​​From Compliance to Resilience: SOCI Reforms in an AI-Driven Threat Landscape​

Introduction

Since its introduction in 2018, the Security of Critical Infrastructure Act (SOCI Act) has transformed the way critical infrastructure owners manage security risk. While the framework has improved visibility of critical infrastructure assets and strengthened governance obligations, recent reforms signal a broader shift in focus. Organisations are increasingly expected to move beyond demonstrating compliance and build resilience against a rapidly evolving threat environment, including the growing influence of artificial intelligence (AI). This article explores the evolution of the SOCI framework, the findings of the 2026 Slay Review, and the practical implications of the latest reforms for critical infrastructure operators. The next phase of Australia’s critical infrastructure regulation is not simply about adding more obligations; it is about ensuring those obligations lead to measurable resilience outcomes, effective controls and stronger operational capability in an increasingly AI-driven threat environment.

For directors, executives and risk leaders, the practical message is clear: SOCI compliance should now be treated as a test of organisational resilience, not merely a reporting exercise. Critical infrastructure operators need to show that controls are understood, exercised, independently reviewed and capable of supporting continuity of essential services during disruption.

SOCI Compliance Framework

The Security of Critical Infrastructure Act 2018 (SOCI Act) established a framework designed to strengthen the security and resilience of Australia’s critical infrastructure assets. Its initial focus was on improving visibility of certain critical infrastructure assets and managing national security risks associated with ownership, control and influence, before later amendments expanded the framework into broader positive security obligations (Cyber and Infrastructure Security Centre, 2018). These obligations now include the registration of critical infrastructure assets, mandatory reporting of significant incidents, and the Critical Infrastructure Risk Management Program (CIRMP) (Cyber and Infrastructure Security Centre, 2018).

Slay Review & Why Change Was Needed

Dr Jill Slay’s 2026 independent review of the SOCI Act identified several systemic challenges affecting the framework’s effectiveness, including regulatory duplication, administrative burden, compliance complexity, poor alignment across existing regulatory frameworks, and a limited focus on operational security outcomes (Slay, 2026). The review found that the SOCI Act had increased board-level awareness, improved asset visibility and established baseline risk management obligations. However, many stakeholders considered the framework overly complex and fragmented, with substantial overlap across APRA, PSPF, Privacy Act and sector-specific regulatory requirements. A consistent theme from industry consultation was that organisations were dedicating significant resources to demonstrating compliance rather than improving their actual security posture (Slay, 2026).

The review concluded that the fundamental issue was not the absence of compliance programs or governance structures, but that compliance activities did not necessarily result in improved resilience or measurable security outcomes (Slay, 2026). It identified a growing gap between compliance evidence and actual security capability, highlighting the need to move from a compliance-driven model towards an outcomes-focused resilience framework. This finding became a key driver for subsequent reforms, including the Enhanced CIRMP Rules, which seek to strengthen risk treatment, governance accountability, operational resilience and security maturity across critical infrastructure sectors (Slay, 2026).

SOCI Reform Timeline

The SOCI framework has evolved significantly since its introduction. The timeline below highlights the major legislative and regulatory reforms that have progressively expanded coverage, strengthened risk management obligations and increased expectations around security resilience.

Year Amendment Key Changes
2018 Security of Critical Infrastructure Act 2018 Established the SOCI framework covering the electricity, gas, water and ports sectors, creating the Register of Critical Infrastructure Assets and providing the government with powers to identify and manage national security risks arising from foreign ownership, control and influence. (Security of Critical Infrastructure Act 2018, 2018)
2021 Security Legislation Amendment (Critical Infrastructure) Act 2021 (SLACI Act) Expanded coverage from 4 sectors to 11 sectors. Introduced mandatory cyber incident reporting, government assistance powers during serious cyber incidents, enhanced cyber obligations for systems of national significance, and began the framework for risk management programs. (Security Legislation Amendment (Critical Infrastructure) Act 2021, 2021)
2022 Security Legislation Amendment (Critical Infrastructure Protection) Act 2022 (SLACIP Act) Introduced the Critical Infrastructure Risk Management Program (CIRMP) obligation. Responsible entities became required to identify and manage material risks across cyber, physical, personnel and supply chain domains. Also formalised the Systems of National Significance (SoNS) framework. (Security Legislation Amendment (Critical Infrastructure Protection) Act 2022, 2022)
2023 Security of Critical Infrastructure (Critical infrastructure risk management program) Rules (LIN 23/006) 2023 The Rules require responsible entities to identify, assess and manage material risks arising from cyber and information security hazards, personnel hazards, supply chain hazards and physical security hazards, and to maintain governance arrangements and annual reporting associated with their CIRMP obligations (Security of Critical Infrastructure (Critical Infrastructure Risk Management Program) Rules (LIN 23/006) 2023, 2023).
2024 Security of Critical Infrastructure and Other Legislation Amendment (Enhanced Response and Prevention) Act 2024 Clarified obligations relating to business-critical data storage systems, expanded government assistance arrangements beyond cyber incidents, enabled directions for seriously deficient CIRMPs, improved information-sharing provisions, and integrated telecommunications security requirements into the SOCI framework. The Act also strengthened oversight arrangements for Systems of National Significance (SoNS) and improved information sharing between government and industry. (Security of Critical Infrastructure and Other Legislation Amendment (Enhanced Response and Prevention) Act 2024, 2024)
2026 Security of Critical Infrastructure Legislation Amendment (Enhanced Critical Infrastructure Risk Management Program) Rules 2026 Enhanced CIRMP requirements through more prescriptive cyber, personnel, supply chain and physical security controls, together with strengthened governance, assurance and cyber maturity expectations for designated critical infrastructure assets. (Security of Critical Infrastructure Legislation Amendment (Enhanced Critical Infrastructure Risk Management Program) Rules 2026, 2026)

