Skip to main content

MyMoney® is reviewing its service model in light of evolving ASIC regulatory guidance. Some features are temporarily unavailable.

AFSL 222640 · Global Mutual Funds Pty Ltd
Cyber Consultant
operational technology security
SOCI Act
ASD

Operational Technology Security in Australia 2026: SOCI Act, ASD Guidance, and How a Cyber Consultant Can Help

OT security is now a critical obligation for Australian businesses under the SOCI Act. Learn what the 2026 ASD guidance means for your operations.

MyMoney® Editorial23 August 2026 7 min read

Operational technology (OT) — the hardware and software that monitors and controls physical processes in industries like energy, water, manufacturing, and transport — has become one of the most targeted attack surfaces in Australia. As IT and OT systems converge, and as state-sponsored threat actors grow more sophisticated, Australian businesses operating critical infrastructure face a rapidly evolving set of legal obligations and security challenges in 2026.

Understanding Operational Technology Security

Operational technology encompasses industrial control systems (ICS), supervisory control and data acquisition (SCADA) systems, programmable logic controllers (PLCs), and distributed control systems (DCS). These systems manage physical processes — from electricity generation to water treatment to manufacturing lines — and their compromise can have consequences far beyond data loss.

Unlike traditional IT environments, OT systems were historically designed for reliability and longevity, not security. Many components run on legacy operating systems that no longer receive vendor patches, operate continuously without maintenance windows, and were never designed to be connected to external networks. The rapid convergence of IT and OT environments — driven by efficiency and remote monitoring demands — has dramatically expanded the attack surface for these systems.

In 2026, the Australian Signals Directorate (ASD) and the Australian Cyber Security Centre (ACSC) have identified OT security as a national priority, releasing updated guidance specifically targeting the risks created by IT-OT convergence and increased remote access to industrial systems.

The Regulatory Framework: SOCI Act and ASD Guidance

The Security of Critical Infrastructure (SOCI) Act 2018 — significantly expanded in 2022 — is the primary legislative framework governing OT security for Australian critical infrastructure operators. The Act covers 11 critical infrastructure sectors, including electricity, gas, water, ports, data storage, and telecommunications.

Under the SOCI Act, responsible entities must register their critical infrastructure assets, implement a Critical Infrastructure Risk Management Program (CIRMP), and report serious cyber incidents to the Australian Signals Directorate within 12 hours of becoming aware of them. Enhanced obligations apply to systems of national significance, including mandatory incident response planning and vulnerability assessments.

In January 2026, the ASD released its "Secure Connectivity Principles for OT" guidance, establishing eight key principles for managing risks arising from increased remote access and third-party connectivity to industrial systems. This guidance complements the ASD's earlier "Principles of Operational Technology Cyber Security," which was co-sealed by international intelligence partners including the US CISA, UK NCSC, and Canadian CCCS.

The ASD has also released "CI Fortify" guidance, which assists critical infrastructure operators in developing strategies to isolate vital OT systems from broader networks during cyber incidents — maintaining operational continuity even when corporate IT systems are compromised.

Key OT Security Risks in 2026

Australian cyber consultants working in the OT space are currently addressing seven critical risk categories that are prevalent across industrial environments.

  • Legacy systems and unpatched components — Many OT components run on discontinued operating systems with no available patches, creating permanent vulnerabilities that cannot be remediated through conventional means
  • IT-OT convergence attack paths — The integration of corporate and operational networks allows IT-side compromises — such as phishing attacks or ransomware — to cascade into physical operations, potentially causing equipment damage or safety incidents
  • Visibility gaps and incomplete asset inventories — Many organisations lack a complete, current inventory of connected industrial devices, creating blind spots that threat actors actively exploit
  • Insecure third-party remote access — Vendor and maintenance access to OT systems frequently relies on shared credentials, persistent VPN connections, or inadequately monitored remote desktop sessions
  • Inadequate backup and recovery for OT — OT environments are frequently excluded from standard disaster recovery plans, resulting in prolonged operational downtime during incidents
  • Weak identity and access controls — Shared operator accounts, default credentials on industrial devices, and the absence of multi-factor authentication remain primary targets for credential abuse
  • Compliance mapping challenges — Organisations often struggle to translate frameworks like the Essential Eight or SOCI Act requirements into practical OT security controls, given the operational constraints of industrial environments

Common Mistakes When Approaching OT Security

Many organisations make avoidable errors when attempting to address OT security, often because they apply IT security frameworks without accounting for the unique constraints of industrial environments.

