Physical Security Under the SOCI Act: The Overlooked Frontier of Critical Infrastructure Protection
Australia's critical infrastructure regulatory landscape is rapidly evolving, most recently with the introduction of the Security of Critical Infrastructure Legislation Amendment (Enhanced Critical Infrastructure Risk Management Program) Rules 2026 (LIN 26/075) (Enhanced CIRMP Rules) under the Security of Critical Infrastructure Act 2018 (Cth) (SOCI Act). While cyber threats have dominated headlines and legislative attention, a growing consensus among regulators, intelligence agencies and industry stakeholders is that physical security is consistently overlooked.
The SOCI Act and the Protective Security Policy Framework (PSPF) are key components of Australia's protective security architecture, yet historically significant gaps have persisted in how physical hazards are managed, tested and mitigated across critical infrastructure asset classes.
This article examines the current regulation of physical security risks for critical infrastructure entities and operators, how regulators are responding to the changing threat environment, and the practical steps entities should be taking now to build genuine resilience against physical hazards.
The recent independent review of the SOCI Act by Dr. Jill Slay (Slay Review) found that the Act's "cyber-heavy focus neglects physical security, personnel security, and all-hazards supply chain resilience."
The review also found that stakeholders across a variety of sectors felt physical security, personnel security and supply chain resilience receive insufficient attention compared with cyber threats, despite being vital for the protection of infrastructure. Many stakeholders criticised the SOCI Act for being too reactive and too slow in the face of evolving and emerging physical security risks.
This view aligns with findings from the Critical Infrastructure Security Centre's (CISC) 2023–24 trial audits. CISC found that despite physical and natural hazards being the most common cause of significant-impact incidents, they were widely overlooked in entities' CIRMPs.
Physical security is a key concern for regulators, in the face of both domestic and global security threats. Australia's Director-General of Security warned in early 2025 that physical sabotage is expected to pose an increasing threat in Australia over the next five years. Physical sabotage of critical infrastructure is not necessarily limited to large-scale, destructive attacks on physical infrastructure. It can also include small-scale, selective and temporary acts that degrade, disrupt or interfere with networked infrastructure and physical systems.
CISC's 2025 Critical Infrastructure Risk Review identified several forms of physical security risk capable of disrupting operations. It reported that copper wire theft had repeatedly disrupted power supply across Australia, including through recent outages in regional Queensland and metropolitan Perth. It further noted that multiple airports suffered perimeter breaches by individuals who directly threatened the safety of flights and passengers.
The review described grey zone tactics as an ongoing challenge for Australian critical infrastructure, citing foreign vessels operating near Australia's exclusive economic zone in proximity to seabed cables and maritime routes that endangered the physical security of aviation and maritime transport.
The CIRMP Rules impose specific obligations on a responsible entity's CIRMP to establish and maintain processes for managing physical security risks. These include obligations in response to unauthorised access to a physical critical component, physical access control arrangements, and testing and reviewing security measures.
In practice, a compliant physical security program should cover the whole life cycle of an incident including detection, containment, investigation, resolution, reporting and recovery. It should identify the internal and external notification pathways that apply to physical security incidents, including law enforcement, CISC and relevant regulators.
Additionally, responsible entities must review their CIRMP on a regular basis and identify any changes that need to be made to ensure it is kept up to date. Every incident, near-miss or realised physical or natural hazard should be subject to a structured post-incident review identifying root causes, control failures and improvement opportunities. Entities should also compare their program against CISC guidance, threat advisories and sector-specific intelligence. Any CISC best-practice guidance should be considered for incorporation into the CIRMP during each review cycle.
CISC’s 2023–24 trial audits identified common deficiencies in CIRMPs relating to physical hazards, including a lack of formal documented processes, guidelines and review mechanisms. Entities should aim to address those gaps now to remain ahead of CISC’s regulatory expectations.
The PSPF applies to non-corporate Commonwealth entities under the Public Governance, Performance and Accountability Act 2013, providing the basis upon which the Department of Home Affairs may issue directions to manage protective security risks.
The PSPF's physical security framework provides recognised best-practice guidance for securing critical infrastructure. Notably, the testing requirements for security arrangements under the CIRMP Rules' directly mirror the PSPF's objectives of deter, detect, delay, respond and recover.
