Skip to content
StrikeCyberStrikeCyber
Research

SOCI Act Critical Infrastructure Security: How Offensive Testing Supports Compliance

21 May 2026·6 min readComplianceIndustry Briefings

SOCI Act critical infrastructure security is now a core obligation for organisations that own or operate essential services in Australia. The Security of Critical Infrastructure Act 2018, significantly expanded by reforms in 2021 and 2022, requires responsible entities across eleven sectors to manage the risks to their critical assets, report cyber incidents quickly, and in the most critical cases meet enhanced security obligations.

This briefing explains how the SOCI framework works, which sectors and asset classes it covers, what a Risk Management Program requires, and how offensive security testing supports both compliance and genuine resilience. It is written for Australian operators who need to move from understanding the law to demonstrating they meet it.

What the SOCI Act Covers

The Act began with a narrow focus but now reaches across the economy. Following the reforms, it applies to eleven sectors:

  • Communications
  • Data storage or processing
  • Financial services and markets
  • Water and sewerage
  • Energy
  • Health care and medical
  • Higher education and research
  • Food and grocery
  • Transport
  • Space technology
  • Defence industry

Within these sectors, the legislation defines specific critical infrastructure asset classes. The practical test is whether your organisation owns or operates an asset that falls within one of those classes. If it does, obligations such as registration, incident reporting and the Risk Management Program are likely to apply.

The Risk Management Program Obligation

The Critical Infrastructure Risk Management Program, often shortened to CIRMP, is the centrepiece of the framework for most responsible entities. It requires you to identify and manage material risks to your critical infrastructure assets across four hazard domains:

  • Cyber and information security hazards
  • Personnel hazards, including malicious insiders
  • Supply chain hazards
  • Physical security and natural hazards

For each domain you must take reasonable steps to minimise or eliminate material risks, and to mitigate the impact of hazards that do occur. The program must be written, kept up to date, reviewed regularly, and supported by an annual report that is approved by the board or governing body. That board approval mirrors a broader trend in Australian regulation: accountability for security sits at the top of the organisation.

Cyber Security Within the Program

Cyber and information security is one of the four hazard domains, and for most modern critical infrastructure it is among the most consequential. The Risk Management Program rules point entities towards recognised cyber security frameworks so that mitigation is structured rather than ad hoc.

To satisfy the cyber component credibly, responsible entities generally need to:

  • Identify the material cyber risks to their critical assets and the systems that support them.
  • Implement controls aligned to a recognised framework and appropriate to the asset's criticality.
  • Test whether those controls actually reduce risk, rather than assuming they do.
  • Track and remediate weaknesses, and review the program as the threat landscape shifts.

This is where offensive security earns its place. A penetration testing engagement gives you evidence of real, exploitable weaknesses in the systems that matter, which is far more useful for a risk program than a list of theoretical vulnerabilities. For operational and complex environments, testing helps you understand not just whether a control exists, but whether it holds.

Enhanced Obligations for Systems of National Significance

The Act also creates a higher tier for the most critical of the critical. Assets that the Minister privately declares to be Systems of National Significance may be subject to enhanced cyber security obligations. These are targeted at a small number of the highest-consequence assets, not every responsible entity.

Enhanced obligations can include:

  • Developing and maintaining cyber security incident response plans.
  • Undertaking cyber security exercises to test the entity's ability to respond to and recover from incidents.
  • Carrying out vulnerability assessments to identify weaknesses.
  • Providing system information to help build a national picture of critical infrastructure and threats.

Where these obligations apply, offensive security testing is a natural fit. A red team engagement can serve as a realistic cyber security exercise, testing detection and response across people, process and technology rather than just probing for individual flaws. This gives operators evidence that their response capability works under conditions that resemble a real attack.

Incident Reporting and Response

The SOCI framework imposes some of the tightest incident reporting timeframes in Australian law. Responsible entities must report cyber security incidents to the Australian Signals Directorate. In broad terms:

  • Critical incidents with a significant impact on the availability of an essential service must be reported within 12 hours.
  • Other relevant incidents must be reported within 72 hours.

Meeting a 12-hour deadline while an incident is unfolding is only realistic if your response is planned and rehearsed. Clear escalation paths, defined roles and practised playbooks make the difference between a controlled response and a scramble. Aligning your testing outcomes with your incident response planning ensures that lessons from testing flow directly into how you would handle a real event.

