Overview

The Australian Government has opened consultation on reforms to laws aimed at protecting Australia's critical infrastructure.

The Security of Critical Infrastructure Act 2018 (Cth) (SOCI Act) provides a framework for managing risks relating to critical infrastructure. It includes obligations on responsible entities of critical infrastructure assets (CI Assets) to develop and maintain a Critical Infrastructure Risk Management Program (CIRMP) for those assets and gives the Australian Government powers to make ministerial directions in respect of those assets.

In response to recommendations from a recent review in January this year, the Government is now consulting on further reforms to the SOCI Act, with a focus on expanding Ministerial Directions powers and enhancing the CIRMP rules.

Through these reforms, the Government is seeking to strengthen Australia’s ability to prevent and respond to serious threats to critical infrastructure, while ensuring obligations remain proportionate and practical for industry.

Ministerial Directions Powers

The proposed amendments to the Ministerial Directions powers in Part 3 of the SOCI Act are intended to provide government with more flexible and targeted tools to address significant national security and resilience risks.

The Government is seeking feedback on the following 5 measures under consideration:

  1. Amend Directions Power: To amend the existing directions power in section 32 to replace the current mandatory Adverse Security Assessment with a more flexible entity-specific ASIO threat advice and to relax the strict exhaustion of alternative regulatory precondition.
  2. Conditions power: To introduce a new "conditions" power to allow Government to provide tailored, ongoing governance controls on reporting entities where ownership, control, or governance arrangements create a material risk to national security that cannot be sufficiently managed.
  3. Vendor-risk product specific directions power: To introduce a new "vendor-risk product specific" directions power to restrict the use of high risk vendors, products and services where necessary to mitigate or eliminate a material risk that is prejudicial to national security.
  4. Continuous disclosure relief: To introduce temporary time-bound relief regarding high-risk cyber incidents from continuous disclosure obligations for listed entities where such disclosure could compromise national security.
  5. Civil penalty provisions: To increase civil penalty provisions for failing to comply with a Ministerial Direction from 250 to 2,000 penalty units.

The Consultation Paper: Proposed amendments to the Ministerial Directions powers in Part 3 of the SOCI Act, provides details on the proposed measures and guidance on the feedback being sought.

In practice, this could allow for more tailored directions to responsible entities where incidents or vulnerabilities threaten essential services, defence capability, or broader economic and social stability. However, the proposals also raise important questions around the thresholds for issuing directions, the limits on these powers, and the appropriate level of oversight and transparency.

The Government asks stakeholders to consider whether the proposed framework strikes the right balance between enabling rapid government intervention in times of crisis and preserving operational autonomy and commercial certainty.

Enhancements to CIRMP Rules

In parallel, the Government has released an Exposure Draft of amendments to the CIRMP Rules (Exposure Draft), which support Part 2A of the SOCI Act.

The draft proposes enhancements to the CIRMP requirements for the following designated categories of CI Assets:

The proposed enhancements are more prescriptive for responsible entities of the designated categories of CI Assets and require responsible entities to:

A copy of the Exposure Draft is included in the consultation paper available here.

Once introduced, a range of grace periods from 6 months – 24 months will apply to the new requirements.

Practical implications for industry

For owners and operators of critical infrastructure assets, these proposals will have practical implications and it is likely to influence:

The consultation process provides an important opportunity for industry, peak bodies and civil society to shape the final form of these reforms.  Stakeholders can highlight where the proposed powers and rules are clear and workable and where further refinement is needed.


For more information or assistance contributing to the consultation, please contact our Technology and Digital Innovation team.