Critical Infrastructure Risk Management Consultants Australia

Specialist SOCI Act compliance consulting. From CIRMP development to annual board attestation.

What is Critical Infrastructure Risk Management?

Australia’s critical infrastructure landscape has fundamentally changed. The Security of Critical Infrastructure Act 2018 (SOCI Act) and its subsequent amendments now require responsible entities across 11 sectors and 13 asset classes to adopt, maintain, and comply with a written Critical Infrastructure Risk Management Program (CIRMP). The first annual reporting period (2024–2025) has passed, and enhanced CIRMP Rules now apply to nine asset classes, with stronger physical security, personnel and supply chain requirements. The CIRMP physical security playbook explains what they mean for physical security.

For boards and executive teams, SOCI compliance is no longer a future obligation. It is an active governance requirement carrying regulatory scrutiny, civil penalties, and reputational exposure. Agilient provides the independent analysis, specialist methodology, and ongoing assurance that responsible entities need to satisfy their CIRMP obligations with confidence. 

For a leader’s roadmap to the obligations, see Agilient’s SOCI Act compliance guide.

Physical, personnel and supply chain hazards

The Critical Infrastructure Risk Management Program (CIRMP) Rules require responsible entities to address four hazard vectors: cyber and information security, personnel, supply chain, and physical and natural hazards. Much of the market concentrates on the cyber vector. Agilient focuses on the other three, where many programs are least developed.

  • Physical and natural hazards: risks to the parts of an asset critical to its functioning, including physical access to sensitive facilities such as control rooms, and exposure to natural hazards such as flood, bushfire and severe storms.
  • Personnel hazards: the trusted insider risk posed by critical workers who have the access and ability to disrupt the asset, and the processes used to identify, assess and manage those workers.
  • Supply chain hazards: the risk that disruption or compromise in a critical supply chain affects the asset, whether the cause is natural, accidental or malicious.

Annual report and board attestation

Responsible entities must give an annual report on their CIRMP within 90 days after the end of the financial year, approved by the board, council or other governing body. Agilient runs an annual cycle for clients: a review of the physical, personnel and supply chain hazard registers, testing of key controls, one exercise, and a briefing pack that supports the governing body’s approval. More detail on the framework is on the critical infrastructure and SOCI Act page, and an example of the work is a construction-phase security risk assessment for a new energy generation facility.

Industrial plant at night
Malicious insiders can cause a lot of damage and personnel checks are vital to the security of Australia’s defence organisations.

why choose us

Why Agilient?

Line icon of a head silhouette with a cog

Proven Track Record

Agilient has delivered more than 300 security projects across Australia’s largest government, healthcare, industrial, and defence networks. This includes multi-site critical infrastructure assessments, CIRMP development programs, and long-term security guardianship engagements.

Line icon of an award medal

Credentialled, Licensed Consultants

Agilient’s team brings senior government, defence and intelligence backgrounds, and Agilient is a DISP member appointed to Australian Government security panels. This enables direct engagement for government and defence-adjacent critical infrastructure entities.

Line icon of a badge with a tick and stars

Standards-Based, Defensible Methodology

Every engagement is benchmarked against recognised frameworks, including:

  • AS ISO 31000:2018 — Risk Management
  • AS 4485 — Security for Healthcare Facilities
  • ISO 22301 — Business Continuity Management Systems
  • The Protective Security Policy Framework (PSPF)
  • The SOCI Act 2018 and CIRMP Rules

This ensures that findings, recommendations, and attestation support are repeatable and defensible under regulatory scrutiny.

We Tailor to Your Industry

Operating nationally, Agilient brings a wealth of experience to every engagement, with a genuine understanding of the nuances and individual needs that vary across industries, regions, and organisations. No two clients are the same, and Agilient takes that seriously. Whether a client is in healthcare, construction, finance, or beyond, the approach is always tailored, considered, and built around the organisation.

For Victorian operators, Agilient’s Melbourne office provides SOCI Act consulting and CIRMP audits in Melbourne.

See all critical infrastructure case studies.

Critical Infrastructure Services

Agilient is not a generalist consultancy. The firm specialises in high-assurance physical and protective security for critical infrastructure environments. Every engagement is designed to move an organisation from a fragmented or undocumented security posture to a position of proven, standards-aligned maturity.

Line icon of a padlock inside a warning triangle

Agilient conducts a comprehensive desktop discovery of existing policies, procedures, registers, and controls to build a technical baseline against the SOCI Act’s CIRMP requirements. This analysis applies a strict regulatory lens, identifying genuine compliance gaps and material risks rather than cataloguing general security preferences. The output is a clear, prioritised register of what must be addressed to satisfy CIRMP obligations.

Line icon of a browser window with a security shield

Targeted Security Threat and Risk Assessments

Attempting a comprehensive, floor-by-floor campus inspection often bogs critical infrastructure projects down in data and logistics. Agilient employs a targeted “Nerve Centre” methodology, isolating and assessing the highest-consequence zones within a facility — such as ICU departments, main plant rooms, ICT server rooms, control centres, and critical supply chain interfaces.
By concentrating assessment effort on these critical components, Agilient can address the vast majority of regulatory risk efficiently and within practical timeframes. Assessments are conducted in accordance with AS/NZS ISO 31000:2018 (Risk Management) and relevant sector-specific standards.

