The SOCI Act, explained: obligations, recent reforms, and where preemptive cyber defense fits

Australia’s Security of Critical Infrastructure Act 2018, usually shortened to the SOCI Act, has quietly become one of the most demanding pieces of cyber regulation in the Asia Pacific. If you run security for an organisation in energy, financial services, healthcare, telecommunications, transport, data storage, or one of the other regulated sectors, it now shapes how you identify risk, what you report, and how quickly you report it.

The framework has also changed a great deal in the past two years, and another round of changes is in consultation right now. This article walks through what the SOCI Act asks of responsible entities, what has shifted recently, and where working ahead of an attack, rather than behind it, helps you meet those obligations rather than just document them.

A note before we start. This is a practitioner explainer, not legal advice. For a formal view on whether your assets are captured and which obligations apply, talk to cyber legal counsel.

What the SOCI Act covers

The SOCI Act sets out the obligations you carry if you own, operate, or hold a direct interest in a critical infrastructure asset. It applies across eleven sectors: communications, financial services and markets, data storage or processing, defence industry, higher education and research, energy, food and grocery, healthcare and medical, space technology, transport, and water and sewerage.

Industries affected
The SOCI Act covers eleven sectors
Communications
Financial services and markets
Data storage and processing
Defence industry
Higher education and research
Energy
Food and grocery
Healthcare and medical
Space technology
Transport
Water and sewerage

A critical infrastructure asset is defined in the Act for each sector, and the definition turns on function. If several components operate together as one system or network that meets the definition, they count as a single asset. If they operate as separate systems, then they are treated separately. The government’s own framing is that these are the facilities, supply chains, and networks that would cause significant harm to the country’s economic or social wellbeing if they were degraded or offline for any length of time.

The interconnection is the part that tends to catch people out. Think of it this way. A prolonged failure in energy does not stay in energy. It reaches medical supply, food and groceries, water and sanitation, telecommunications, transport, and banking. The regulation is written with that cascade in mind.

The obligations, in plain terms

For most responsible entities, the SOCI Act comes down to three positive security obligations.

Register the asset

You provide operational and ownership information to the Register of Critical Infrastructure Assets, maintained by the Cyber and Infrastructure Security Centre (CISC).

Report cyber incidents

A critical incident that has a significant impact on the availability of your asset must be reported to the Australian Signals Directorate within 12 hours of you becoming aware of it. Incidents with a relevant but lesser impact carry a 72 hour reporting window.

Maintain a risk management program

You adopt, maintain, and comply with a written Critical Infrastructure Risk Management Program, the CIRMP. It has to identify and manage material risk across cyber, physical, personnel, and supply chain hazards, it has to be approved by the board, and it has to be reported on annually.

There is a second tier for assets designated as Systems of National Significance (SoNS), which carry four Enhanced Cyber Security Obligations. These cover incident response planning, cyber security exercises, vulnerability assessments, and providing system information so the government can build and maintain a near real-time threat picture. That last obligation is worth thinking about, because it points directly at the kind of forward visibility this Act increasingly expects.

What has changed, and what is coming

SOCI today is not the SOCI of a few years ago. The ERP Act 2024 widened the framework in late 2024, bringing in data storage and telecommunications and giving the regulator broader powers, and the Cyber Security Act 2024 added related obligations on ransomware reporting and IoT security. A further round of reforms is in consultation now, with proposals to extend duties to third parties such as managed service providers and to tighten supply chain expectations under the CIRMP.

If you own, operate, or supply an Australian critical infrastructure asset, these obligations can reach you wherever your organisation is based, and they keep expanding what counts as your risk surface while asking you to show you are on top of it before something goes wrong.

Where preemptive cyber defense fits

These obligations all turn on timing in one way or another. A CIRMP is meant to show you are managing material cyber risk while it is still developing, and the enhanced SoNS obligations go further, expecting you to feed into a near real-time threat picture and to keep finding vulnerabilities before they are used against you. Even the incident reporting rules reward early awareness, since the clock starts as soon as you become aware of an incident, well before you have worked out its full scope.

Traditional detection tooling only tells you sooner in relative terms. It fires once an adversary is ‘live’, already inside your environment or already interacting with your asset, and by that point the reporting clock is running and the risk has already materialised.

Preemptive cyber defense works in the window before that. The most capable actors targeting regulated infrastructure do not appear without warning. They register domains, age them, stand up hosting, and stage campaigns for weeks or months before anything is delivered. Silent Push maps that preparation phase. The Context Graph continuously tracks how infrastructure is created, managed, and connected across DNS, WHOIS, certificate, and hosting data at internet scale. When those patterns match the way adversaries build and run campaigns, Silent Push issues Indicators of Future Attack® (IOFA): verified signals that a staging ground exists now, before it has been pointed at anyone.

For a responsible entity, that maps onto SOCI obligations in a few concrete ways:

  • It strengthens the threat picture the SoNS obligations ask for, because origin and infrastructure intelligence gives your team visibility into adversary activity that is aimed at your sector before a campaign launches.
  • It gives your CIRMP something to act on. Material cyber risk is easier to identify and manage when you can see the infrastructure being assembled against organisations like yours, rather than reconstructing it after an incident.
  • It supports the reporting obligations by shortening the distance between adversary activity and your awareness of it, which is exactly what a 12 hour clock demands.

And as the 2026 proposals push supply chain risk to the front, mapping the infrastructure connected to your suppliers and partners becomes part of the same picture.

Preemptive cyber defense
The window where risk is reduced
Before
Adversary stages infrastructure
You act here
Silent Push issues IOFA®
Day zero
Attack launches
After
Public IOCs emerge

None of this replaces a CIRMP, an incident response plan, or the legal work of confirming which obligations apply to you. What it does change is the position you operate from. SOCI is steadily raising the bar on how early and how thoroughly you are expected to understand the threats facing your assets. Seeing adversary infrastructure while it is still being built is how you meet that expectation with room to act, instead of documenting a breach after the fact.

If you run critical infrastructure in the region and want to see what that early visibility looks like against your own environment, book a demo and we will walk you through it.


What is the SOCI Act?
The Security of Critical Infrastructure Act 2018, known as the SOCI Act, is Australian law that sets cyber, physical, personnel, and supply chain security obligations for organisations that own or operate critical infrastructure assets across eleven sectors, including energy, financial services, healthcare, telecommunications, transport, and data storage.

Who does the SOCI Act apply to?
It generally applies to entities that own, operate, or hold a direct interest in an Australian critical infrastructure asset, regardless of where the organisation is headquartered. Whether a specific asset is captured is a legal question for your counsel.

What are the main obligations under the SOCI Act?
For most responsible entities there are three: registering the asset, reporting cyber incidents, and maintaining a board-approved Critical Infrastructure Risk Management Program. Assets designated as Systems of National Significance carry additional Enhanced Cyber Security Obligations.

What are the cyber incident reporting timeframes?
As it stands, a critical incident with a significant impact is reported within 12 hours of awareness, and an incident with a relevant but lesser impact within 72 hours. Confirm the current thresholds against the legislation, since reporting rules have been changing.

Does the SOCI Act reach overseas or third-party providers?
It can. Foreign owners of Australian assets are captured, and the proposed 2026 reforms would extend duties to third parties such as managed service providers, alongside stronger supply chain expectations. The detail is still being consulted on.

How does Silent Push preemptive cyber defense support the SOCI Act obligations?
Obligations like contributing to a near real-time threat picture and meeting the incident reporting clock are easier to satisfy with early warning. Seeing adversary infrastructure while it is still being built lets teams reduce risk before an incident, which is the gap Silent Push works in.