Skip to content
StrikeCyberStrikeCyber
Research

Cyber Security for Mining and Energy in Australia: Securing OT and Critical Infrastructure

28 May 2026·6 min readComplianceIndustry Briefings

Cyber security mining energy Australia has moved from a background concern to a board-level priority. Mining, energy and utility operators run the systems that keep the country powered, watered and moving, and those same systems are now squarely in the sights of both criminal groups and state-aligned actors. The stakes are unusually high because a serious incident does not just expose data. It can halt production, disrupt essential supply and, in the worst cases, threaten the safety of people on site.

This briefing is written for Australian operators in mining, energy and utilities. It explains why these environments are different, how IT and OT convergence changes the risk picture, where industrial control systems and SCADA are exposed, and how safety-first offensive security testing supports both the SOCI Act and IEC 62443 without disrupting the operations it is meant to protect.

Why Mining and Energy Are Different

Most cyber security advice is written for corporate IT, where the priority is protecting the confidentiality of data. Operational environments invert that order. In a control room, availability and safety come first. A process that stops unexpectedly can damage equipment, interrupt supply to thousands of customers, or create a genuine hazard for workers.

Several factors make these environments distinctive:

  • Long asset lifecycles mean control equipment can remain in service for decades, well beyond the point where vendors issue security patches.
  • Downtime is expensive and sometimes dangerous, so systems cannot simply be taken offline for routine maintenance or testing.
  • Safety instrumented systems and physical processes mean a cyber event can have real-world, physical consequences.
  • Sites are frequently remote, unmanned or in harsh conditions, connected by links that are themselves part of the attack surface.

Understanding these constraints is the starting point for any credible security program in the sector. Controls and testing that ignore them are either unsafe or unrealistic.

The IT and OT Convergence Risk

For years, operational technology was protected largely by isolation. Control networks were separated from the corporate world, and that separation did much of the security work. That model has eroded. Operators now connect plant and field systems to corporate networks and cloud platforms to enable remote monitoring, predictive maintenance, analytics and remote operations centres.

The business case for this convergence is strong. The security consequence is that the old air gap is mostly gone. An attacker who compromises a corporate laptop through a phishing email, or a vendor account through weak remote access, may be only a few steps away from the systems that run physical processes.

The most important control in a converged environment is the boundary between IT and OT. That means well-designed segmentation, tightly controlled and monitored crossings between zones, and no forgotten connections that quietly bridge the two. These boundaries are exactly the kind of control that looks solid on a network diagram but often fails in reality. A penetration testing engagement scoped around the IT and OT boundary is one of the most valuable investments an operator can make, because it tests whether that separation actually holds when someone tries to cross it.

Where ICS and SCADA Are Exposed

Industrial control systems and SCADA platforms were designed for reliability and long service life, not for a hostile, internet-connected world. Common areas of exposure include:

  • Legacy protocols that carry no authentication or encryption, so commands can be observed or forged by anyone on the network.
  • Engineering workstations and human-machine interfaces running old operating systems that can no longer be patched.
  • Remote access for vendors and integrators that is broad, shared or poorly monitored.
  • Default or shared credentials on field devices and controllers.
  • Flat networks where a single foothold provides reach across large parts of the control environment.

The point of identifying these weaknesses is not to alarm engineers who already run these systems safely every day. It is to bring an attacker's perspective to an environment that was never built with attackers in mind, so that the highest-consequence paths can be closed first. A vulnerability assessment tailored to OT builds a clear, prioritised picture of that exposure across both control systems and the supporting infrastructure.

SOCI Act Obligations and IEC 62443

Australian operators in these sectors sit inside a maturing regulatory framework. The Security of Critical Infrastructure Act covers energy, water and sewerage and other sectors, and captures many resources operations through their critical infrastructure assets. Responsible entities must maintain a Critical Infrastructure Risk Management Program that addresses cyber, personnel, supply chain and physical hazards, report significant cyber incidents to the Australian Signals Directorate within tight deadlines, and meet enhanced obligations where an asset is declared to be of national significance.

Alongside this legal obligation, IEC 62443 provides the technical framework for securing industrial automation and control systems. Its concepts of zones and conduits, security levels and defined responsibilities for asset owners give operators a structured way to organise OT security rather than treating it as a collection of one-off fixes.

Offensive security testing supports both:

  • It identifies and evidences the material cyber risks a Risk Management Program is required to manage.
  • It validates that the zones and conduits described in IEC 62443 actually contain an attacker.
  • It exercises detection and response, which underpins the ability to meet tight incident reporting timeframes.
  • It provides the independent assurance that boards need to sign off risk programs with confidence rather than hope.

Compliance is the floor here, not the ceiling. The organisations that do this well use the frameworks as a prompt to test their defences honestly and fix what they find.

