Skip to Content

Critical Infrastructure Compliance & Assurance

The enhanced CIRMP regime is already running. Most programmes weren’t built for it.

Critical infrastructure, SOCI Act, CIRMP and TSRMP advisory for regulated entities, built on operational ownership of CIRMP and TSRMP delivery inside a critical infrastructure entity, not desk-based advice, and rated BASELINE MET, BASELINE GAP or ENHANCED EXPOSURE so a board knows exactly where its programme actually stands against the current Rules.

Quick answer: This practice provides SOCI Act, CIRMP and TSRMP compliance and assurance advisory for Australian critical infrastructure entities, built by a former de facto Chief Risk Officer who owned CIRMP and TSRMP delivery operationally. Services range from a rated gap diagnostic from A$9,500 to fully scoped development, uplift and standing assurance programmes.

Most CIRMP and TSRMP programmes are built once, against the compilation of the Act and the Rules current at the time, and then left unreviewed while the regime moves on. From 10 June 2026, the enhanced CIRMP requirements under LIN 26/075 add a second, higher tier of obligation, credential compromise, lateral movement, enhanced personnel clearance and supply chain FOCI exposure, for nine high-risk asset classes, against a 12 and 24-month clock that is now running. A programme built to satisfy the regime as it stood a year ago will not satisfy it today.

Know where you actually stand

Every engagement starts with a disclosed rating: BASELINE MET, BASELINE GAP or ENHANCED EXPOSURE, applied to your existing CIRMP or TSRMP with the reasoning shown, not softened for comfort.

Built by someone who has carried the obligation

CIRMP and TSRMP obligations delivered as the accountable owner inside a regulated entity, not assembled from a template by an adviser who has never carried the compliance risk personally.

Current with the regime, not the last edition

The baseline and enhanced CIRMP tiers, and the 2026 grace-period clock, are treated as live inputs. Practice has to move as the evidence and the regulation move, the same discipline applied across every standard this practice works against.

Track record

As de facto Chief Risk Officer at VicTrack, the Victorian Government’s custodial asset manager for the state’s rail land and rail assets, freight terminals and telecommunications network, a combination of scale and complexity that makes it, in effect, the state’s own telecommunications infrastructure provider, CIRMP completion was owned directly for a regulated freight terminal under the SOCI Act, and TSRMP development and expert review was led for the rail telecommunications network. The entity’s enterprise risk framework was rewritten from the ground up on a converged State and Commonwealth baseline, spanning the state government risk framework, financial management legislation, SOCI, PSPF and TSRMP, with the first structured Risk Appetite Framework and Statements established for the entity.

As part of that same VicTrack and state government role, not a separate commercial engagement, membership of the Critical Infrastructure Crime and Sabotage Working Group (CISCWG) contributed to the group’s advice to the Department of Home Affairs, work that began as a copper theft initiative and escalated in scope to critical infrastructure sabotage more broadly, with research interest from the Australian Institute of Criminology. A formal white paper authored on critical infrastructure sabotage triggered confidential briefings from a UK metropolitan police force and submissions to the Commonwealth law and justice department, intelligence services and federal police.

Separately, an independent consulting engagement with Lochard Energy, an operator of gas transmission infrastructure, built the information asset registers, Business Impact Level analysis, systems analysis and SBOM and data architecture review that laid the foundational architecture for the entity’s later CIRMP under the SOCI Act.

Beyond named roles and engagements, advisory contribution has also been made to a small number of confidential discussions on critical infrastructure destruction and sabotage modelling. These were advisory in nature; no commercial engagement or client relationship is claimed, and no organisation is named.

Generic compliance review vs this practice

DimensionGeneric CIRMP/TSRMP reviewThis practice
Prior ownershipAdvises from outside; has not carried the obligation personallyOwned CIRMP completion for a regulated freight terminal and led TSRMP development and expert review for a state rail telecommunications network, as the accountable de facto CRO
Regime currencyOften built against the last compilation reviewedTracks the current Act, current CIRMP Rules, and the 2026 enhanced regime as live obligations
Vocabulary disciplineThreat and hazard used interchangeably; compliance and assurance blurredHazard-framed to the Act’s own section 30AH structure; compliance and assurance treated as separate evidence standards
Sabotage and physical threat pictureDesk-based, generic threat reportingContributed to the pioneering identification and research of critical infrastructure copper theft and sabotage risk, briefed to Home Affairs and a UK metropolitan police force
ScalabilityOne-size package regardless of asset countScoped explicitly to the number of designated assets, sites and systems in play

Every CIRMP/TSRMP Diagnostic returns one of these three ratings. This scale is separate from the comparison above, it is the output of the Diagnostic tier, not a row-by-row key to the table.

BASELINE MET
The programme satisfies current baseline CIRMP or TSRMP requirements under the Rules.
BASELINE GAP
The programme does not yet satisfy baseline requirements under the current Rules.
ENHANCED EXPOSURE
Baseline is met, but the 2026 enhanced requirements for high-risk asset classes are not yet addressed, and the compliance clock is running.

Three tiers, one standard

Qualitatively different in the depth of assurance carried, and scaled to the number of designated assets, sites or systems in scope, not a fixed package.

1. CIRMP / TSRMP Diagnostic

From A$9,500

A rated gap assessment of your current CIRMP or TSRMP against the BASELINE MET / BASELINE GAP / ENHANCED EXPOSURE standard, with a board-ready gap report. Scales with the number of designated assets, sites or systems in scope. No delivery included at this tier.

2. CIRMP / TSRMP Development & Uplift Delivery

Scoped and priced at engagement

Development, remediation or enhanced-regime uplift delivered directly against the specific assets and obligations in scope. Not templated: a one-site and a fifty-site programme are not the same engagement.

3. Standing CIRMP / TSRMP Assurance Programme

Scoped and priced at engagement

Ongoing review, annual report support and standing assurance aligned to the compliance cycle, including monitoring of the enhanced-regime grace-period clock where it applies.

All fees in Australian dollars (AUD), indicative and exclude GST where stated. Final scope and fee confirmed against your obligations.

30+
years enterprise risk leadership
40+
countries, security operations directed
$104B+
in assets under risk oversight
1
independent practice, no panel seat to protect

If your CIRMP or TSRMP was built before the 2026 enhanced regime, that is worth knowing now.

To rate a current CIRMP or TSRMP programme, or to scope delivery against a specific SOCI, CIRMP or TSRMP obligation:

Start a scoping conversation

Tony Ridley MSc CSyP FSyI SRMCP