Quick one from the OT security corner
Australia is quietly upping the game when it comes to critical infrastructure. The Critical Infrastructure Risk Management Program (CIRMP) is Australia’s requirement for certain critical infrastructure owners to have a written program for managing key risks across cyber, OT, physical, personnel and supply chain. That program is now being expanded for many high-risk assets into Enhanced CIRMP.
Baseline CIRMP still applies as the foundation; Enhanced CIRMP sits on top of it as an extra tier of obligations for higher-risk asset classes in sectors like energy, water, liquid fuels, broadcasting, and freight services and infrastructure. For those assets, Enhanced CIRMP means stronger expectations around cyber and operational technology, physical and personnel security, and supply chain and foreign influence risk, backed by new transition periods and final compliance deadlines.
The way I think about it
CIRMP – and now Enhanced CIRMP – is less about filling out new forms and more about proving you’re taking real risks seriously. Boards have to sign off on the CIRMP and its annual report, recognised cyber frameworks must be adopted, and there’s now a much sharper lens on OT and critical systems – not just laptops and email. OT has been – and is increasingly – a board-level problem, whether we treat it that way or not.
A box-tick exercise
If we turn CIRMP – and Enhanced CIRMP – into a tick-box exercise, we’ll probably “pass the test” but miss the point. It’s like servicing a truck just enough to get through rego, instead of actually fixing the dodgy brakes you know are there.
On plant floors, those “dodgy brakes” are things like old controllers that everyone is scared to touch, mystery remote access paths, and vendors who still quietly have the keys. For OT-heavy assets, this is not just a compliance project – it’s a chance to clean up a lot of long-standing OT risk under the banner of something the board already cares about. Treating the dates as an opportunity rather than a nuisance lets you use the compliance push to get those brakes properly fixed.
A couple of questions worth asking
Are we treating Enhanced CIRMP as a genuine security and reliability uplift for our OT environments, or just another document to file?
If a regulator asked how we’re reducing real-world OT risk, could we point to anything beyond policies and paper?
Here to help
At Implicit OT we’re helping critical infrastructure owners turn CIRMP obligations into practical OT outcomes: visibility of legacy assets, rationalised remote access, and controls that actually reduce the chance of a bad day on site.
If you’d like to sanity-check where your OT environment sits against the CIRMP expectations, I’m always happy to talk.