Key Takeaways
- Australia’s Cyber and Infrastructure Security Centre (CISC) has issued the Security of Critical Infrastructure Legislation Amendment (Enhanced Critical Infrastructure Risk Management Program) Rules 2026 to uplift security posture across essential services.
- The rules target a broad set of asset classes—energy, electricity, gas, liquid fuel, water, broadcasting, domain‑name systems, freight services and freight infrastructure—and require legacy‑system risk assessments, AI‑related controls, phishing‑resistant MFA, system segregation and alignment with recognised cybersecurity frameworks.
- Enhanced CIRMP also mandates identification and mitigation of insider threats, supply‑chain risks (including foreign ownership influence), offshoring of staff or data, and physical‑hazard considerations tied to asset location.
- The measures dovetail with Horizon 2 of the 2023‑2030 Australian Cyber Security Strategy, which emphasizes a whole‑of‑ecosystem approach, real‑time risk management, and human‑behaviour factors.
- An additional $89.3 million over four years will fund Horizon 2 actions, including expanded national exercises, stronger cyber‑supply‑chain security, and emerging‑technology safeguards such as drone and subsea‑cable protection.
- Current threat data show cybercrime costing Australia ≈ $25 billion yearly, with average incident costs rising to $80,000 and a potential single catastrophic event costing up to $35 billion (≈ 1.3 % of GDP).
- AI adoption expands the attack surface (97 % of organisations lack adequate AI access controls), AI is involved in 16 % of 2024 data breaches, and exploitation of edge devices rose from 3 % to 22 % year‑over‑year.
- Human error remains a factor in ~60 % of breaches, while state‑based actors increasingly target government and critical‑infrastructure systems for espionage and pre‑positioning.
- Most requirements commence in 2027, with extended grace periods for the most complex measures, allowing industry time to adapt while bolstering national resilience.
Overview of Enhanced CIRMP Rules
Australia’s Cyber and Infrastructure Security Centre (CISC) announced the Security of Critical Infrastructure Legislation Amendment (Enhanced Critical Infrastructure Risk Management Program) Rules 2026. These rules are designed to strengthen protections for the nation’s critical infrastructure by ensuring owners and operators adopt stronger security measures. The goal is to improve resilience against evolving threats that could disrupt essential services and nationally significant assets. By embedding a more rigorous risk‑management framework, the Enhanced CIRMP seeks to lift the overall security posture of critical sectors across the country.
Consultation and Asset Class Scope
The Enhanced CIRMP Rules were informed by extensive consultation with industry representatives, government stakeholders, and subject‑matter experts. This collaborative process helped identify the specific asset classes that require uplifted risk‑management obligations. The rules now cover critical energy market operator assets, critical electricity assets, critical gas assets, critical liquid fuel assets, critical water assets, critical broadcasting assets, critical domain‑name systems, critical freight service assets, and critical freight infrastructure assets. By spanning these diverse sectors, the framework aims to create a uniform baseline of security across Australia’s essential services.
Cybersecurity Measures Required
Under the Enhanced CIRMP, entities must undertake a series of concrete cybersecurity actions. They are required to assess risks associated with legacy systems and novel or emerging technologies, including artificial intelligence (AI). Phishing‑resistant multi‑factor authentication (MFA) must be implemented for all critical systems. Critical systems also need to be segregated from non‑critical environments to limit lateral movement by attackers. Finally, organisations must increase their compliance with established cybersecurity frameworks such as the Australian Government Information Security Manual (ISM) and internationally recognised standards like ISO/IEC 27001.
Risk Identification and Mitigation
Beyond technical controls, the Enhanced CIRMP mandates a holistic risk‑identification process. Operators must identify and then minimise, mitigate, or eliminate risks across their asset portfolios. This includes cybersecurity risks stemming from legacy infrastructure, AI deployment, and connections between critical and non‑critical systems. The rules also address non‑cyber vectors such as offshoring of critical staff or data, insider threats, and supply‑chain vulnerabilities. By integrating these considerations, the framework seeks to reduce both digital and physical exposure points.
