Australia Security of Critical Infrastructure Act 2018
Australian law protecting critical infrastructure assets. Requires mandatory incident reporting within 72 hours and comprehensive risk management programs.
What SOCI Act draws on
This framework pulls on all three pillars — which is why running them as three separate tools means reconciling three sets of evidence at audit time.
Compliance
Security
What your auditor cites,
and what produces the evidence
The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.
Critical Infrastructure Risk Management
Responsible entities MUST adopt and maintain a critical infrastructure risk management program.
A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.
Cyber Security Incidents
Critical cyber security incidents MUST be reported to the Australian Signals Directorate within 72 hours.
Notification clocks start when you become aware, so detection latency is the whole exposure. Behavioural baselines score each deviation as it happens and flag it in under a second, rather than surfacing it in a weekly review. Severity is decided at the collector and routed immediately, so the window between the access and someone knowing about it is measured in seconds — and the audit trail behind it already holds what was reached, by whom, and when.
System of Records
Entities MUST maintain records of access to critical infrastructure systems for forensic investigation.
A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.
Ransomware Reporting
Ransomware payments MUST be reported within 72 hours of making or becoming aware of the payment.
Notification clocks start when you become aware, so detection latency is the whole exposure. Behavioural baselines score each deviation as it happens and flag it in under a second, rather than surfacing it in a weekly review. Severity is decided at the collector and routed immediately, so the window between the access and someone knowing about it is measured in seconds — and the audit trail behind it already holds what was reached, by whom, and when.
What SOCI Act covers
Security of Critical Infrastructure Act 2018, s. 5 — business critical data
Data that, if compromised, would prejudice the socio-economic stability, defence or national security of Australia — defined partly by a headcount threshold.
In scope
- Personal information about at least 20,000 individuals
- Information about research and development in relation to a critical infrastructure asset
- Information about systems needed to operate a critical infrastructure asset
- Risk management and systems information for the asset
The 20,000-individual threshold is a rare instance of a data definition turning on volume rather than on kind, which means a dataset can enter scope through growth alone.
Security of Critical Infrastructure Act 2018 · as at 2026-08
How SOCI Act is enforced
Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by The Cyber and Infrastructure Security Centre, within the Department of Home Affairs.
| Published maximum | Charged | As at |
|---|---|---|
| 200 penalty units | for failing to adopt and maintain a critical infrastructure risk management programme | 2026-08 |
| 750 penalty units | per day of contravention for a company missing the annual report. A court may order up to five times the maximum against a body corporate | 2026-08 |
The Act prices each obligation separately rather than setting one ceiling. Failing to adopt and maintain a critical infrastructure risk management programme attracts up to 200 penalty units; missing the annual report attracts 750 units per day of contravention for a company. Where the contravener is a body corporate a court may order up to five times the maximum.
The value of a penalty unit is indexed periodically, so the dollar equivalent of each figure moves.
Uncapped exposure that sits outside this instrument
These come from company law rather than from SOCI Act, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.
Duty of oversight
Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.
Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.
Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.
This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.
In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).
Enforcement data reviewed August 2026. Several figures are indexed annually and move.
Built for SOCI Act,
not configured for it afterwards
Critical Infrastructure Monitoring
Comprehensive logging for Australian critical infrastructure databases
SOCI Incident Report
72-hour compliant incident documentation for ASD reporting
Critical Asset Data
Identify data supporting critical infrastructure operations
Cyber Incident Detection
Real-time detection for 72-hour reporting compliance
Other Security frameworks
Walk into the SOCI Act audit knowing the answer
228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.