For Critical Infrastructure

Critical infrastructure that fails safely.

The blast radius is national. AU SOCI 2018+amendments, EU NIS2, US CIRCIA — the regulators are converging on the same shape: known supply-chain, evidenced controls, fast incident reporting, tested resilience. IT/OT convergence is the hard part: the substrate of one sector can’t pretend the other doesn’t exist.

The regulatory floor — critical infrastructure

  • AU SOCI Act 2018 + 2022 SLACIP amendments · mandatory risk programmes, fast incident reporting
  • EU NIS2 Directive · enforced; expanded scope; board accountability
  • US CIRCIA · covered-entity 72-hour incident + 24-hour ransom-payment reporting
  • IEC 62443 · the OT-security standard floor (industrial control systems)
  • NIST SP 800-82 · OT cybersecurity guidance, latest revision
  • SLSA v1.0 + SSDF · supply-chain attestation for IT/OT integration points

Working on this in Critical Infrastructure?

These are field notes on the patterns that recur in critical infrastructure — responding to SOCI / NIS2 / CIRCIA obligations, hardening IT-OT integration points, rebuilding the SRE programme behind a critical-service SLA. If they’re useful, or you’d push back on them, I’m glad to compare notes.

   [email protected]
Also on this site