Link to Horizon 2 Cyber Security Strategy
The Enhanced CIRMP Rules directly support Horizon 2 of Australia’s 2023‑2030 Cyber Security Strategy, which was released last week. Horizon 2 sets out a coordinated national effort to lift cyber resilience across government, industry, and the broader economy. CISC noted that the uplifted CIRMP requirements help meet specific Horizon 2 Action Plan targets, including bolstering the cybersecurity of critical infrastructure, strengthening logging and monitoring standards, and preparing entities to manage emerging technology risks such as AI and quantum computing.
Strategic Focus of Horizon 2
At its core, Horizon 2 shifts the focus from protecting isolated systems to safeguarding Australia’s entire digital ecosystem. The strategy places strong emphasis on critical infrastructure, supply chains, and emerging technologies. It outlines a broad program of actions designed to raise cyber maturity across essential services, improve real‑time risk identification, management, and response, and place significant weight on human behaviour as a security factor. By targeting vulnerabilities linked to error and fostering organisational resilience, Horizon 2 aims to create a more adaptive defence posture.
Funding and Implementation Initiatives
To realise Horizon 2’s objectives, the Australian government will invest an additional $89.3 million over four years. This funding is directed at strengthening economic resilience and national security by enhancing the security of infrastructure that underpins essential services, covering both government and industry systems. A key component of the investment is an expanded national exercise programme, which will test real‑world coordination and response capabilities across sectors. The initiative also places a stronger focus on cyber supply‑chain security, ensuring that third‑party relationships do not become weak links.
Emerging Threat Areas and Collaboration
Horizon 2 and the Enhanced CIRMP jointly target emerging risk areas such as drone security and the protection of subsea cables, reflecting the expanding definition of critical infrastructure. These measures will be delivered through close collaboration with industry operators, critical infrastructure owners, and international partners. By working together, stakeholders aim to secure new and rapidly evolving technologies as they come online, ensuring that protective measures keep pace with innovation.
Current Threat Landscape and Statistics
Since the launch of the Cyber Security Strategy in 2023, the cyber threat environment has continued to evolve, with both the number and sophistication of malicious actors increasing. Systems are becoming more connected and automated, creating additional exploitable vulnerabilities. AI tools are being used to automate and enhance criminal capabilities, driving up incident costs. Cybercrime now costs the Australian economy an estimated $25 billion per year. The average cost of a cybercrime reported to the Australian Signals Directorate rose by 50 % between 2023‑24 and 2024‑25, reaching $80,000 per incident. A single catastrophic cyber event could impose systemic losses of up to $35 billion, roughly 1.3 % of GDP.
AI, Edge Devices and Human Error
Rapid AI adoption is delivering productivity gains while simultaneously expanding the attack surface; 97 % of organisations report AI‑related security incidents stemming from inadequate AI access controls. Malicious actors are leveraging AI and automation, with AI involved in 16 % of data breaches observed in 2024. Exploitation of edge devices such as routers, modems, and virtual private networks has surged, climbing from 3 % in 2023 to 22 % in 2024. Human error remains a major vulnerability, contributing to approximately 60 % of data breaches, underscoring the need for ongoing training and awareness programmes.
State‑Based Threats and Insider Risks
Government and critical‑infrastructure systems are increasingly targeted by state‑based actors conducting espionage, disruption, and potential pre‑positioning for future cyber operations. The Enhanced CIRMP Rules therefore require organisations to assess insider‑threat risks and evaluate major supplier risks linked to foreign ownership, control, and influence. By integrating these considerations into a centrally managed framework that accounts for asset locations, the rules aim to bolster resilience against both internal and external adversaries.
Implementation Timeline and Grace Periods
Most of the Enhanced CIRMP Requirements will commence in 2027, providing industry with a window to adapt processes, technologies, and governance structures. Recognising that some measures—particularly those involving complex AI controls, supply‑chain vetting, and system segregation—are more demanding, the legislation includes extended grace periods for these components. This phased approach balances the need for rapid uplift in security posture with the practical realities of implementation across diverse critical‑infrastructure sectors.

