Security of Critical Infrastructure: From Attestation to Assurance – What the New CIRMP Annual Reporting Questions Signal About the Future of Critical Infrastructure Governance
Recently, many critical infrastructure responsible entities covered by the Security of Critical Infrastructure Act 2018 (SOCI Act) are likely to have noticed a significant evolution in the annual Critical Infrastructure Risk Management Program (CIRMP) reporting process, with the FY2025–26 reporting cycle signalling a broader shift in regulatory expectations surrounding governance, resilience, and Board accountability. The revised annual reporting […]