These reforms demonstrate a shift from asset visibility and ownership transparency towards active risk management, resilience assurance and security maturity. They reflect an increasing recognition that critical infrastructure security depends on ongoing organisational capability, not periodic compliance activity. The value of the SOCI reforms is not that they require organisations to produce more documentation, but that they force a more difficult question: would security arrangements actually work during a disruption?

AI-Driven Threat Landscape

Artificial Intelligence (AI) is fundamentally changing the threat landscape for critical infrastructure. While AI can help critical infrastructure operators improve efficiency, decision-making and automation, it can also introduce new cyber, operational and security risks that need to be managed. AI can help threat actors automate reconnaissance activities, develop malicious code, generate more convincing social engineering content and scale attacks more rapidly (Cyber and Infrastructure Security Centre, 2025). It can lower the technical barrier for some cybercrime and state-sponsored activity, increasing the likely volume and sophistication of attempts targeting both people and systems. AI systems themselves are also vulnerable to attack. Attackers can poison data by manipulating data used to train and refine an AI system, potentially influencing outputs and decisions without directly compromising the system. As a result, AI should not be viewed solely as a cyber risk, but as a force multiplier that amplifies existing risks across physical security, insider threats, supply chains, information environments and operational technology systems. This broader risk profile reinforces the need for an all-hazards approach to critical infrastructure protection (Cyber and Infrastructure Security Centre, 2025).

The significance of the SOCI reforms is that they respond to a threat environment where risk is no longer static. AI-enabled threats can accelerate reconnaissance, make phishing and impersonation more convincing, lower the barrier for less sophisticated actors, and increase the speed and scale at which attacks can occur (Cyber and Infrastructure Security Centre, 2025). For critical infrastructure operators, this means compliance documentation alone is not enough. Organisations need to demonstrate that they understand their critical functions, dependencies, vulnerabilities and response capability in practice.

Practical Implications for Critical Infrastructure Operators

For critical infrastructure operators, the practical effect of the SOCI reforms is that the CIRMP needs to operate as a live risk management tool rather than a static compliance document. It should help organisations identify which functions are genuinely critical, which dependencies could affect service continuity, and whether existing controls would perform under pressure. This requires stronger coordination between executive leadership, cyber security, operations, physical security, procurement and risk teams, particularly where AI-enabled threats can affect people, systems and suppliers at the same time.

The reforms also place greater emphasis on testing and assurance. It is no longer enough for operators to state that controls exist; they need to be able to demonstrate that arrangements are understood, exercised and improved over time. In practice, this means conducting scenario-based exercises, reviewing supplier and technology dependencies, testing incident escalation pathways, and using lessons learned to strengthen resilience before a real disruption occurs.

A practical starting point for operators is to ask five questions: Which services are truly critical? Which systems, suppliers and people do those services depend on? Which controls have been tested under realistic disruption scenarios? How would AI-enabled threats change the speed, scale or plausibility of those scenarios? What evidence would demonstrate that lessons learned have strengthened resilience over time?

Conclusion

The evolution of the SOCI framework reflects a broader shift in how critical infrastructure security is understood in Australia. Early reforms focused on visibility, governance arrangements and compliance obligations. Recent amendments increasingly seek to strengthen operational resilience and measurable security outcomes. This shift is particularly important in an environment where AI is accelerating the scale, speed and sophistication of threats across cyber, physical, personnel and supply chain domains. For critical infrastructure operators, resilience will depend not on compliance documentation alone, but on their ability to understand critical functions, manage dependencies, adapt to emerging threats and continuously improve security capability. In an era of AI-enabled threats and increasingly interconnected infrastructure systems, the question is no longer whether an organisation can show it is compliant. The more important question is whether it can continue delivering essential services when disruption occurs.

References