Operational industry

Critical Infrastructure

SOCI Act-aligned OT/ICS cybersecurity for energy, water, telecommunications, transport and data-storage operators.

SOCI-aligned critical infrastructure cyber security across IT and OT.

Under the SOCI Act, responsible entities across 11 critical infrastructure sectors carry legislated cyber security obligations: Risk Management Programs, enhanced reporting and, for Systems of National Significance, mandatory engagement with the ACSC. Vectra designs and operates cyber programs that bridge IT and OT without changing how plant works. Our OT monitoring is passive by default, our SOC is sovereign, and our methodology aligns to the CIRMP Rules, the NIST CSF and IEC 62443.

22+
Responsible entities supported
15
CIRMP programs delivered
Zero-touch
Passive OT monitoring
AUsovereign
Co-located with SOC

Cyber threats targeting Australian critical infrastructure.

OT/ICS-targeted malware

Industroyer, TRITON and INDUSTROYER2-class capabilities demonstrated by state-aligned actors against adjacent geographies.

IT-to-OT lateral movement

Ransomware pivoting from corporate AD into historian, engineering workstations and DMZ-exposed HMIs.

Supply chain and vendor remote access

OEM and integrator remote-support channels used as persistent backdoors into Purdue Level 2 and below.

Data exfiltration under SOCI

Targeted theft of operational data protected under the SOCI Act, including network diagrams and SCADA configs.

SOCI Act and CIRMP obligations we align to.

  • SOCI Act (Security of Critical Infrastructure Act 2018)
  • CIRMP Rules (Critical Infrastructure Risk Management Program)
  • Systems of National Significance (SoNS) obligations
  • NIST Cybersecurity Framework
  • IEC 62443 (Industrial automation and control systems security)
  • AEMO AESCSF (Australian Energy Sector Cyber Security Framework)

How responsible entities engage Vectra for OT security.

Virtual CISO

Fractional leadership that can speak to both engineering and executive.

Critical infrastructure outcomes ready for ACSC scrutiny.

  • CIRMP documentation and evidence ready for Home Affairs annual attestation
  • Continuous passive OT visibility without any change to control-network topology
  • Defined IT-to-OT segmentation validated against IEC 62443 zones and conduits
  • SoNS-aligned incident response pre-exercised with ACSC liaison channels established
  • Executive reporting framed around public-safety outcomes, not asset counts

Questions

Will you actively probe our control network?

No. OT monitoring defaults to passive SPAN/TAP-based collection. Any active scanning requires written engineering approval, a tested maintenance window and a rollback plan.

Can you map controls across IT and OT at once?

Yes. Our assessment templates run Essential Eight and IEC 62443 in parallel so the IT and OT control uplift tracks on one plan, not two.

Do you support AEMO AESCSF self-assessment?

Yes. We run the AESCSF assessment and produce the MIL-level evidence pack that energy market participants submit annually to AEMO.

What if we're a SoNS?

We run the extended SoNS cyber-security obligations engagement, covering enhanced reporting, information-gathering directions and ACSC engagement, and we pre-populate templates for Home Affairs submissions.