Remote and Hostile-Environment Operations

Mining and energy assets are rarely in convenient locations. Sites can be remote, unmanned and connected by satellite, microwave or long-haul links, with control increasingly handled from centralised remote operations centres. This geography expands the attack surface in ways that a standard corporate assessment would miss.

Good testing accounts for it. That means assessing the security of remote connectivity and the resilience of remote access used by staff and vendors, examining the exposure of edge devices and field sites, and considering how an attacker might exploit the trust between a remote operations centre and the assets it controls. Much of this can be delivered remotely against the relevant systems and links, with any on-site activity planned carefully and only where it genuinely adds value.

Safety-First Testing

The single most important principle for offensive security in these environments is that assurance must never come at the cost of safety or supply. Live control systems and safety instrumented systems can be fragile, and the wrong technique against a production asset is simply not acceptable.

Safety-first testing means:

  • Scoping every engagement in close coordination with plant engineers and operations teams.
  • Favouring passive, read-only assessment against sensitive production systems.
  • Using test benches, engineering environments and planned maintenance windows for anything more intrusive.
  • Testing corporate IT and the IT and OT boundary fully, since that is where most real attacks begin.
  • Treating the safety of people and continuity of supply as non-negotiable constraints, not afterthoughts.

Delivered this way, offensive testing gives operators genuine insight into how an attacker would approach their environment, without ever threatening the services and people it exists to protect. When an incident does occur, the same understanding underpins a faster, calmer response, which is why testing and incident response readiness belong together.

Building Resilience That Lasts

For mining, energy and utility operators, cyber security is ultimately about resilience: keeping essential services running even when they are targeted, and keeping people safe while doing it. That resilience comes from understanding your environment as an attacker would, closing the highest-consequence paths first, and rehearsing what happens when something goes wrong.

If you need OT-aware testing scoped around your critical assets and delivered with safety first, our team of expert operators can help. Explore our penetration testing services, review our red teaming capability for adversary emulation across converged environments, or get in touch for a scoping conversation. You can also call StrikeCyber on 1300 654 898.

Frequently asked questions

What makes cyber security different for mining and energy operators?

Mining, energy and utility operators run operational technology such as industrial control systems, SCADA and safety instrumented systems alongside conventional corporate IT. These environments prioritise availability and safety over confidentiality, often rely on legacy equipment that cannot be patched easily, and control physical processes where a failure can injure people or interrupt essential supply. Cyber security here has to protect both data and physical safety, which changes how testing is scoped and delivered compared with a standard corporate network.

What is IT and OT convergence and why is it a risk?

IT and OT convergence is the increasing connection between corporate IT networks and the operational technology that runs plant, control systems and field devices. Convergence brings real benefits such as remote monitoring, predictive maintenance and better data, but it also removes the air gap that once isolated control systems. An attacker who gains a foothold in corporate IT can potentially move laterally toward OT, so the boundary between the two environments becomes one of the most important controls to design, segment and test.

How does the SOCI Act apply to mining, energy and utilities?

The Security of Critical Infrastructure Act covers sectors including energy and water and sewerage, and many mining and resources operations are captured through their critical infrastructure assets. Responsible entities must maintain a Critical Infrastructure Risk Management Program covering cyber, personnel, supply chain and physical hazards, report cyber incidents to the Australian Signals Directorate within tight timeframes, and meet enhanced obligations for the most significant assets. Offensive security testing is one of the clearest ways to identify and evidence the cyber risks the program is meant to manage.

What is IEC 62443?

IEC 62443 is the international series of standards for the cyber security of industrial automation and control systems. It provides a structured approach to securing OT environments, including concepts such as zones and conduits for segmentation, security levels, and requirements for asset owners, system integrators and product suppliers. For Australian operators it offers a practical framework to organise OT security, and offensive testing can validate that the segmentation and controls it describes actually hold up in practice.

Is it safe to run penetration testing against OT and SCADA systems?

Yes, when it is scoped and delivered with safety first. Live control systems and safety instrumented systems can be fragile, so experienced operators avoid intrusive techniques against sensitive production assets, favour passive and read-only assessment where appropriate, and often work against test benches, engineering environments or maintenance windows. The goal is genuine assurance about the security of the environment without ever putting production, supply or personnel safety at risk. Good scoping and close coordination with plant engineers are essential.

How do you test remote and hostile-environment operations?

Mining and energy assets are often in remote or harsh locations connected by satellite, microwave or long-haul links, with unmanned sites and remote operations centres. Testing considers the security of these communications paths, the resilience of remote access for vendors and staff, and the physical and network exposure of field sites and edge devices. Much of this work can be performed remotely against the relevant systems and connectivity, with on-site activity planned carefully where it adds value.

Ready to take the offensive?

StrikeCyber specialises in penetration testing and red teaming engagements that deliver actionable findings. Connect with us for a free consultation.

No obligation, no sales pressure. A senior operator replies within one business day.

1300 654 898Free Consultation