New Laws Merge Physical, Cyber Asset Security

Boon Edam Australia

Key Facts:

  • Australia's Enhanced Critical Infrastructure Risk Management Program (CIRMP) Rules 2026 are now law, introducing prescriptive physical and cybersecurity obligations for high-risk critical infrastructure sectors including energy, water, broadcasting, freight, and domain name systems.
  • The new rules require operators to implement explicit physical security measures — including access controls, alarm system maintenance, and continuous monitoring — to guard against sabotage, theft, and unauthorised entry, moving from broad principles to mandatory standards.
  • The framework adopts an all-hazards approach aligned with Zero Trust Architecture principles, treating physical and cyber security as overlapping rather than separate disciplines, with 12- to 24-month grace periods for compliance.
  • Personnel security requirements are significantly strengthened, with critical workers required to undergo AusCheck background checks or hold a Negative Vetting 1 security clearance, with reassessment at least every five years.

By Mike Fisher*

New strengthening of the laws governing security requirements protecting Australia's critical infrastructure is now in force, covering both cybersecurity and physical safeguards for specific high-risk critical infrastructure sectors.

The changes – which are of particular interest to planners, designers, builders, operators, and owners of critical facilities – require explicit physical security measures to guard against sabotage, theft, and unauthorised entry.

The strengthened requirements also bring Australia's critical infrastructure framework into closer alignment with international security best practice, including the principles of Zero Trust Architecture (ZTA). Rather than treating physical and cyber security as separate disciplines, ZTA assumes that every person, device and access attempt should be continuously verified, reinforcing a layered approach to protecting critical infrastructure.

The latest changes complement and expand the original protections under the Security of Critical Infrastructure (SOCI) Act, which cover 11 critical infrastructure sectors, including communications, data storage or processing, and financial services and markets.

The new Critical Infrastructure Risk Management Program (CIRMP) Rules of SOCI now introduce prescriptive security obligations for specific high-risk critical infrastructure sectors including:

  • Critical energy market operator assets
  • Critical electricity assets
  • Critical gas assets
  • Critical liquid fuel assets
  • Critical water assets
  • Critical broadcasting assets
  • Critical domain name systems
  • Critical freight service assets
  • Critical freight infrastructure assets.

The new Security of Critical Infrastructure Legislation Amendment (Enhanced Critical Infrastructure Risk Management Program) Rules 2026 (Enhanced CIRMP Rules) represent a substantial change, by moving from broad principles to specific, mandatory standards for high-risk assets

They continue to require an "all-hazards" approach that treats physical and digital domains as overlapping risks rather than separate silos, in accordance with the original provisions of the SOCI Act.

These Enhanced CIRMP Rules 2026 – which require explicit physical security measures to guard against sabotage, theft, and unauthorised entry – are officially law, having been registered and commenced mid-year, with 12- to 24-month grace periods.

Key physical security changes

The Enhanced CIRMP Rules 2026 under Australia's Security of Critical Infrastructure Act 2018 integrate updated physical and natural hazard measures requiring operators to manage facilities holistically, control access to critical components, and maintain physical security.

Complementing a strong focus of cybersecurity, the Enhanced CIRMP Rules 2026 establish prescriptive physical entrance and access controls for workers, visitors, and the public, requiring central management of physical security, maintenance of alarm systems, and continuous monitoring. They include:

  • Access Control and Limitations: Operators must establish and maintain processes to control and limit access to physical critical components, restricting entry strictly to authorised critical workers and visitors.
  • System Testing and Maintenance: Entities are required to regularly test and maintain physical security arrangements and protective components to effectively detect, delay, deter, respond to, and recover from security breaches.
  • All-Hazard Approach: The framework explicitly mandates a holistic view where physical security strategies account for the physical consequences and cascading impacts originating from other hazard types, including cyber disruptions and supply-chain failures.

The Enhanced CIRMP Rules 2026 are part of a broader, multi-stage reform of Australia's critical infrastructure regulations. They form part of Tranche 1 of the Department of Home Affairs updates under the 2018 SOCI Act.

Personnel security considerations

Commercial law authority Clayton Utz, which is one of Australia's oldest, largest, and leading top-tier commercial law firms, says the enhanced CIRMP Rules significantly strengthen personnel security requirements that need to be taken into account.

In addition to core cyber risks, the CIRMP for affected assets will also need to address risks associated with:

  • Unauthorised or unsupervised access to critical components
  • Compromise or misuse of credentials and privileged access used by individuals
  • Access to the CI asset by persons other than critical workers
  • Incoming and outgoing critical workers

Clayton Utz says that, in particular, the Enhanced CIRMP Rules require critical workers to undergo an AusCheck background check or hold a Negative Vetting 1 (or higher) security clearance to be deemed suitable for access to critical components of an asset, and require proactive monitoring of any changes that may affect the ongoing suitability of the person to have that access.

AusCheck background checks (and a reassessment of suitability) are required at least every five years for individuals with continued access to critical components.

Boon Edam involvement in physical protections for critical infrastructure

The new and expanded laws governing specific high-risk critical infrastructure sectors are particularly relevant to the activities of the company of which I am part, as a branch of the global Boon Edam Group.

Boon Edam's specific critical infrastructure experience spans major AI and data centre operators, power generators, and military/government assets, aligning physical entry networks with strict regulatory mandates such as Australia's SOCI Act.

As an advocate of Zero Trust Architecture, Boon Edam integrates ZTA principles into its layered physical security approach, helping critical infrastructure operators strengthen access control, reduce risk and support compliance with evolving regulatory requirements.

Our relevant Core Technologies and Risk Mitigation addressing issues raised include:

  • Tailgating and Piggybacking Prevention: Employs physical solutions like the Tourlock security revolving door and Circlelock single-person portals to eliminate unauthorised entry.
  • Advanced Sensor Integration: Utilises overhead 3D optical and near-infrared systems (such as StereoVision) to accurately discriminate and detect volume/shapes without lighting interference.
  • Compliance and Audit Trails: Generates immutable 90-day archived records and automated alarm management.

Our work with some of the biggest global names in data processing and AI includes ongoing layered safeguards for critical server rooms and perimeters against contractor flow drift and badge sharing. For Government and Utilities, we also Implement a layered security approach from the outer perimeter down to classified internal zones.

/Public Release. This material from the originating organization/author(s) might be of the point-in-time nature, and edited for clarity, style and length. Mirage.News does not take institutional positions or sides, and all views, positions, and conclusions expressed herein are solely those of the author(s).