Learn More about Benny Czarny's Book Cybersecurity Upside Down

Learn More
We utilize artificial intelligence for site translations, and while we strive for accuracy, they may not always be 100% precise. Your understanding is appreciated.

An Update on SOCI’s Critical Infrastructure Risk Management Program

Australia's new critical infrastructure rules, translated into controls operators can evidence
By Adam Bradley, SE ANZ, OPSWAT
Share this Post

On 10 June 2026, the Australian Government’s Security of Critical Infrastructure Legislation Amendment (Enhanced Critical Infrastructure Risk Management Program) Rules 2026 came into effect.

The Department of Home Affairs introduced additional requirements covering cyber maturity, patching and legacy technology, credential compromise, lateral movement, personnel access, supply chain dependencies and the interaction between cyber and physical security risks.

For critical infrastructure operators, this reinforces an important principle: resilience must be engineered into the environment and demonstrated through enforceable controls, monitoring, evidence and recovery capability.

Strategies to Transition to the Enhanced CIRMP (Critical Infrastructure Risk Management Program) Rules

This is an update based on a previous blog from March 2026.

The new requirements align closely with several areas addressed by OPSWAT’s critical infrastructure protection portfolio:

  • Credential compromise and controlled remote access: The rules introduce explicit requirements around phishing-resistant multi-factor authentication for relevant systems, privileged access and remote access, together with central logging and monitoring of authentication activity. MetaDefender™ Endpoint integrates with existing identity providers and MFA services while adding device-compliance enforcement before access is granted.

    For operational environments, MetaDefender OT Access provides identity-aware, policy-controlled remote access with session monitoring, auditing and granular restrictions on what remote employees or third-party vendors can access. Phishing-resistant MFA itself should be implemented through an appropriate identity provider where required by the rules, which sets this as a separate hazard under 8B Credential Compromise.
  • Network segregation and lateral movement: Under the 8C Lateral Movement hazard, the rules establish specific expectations for understanding how critical systems are connected, restricting communications between them, applying least privilege, centrally monitoring communication paths and supporting recovery while maintaining critical operations. MetaDefender Industrial Firewall provides protocol-aware inspection and zone-based segmentation for OT environments.

    MetaDefender NetWall™ can provide hardware-enforced isolation and controlled data flows between networks of different security classifications. These controls can form part of a broader architecture designed to reduce lateral movement and preserve operational independence during an incident. It can also provide a strategy on helping critical infrastructure operators with meeting CI Fortify’s guidance of having the ability to stay operational while offline for a 90-day period.
  • Third-party and supply chain risk: Under the 10A Supply Chain hazard, the rules require affected entities to map major suppliers and critical components, identify supply chain risks, consider maximum acceptable outages and assess risks associated with major suppliers. Technical controls do not replace supplier due diligence or assessments of foreign ownership, control or influence; however, OPSWAT can reduce the cyber risk created by software, files and data entering critical environments through those supply chains.

    MetaDefender™ Core can inspect software and files for malware and known vulnerabilities and generate software bills of materials (SBOMs). MetaDefender™ Kiosk controls files introduced through removable media, while MetaDefender™ Managed File Transfer applies inspection, access controls, policy enforcement and audit trails to file exchange between IT, OT and third-party environments.
  • Offshore and remote access to critical systems and data: With the introduction of material risks under 6A All-hazard, the government recognizes offshore or remote access to critical components and business-critical data as additional material risks. MetaDefender OT Access can restrict and monitor third-party or remote access to specific OT assets and activities, while MetaDefender Managed File Transfer and MetaDefender NetWall can enforce controlled movement of data across security boundaries. This enables organizations to reduce unnecessary connectivity and establish stronger enforcement points around remote interactions with critical environments
  • Cyber-physical consequences: The Enhanced CIRMP Rules require organizations to consider physical-security consequences arising from cyber, credential, lateral-movement, personnel and supply-chain hazards. This is particularly relevant in OT and cyber-physical environments, where a cyber compromise can affect the availability or safe operation of physical processes. Segmentation, secure remote access, controlled file transfer and preventative inspection can help reduce pathways through which a digital compromise develops into an operational or physical event. These technology controls complement, rather than replace, the physical security and business continuity processes required under the CIRMP.

What Compliance Looks Like by 2028

The recent SOCI Act legislation amendments for the enhanced CIRMP rules also raise the expected level of cybersecurity maturity for affected assets. They reference frameworks including ISO/IEC 27001:2023, NIST Cybersecurity Framework 2.0, Essential Eight Maturity Level 2, C2M2 Maturity Indicator Level 2 and AESCSF Security Profile 2, or an applicable equivalent approach.

For organizations already subject to CIRMP obligations, the 2026 changes therefore represent more than another compliance update. They provide a clearer technical direction: know what is connected to critical systems, control who and what can access them, minimize opportunities for lateral movement, scrutinize third-party pathways, maintain evidence of security controls and design environments capable of continuing critical operations when other systems are compromised or under recovery.

OPSWAT is here to help critical infrastructure entities support this transition by providing preventative and enforceable controls across files, removable media, endpoints, remote access, OT networks and cross-domain data flows. No individual technology establishes CIRMP compliance by itself, but integrating these capabilities into a broader risk-management program can help responsible entities translate regulatory requirements into measurable, auditable operational resilience.

To assess your readiness ahead of the 2027 and 2028 deadlines, chat with an OPSWAT critical infrastructure expert.

Stay Up-to-Date With OPSWAT!

Sign up today to receive the latest company updates, stories, event info, and more.