Home Thursday Thoughts Cyber Security: The CIRMP clock is ticking for Australia’s critical infrastructure

Cyber Security: The CIRMP clock is ticking for Australia’s critical infrastructure

In this article

Quick one from the OT security corner

Australia is quietly upping the game when it comes to critical infrastructure. The Critical Infrastructure Risk Management Program (CIRMP) is Australia’s requirement for certain critical infrastructure owners to have a written program for managing key risks across cyber, OT, physical, personnel and supply chain. That program is now being expanded for many high-risk assets into Enhanced CIRMP.

Baseline CIRMP still applies as the foundation; Enhanced CIRMP sits on top of it as an extra tier of obligations for higher-risk asset classes in sectors like energy, water, liquid fuels, broadcasting, and freight services and infrastructure. For those assets, Enhanced CIRMP means stronger expectations around cyber and operational technology, physical and personnel security, and supply chain and foreign influence risk, backed by new transition periods and final compliance deadlines.

The way I think about it

CIRMP – and now Enhanced CIRMP – is less about filling out new forms and more about proving you’re taking real risks seriously. Boards have to sign off on the CIRMP and its annual report, recognised cyber frameworks must be adopted, and there’s now a much sharper lens on OT and critical systems – not just laptops and email. OT has been – and is increasingly – a board-level problem, whether we treat it that way or not.

A box-tick exercise

If we turn CIRMP – and Enhanced CIRMP – into a tick-box exercise, we’ll probably “pass the test” but miss the point. It’s like servicing a truck just enough to get through rego, instead of actually fixing the dodgy brakes you know are there.

On plant floors, those “dodgy brakes” are things like old controllers that everyone is scared to touch, mystery remote access paths, and vendors who still quietly have the keys. For OT-heavy assets, this is not just a compliance project – it’s a chance to clean up a lot of long-standing OT risk under the banner of something the board already cares about. Treating the dates as an opportunity rather than a nuisance lets you use the compliance push to get those brakes properly fixed.

A couple of questions worth asking

Are we treating Enhanced CIRMP as a genuine security and reliability uplift for our OT environments, or just another document to file?

If a regulator asked how we’re reducing real-world OT risk, could we point to anything beyond policies and paper?

Here to help

At Implicit OT we’re helping critical infrastructure owners turn CIRMP obligations into practical OT outcomes: visibility of legacy assets, rationalised remote access, and controls that actually reduce the chance of a bad day on site.

If you’d like to sanity-check where your OT environment sits against the CIRMP expectations, I’m always happy to talk.

Related Posts

Can we prevent every compromise?

OT Cybersecurity Risk Assessment: A Practical Guide

A practical guide to OT cybersecurity maintenance—what industrial teams should review, test and maintain to keep security controls effective over time.

OT Cybersecurity Maintenance: What to Review, Test and Maintain

A practical guide to OT cybersecurity maintenance—what industrial teams should review, test and maintain to keep security controls effective over time.