This represents a clear link between government protective security standards and private sector critical infrastructure operators. We consider entities should use these to their advantage. CISC itself has noted that the recent amendments to the CIRMP Rules were informed by PSPF principles.
Notably, under the Enhanced CIRMP Rules', the previously optional measure that 'critical workers' could be assessed as suitable via an AusCheck background check has now become a mandatory requirement for entities. With this emerging pattern of compliance recommendations becoming regulatory mandates, responsible entities of high-risk critical assets should consider benchmarking their own arrangements against the PSPF now, in order to identify any gaps or improvement opportunities.
A testing and review program based on the five PSPF protective security outcomes (detect, delay, deter, respond and recover) would demonstrate genuine security uplift in alignment with the enhanced section 11A requirements of the CIRMP Rules, rather than mere compliance documentation. Testing may include scheduled and unannounced physical security reviews, moderated attempts to test access controls, tabletop exercises and scenario-based simulations. After testing, entities should prepare a formal report that records the findings, the weaknesses identified, and the priority actions needed to mitigate them. This creates an auditable record for continuous improvement.
Testing frequency should be adjusted appropriately to reflect the entity's threat environment and the importance of the component being tested. This will support infrastructure resilience through contingency planning, emergency exercises and simulations that are consistent with CISC guidance. Stakeholders have called for reviews that test the effectiveness of controls, rather than simply checking whether procedures exist. They have also called for maturity-based tiers that reward a strong security position. Physical security testing that goes beyond paperwork and assesses layered defences in practice will distinguish resilient entities from those that are compliant only on paper.
Recent trends suggest that Australia's SOCI regime will continue to evolve, becoming more agile and responsive, as regulators prioritise clear and unambiguous compliance obligations. The Tranche 2 consultation paper confirms this trajectory by proposing clearer governance expectations, mandatory independent assurance, and increased civil penalties. These reforms collectively signal that physical security will be subject to greater scrutiny and accountability. This means responsible entities for critical infrastructure should not wait for mandatory physical security measures to come into force before investing in comprehensive programs that align with recognised best-practice.
Critical infrastructure entities should proactively design, implement and test layered physical security arrangements, underpinned by PSPF principles. These measures should be integrated with their CIRMPs and reviewed on a regular basis. Entities that take these proactive steps will be best placed to meet the evolving regulatory expectations.
Authors: Clare Doneley, Partner; John Moore, Director, Risk Advisory; Sanjam Bajwa, Lawyer and Georgina Whittle, Graduate.
This publication is a joint publication from Ashurst Perkins Coie Australia and Ashurst Perkins Coie Risk Advisory Pty Ltd, which are part of the Ashurst Perkins Coie Group.
Ashurst Perkins Coie Australia (ABN 75 304 286 095) is a general partnership constituted under the laws of the Australian Capital Territory.
Ashurst Perkins Coie Risk Advisory Pty Ltd is a proprietary company registered in Australia and trading under ABN 74 996 309 133.
The Ashurst Perkins Coie Group comprises Ashurst Perkins Coie UK LLP, Ashurst Perkins Coie US LLP, Ashurst Perkins Coie Australia and their respective affiliates (including independent local partnerships, companies or other entities) which are authorised to use the name "Ashurst Perkins Coie" or describe themselves as being affiliated with Ashurst Perkins Coie. Some members of the Ashurst Perkins Coie Group are limited liability entities. Some members of the Ashurst Perkins Coie Group provide legal services and some provide non-legal services. Different legal entities in the group may operate in the same jurisdictions. Information about which Ashurst Perkins Coie Group entity operates in any country can be found on our website at www.ashurstperkinscoie.com.
The services provided by Ashurst Perkins Coie Risk Advisory Pty Ltd do not constitute legal services or legal advice, and are not provided by qualified legal practitioners acting in that capacity. The laws and regulations which govern the provision of legal services in the relevant jurisdiction do not apply to the provision of non-legal services.
This material is current as at 25 August 2026 but does not take into account any developments after that date. It is not intended to be a comprehensive review of all developments in the law or in practice, or to cover all aspects of those referred to, and does not constitute professional advice. The information provided is general in nature, and does not take into account and is not intended to apply to any specific issues or circumstances. Readers should take independent advice. No part of this publication may be reproduced by any process without prior written permission from Ashurst Perkins Coie. We accept no liability for use of these materials and reliance upon it by any person.