One of the most common mistakes is treating OT security as an extension of IT security. Standard IT security tools — such as vulnerability scanners and endpoint detection agents — can disrupt or crash OT systems if deployed without careful testing. OT environments require purpose-built security tools that operate passively and do not interfere with real-time control processes.

Another frequent error is relying on network segmentation alone as a security control. While segmentation is essential, it is not sufficient. Threat actors have demonstrated the ability to traverse air gaps through supply chain compromises, removable media, and compromised vendor access. Defence-in-depth — combining segmentation with monitoring, access controls, and incident response capability — is required.

Organisations also commonly underestimate the importance of OT-specific incident response planning. A generic IT incident response plan will not address the operational, safety, and regulatory considerations that arise when an industrial control system is compromised. Tabletop exercises that simulate realistic OT attack scenarios are essential for testing response capability.

Australian Regulatory Context

Beyond the SOCI Act, OT security in Australia intersects with several other regulatory frameworks that cyber consultants must navigate on behalf of their clients.

The Cyber Security Act 2024 introduced mandatory reporting obligations for ransomware payments, creating a dual-reporting burden for critical infrastructure operators who may need to notify both the ASD (within 12 hours under the SOCI Act) and the ASD's ransomware reporting portal (within 72 hours under the Cyber Security Act). Cyber consultants must ensure their clients have clear escalation procedures that satisfy both obligations simultaneously.

For organisations in the financial services sector, APRA's Prudential Standard CPS 234 (Information Security) and CPS 230 (Operational Risk Management) impose additional obligations regarding the security of information assets — including OT systems used in financial infrastructure. The Financial Accountability Regime (FAR) has also introduced personal executive accountability for cyber security failures, meaning senior leaders can be held individually responsible for inadequate OT security governance.

The ASD's Essential Eight framework, while primarily designed for IT environments, is increasingly being referenced in SOCI Act compliance assessments. Cyber consultants should be prepared to advise on how Essential Eight controls can be adapted for OT contexts, and where alternative controls may be more appropriate.

Questions to Ask a Cyber Consultant About OT Security

If your organisation operates industrial systems or critical infrastructure, the following questions will help you evaluate a cyber consultant's OT security capability.

  • Do you have specific experience with OT security assessments in our industry sector?
  • Are you familiar with the ASD's OT security principles and the SOCI Act CIRMP requirements?
  • What OT-specific security tools do you use for asset discovery and network monitoring that will not disrupt our operations?
  • How do you approach the challenge of securing legacy OT systems that cannot be patched or replaced?
  • Can you help us develop an OT-specific incident response plan and conduct tabletop exercises?
  • How do you assess and manage the security risks posed by our third-party vendors and maintenance contractors?
  • What is your approach to network segmentation between our IT and OT environments?

A qualified cyber consultant with genuine OT security expertise will be able to answer these questions with specific, practical responses — not generic IT security frameworks applied without adaptation.

How MyMoney® Can Help

OT security is a specialised discipline that requires consultants with deep industrial systems knowledge, regulatory expertise, and hands-on experience in environments where security controls must coexist with operational continuity requirements. Finding the right professional is critical — and MyMoney® makes it straightforward.

MyMoney® connects Australian businesses and critical infrastructure operators with qualified cyber security consultants who have demonstrated expertise in OT security, SOCI Act compliance, and ASD framework implementation. Whether you need an OT security assessment, a CIRMP review, or ongoing advisory support, our marketplace helps you find the right specialist for your environment.

Post a Brief to outline your OT security requirements and receive tailored proposals from experienced cyber consultants. Or Browse Cyber Consultants to explore profiles and find a specialist with the right industrial sector experience.

This article provides general information only and does not constitute personal financial advice. Consider whether the information is appropriate for individual circumstances before acting on it. MyMoney® Marketplace is operated by Global Mutual Funds Pty Ltd (ABN 20 090 555 436, AFSL 222640).

Need Professional Help?

Post a brief and let verified professionals compete with transparent, scored proposals.