Articles

The legislation reviews in the Australian critical infrastructure industry have brought up an interesting proposal, with implications going beyond the asset owner, a term called “relevant operator.”
This year the Department of Home Affairs opened consultation for the second tranche of reforms to the Security of Critical Infrastructure (SOCI) Act 2018. Tranche 2 is an impactful structural rewrite based on the independent review by Dr. Jill Slay AM, who’s findings and suggestions to the department have led to attempts of making obligations less complex, prevent overlapping, and more connected with how the Australian critical infrastructure assets actually operate.
The government accepted most of her recommendations in principle and hiding in those newly proposed measures was the concept of a certain type of third-party service provider.
A formal legislative draft is yet to be released by the Home Affairs post industry feedback, however, the incumbents are seeking answers as to what it means to be a “relevant operator”.
An organisation or a person will be categorised as a "relevant operator”, if they meet both of the below criteria:
The above criteria will most often apply to a third-party service provider such as managed service provider (MSP), O&M, administrator, or contractor with influence, control, and power over the operations of critical asset. This status will be assumed based on the real responsibilities and day-to-day work performed by the organisation instead of what’s labelled in a contract. Invariably, it will exclude engagements like consultation, solely monitoring services, minor maintenance, or ad hoc support.
Are you wondering what happens if you are classified as a “relevant operator”?
Let’s look at the proposed responsibilities for this:
The concept also offers some safety net to the responsible entities who can’t fully get co-operated efforts from their relevant operator in ensuring security of systems and processes if documented well.
If your organisation deals with third-party services to help run the critical asset or systems, or if you are the external provider whose services align with this concept beyond what it looks like on the contract, you need to map inventories, systems, security practices, and documentation as per the CIRMP rules now. The time to implement the obligations starts now while the rules continue to take shape and become a part of the legislated regulations.
This is the space that OpusV operates in daily, enabling us to offer a unique perspective on OT networks, cyber security, and network design informed by our boots-on-the- ground experience with some of the biggest critical infrastructure assets in Australia. We are not only talking about policy or compliance but we are the ones with hands on OT networks, cyber security landscape, and network designs for some of the biggest electricity generation patrons.
We have witnessed that supply chain participants and third-party access points are one of the most under the radar risk surfaces posing challenges in the critical infrastructure today.
Do you know if you or your service provider meets the threshold of “relevant operator”? If you’re unsure, it’s worth a conversation with the seasoned industry specialists, before it becomes a legal ask than a best practice. Contact us.