 11 Critical Sectors

The government has sorted critical infrastructure into 11 broad sectors, which are then divided into 22 specific asset classes. If your business operates in any of these areas, there’s a very good chance the Act applies to you.

The 11 sectors are:

Recent changes have massively expanded the Act’s reach. What started with just four sectors in 2018 grew to the current 11 sectors and 22 asset classes by 2022. For anyone managing a retail site or organising an event, this means you need to take a hard look at who provides your power, water, and communications. You can learn more about what the SOCI Act reforms impact various industries and what this means for your supply chain.

Identifying Your Role as a Responsible Entity

If you've spotted a connection, the next step is figuring out your legal role. The SOCI Act uses two main titles: Responsible Entities and Direct Interest Holders. In simple terms, a Responsible Entity is the person or organisation that owns or operates the critical asset.

A Responsible Entity is the one with the primary duty to comply. This means registering assets, creating a risk management program, and reporting any serious cyber incidents under the Security of Critical Infrastructure Act 2018.

If you own a venue, you are almost certainly the Responsible Entity for that building. For an event organiser leasing that same venue, the lines can get blurry. If you bring in your own critical systems, like temporary cell towers or large-scale generators, you could share some of those responsibilities.
Actionable Insight: It’s absolutely vital to clarify these roles in your contracts with partners and suppliers to make sure nothing falls through the cracks and compliance responsibilities are clearly assigned.

Understanding Your Key Compliance Obligations

The Security of Critical Infrastructure Act 2018 (SOCI Act) isn't just a list of definitions; it places real, proactive duties on the shoulders of anyone running a critical asset. Let's be clear: compliance isn't a friendly suggestion, it's a legal must-have. Getting your head around these core obligations is the only way to protect your operations and steer clear of some very serious penalties.

For those of us managing venues, event sites, and major construction projects, these responsibilities really boil down to two key areas: mandatory incident reporting and having a solid risk management program.

The Clock Is Ticking: Mandatory Cyber Incident Reporting

One of the most pressing duties you have under the SOCI Act is the requirement to report cyber incidents, and you can't afford to hang around. The government needs to know about threats immediately to coordinate a national response, which is why the reporting windows are incredibly tight.

This is a non-negotiable part of the Act. If a critical cyber incident has a significant impact on your asset's availability, you must report it to the Australian Cyber Security Centre (ACSC) within 12 hours. For other incidents that are disruptive but less severe, you have a 72-hour window. Missing these deadlines can result in hefty fines.

So, what does this actually mean for you?

The Critical Infrastructure Risk Management Program (CIRMP)

Your second major obligation is to develop and maintain a Critical Infrastructure Risk Management Program (CIRMP). Think of this as your organisation's official playbook for identifying and handling any and all relevant hazards—not just cyber threats. The government wants to see an 'all-hazards' approach.

Your CIRMP is the documented proof of how you proactively find and reduce risks to your critical asset. This program needs to cover everything from physical and personnel security to your supply chain and cyber vulnerabilities.

For any organisation affected by the SOCI Act, mastering effective risk compliance management is absolutely essential. Your CIRMP is the living document that demonstrates you're meeting your Positive Security Obligations by detailing the specific controls and procedures you have in place.

In practical terms for a venue operator or site manager, this means documenting how you use:

Ultimately, your duties under the security of critical infrastructure act 2018 demand that you take a comprehensive and forward-thinking approach to security. A robust CIRMP and a clear incident response plan aren't just nice to have; they are fundamental to doing business.

Building Your Compliant Risk Management Program

The Security of Critical Infrastructure Act 2018 isn't just about theory; it’s about action. This is where the Critical Infrastructure Risk Management Program (CIRMP) comes into play. Think of it as your legally required security playbook, the documented plan that shows how you're actively protecting your asset.

Developing your CIRMP is the process of turning those legal obligations into concrete, everyday tasks for your venue, event, or site. It’s not about ticking a box. It’s about creating a living, breathing plan that genuinely protects your people, property, and operations from all relevant hazards—a core principle of the SOCI Act.

When an incident does happen, the Act lays out a clear and direct response process, as you can see below.

This process really boils down to three straightforward steps: identify the incident, report it within the legally mandated timeframe, and get to work containing the threat.

Conducting an All-Hazards Risk Assessment

So, where do you begin? Your CIRMP must be built on the foundation of a thorough risk assessment. Crucially, this is an 'all-hazards' assessment, which means looking far beyond just cyber threats. You need to identify any hazard—natural, malicious, or even accidental—that could realistically disrupt your operations.

For a construction site manager, this means thinking through scenarios like:

Actionable Insight: A good assessment forces you to ask tough questions. What’s your plan if the main communication network at your festival goes down? How would you control entry and exit if the electronic gates at your venue suddenly failed? Getting these risks down on paper is the essential first step to managing them effectively.

Implementing and Documenting Security Controls

Once you know what you’re up against, your CIRMP needs to outline the specific controls you’ll use to mitigate those risks. These are the practical, on-the-ground measures that make up your security framework.

Your documented controls are your proof of compliance. When regulators come knocking, this is the evidence they'll want to see to confirm you're meeting your Positive Security Obligations under the Security of Critical Infrastructure Act 2018.

Here are a few real-world examples of how this looks in your CIRMP:

  1. Securing a Festival's Network: To protect a festival's ticketing and communication systems, your CIRMP might detail the use of a dedicated, encrypted network. You’d also document having IT staff and security personnel on standby to respond to any outages or attempted hacks.