Line icon of a hooded figure with a padlock

Risk Control Effectiveness Validation

Recording that a security control exists is not the same as proving it works. Agilient validates Risk Control Effectiveness (RCE) through day and night on-site inspections conducted in live operational environments. This includes verifying that access control systems, CCTV surveillance, intrusion detection, duress alarms, and procedural controls actively detect, delay, or deter threats under real-world conditions.

Line icon of a group of people with a padlock

Tiered Security Uplift Roadmaps

Technical findings are translated into practical, fundable recommendations structured for executive decision-making. Agilient’s uplift roadmaps are categorised into three tiers:

Must-Do — risk-critical rectifications required for mandatory SOCI Act and life-safety compliance.

Consider-Doing — risk-based, cost-efficient security enhancements that materially reduce residual risk.

Nice-to-Have — future-state capabilities and emerging technology options.

This tiered structure allows boards and executive teams to allocate capital with a clear understanding of regulatory priority versus discretionary investment.

Line icon of a shield with a padlock

Strategic Security Guardianship (Ongoing Assurance)

Maintaining CIRMP compliance is not a one-off exercise. Agilient offers an ongoing security guardianship partnership designed to remove the administrative burden of compliance from internal teams. This includes:

  • Operational integrity audits against CIRMP requirements.
  • Asset lifecycle oversight and risk register maintenance.
  • Preparation and review of the mandatory annual board-approved SOCI attestation report.
  • Monitoring of regulatory developments, including enhancements to the CIRMP Rules.
Line icon of a hand holding a shield with a padlock

Sectors and Asset Classes

The SOCI Act applies across 11 critical infrastructure sectors. Agilient provides risk management services to responsible entities operating within these sectors, including:

Agilient is appointed to multiple Australian Government procurement panels, including the Department of Home Affairs Security Services Panel, the DFAT Security Services Panel, and the Defence Support Services Standing Panel, so government clients can engage Agilient directly. Agilient is independent and vendor-neutral; its founder, Mark Bezzina, has more than 20 years’ experience running security and resilience companies and has led over 300 projects, and every consultant has at least 20 years’ experience, typically as security managers within large organisations, including former senior Australian Defence, intelligence and police personnel. Agilient is licensed to operate in New South Wales, the Australian Capital Territory, Victoria, Queensland and South Australia, and has delivered more than 300 projects for Australian organisations. Contact Agilient to discuss your requirements.

Secure Your Critical Infrastructure

Regulatory obligations under the SOCI Act are increasing, and the Department of Home Affairs continues to consult on enhancements to the CIRMP Rules. Do not wait for a regulatory audit or a critical incident to test your resilience.
Partner with Agilient to build a defensible, risk-based Critical Infrastructure Risk Management Program that protects your people, your assets, and your reputation.

OUR LOCATIONS

Security Solutions Nation-Wide

With a national footprint, our security consulting services support organisations across Australia in managing risk, compliance, and security strategy. We combine industry expertise with a practical approach to deliver consistent outcomes across all states and territories.

faqs

Frequently Asked Questions

The Security of Critical Infrastructure Act 2018 (SOCI Act) is the Australian Government’s legislative framework for protecting critical infrastructure assets. It establishes obligations for responsible entities across 11 sectors, including mandatory incident reporting, registration requirements, and the adoption of a written Critical Infrastructure Risk Management Program (CIRMP).

Responsible entities for critical infrastructure assets in 13 specified asset classes are required to adopt, maintain, and comply with a CIRMP. These asset classes span sectors including healthcare (designated hospitals), energy, water, transport, telecommunications, data storage, financial services, defence industry, food and grocery, and space technology.

The SOCI Act requires CIRMPs to address material risks across four mandatory hazard vectors: physical security and natural hazards, cyber and information security, personnel security (trusted insider threats), and supply chain security.

The Critical Infrastructure Risk Management Program (CIRMP) Rules (LIN 23/006), made under the Security of Critical Infrastructure Act 2018, require responsible entities for certain critical infrastructure assets to adopt and maintain a written risk management program. The program must identify and manage material risks across four hazard categories — cyber and information security, personnel, supply chain, and physical security and natural hazards — and is subject to annual, board-approved reporting. Agilient helps responsible entities build and maintain a compliant CIRMP.

Responsible entities are required to submit an annual report to the Cyber and Infrastructure Security Centre (CISC) and obtain board-level sign-off on the CIRMP each reporting period. The first mandatory reporting period was 2024–2025.

Yes. Agilient provides ongoing strategic security guardianship, which includes preparation and review of the annual board-approved SOCI attestation report, as well as continuous monitoring of regulatory changes to the CIRMP Rules.

Worker in high-visibility clothing at an industrial site