The weekly briefing for Australia's critical infrastructure leaders.

We read everything. You get the things that matter.

For CIOs, Technology Managers, Risk Officers and those responsible for SOCI compliance.

Weekly. Free. No spam. Unsubscribe anytime.

A growing readership|Weekly, every Friday|Independent · Australian · Human-reviewed

Last edition

412articles reviewed
37trusted sources monitored
11SOCI sectors covered
6stories that mattered

What a typical edition looks like

Threat IntelligenceSource: Dragos

Ransomware group targets Australian energy operator

A known threat actor has added an Australian energy utility to its leak site following a suspected OT network intrusion. Operations were not disrupted but data exfiltration is confirmed.

Editorial Analysis

Here's what stands out to me: this group didn't need a zero-day. They got in through the corporate network and worked their way toward OT. That path — IT to OT — is exactly what most organisations have been warned about for years, and it's still working. If your segmentation hasn't been tested under real lateral movement pressure, this is the reminder to do it.

Action Required

Review your incident notification playbook now and confirm your designated CISC reporting contact — do not wait for a breach to locate this information.

→ Read full article
Governance & ComplianceSource: ASD/ACSC

Essential Eight maturity guidance updated for OT environments

The ACSC has revised its Essential Eight guidance with new notes on applying application control and patching in operational technology contexts.

Editorial Analysis

I've seen OT teams use 'we can't patch' as a blanket exemption for years. This update closes that door — it gives auditors clearer criteria for what a legitimate OT patching exemption looks like, which means undocumented exemptions just became a compliance gap. If your self-assessment relies on informal workarounds, now is the time to document them properly.

Action Required

Review the updated patching exemption criteria against your existing OT asset register and update your Essential Eight self-assessment before your next compliance review.

→ Read full article
OT/ICS FocusSource: Claroty

Critical vulnerability disclosed in widely-used PLC firmware

A remotely exploitable flaw has been disclosed in a PLC line common in water and mining sites. No public exploitation has been confirmed yet, but a vendor patch is available.

Editorial Analysis

Remotely exploitable means no physical access required — and 'no confirmed exploitation yet' is a window, not a guarantee. The sites most at risk are the ones that discover they have the affected firmware after someone else gets hit. Pull your asset register today and find out if you're exposed before someone does it for you.

Action Required

Confirm whether your asset register includes the affected PLC model, schedule a maintenance window to apply the vendor patch, and isolate the device from external networks in the interim.

→ Read full article

Built for Australian critical infrastructure

CommunicationsData Storage & ProcessingDefence IndustryEducationEnergyFinancial ServicesFood & GroceryHealthSpaceTransportWater & SeweragePortsOther

Curated by a practitioner, not a journalist

Every week we monitor 30+ trusted intelligence sources, review hundreds of articles, and publish only the developments that matter to Australian critical infrastructure. Every edition is reviewed and approved by a human before it reaches your inbox.

The SOCI Brief is edited by James Walker, a technology leader with 20+ years of experience delivering ICT and operational technology across critical infrastructure.

→ About James

Join a growing community of critical infrastructure professionals

Weekly. Free. Takes 10 seconds to subscribe.

Weekly. Free. No spam. Unsubscribe anytime.