Under lock and (SO)CI: Proposed cyber updates to the security of critical infrastructure framework
Market Insights
The Department of Home Affairs has released its consultation paper (Consultation Paper) on the proposed Tranche 2 reforms to the Security of Critical Infrastructure Act 2018 (Cth) (SOCI Act), representing the next stage of the Government’s response to the 2025-26 Independent Review of the SOCI Act. Our broader discussion of the Consultation Paper appears here.
In the Consultation Paper, the Government proposed a number of amendments that go towards the cybersecurity requirements that need to be met in respect of critical infrastructure assets.
Expanding regulated assets
Data storage or processing capture pathways
The Consultation Paper proposes a fundamental redesign of the way data storage and processing assets are identified under the SOCI framework. Under the SOCI Act as it applies today, relevant data services can be caught as critical assets where they are aware that they are handling data that is critical to other critical infrastructure assets or to government. This is supported by an obligation on the operators of other critical infrastructure assets to provide notice to their relevant data storage and processing providers.
The Department’s concern is that the current model relies heavily on customer identity, customer notifications and the characterisation of particular datasets, making it difficult for providers to determine their regulatory status based on information available to them. The proposal would replace this with a series of objective pathways based on facility characteristics, service scale, certification status and, in limited circumstances, ministerial designation.
This change moves the focus away from the data being handled by data storage and processors, and towards the nature of those assets themselves. This highlights the importance of data storage and processing assets in Australia more generally, and not just as a subsidiary of other forms of critical infrastructure assets.
This potentially changes the risk profile of the regime. Under the current framework, capture is linked to the criticality of the data being processed. It is likely that most of these entities will be captured under the proposed framework, however, certain providers handling sensitive or business-critical information may fall outside the regime if they do not satisfy the relevant facility, service, or certification thresholds. This could create a gap that results in data remaining at risk, though further proposals discussed below may go some way to closing that gap for key outsourced providers. Conversely, large-scale providers may be regulated regardless of the particular datasets they host.
Submarine telecommunications cables and associated infrastructure
The Consultation Paper seeks to address uncertainty regarding the treatment of submarine telecommunications cables and associated infrastructure under the SOCI framework. Modern submarine cable systems extend beyond the cable itself and comprise a broader ecosystem of landing stations, terrestrial backhaul, power infrastructure, network management systems, and other supporting assets. The Department considers that existing asset boundaries do not adequately reflect the operational reality of these interconnected systems.
The proposal reflects the increasing importance of submarine cables to Australia’s communications networks, economic activity, and national security. Given Australia’s geographic position, international connectivity is heavily dependent on submarine cable infrastructure, and disruption of cable systems has the potential to affect telecommunications, cloud services, financial services, and other critical sectors simultaneously.
While the measure is not directed at data sovereignty or restrictions on overseas data transfers, it reinforces the strategic importance of the infrastructure through which those transfers occur. Organisations that rely heavily on offshore cloud platforms, international connectivity, or global technology supply chains may therefore see increased regulatory attention or restrictions.
Expanding obligations to apply to more entities
The Consultation Paper proposes to expand the number of entities subject to cybersecurity obligations. Specifically, the proposition is that corporate group entities and other entities that exercise material practical control over a critical infrastructure asset or critical function (such as a managed service provider) will be subject to obligations such as cooperating with the responsible entity and to notify responsible entities if they become aware of circumstances that could materially affect the critical infrastructure asset. This includes cyber security related events.
Expanding cybersecurity obligations beyond the responsible entity is particularly important given responsible entities often outsource these IT activities to related entities or managed service providers.
The proposal to extend cyber obligations to ‘relevant operators’ like managed service providers is also interesting in the context of proposed reforms to the definition of ‘critical data storage or processing asset’, discussed above. Some of these service providers might previously have qualified as ‘critical data storage or processing assets’ by virtue of their engagement, and become subject to the SOCI Act as a critical asset in their own right. While that compliance obligation may fall away for some service providers, these new requirements might take their place.
Changes to CIRMP obligation
The Consultation Paper proposes to strengthen the supply chain elements of the CIRMP framework by introducing more explicit cyber security assurance requirements for critical suppliers, managed service providers, and other significant third party relationships. The proposal is based on the Department’s view that existing CIRMP obligations are not clear about how entities should obtain assurance that suppliers are appropriately managing supply chain risks in practice.
The Consultation Paper proposes a framework that required entities to obtain greater visibility over supplier cyber security controls and maintain evidence supporting their assessment of supplier cyber resilience. Although significant implementation detail remains to be developed, the proposal signals a shift away from reliance on contractual promises alone and towards ongoing verification and assurance activities.
This framework presents parallels with the Australian Prudential Regulation Authority’s approach under CPS 230 in relation to the oversight of material service providers and operational resilience. Affected entities should anticipate a need for more structured supplier governance, stronger due diligence processes, enhanced audit and reporting rights, and greater contractual leverage over critical technology and service providers. Organisations may ultimately need to revisit cloud, managed services, outsourcing, and IT contracts to ensure they can obtain the information and assurances required to satisfy the expanded CIRMP expectations.
Cyber Security Incident definition changes
The Consultation Paper proposes to modernise the definition of a cyber security incident by expressly extending it to incidents involving automated systems, software agents, and artificial intelligence technologies. The concern is that the existing definition was developed before the widespread deployment of autonomous and AI-enabled systems and may not clearly capture incidents that arise through their operation, compromise, or misuse rather than through human actions.
The proposal is intended to ensure that incident reporting obligations remain effective as organisations and threat actors increasingly depend on automated decision-making tools, AI systems, and software agents performing functions that were previously undertaken by human operators. Rather than focusing on the actor responsible for the activity, the revised definition would focus on the consequences of the incident and its impact on the relevant system or asset.
Most regulated entities already treat significant failures, compromises, or misuse of automated systems as cyber security events from an operational perspective. The principal effect of the amendment is to remove ambiguity and make it clear that reportable incidents can arise from the operation of automated technologies, regardless of whether a human user was directly involved in the conduct that triggered the incident.
Next steps
The Consultation Paper seeks to strengthen Australia’s critical infrastructure regime in response to an increasingly complex cyber threat environment.
The proposed reforms would expand the scope of entities and assets subject to regulation, introduce greater scrutiny of supply chain cyber security practices, and modernise the framework to address emerging technologies such as AI and automated systems.
While the proposals remain subject to consultation, organisations should consider the potential impact of the reforms on their operations and begin assessing whether existing cyber security, governance, and supplier management arrangements are fit for purpose under an expanded regulatory framework.
HWLE Lawyers’ Intellectual Property, Privacy and Technology team has extensive experience in advising businesses regarding privacy and technology law. If you are concerned about your obligations under the SOCI framework, please contact us for further information on how we can assist you.
This article was written by Daniel Kiley, Partner, Ashlee Broadbent, Associate, Maximilian Soulsby, Associate, and Jasper Dowdell, Law Graduate.
Subscribe for publications + events
HWLE regularly publishes articles and newsletters to keep our clients up to date on the latest legal developments and what this means for your business. To receive these updates via email, please complete the subscription form and indicate which areas of law you would like to receive information on.
* indicates required fields
