Quick answer: Australian critical infrastructure operators must apply a four-step Identify, Know, Prioritise, Share framework under the SOCI Act. What each step actually requires in a national security risk assessment.
Originally published on LinkedIn: 20 April 2026.
Under Australia's Security of Critical Infrastructure Act 2018 (SOCI), responsible entities must adopt a rigorous all-hazards approach to risk management that integrates cyber, physical, personnel, and supply chain security. Effective practice requires boards and resilience specialists to follow a four-step framework — Identify, Know, Prioritise, and Share — to evaluate asset criticality by defining the functions and components needed for operational continuity. The methodology is designed to counter state-sponsored cyber-extortion, malicious insiders, and intensifying natural hazards that cause cascading, compounding, and converging disruptions. Getting this right protects the availability, integrity, and reliability of services essential to Australia's national security and socio-economic resilience.
An Evolving Threat Landscape
Australia's critical infrastructure now sits inside a threat environment defined by increasing frequency, intensity, and sophistication. Risks are no longer isolated incidents but interconnected challenges touching the nation's economic and social wellbeing. Four vectors dominate: human-induced threats such as ransomware, physical espionage, and supply chain exploitation from state-sponsored and criminal actors; natural hazards intensified by climate change, producing longer recovery periods and complex societal impacts; geopolitical instability from regional conflict, trade disputes, and sanctions that threaten supply chains and embolden foreign intelligence activity; and emerging technology, where AI and interconnected networks create new vulnerabilities requiring constant re-evaluation of security posture.
Interconnectedness and Dependencies
Australia's exposure is compounded by import dependency: the Middle East supplies 61% of crude oil imports, South and Southeast Asia provides 86% of diesel, and semiconductors and skilled personnel arrive from international sources. Domestically, ten infrastructure sectors interlock around energy at the centre — water utilities need energy for pumping while supplying cooling water back to generators; transport depends on fuel imports and electrified rail; telecommunications need power and data hosting; hospitals need power, water, transport, and data services simultaneously. A single disruption to Middle East oil cascades through energy generation into water treatment, hospital equipment, transport, telecommunications, and cold-chain logistics. No sector operates independently, which is why critical infrastructure protection demands whole-of-system thinking rather than sector-by-sector analysis.
Determining Asset Criticality
Identifying which sites and components are essential to an asset's function is central to the assessment. Critical sites — pump stations, chemical storage — support the "proper function" of an asset: the goods or services underpinning national wellbeing, defence, or security. Criticality itself is assessed through the DRT model: Dependency (how much other sectors rely on the service), Recoup (how easily the service can be recovered), and Time (how long full restoration takes).
Cascading, Compounding, and Converging Effects
Infrastructure risk is rarely linear. Cascading effects are nonlinear chains where a single failure's impact extends well beyond its original site or sector. Compounding effects occur when a primary hazard triggers a sequence of follow-on events — a power outage disrupting communications, which then disrupts banking, finance, and transport. Converging threats occur when adversaries exploit multiple vulnerabilities simultaneously, such as pairing a cyber-attack with physical tampering, or when internal organisational silos block an integrated view of risk. Recovery timelines vary sharply: some compounding issues, like PNT signal loss, self-correct within hours; a burned-out substation transformer can take years to replace.
All-Hazards Risk Management
Under the Critical Infrastructure Risk Management Program (CIRMP) Rules 2023, owners and operators must assess "relevant impact" across four dimensions: availability (can the asset deliver critical services), integrity (is operational data authentic and untampered), reliability (can data be trusted for output), and confidentiality (is data about the asset protected).
The Four-Step Mitigation Framework
Entities facing risks that are poorly understood or lack clear ownership should apply: Identify all-hazard risks by collaborating across business units, supply chain stakeholders, law enforcement, and emergency services; Know the drivers for impact management — deciding whether to target the most likely risks, the most damaging impacts, or specific external vulnerabilities; Prioritise treatment implementation by weighing cost-effectiveness, ease of implementation, legal and regulatory obligations, and unintended consequences; and Share risk outcomes with the Cyber and Infrastructure Security Centre (CISC), AusCheck, the Australian Signals Directorate, and the National Intelligence Community. "Reasonably practicable" mitigation means resourcing decisions are justified against these criteria rather than applied uniformly — some low-probability risks may not warrant major investment, while critical components demand it.
Ultimately, these rigorous assessments safeguard the availability, integrity, and reliability of essential services, protecting Australia's national security and socio-economic resilience against an increasingly volatile threat landscape.
Tony Ridley, MSc CSyP FSyI SRMCP, is Chief Security & Risk Advisor with more than 30 years of enterprise risk governance experience across critical infrastructure, capital programs, Australian Defence Force service, and international advisory through EMA Global. For boards and operators working through SOCI Act and CIRMP obligations, he advises on asset criticality assessment, all-hazards risk frameworks, and defensible information-sharing arrangements with government and intelligence bodies — reach out to discuss your entity's current compliance posture.