Somewhere in the noise of the last few weeks, the obligation sitting over Australia’s critical infrastructure quietly changed shape, and not many people seem to have registered how much. The Enhanced CIRMP Rules, now in force, do not simply raise the cyber bar. They take cyber security, physical security and personnel security, three disciplines that most organisations have always run in separate rooms with separate teams, separate budgets and separate tools, and they treat them as a single all-hazards obligation to be managed together and proven together. On paper it is one tidy phrase, all-hazards. In practice it asks operators for something very few of them were built to give.
The convergence is the point
Look at what the phrase actually contains. Cyber and information security, physical and natural hazards, supply chain, and personnel, four hazard categories that the responsible entity is now expected to identify, mitigate and continuously manage as one program rather than four workstreams. Personnel security that is re-verified on a recurring cycle rather than checked once at onboarding. A posture that leans toward continuous verification rather than a perimeter drawn once and trusted thereafter. And for energy specifically, the cyber-framework uplift to AESCSF Security Profile 2, due by 2028 under a board-approved attestation, sits inside this same all-hazards program rather than beside it. The regulator is no longer asking whether each discipline is handled somewhere in the organisation. It is asking whether they add up to a single defensible position.
The easy reading of all of this is that it is another uplift, that you add the physical and personnel controls to the pile, tick them, and move on. That reading is exactly where the risk lives.
Convergence on paper, three silos in practice
Because a convergence obligation met with divergent processes has not really been met. If your cyber posture lives in one platform, your physical security in a facilities register, and your personnel vetting in an HR system that speaks to neither, then what you hold is three snapshots that were each true on a different day, and no single position that is true today. The regulator reads the whole, which means the weakest and least current corner is the one that sets your exposure, not the polished corner you would prefer to show. A physical control that is immaculate does nothing for a personnel gap that nobody has looked at since the person was hired, and an ageing register that still looks complete is more dangerous than an obvious gap, because it buys false confidence right up until the disruption it failed to anticipate arrives.
All-hazards is not three obligations stacked on a desk. It is one position that has to hold across all of them at once.
The front is still moving
Even as operators absorb the enhanced rules, the next round of reforms, the package many are already calling SOCI 2.0, is out for consultation, and it proposes to widen the perimeter again: pulling managed service providers, operational contractors and corporate-group entities into scope, modernising the definition of a cyber incident to account for AI and automated agents, adding distributed energy assets as their own class, and pressing supply-chain assurance onto major suppliers. Whatever the final shape, the direction is unmistakable, and even a perfect snapshot taken today is already aimed at where the target used to be.
The bar here is not a line you cross once. It is a position you have to hold against something that keeps advancing.
Who this actually lands on
It is worth being honest about who this lands on. It lands on teams that were already carrying more than they can comfortably hold, the same teams that are invisible on the year nothing goes wrong and named in the report on the day something does. The incidents that have been in the news lately did not happen because those people were careless. They happened because the surface keeps expanding faster than any single team can watch it, and the honest response to that is not to hand them a fourth spreadsheet and a longer checklist. It is to change the shape of how the position is held.
You cannot checklist your way across this
Which is the real question underneath this week’s news, and it is a practical one rather than a philosophical one. You cannot checklist your way across it, and you cannot close it by handing your own stretched team another tool to run, because a platform in your own hands, however capable, still only holds each view rather than operating the whole, and it quietly hands the operating back to the people who were already at capacity. You cannot easily hire your way across it either, because the senior people who can genuinely hold judgement across all of these domains are scarce, expensive and largely already employed. What an all-hazards obligation quietly implies, once you follow it to the end, is a single owner of a single continuous position, senior enough to exercise judgement across every domain at once, who operates that position on your behalf, keeps it current as the environment moves, and can put it in front of a regulator or a board on an ordinary week rather than only when an audit forces the issue.
The question worth sitting with
So the question worth sitting with, now that the rules are live and the attention is already drifting to the next reform, is not whether you have added the physical and personnel controls to your program. It is who holds your single, all-hazards position on an ordinary Tuesday, when nothing is on fire and no deadline is forcing anyone’s hand, and whether that person has the seniority and the capacity to keep it current and to prove it the moment someone asks. If the honest answer is that the controls are scattered across three systems while the ownership of the whole is sitting nowhere in particular, then the obligation has not really been met. It has only been divided up and filed.
References
- Australian Security Magazine, “New CIRMP critical asset security laws underline integration of physical and cyber security,” August 2026. https://australiansecuritymagazine.com.au/new-cirmp-critical-asset-security-laws-underline-integration-of-physical-and-cyber-security/
- Industrial Cyber, “CISC unveils Enhanced CIRMP Rules to address AI, legacy systems, supply chain, and insider risks across critical infrastructure,” 2026. https://industrialcyber.co/regulation-standards-and-compliance/cisc-unveils-enhanced-cirmp-rules-to-address-ai-legacy-systems-supply-chain-and-insider-risks-across-critical-infrastructure/
- Clayton Utz, “Australia’s Enhanced CIRMP Rules: what critical infrastructure operators need to know,” June 2026. https://www.claytonutz.com/insights/2026/june/australias-enhanced-cirmp-rules-what-critical-infrastructure-operators-need-to-know
- Allens, “SOCI Act 2.0: sweeping reforms proposed to Australia’s critical infrastructure framework,” 13 July 2026. https://www.allens.com.au/insights-news/insights/2026/07/soci-act-2-0-sweeping-reforms-proposed-to-australias-critical-infrastructure-framework/
- Cyber and Infrastructure Security Centre (Department of Home Affairs), “Consultation on the amended Critical Infrastructure Risk Management Program Rules under the SOCI Act,” 2026. https://www.cisc.gov.au/legislation-regulation-and-compliance/consultation-ministerial-directions-powers-and-draft-of-amended-cirmp-rules
- AEMO, “Australian Energy Sector Cyber Security Framework (AESCSF),” framework and Security Profiles resources. https://www.aemo.com.au/initiatives/major-programs/cyber-security