How Testing Supports SOCI Compliance and Resilience

Offensive security testing supports the SOCI framework in several concrete ways:

  • It identifies material cyber risks with evidence, strengthening the Risk Management Program.
  • It validates that mitigations work, so board-approved reporting reflects reality.
  • It can satisfy the cyber security exercise and vulnerability assessment expectations for the most critical assets.
  • It exercises detection and response, which underpins the ability to meet tight reporting deadlines.
  • It builds a track record of continuous improvement that supervisors and boards can rely on.

To direct testing effort well, it helps to know where you stand. A security maturity assessment benchmarks your current controls and governance so you can prioritise the assets and risks that matter most under SOCI, rather than testing everything at once.

Common Pitfalls for Responsible Entities

Meeting the SOCI framework on paper is not the same as being resilient, and several recurring mistakes leave operators exposed. Being aware of them helps you build a program that stands up to both a regulator and a real attacker:

  • Treating the Risk Management Program as a document to be filed rather than a living program that drives real mitigation and review.
  • Scoping cyber testing to corporate IT while overlooking the operational technology and control systems that actually keep essential services running.
  • Underestimating supply chain risk, when material service providers and shared platforms are often the softest path into a critical asset.
  • Assuming controls work without testing them, so the annual board-approved report reflects intent rather than reality.
  • Leaving incident reporting until an incident occurs, then discovering the 12-hour deadline is impossible to meet without a rehearsed process.

Operational environments deserve particular care. Many critical infrastructure assets rely on systems that cannot simply be taken offline for testing, so engagements must be planned with safety and availability front of mind. Experienced testers scope this work carefully, using appropriate techniques and timing so that assurance never comes at the cost of the very services the SOCI Act exists to protect.

From Obligation to Genuine Resilience

The SOCI Act is ultimately about resilience: keeping essential services running even when they are targeted. Treating it as a paperwork exercise misses the point and leaves real risk on the table. The operators who do it well use the framework as a prompt to test their defences honestly and fix what they find.

If you need SOCI-aligned testing scoped around your critical assets and reported for both boards and regulators, our team of expert operators can help. Explore our penetration testing services, review our red teaming capability, or get in touch for a scoping conversation. You can also call StrikeCyber on 1300 654 898.

Frequently asked questions

What is the SOCI Act?

The Security of Critical Infrastructure Act 2018, as amended by reforms in 2021 and 2022, is the Australian legislation that governs the security and resilience of critical infrastructure. It expands well beyond its original scope to cover eleven sectors and a range of critical infrastructure asset classes. The Act places obligations on responsible entities, including a Risk Management Program, mandatory cyber incident reporting, and enhanced obligations for the most important assets.

Which sectors does the SOCI Act cover?

The Act covers eleven sectors: communications, data storage or processing, financial services and markets, water and sewerage, energy, health care and medical, higher education and research, food and grocery, transport, space technology, and defence industry. Within these sectors, specific critical infrastructure asset classes are defined. If your organisation owns or operates an asset that falls within one of these classes, SOCI obligations are likely to apply to you.

What is a Risk Management Program under SOCI?

The Critical Infrastructure Risk Management Program obligation requires responsible entities to identify and manage material risks to their critical infrastructure assets across four hazard domains: cyber and information security, personnel, supply chain, and physical and natural hazards. Entities must adopt and maintain a written program, review it regularly, and provide an annual report approved by the board or governing body. Cyber security is a central pillar of this program.

What are enhanced cyber security obligations?

Enhanced cyber security obligations apply to assets declared Systems of National Significance, the most critical of the critical infrastructure. These obligations can require incident response planning, cyber security exercises to test response capability, vulnerability assessments, and the provision of system information to build a national threat picture. They are targeted at a small subset of the highest-consequence assets rather than every responsible entity under the Act.

Does the SOCI Act require penetration testing?

The Act does not mandate penetration testing by name for every entity. However, the Risk Management Program requires you to identify and mitigate material cyber risks, and enhanced obligations for the most critical assets can require vulnerability assessments and cyber security exercises. Offensive security testing is one of the clearest ways to identify those risks and demonstrate that mitigations work, which is why many responsible entities include it in their assurance activities.

What are the incident reporting rules under SOCI?

Responsible entities for critical infrastructure assets must report cyber security incidents to the Australian Signals Directorate. Critical incidents that have a significant impact on the availability of an asset must generally be reported within 12 hours, and other relevant incidents within 72 hours. These timeframes are tight, so a rehearsed incident response capability and clear internal escalation paths are essential to meeting the obligation in practice.

Ready to take the offensive?

StrikeCyber specialises in penetration testing and red teaming engagements that deliver actionable findings. Connect with us for a free consultation.

No obligation, no sales pressure. A senior operator replies within one business day.

1300 654 898Free Consultation