Melbourne city skyline, where Agilient provides SOCI Act consulting and CIRMP audits

Agilient provides SOCI Act consulting in Melbourne for critical infrastructure operators that need to build, audit or strengthen a critical infrastructure risk management program (CIRMP). The work is delivered from Agilient’s Melbourne office on Collins Street, by consultants who assess physical, personnel, supply chain and cyber hazards together rather than in isolation.

Victorian operators often face two regimes at once: the Commonwealth Security of Critical Infrastructure Act 2018 and Victoria’s own critical infrastructure resilience arrangements. Agilient helps boards and risk owners meet both with one coherent, evidence-based program. For a plain-English overview of the obligations, see the SOCI Act compliance guide.

SOCI Act consulting

What does SOCI Act consulting in Melbourne cover?

SOCI Act consulting helps a responsible entity understand which obligations apply to its assets and then meet them in a way that stands up to board and regulator scrutiny. For most Melbourne clients the centre of the work is the CIRMP, the written program that identifies material risks to the asset and sets out how they are minimised or eliminated.

  • Applicability and obligations review. Confirming which assets are captured, which obligations apply and who is accountable.
  • CIRMP development or uplift. Building the program, or strengthening an existing one, across all four hazard vectors.
  • CIRMP audit and compliance review. Independent testing of the program and the evidence behind it.
  • Board assurance. Preparing the board or governing body to approve the annual report with confidence.
CIRMP audit

What is a SOCI Act compliance audit or CIRMP audit?

A CIRMP audit is an independent review of the program against the Security of Critical Infrastructure (Critical infrastructure risk management program) Rules. Agilient tests whether material risks have been identified for each hazard vector, whether controls exist and work, whether the program is being kept up to date, and whether there is enough evidence to support the annual report.

The audit is grounded in site work, not only document review. Consultants visit Melbourne and regional Victorian sites to test the physical and personnel controls that desk-based reviews tend to miss, drawing on Agilient’s security audit method and security risk assessment practice. The output is a prioritised findings report, written for the board as well as the risk team.

The four hazards

Which hazards must a CIRMP address?

The CIRMP Rules require a responsible entity to address four hazard vectors. Agilient’s advice covers all four, with particular depth in the physical and personnel areas where many programs are weakest.

  • Physical security and natural hazards. Identifying critical components, controlling access to them and planning for events such as bushfire, flood, storm and heat.
  • Personnel. Identifying critical workers, assessing their suitability and managing the insider risk from staff and contractors.
  • Supply chain. Managing risks from suppliers, vendors and dependencies, including foreign ownership and control where relevant.
  • Cyber and information security. Meeting a recognised cyber security framework, which Agilient addresses at the governance level and coordinates with the operator’s technical specialists.

The critical infrastructure and SOCI Act framework page explains each obligation in more detail.

Victoria

How do Victoria’s critical infrastructure arrangements fit with the SOCI Act?

Victoria has its own critical infrastructure resilience framework under Part 7A of the Emergency Management Act 2013. Owners and operators of infrastructure declared vital must understand their emergency risks, develop mitigation plans and test their preparedness, in line with Ministerial Guidelines that set minimum standards for planning, exercises and audits.2

The two regimes are separate, but they overlap in practice. An operator that is both a SOCI responsible entity and the owner of vital infrastructure in Victoria can use one aligned risk assessment, one set of controls and one exercise program to support both. Agilient designs programs with that alignment in mind, so the same evidence serves the Commonwealth regulator and the Victorian framework.

Why Agilient

Why Melbourne operators choose Agilient

Local presence

A Melbourne office at Level 14, 333 Collins Street, with consultants available for site work across Victoria.

Independent advice

Agilient does not sell or install equipment, so its findings serve only the client’s risk.

Senior experience

Every consultant has at least 20 years’ experience, typically as security managers within large organisations.

Physical and personnel depth

Strength in the hazard vectors that desk-based cyber reviews often underplay.

Critical infrastructure experience

Work across energy, utilities, ports, liquid fuels and data centres. See the critical infrastructure case studies.

Board-ready reporting

Findings written so that directors can approve the annual report with confidence.

Agilient is licensed to operate in Victoria and works across Sydney, Melbourne, Brisbane, Adelaide, Canberra and regional Australia. Its wider Melbourne security consulting services are described on the Melbourne page, and its national critical infrastructure risk management service covers operators in every state.

Talk to Agilient about SOCI Act compliance in Melbourne

A short briefing will establish where your CIRMP stands, what the board needs before the next annual report, and whether a gap assessment or a full audit is the right next step.

Book a SOCI Act briefingor see the critical infrastructure risk management service

FAQs

SOCI Act consulting in Melbourne: frequently asked questions

Does Agilient have a Melbourne office?
Yes. Agilient has a Melbourne office at Level 14, 333 Collins Street, Melbourne VIC 3000. It holds a Victorian private security business licence, and its consultants work with critical infrastructure operators across Melbourne and regional Victoria.
What is a CIRMP audit?
A CIRMP audit is an independent review of a critical infrastructure risk management program against the Security of Critical Infrastructure (Critical infrastructure risk management program) Rules. It tests whether material risks are identified across the cyber, personnel, supply chain and physical hazard vectors, whether controls are in place and whether there is evidence to support the annual report to the regulator.
Who needs SOCI Act compliance support?
Responsible entities for the asset classes covered by the CIRMP Rules, including electricity, gas, water and sewerage, liquid fuels, freight infrastructure and services, energy market operators, payment systems, data storage and processing, designated hospitals, broadcasting, domain name systems, and critical food and grocery supply.
How does the SOCI Act relate to Victoria’s critical infrastructure resilience arrangements?
They are separate regimes. The SOCI Act is Commonwealth legislation. Victoria also has its own arrangements under Part 7A of the Emergency Management Act 2013, which require owners and operators of infrastructure declared vital to plan for, exercise and audit their emergency risk management. A Victorian operator can be subject to both, and a single aligned risk program can support both sets of obligations.
When is the CIRMP annual report due?
A responsible entity must give the regulator an annual report, approved by its board or governing body, within 90 days after the end of each Australian financial year. The report states whether the program was up to date and, where relevant, how it responded to hazards that had a significant impact on the asset.
What does a SOCI Act gap assessment involve?
A gap assessment compares the current risk program, policies and controls with the CIRMP Rules. It identifies missing or weak elements, prioritises the fixes, and gives the board a clear view of what is needed before the next annual report.
References

  1. Cyber and Infrastructure Security Centre, Security of Critical Infrastructure Act 2018 and the CIRMP Rules, cisc.gov.au
  2. Emergency Management Victoria, Critical infrastructure resilience, emv.vic.gov.au