Critical Infrastructure Compliance & Assurance
The enhanced CIRMP regime is already running. Most programmes weren’t built for it.
Critical infrastructure, SOCI Act, CIRMP and TSRMP advisory for regulated entities, built on operational ownership of CIRMP and TSRMP delivery inside a critical infrastructure entity, not desk-based advice, and rated BASELINE MET, BASELINE GAP or ENHANCED EXPOSURE so a board knows exactly where its programme actually stands against the current Rules.
Quick answer: This practice provides SOCI Act, CIRMP and TSRMP compliance and assurance advisory for Australian critical infrastructure entities, built by a former de facto Chief Risk Officer who owned CIRMP and TSRMP delivery operationally. Services range from a rated gap diagnostic from A$9,500 to fully scoped development, uplift and standing assurance programmes.
Most CIRMP and TSRMP programmes are built once, against the compilation of the Act and the Rules current at the time, and then left unreviewed while the regime moves on. From 10 June 2026, the enhanced CIRMP requirements under LIN 26/075 add a second, higher tier of obligation, credential compromise, lateral movement, enhanced personnel clearance and supply chain FOCI exposure, for nine high-risk asset classes, against a 12 and 24-month clock that is now running. A programme built to satisfy the regime as it stood a year ago will not satisfy it today.
Know where you actually stand
Every engagement starts with a disclosed rating: BASELINE MET, BASELINE GAP or ENHANCED EXPOSURE, applied to your existing CIRMP or TSRMP with the reasoning shown, not softened for comfort.
Built by someone who has carried the obligation
CIRMP and TSRMP obligations delivered as the accountable owner inside a regulated entity, not assembled from a template by an adviser who has never carried the compliance risk personally.
Current with the regime, not the last edition
The baseline and enhanced CIRMP tiers, and the 2026 grace-period clock, are treated as live inputs. Practice has to move as the evidence and the regulation move, the same discipline applied across every standard this practice works against.
Track record
As de facto Chief Risk Officer at VicTrack, the Victorian Government’s custodial asset manager for the state’s rail land and rail assets, freight terminals and telecommunications network, a combination of scale and complexity that makes it, in effect, the state’s own telecommunications infrastructure provider, CIRMP completion was owned directly for a regulated freight terminal under the SOCI Act, and TSRMP development and expert review was led for the rail telecommunications network. The entity’s enterprise risk framework was rewritten from the ground up on a converged State and Commonwealth baseline, spanning the state government risk framework, financial management legislation, SOCI, PSPF and TSRMP, with the first structured Risk Appetite Framework and Statements established for the entity.
As part of that same VicTrack and state government role, not a separate commercial engagement, membership of the Critical Infrastructure Crime and Sabotage Working Group (CISCWG) contributed to the group’s advice to the Department of Home Affairs, work that began as a copper theft initiative and escalated in scope to critical infrastructure sabotage more broadly, with research interest from the Australian Institute of Criminology. A formal white paper authored on critical infrastructure sabotage triggered confidential briefings from a UK metropolitan police force and submissions to the Commonwealth law and justice department, intelligence services and federal police.
Separately, an independent consulting engagement with Lochard Energy, an operator of gas transmission infrastructure, built the information asset registers, Business Impact Level analysis, systems analysis and SBOM and data architecture review that laid the foundational architecture for the entity’s later CIRMP under the SOCI Act.
Beyond named roles and engagements, advisory contribution has also been made to a small number of confidential discussions on critical infrastructure destruction and sabotage modelling. These were advisory in nature; no commercial engagement or client relationship is claimed, and no organisation is named.
Generic compliance review vs this practice
| Dimension | Generic CIRMP/TSRMP review | This practice |
|---|---|---|
| Prior ownership | Advises from outside; has not carried the obligation personally | Owned CIRMP completion for a regulated freight terminal and led TSRMP development and expert review for a state rail telecommunications network, as the accountable de facto CRO |
| Regime currency | Often built against the last compilation reviewed | Tracks the current Act, current CIRMP Rules, and the 2026 enhanced regime as live obligations |
| Vocabulary discipline | Threat and hazard used interchangeably; compliance and assurance blurred | Hazard-framed to the Act’s own section 30AH structure; compliance and assurance treated as separate evidence standards |
| Sabotage and physical threat picture | Desk-based, generic threat reporting | Contributed to the pioneering identification and research of critical infrastructure copper theft and sabotage risk, briefed to Home Affairs and a UK metropolitan police force |
| Scalability | One-size package regardless of asset count | Scoped explicitly to the number of designated assets, sites and systems in play |
Every CIRMP/TSRMP Diagnostic returns one of these three ratings. This scale is separate from the comparison above, it is the output of the Diagnostic tier, not a row-by-row key to the table.
The programme satisfies current baseline CIRMP or TSRMP requirements under the Rules.
The programme does not yet satisfy baseline requirements under the current Rules.
Baseline is met, but the 2026 enhanced requirements for high-risk asset classes are not yet addressed, and the compliance clock is running.
Three tiers, one standard
Qualitatively different in the depth of assurance carried, and scaled to the number of designated assets, sites or systems in scope, not a fixed package.
1. CIRMP / TSRMP Diagnostic
From A$9,500
A rated gap assessment of your current CIRMP or TSRMP against the BASELINE MET / BASELINE GAP / ENHANCED EXPOSURE standard, with a board-ready gap report. Scales with the number of designated assets, sites or systems in scope. No delivery included at this tier.
2. CIRMP / TSRMP Development & Uplift Delivery
Scoped and priced at engagement
Development, remediation or enhanced-regime uplift delivered directly against the specific assets and obligations in scope. Not templated: a one-site and a fifty-site programme are not the same engagement.
3. Standing CIRMP / TSRMP Assurance Programme
Scoped and priced at engagement
Ongoing review, annual report support and standing assurance aligned to the compliance cycle, including monitoring of the enhanced-regime grace-period clock where it applies.
All fees in Australian dollars (AUD), indicative and exclude GST where stated. Final scope and fee confirmed against your obligations.
If your CIRMP or TSRMP was built before the 2026 enhanced regime, that is worth knowing now.
To rate a current CIRMP or TSRMP programme, or to scope delivery against a specific SOCI, CIRMP or TSRMP obligation:
Start a scoping conversationTony Ridley MSc CSyP FSyI SRMCP