  2. Controlling Construction Site Access: For a large construction site, the plan could specify using gatehouse guards to verify all personnel and vehicles. It would also need to document regular perimeter patrols, perhaps with K9 units, to deter intruders.

  3. Protecting a Retail Centre: A shopping centre's CIRMP would list its CCTV system and monitoring protocols, detail the duties of loss prevention officers, and include emergency evacuation plans developed with local emergency services.

Building a solid CIRMP takes time and attention to detail, but it’s a straightforward process when you break it down. It’s all about being prepared, being proactive, and having the documentation to prove you’ve taken every reasonable step to secure your critical asset.

How a Security Partner Simplifies SOCI Compliance for the Security of Critical Infrastructure Act 2018

Getting your head around the security of critical infrastructure act 2018 is one thing. Actually putting its requirements into practice on the ground? That’s a completely different challenge. The good news is, you don’t have to tackle this complex web of obligations on your own. Bringing in a professional security partner is like adding a specialist to your team, one who can turn those legal duties into effective, real-world security.

Working with an expert partner takes compliance off the page and puts it into action. Their know-how is invaluable for meeting your Positive Security Obligations, giving you both the high-level strategy and the physical presence needed to properly secure your asset.

This kind of partnership makes the whole compliance process much smoother. For example, a security provider’s risk assessment team can work directly with you to build your Critical Infrastructure Risk Management Program (CIRMP), making sure it genuinely addresses all the physical, personnel, and procedural hazards your site faces.

From Legal Jargon to Actionable Security

One of the biggest wins of partnering with a security expert is their ability to translate the Act’s dense language into clear, decisive actions. They deliver the kind of documented, fit-for-purpose security deployments that regulators want to see as proof you’re taking your obligations seriously.
Practical Example: This can be anything from posting static guards with specific post-orders at a major corporate event to setting up GPS-tracked vehicle patrols around a large-scale construction site.

These services directly tick the boxes for specific SOCI obligations:

For the cyber side of things, engaging a partner for services like Vulnerability Management as a Service can also be a game-changer, helping you manage ongoing digital risks without overwhelming your internal teams.

Actionable Insight: When you outsource these specialised functions, you’re not just hiring guards; you’re gaining access to trained professionals whose entire focus is security. This frees up your own team to concentrate on what they do best, with the confidence that your compliance duties are being handled by experts.

Ultimately, the right security partner provides something more valuable than just personnel—they provide peace of mind. They ensure your security measures are not only compliant with the security of critical infrastructure act 2018 but are also robust, properly documented, and genuinely effective.

Frequently Asked Questions (FAQ) about the Security of Critical Infrastructure Act 2018

We get a lot of questions from managers trying to get their heads around what this legislation means for them. Let's walk through some of the most common ones.

Does the SOCI Act Apply to Temporary Events?

Absolutely. The Act doesn't really care if an asset is permanent or temporary; it cares about the function it performs and the potential impact if it fails.

Practical Example: Think about a major music festival or a large-scale construction project. If you're bringing in significant temporary power generation to run the site, you could be considered a critical energy asset in your own right. Even your reliance on local telecommunications for ticketing, EFTPOS, and emergency services can bring you under the Act's umbrella.

Actionable Insight: The real test is this: would a significant disruption at your event or site cause a serious, cascading effect on public safety or the local economy? If the answer is yes, you almost certainly have obligations under the security of critical infrastructure act 2018.

What Are the Penalties for Non-Compliance?

The government isn't messing around here. The penalties for non-compliance are severe enough to make any director or board member sit up and take notice. For a corporation, the financial hit can be massive. For example, failing to have a proper Critical Infrastructure Risk Management Program (CIRMP) in place can lead to fines of up to 2,000 penalty units, which currently translates to $626,000. And that's just one example; other breaches can attract even steeper penalties.

On top of that, there are strict deadlines for reporting cyber security incidents. You have just 12 hours to report a significant incident and 72 hours for other types. Missing these windows also comes with its own set of substantial fines. These penalties make it crystal clear: having documented, well-rehearsed processes for risk management and reporting isn't optional.

What Is a Positive Security Obligation (PSO)?

This is probably the biggest mental shift the SOCI Act introduces. A Positive Security Obligation (PSO) means you can no longer just react to threats as they happen. The law now requires you to be proactive. Essentially, you have a legal duty to actively find, analyse, and take steps to mitigate risks to your critical asset. It’s about moving from a "wait and see" approach to a "plan and prevent" one.

For a venue operator or site manager, this isn't just theory. It means taking real, tangible actions, such as:

How does a security partner help with CIRMP documentation?

A quality security partner will provide you with detailed operational plans, incident logs, and shift reports. This paperwork becomes direct evidence for your CIRMP, showing that you have implemented the necessary controls to manage the risks you’ve identified.

Can a security provider assist with staff training for SOCI?

Absolutely. Many specialised security firms offer training for your staff covering security awareness, how to spot a potential incident, and what to do in an emergency. This is a practical way to address the "personnel hazards" component of your risk management program.


Getting to grips with the security of critical infrastructure act 2018 is a serious undertaking, but you don't have to figure it all out on your own. GM GROUP Services specialises in expert risk assessments and security solutions that are built to meet compliance obligations while keeping your people and property safe.

Partner with us to build a robust and compliant security framework.

Exit mobile version