Skip to content

Critical infrastructure

Meet your SOCI Act cyber obligations with infrastructure that is engineered for them.

The Security of Critical Infrastructure Act asks for a risk management program that complies with a recognised cyber framework, incident reports within hours, and evidence that holds up to a board and a regulator. We engineer the controls, detection and recovery behind those obligations.

Start with an Essential Eight assessment
Electrical substation with transformers and steel gantries at dusk.

Where we help

  • Framework compliance for the risk management program, such as the Essential Eight at Maturity Level One
  • An inventory of the IT and operational technology connected to the critical asset
  • Detection and escalation that can meet the 12-hour and 72-hour reporting windows
  • Segmentation between corporate IT and operational technology
  • Backup and recovery tested for the systems the asset depends on
  • Evidence for the annual report to the board
A checklist of six security findings, four ticked as closed and two still open, connected to three areas of work: identity, endpoint and detection.

Reporting windows need round-the-clock detection

Incidents with a significant impact must be reported within 12 hours of becoming aware of them. That needs monitoring outside business hours, a clear escalation path and someone who can make the call. North Ark's security operations centre monitors around the clock, and incident response is available day and night.

IT and OT together

Many critical assets depend on operational technology connected to corporate networks. We work on the IT side and the connections between IT and OT: identity, remote access, segmentation, monitoring and recovery, alongside the engineers and vendors who run the control systems.

Where to start

  1. An Essential Eight assessment or cyber risk assessment against the framework your program uses.
  2. Uplift delivered as code, with evidence kept as the work is done.
  3. Controls, monitoring and reporting kept current under Managed Engineering.

Questions buyers ask

Which framework should our program use?

The rules list several, including the Essential Eight at Maturity Level One, ISO/IEC 27001, the NIST Cybersecurity Framework, the Australian Energy Sector Cyber Security Framework and the Cybersecurity Capability Maturity Model. For many Microsoft-centred organisations the Essential Eight is the most direct fit.

Do you work on operational technology?

We work on the IT that connects to OT and the boundary between them. Control system engineering stays with your OT engineers and vendors, and we coordinate with them.

Can you help us report an incident?

Yes. Incident response is available day and night, and we gather the evidence you need to report within the required windows.

Can you provide evidence for the board's annual report?

Yes. Framework compliance, control status and incidents are reported monthly, which makes the annual report a summary.

Do you work with water, energy and transport operators?

Yes, and with the other sectors the Act covers. The obligations depend on the asset class, so we start by confirming which apply to you.

Start a conversation

Engineer the controls behind your SOCI obligations.

Tell us which obligations apply and what is due next.

Talk to an Engineer