Critical Infrastructure

SOCI Act CIRMP: A Practical Guide to the Four Hazard Domains

A practical guide to the SOCI Act Critical Infrastructure Risk Management Program (CIRMP): the four hazard domains, cyber framework alignment, and preparing for Board attestation.

Muhammad Anwar
· 3 min read

For responsible entities of critical infrastructure assets, the Critical Infrastructure Risk Management Program (CIRMP) is one of the most significant obligations under the Security of Critical Infrastructure Act 2018 (SOCI Act). Done well, a CIRMP gives the Board genuine visibility of the hazards that could disrupt essential services. Done poorly, it’s a compliance binder nobody reads.

What a CIRMP must do

Under the SOCI Act framework, administered by the Cyber and Infrastructure Security Centre, a CIRMP requires responsible entities to identify material risks to their assets, minimise or eliminate them where reasonably practicable, and mitigate their impact. Entities report annually, with Board-level approval.

The program must address all hazards — not just cyber.

The four hazard domains

1. Cyber and information security

Cyber threats to operational technology and IT. Entities are generally expected to align with a recognised cybersecurity framework — such as the AESCSF for energy, or other frameworks named in the rules — to a specified maturity. Check the current rules for your sector’s requirements.

2. Personnel

Risks from trusted insiders: background checks for critical workers, access management, and off-boarding. This is often the least mature domain because it crosses HR, security and operations.

3. Supply chain

Risks from suppliers, vendors and service providers — including offshore dependencies, single points of failure and, increasingly, AI features inside supplier products.

4. Physical and natural

Physical security of sites and assets, plus natural hazards such as bushfire, flood and extreme heat that can affect availability.

Common CIRMP pitfalls

  • Cyber-only thinking. The cyber domain gets all the attention while personnel and supply chain lag.
  • Risk registers without owners. Hazards are listed but nobody is accountable for treatment.
  • No link to operations. The CIRMP sits with compliance, disconnected from the engineers who manage the assets.
  • Boards asked to attest blind. Directors receive a summary the week before sign-off, without the context to challenge it.

Building a CIRMP that works

  1. Map your critical assets and the essential services they support.
  2. Run all-hazards workshops with operations, security, HR, procurement and facilities.
  3. Assess each hazard domain with consistent likelihood and consequence criteria.
  4. Align cyber controls with your required framework and target maturity.
  5. Assign owners and treatments for each material risk.
  6. Report to the Board through the year, not just at attestation time.
  7. Review and update after incidents, significant changes and annually.

The best Board attestations are the least dramatic — because directors have already seen the risks, the trends and the progress during the year.

Preparing the Board

Directors are attesting to the program, so give them what they need: a clear view of material risks, the status of treatments, framework maturity against target, and any significant variations. Short, regular risk reporting beats a once-a-year briefing pack.

Frequently asked questions

Does every critical infrastructure asset need a CIRMP?

No. CIRMP obligations apply to specified asset classes. Check the current SOCI rules and CISC guidance to confirm whether your assets are covered.

Which cybersecurity framework should we use?

The rules list acceptable frameworks and maturity levels. Energy entities often use the AESCSF; others may use the Essential Eight, NIST CSF or ISO 27001, depending on the rules for their sector.

What happens at annual reporting?

Responsible entities submit an annual report on their CIRMP, approved by the Board or equivalent governing body. The report should reflect the program as it operates, including any significant variations during the year.


Building or refreshing your CIRMP? Explore critical infrastructure services or talk to my AI agent.

Muhammad Anwar

Cybersecurity & Compliance Assurance Leader specialising in the ISM, PSPF, NIST SP 800-53, SOCI Act and AI governance (ISO 42001). Views are my own.