SOCI Act & Critical Infrastructure
SOCI Act Supply Chain Alignment
CIRMP gap assessments and IT/OT network segregation for vendors and service providers operating within SOCI-regulated water, energy, transport, healthcare, and agribusiness sectors.
Recommended For
- Vendors, contractors, and IT/OT service providers to critical infrastructure asset owners subject to the SOCI Act
- Organisations required to comply with Critical Infrastructure Risk Management Program (CIRMP) supply chain rules
- Engineering and industrial firms needing verified network segregation between corporate IT and SCADA/ICS OT environments
Service Overview
Protect Supply Chain Access Under National Security Mandates
Australia's Security of Critical Infrastructure Act (SOCI Act) enforces mandatory Critical Infrastructure Risk Management Programs (CIRMP) across 11 key sectors — including energy, water, freight, healthcare, food, and defense supply chains. Critical infrastructure asset owners are legally responsible for hazards introduced by third-party contractors and vendors possessing network access.
Whitesec AU delivers independent SOCI Act supply chain alignment. We audit your technical controls, verify IT/OT network air-gaps, enforce privileged vendor access controls, and provide defensible attestation packages that satisfy prime contractor risk managers and Department of Home Affairs (Cyber and Infrastructure Security Centre) auditors.
12 Hours
Mandatory notification timeframe under SOCI Act for critical cyber incidents — requiring rapid incident playbooks.
Regulatory & Standards Alignment
Security of Critical Infrastructure Act 2018 (SOCI)
Federal legislation establishing security obligations, incident reporting, and supply chain rules across 11 critical sectors.
SOCI CIRMP Rules (Risk Management)
Requires critical asset operators to audit primary vendors for cyber supply chain and operational hazards.
ISA/IEC 62443 Industrial Cybersecurity
International standard for security in industrial automation and control systems (IACS) referenced during OT boundary reviews.
Executive Business Value & Outcomes
Contract Protection with Primes
Retain high-value contracts with critical infrastructure operators by passing mandatory CIRMP supply chain audits.
IT/OT Network Isolation
Ensure corporate IT compromises cannot jump perimeters into SCADA, PLC, or industrial control system (ICS) environments.
Defensible CIRMP Evidence
Receive a formal alignment scorecard and technical documentation ready for submission to government regulators.
Vendor Access Control
Deploy jump-box architectures, multi-factor authentication, and session logging for remote engineering maintenance.
Regulatory Incident Compliance
Establish escalation playbooks compliant with 12-hour and 72-hour SOCI Act mandatory reporting rules.
C-Suite Risk Reduction
Protect directors from personal regulatory liability associated with critical infrastructure security failures.
The Problem
Challenges We Solve
The situations that bring organisations to this engagement in the first place.
Liable for hazards you did not introduce
Critical infrastructure asset owners are legally responsible for hazards introduced by third-party contractors and vendors holding network access.
IT/OT separation assumed, not proven
Air-gaps between corporate IT and operational technology are believed to exist but have never been independently verified.
CIRMP obligations across eleven sectors
Mandatory Critical Infrastructure Risk Management Programs now reach energy, water, freight, healthcare, food, and defence supply chains.
Scope of Service
Scope of Alignment Activities
Comprehensive technical and governance verification for critical infrastructure supply chains.
CIRMP Supply Chain Risk Review
Auditing your security controls against Critical Infrastructure Risk Management Program mandatory requirements.
IT/OT Boundary & Firewalls Audit
Technical review of firewalls, DMZs, and unidirectional gateways separating corporate networks from OT assets.
Remote Access & Vendor Session Logging
Enforcing PAM, MFA, and screen recording on third-party engineering access to industrial control systems.
SOCI Incident Escalation Playbook
Developing incident detection and escalation procedures aligned to federal CISC reporting windows.
Methodology
Engagement Roadmap
A structured 2 to 4-week alignment process for industrial and commercial environments.
SOCI Scope & Asset Mapping
We identify critical assets, data flows, and remote connectivity channels linked to your client's infrastructure.
Technical Control & Boundary Review
Our engineers inspect perimeter firewalls, jump host configurations, and authentication mechanisms.
Remediation & Boundary Hardening
We implement missing isolation controls, script execution blocks, and privileged access restrictions.
CIRMP Attestation Pack Delivery
We issue a signed CIRMP Alignment Report and Executive Scorecard for submission to prime contractors.
Deliverables
What You Receive
The artifacts that land in your hands at the end of the engagement.
SOCI Act / CIRMP Alignment Report
Comprehensive technical audit detailing compliance status against national critical infrastructure rules.
IT/OT Network Segregation Diagram & File
Verified network topology map documenting boundary controls between corporate IT and industrial OT.
CISC Mandatory Incident Response Playbook
Escalation procedures designed to satisfy 12-hour and 72-hour federal incident notification requirements.
FAQ
Frequently Asked Questions
Secure Your Critical Infrastructure Position
Request a SOCI Act supply chain alignment audit with our Perth specialists.