Skip to main content
search

The SOCI reforms have landed.

Does your board know how many identities it's now accountable for?

For years, the Security of Critical Infrastructure Act has been treated as a compliance document – something risk and IT teams manage, and boards sign off on once a year. That’s about to change. 
 
The independent review of the SOCI Act, handed down in early 2026, found the Act has done its job of lifting baseline governance and board awareness, but it’s too complex, and still too compliance-driven rather than outcomes-driven. The government’s response doesn’t loosen the framework, it sharpens it, and it moves more of the accountability onto boards directly. 
 
CIRMP stands for Critical Infrastructure Risk Management Program, a mandatory written risk-management framework required under Australia’s Security of Critical Infrastructure Act 2018 (SOCI Act). It requires responsible entities to identify and manage material risks across cyber, personnel, supply-chain, and physical/natural hazard categories.

The reforms tightening risk management are no longer just proposals — they’re now law. Following the independent review, an exposure draft of enhanced CIRMP Rules opened for consultation on 25 March 2026, and the Security of Critical Infrastructure Legislation Amendment (Enhanced Critical Infrastructure Risk Management Program) Rules commenced on 10 June 2026. They apply to several designated high-risk asset classes — critical broadcasting, domain name systems, electricity, energy market operator, freight infrastructure, freight services, gas, liquid fuel, and water assets, with tightened obligations specifically around cyber and information security, supply chain, and personnel risk, plus new physical security requirements. 

 Grace periods apply rather than a single hard deadline: certain cyber risk and personnel access management obligations carry a 12-month grace period, with compliance required by 10 June 2027, while other obligations carry a 24-month grace period, with compliance required by 10 June 2028. For energy sector operators specifically, one of the headline uplifts is the AESCSF requirement — achieving Maturity Indicator Level 2 (MIL-2) across all AESCSF domains by 30 June 2028.

Three changes matter most at board level

Penalties are no longer symbolic

Non-compliance with a Ministerial direction is set to rise from a modest daily penalty to civil penalties of up to $3.3 million for corporations. That’s a different order of financial exposure than most boards have priced into their risk registers for this Act.

Governance expectations are explicit, not implied

Directors are expected to approve the CIRMP, set risk appetite, and receive regular cyber-risk reporting — not annually, but on an ongoing basis. A CIRMP that was rubber-stamped once and filed away won’t hold up to scrutiny under the reformed framework.

High-risk asset classes face a materially heavier Critical Infrastructure Risk Management Program

The proposed rules go beyond “have a policy” and into specifics, including a requirement to actively manage the risk carried by unsupported, unpatched, or legacy systems, not just note that they exist.

The gap most boards don't know they have

Here’s the part that will catch organisations out. Most organisations still think about “privileged access” as a human problem — who has admin rights, who’s logged in as root. But identity security research now puts machine identities — service accounts, application credentials, automated processes, agentic workflows — at over 100 times the number of human identities in a typical enterprise. Palo Alto Networks’ 2026 Identity Security Landscape found machine identities now outnumber humans 109 to 1, up from 82 to 1 the year before — a 33% jump in just twelve months, with AI agents making up a growing and increasingly hard-to-govern share of that total. 

  
Despite that, the majority of organisations still define “privileged user” as human-only when they think about risk. 
 
That gap is invisible at board level because it’s never been asked about directly. It’s not that boards are being negligent — it’s that the question has never been on the agenda in a form a non-technical director could ask. 
 
That changes under the reformed CIRMP. If a board is expected to set risk appetite and receive assurance on cyber risk, “we have a policy” is no longer a sufficient answer. The board needs to know whether management can actually demonstrate control — and for many critical infrastructure operators, particularly those running on-premises or legacy environments, the honest answer right now is: not fully. 
 
Regulators are closing the gap that used to let this slide. SOCI Act CIRMP rules require critical infrastructure operators to align with a recognised framework — Essential Eight, NIST CSF, C2M2, ISO 27001, or the Australian Energy Sector Cyber Security Framework. With Essential Eight being retired, operators who’ve anchored their CIRMP to it now have a live compliance gap to fix. Read our whitepaper – Beyond Essential 8. 
 
On-premises systems in particular carry a specific version of this risk. There’s a common but mistaken assumption that being on-prem, rather than in the cloud, is itself a security control. It isn’t. On-prem and legacy environments often carry more unmanaged local admin accounts, less visibility, and less modern tooling than cloud-native environments — not less risk, more.

What good board oversight looks like now

Boards don’t need to become technical experts in privileged access management. What they need is a small set of direct questions that surface whether management actually has control — questions that expose vague or uncertain answers rather than requiring the board to evaluate technical detail themselves. 
 
Questions your board should be asking management:

  • Can you tell us, right now, how many accounts have privileged access to our critical systems? 
  • Are those credentials rotated on a defined policy, or does that depend on someone remembering to do it?
  • If a regulator asked for an audit trail of privileged access tomorrow, how long would it take us to produce one?
  • What access do our third-party vendors and contractors have — and is it switched off automatically when the work ends?
  • Do we know which of our systems are running unsupported or unpatched software, and what’s covering the risk in the meantime?
  • Has this CIRMP actually been approved by this board in the last 12 months, or just circulated?

For Non-Human Identities: 

  • “How many non-human identities — service accounts, API keys, tokens, certificates — do we have, and who owns them?” 
  • “Do we have any AI agents with standing access to production or OT systems, and who approved them?” 
  • “Which of our privileged accounts have zero standing privilege today, and which are permanently on?” 
     
    A confident, specific answer to each of these is reassuring. A vague one — “I’d have to check,” “roughly,” “I believe so” — is the signal a director should catch. That’s the actual value of asking: not testing the board’s technical knowledge, but testing management’s operational readiness.

The Future Depends on Unified Observability and Security 

Grace periods attached to the proposed cyber and personnel security measures run 12 and 24 months from commencement. That sounds like time. In practice, closing a genuine gap in privileged access and identity governance — inventorying every account, standing up vaulting and rotation, building audit-ready reporting — is not a project that starts well six months before a deadline. 
 
Boards that start asking these questions now, while the rules are still being finalised, put their organisations in a position to shape a considered response. Boards that wait until the rules commence will be managing a compliance scramble instead. 
 
This briefing is intended to support board-level discussion of privileged access governance under the reforming SOCI Act. It is not legal advice — organisations should seek their own advice on specific CIRMP obligations as the rules are finalised. 

See how Avocado maps CIRMP, Privacy Act, and ISO obligations into one evidenced governance framework

Explore our related content

SOCI Act Reforms 2026

Learn what critical infrastructure operators need to know

On-prem doesn’t mean secure

See why legacy identity gaps are the blind spot the reformed SOCI Act is about to make impossible to ignore.

Hospitality Industry – Cybersecurity Uplift

Read the case study

Most Australian businesses aren’t Essential Eight compliant

See why compliance isn’t the goal and what actually reduces your cyber risk

Close Menu