On June 10, 2026, Australia’s enhanced Critical Infrastructure Risk Management Program (CIRMP) rules came into force — and with them, the most prescriptive cybersecurity obligations yet imposed on nine specific asset classes: energy market operators, electricity, gas, liquid fuel, broadcasting, domain name systems, water, and freight services and infrastructure. The problem isn’t the new checklist. It’s that the checklist assumes a detection capability most security teams don’t have yet.
The Evolution from SOCI Act to CIRMP
Australia’s Security of Critical Infrastructure Act 2018 (SOCI Act) has been tightening steadily since 2021, but June 2026 marks a turning point. Following the first Independent Review of the Act, delivered by Dr. Jill Slay AM in February 2026 and made public the following month, the government registered the Security of Critical Infrastructure Legislation Amendment (Enhanced Critical Infrastructure Risk Management Program) Rules 2026 on June 9, and they commenced the next day. These nine asset classes are now subject to detailed, auditable cyber, supply-chain, personnel, and physical security requirements. A second reform, expanding the Minister’s power to direct entities to drop risky vendors and raising civil penalties to AUD $660,000 for individuals and AUD $3.3 million for corporations, is still moving through consultation.
The SOCI Act’s full 11-sector scope — which also includes financial services, healthcare, data storage, communications carriers broadly, higher education, and defence industry — still carries the baseline three obligations; it’s just the nine asset classes above that now carry this newer, more prescriptive layer.
The Independent Review emphasized a shift from “light touch” compliance to accountability for security outcomes and enforcement. This transition mirrors similar international developments, such as Europe’s NIS2 Directive and recent U.S. vulnerability-management reforms.
Near-Real-Time Threat Requirements
Most critical infrastructure entities in Australia already carry three Positive Security Obligations under SOCI: registering their assets, reporting cyber incidents within strict windows — 12 hours for “significant” incidents, 72 hours for “relevant” ones — and maintaining a written CIRMP covering cyber, supply-chain, personnel, and physical hazards. Entities designated as Systems of National Significance carry an additional, more demanding obligation: they must maintain what the legislation calls a “near-real-time threat picture”.
This obligation requires continuous awareness of the threat landscape surrounding assets, identifying risks before they escalate into incidents that trigger reporting deadlines. The updated CIRMP rules specify requirements for:
- network segregation
- phishing-resistant multi-factor authentication
- centralized logging
- legacy software management
- continuous assessment of supply-chain and vendor vulnerabilities, including foreign control risks
Deadlines are staged, with energy operators required to reach Maturity Indicator Level 2 under the Australian Energy Sector Cyber Security Framework by June 30, 2028.
The newly commenced CIRMP rules add specificity to what “minimizing cyber material risk” now means in practice: network segregation between critical and non-critical systems, phishing-resistant multi-factor authentication with centralized logging, active management of unpatched legacy software, and notably a requirement to map and continuously assess supply-chain vulnerabilities and vendor risk, including exposure arising from foreign ownership, control, or influence. Grace periods stretch from 12 to 24 months from commencement, with energy operators required to reach Maturity Indicator Level 2 under the Australian Energy Sector Cyber Security Framework by June 30, 2028. The deadlines are staged. The obligation to be watching continuously is not.
The Challenge of Asymmetric Reporting
A 12-hour reporting clock necessitates immediate visibility into threat activity. Organizations without pre-existing detection capabilities often struggle to comply once the reporting window opens.
For instance, when early exploit activity is detected (such as the Fortinet FortiWeb zero-day, identified 38 days before its inclusion in CISA’s Known Exploited Vulnerabilities catalog), organizations with integrated threat intelligence gain a significant advantage. By validating controls and hardening systems early, these entities are better prepared to meet reporting requirements when formal advisories eventually emerge.

Implementation: Integrating Intelligence and Risk Management with Dataminr
The enhanced CIRMP rules align with established Gartner© industry frameworks:
- Unified Cyber Risk Intelligence (UCRI): Integrating external threat signals, internal exposure, and business risk into a single decision model.
- Continuous Threat Exposure Management (CTEM): Continuously scoping, discovering, validating, and prioritizing exposure rather than relying on quarterly audits.
The new requirement for supply-chain and vendor-risk mapping necessitates a CTEM approach. With vulnerability exploitation and third-party breaches increasing, static, point-in-time assessments are no longer sufficient — whether that’s a patch cycle that only catches up after the fact, or a threat feed that flags an exposure without ever connecting it to your specific assets and controls. Both failure modes trace back to the same root cause: treating security as a periodic check instead of a continuous, environment-aware picture. Dataminr for Cyber Defense is designed to operationalize these requirements continuously.
Three Dataminr Capabilities That Close the Gap
Client-Tailored Threat Intelligence
Fuses early external threat signals—sourced from over one million public sources—with an organization’s specific assets, controls, and exposure history. This provides relevant, actionable intelligence rather than generic feeds, supporting the “near-real-time” requirement.
Agentic TI Ops
Converts early signals into structured, lifecycle-managed intelligence. This includes details on actors, tactics, and indicators of compromise, which streamlines response and reporting. When a 72-hour reporting obligation arises, the necessary documentation can be generated efficiently based on this continuous work.
Predictive Threat Exposure Management
Cataloging which controls exist isn’t the same as knowing which ones matter. Under a 72-hour clock, security teams need to know in advance which exposures are actually reachable and material in their environment — not just which controls are technically in place. Predictive Threat Exposure Management validates controls against live telemetry, quantifies which risks are real versus theoretical, and gives boards the same accountability the Independent Review recommends: not a checklist of controls, but a live picture of what’s actually exposed.
Conclusion
Australia’s enhanced SOCI Act regulations prioritize demonstrable security outcomes over documentation. Organizations that adopt a continuous threat exposure management approach are better positioned to meet these obligations. The current 12-to-24-month grace periods provide a window to build the necessary threat picture capabilities before the most stringent deadlines arrive.
The nine asset classes now subject to the enhanced CIRMP rules have 12 to 24 months before the hardest deadlines land. That is enough time to build a threat picture that’s actually near-real-time, or enough time to still be assembling one when the next reportable incident starts the clock.
The organizations that treat June 10, 2026 as the date the requirement became continuous, rather than the date a new form appeared, are the ones that will meet the letter of the law by having already met its intent.

Dataminr for Cyber Defense
Learn how Dataminr for Cyber Defense supports critical infrastructure operators in meeting CIRMP rules requirements.
Learn more