Skip to main content
search

Security of Critical Infrastructure (SOCI) Services

CONNECT WITH US
Clients - TfNSW
Client - Colliers
Client - Sydney Water
Client - Pacific Smiles Dental
Client - Sydney Metro
Client - UNSW

Mitigate threats. Limit downtime. Proactively respond.

Cyber Security Services

Australia now regulates the security of critical infrastructure under the SOCI Act 2018 to ensure Australia’s supply chain remains resilient in an environment of increasing threats.  

The security of critical infrastructure (SOCI) is reliant on ensuring Australia’s supply chain network can defend itself from service failure or disruption that could have widespread and detrimental effects.  

This enhanced regulatory regime places obligations on the owners and operators of critical infrastructure assets and those who have a direct interest in them. The Security of Critical Infrastructure applies to 11 sectors and 22 asset classes, with fierce penalties applying for non-compliance. 

Underpinning an organisation’s supply chain resilience are robust digital systems.

Avocado helps our clients meet their enhanced cyber security obligations through end-to-end technology services. We help you: 

  • Understand and address risks identify and remediate vulnerabilities. 
  • Create an incident response plan and test your cyber incident response. 
  • Ensuring the robustness of systems through vigorous testing. 
  • Implement technology solutions that prevent system failure and give a Realtime threat picture of your critical infrastructure assets.  
  • Bridge the resource gap with a Managed Service.
CONTACT US

How we help

Avocado supports all those impacted by the Security of Critical Infrastructure (SOCI) Act including: 

Electricity

Communications

Data Storage or Processing

Financial Services & Markets

Water

Health Care & Medical

Higher Education & Research

Food & Grocery

Transport

Space Technology

Defence

Significantly, we specialise in supporting the robustness of Operational Technology (OT)  

OT plays a vital role in maintaining the functionality of essential infrastructure and industrial settings. It encompasses both software and hardware components utilised to oversee, safeguard, and regulate industrial control systems (ICS), devices, and processes within your operational technology environment. Avocado has experience in operational technology assessment and monitoring for critical infrastructure industries including transport, water, telecommunications, food and grocery, Healthcare and emergency services.  

Explore our security of critical infrastructure services below. 

Contact us

Our Capabilities

Avocado offers a range of professional services for all those operating in the Critical Infrastructure sector. Find out how we help you comply with your enhanced obligations under the SOCI Act within these three key areas:

Organisations must identify and remediate vulnerabilities and perform vulnerability assessments. 

SOCI sectors must have an incident response plan and test their cyber incident response.  

SOCI sectors must take steps to prevent system failure which includes providing system information to ensure a near-real time threat picture. 

Audit and Assessment Services

Avocado supports critical infrastructure industries adopt and adhere to the appropriate industry-based standards and frameworks to ensure regulatory compliance and resilience. This includes threat and risk assessments, third party risk management, and other GRC audit assessments.

Explore this service

Vulnerability Detection and Penetration Testing

Avocado’s technical assurance and testing helps you discover your exposure to internal and external threats by evaluating the security measures implemented for assets to ensure their effectiveness and appropriateness. We can also undertake Test Capability Reviews to uplift inhouse teams.

Explore this service

Cyber Resilience Uplift

Avocado enhances operational models, establishes Business Continuity and Disaster Recovery Plans, and designs, delivers, and oversees Cyber Resilience programs.

Explore this service

Security Solutions

Avocado offers end-to-end advice and solutions aimed at understanding your architecture and addressing risk across the cyber-attack lifecycle. Our teams support the implementation, configuration and ongoing support of your critical business assets. This includes deploying application and infrastructure security monitoring platforms; end point and identity platforms and cloud data security.

Explore this service

Managed Services

Avocado offers a managed service with flexible operational management and support from certified security experts to ensure your platforms are managed and optimised. Avocado’s Managed Service addresses your skill gaps, mitigates operational risk and improves business outcomes by giving your teams more time to focus on innovation.

Explore this service

Strengthen your supply chain resilience with robust digital systems

Contact our team today

ENQUIRE NOW

What should organisations be doing now?

Organisations had until August 2023 to develop and implement a risk management program.

They now have until 18 August 2024 to meet the requirements of the cyber security framework identified in the risk management program. They must also submit a board approved report no later than 28 Sept 2024.

It’s crucial for organisations to prioritise resilience in the Critical Infrastructure sector. The Critical Infrastructure Act (SOCI Act) offers a chance to gain a competitive edge by fostering proactive, customer-centric, and adaptable businesses. Such resilience significantly improves risk management, reputation, and revenue.

Read our latest case studies

Security Testing During an Organisational Transformation

Avocado’s penetration testing framework delivered detailed risk findings and recommendations, giving our client a comprehensive understanding of vulnerabilities to critical assets and systems resulting from an operational restructure. This enables them to initiate remediation and reduce risks while preserving their security posture.

Threat and Risk Assessment for a Leading Health Service Provider 

We supported a leading health service provider in conducting a targeted threat and risk assessment (TRA) to help align the organisation’s cybersecurity plans with its unique risk profile. Our cost-justified roadmap efficiently integrated IT and cyber strategies, facilitating informed business decisions, improving stakeholder communication, and safeguarding client trust, patient data, and service continuity.

Remediating Security and Privacy Risks in a Complex and Regulated Environment

Read more to discover we supported our client by building an actionable roadmap that demonstrated financial justification, facilitating the harmonisation of their IT and cyber roadmaps, enabling a more efficient allocation of resources.

Creating a scalable, efficient and secure Operational Technology environment

Avocado Consulting collaborated closely with the agency to enhance their recently built Splunk environment. The focus was on transitioning it into a robust, operationally supported system managed by Avocado’s expertise

Keeping Australians safe in an emergency

This project was high-risk, in a regulated, multi-stakeholder, multi-vendor environment that needed mature leadership and technical excellence. Avocado injected testing leadership, bringing all parties to a common roadmap that successfully delivered the project

Not sure where to start?

Ask about our complimentary cyber-security-discovery-session:

LEARN MORE
Close Menu