DrochaidHorizon3.ai
NodeZero/Australia & NZ compliance/AESCSF
Australia & NZ compliance

AESCSF — Australian Energy Sector Cyber Security Framework

The national cyber security standard for Australia's electricity and gas sectors, managed by AEMO. Based on the US C2M2 model with Australian-specific additions covering critical infrastructure obligations and cross-sector information sharing.

See where NodeZero applies

What is the AESCSF?

The Australian Energy Sector Cyber Security Framework is the national cyber security standard for Australia's electricity and gas sectors, managed by the Australian Energy Market Operator (AEMO). Based on the US Department of Energy's C2M2 model, the AESCSF adds Australian-specific practices covering critical infrastructure obligations, cross-sector information sharing, and alignment with ASD guidance. Energy market participants complete annual self-assessments against the framework, with results reported to AEMO and used to benchmark sector-wide maturity.

The framework assesses 10 domains at Security Profile levels determined by the criticality of the entity's role in the energy market. Generators, transmission network service providers, and market operators typically face higher profile requirements than smaller participants. While the AESCSF shares C2M2's governance-heavy structure, the Australian additions place stronger emphasis on incident reporting to AEMO and the Australian Cyber Security Centre, OT/IT convergence risks, and alignment with SOCI Act obligations.

AEMO — AESCSF

Where NodeZero applies

NodeZero addresses the IT side of AESCSF compliance by testing the same three domains where technical evidence is critical: Identity and Access Management, Threat and Vulnerability Management, and Situational Awareness. Importantly, NodeZero operates exclusively in IT environments and does not exploit OT or SCADA systems -- where the inherited control mappings mention OT, NodeZero's role is enumerating reachable OT assets from the IT side and testing whether the IT/OT segmentation boundary holds, a distinction that matters in the energy sector where IT/OT boundaries are a key assessment focus. For governance domains and OT-specific practices, we map what sits outside autonomous testing so your self-assessment covers both environments accurately.

AESCSF v2

This mapping reflects our best-effort analysis of where NodeZero's autonomous pentesting produces relevant technical evidence against each requirement. It is intended to help you focus security effort on the controls NodeZero can test — not to serve as a compliance certification. You remain responsible for your own compliance assessment, for validating applicability to your environment, and for evidencing the requirements NodeZero does not directly test.

Please note the following require separate evidence: Risk management, Event and incident response, continuity of operations, Workforce management and Cybersecurity programme management.

Showing coverage grouped by compliance category.

Asset, change, and configuration management

Partial coverage. NodeZero discovers assets and identifies configuration weaknesses.

Internal pentestingCore

Enumerates every reachable host and service from the attacker perspective — often surfacing assets the inventory doesn't track.

High-Value TargetingElite only

Infers which assets carry the most business risk and prioritises attack paths to them — supporting input to the documented asset-prioritisation criteria this practice asks you to define and apply.

4 controls mapped

Identity and access management

Strong coverage. NodeZero directly tests IAM controls and credential security.

AD Password AuditCore

First AI to solve GOAD in 14 minutes (Horizon3-reported); audits password strength and reuse on privileged, service, and break-glass accounts — it is not uncommon for NodeZero to crack more than 50% of the passwords it tests on a first audit.

Phishing Impact TestingCore

Takes a phished credential and demonstrates its blast radius — what an attacker reaches when a single factor is enough — surfacing higher-risk access where a stronger or multifactor credential is not actually required.

Internal pentestingCore

Proves end-to-end paths from initial access to domain compromise — evidence of whether least-privilege is actually enforced.

BloodHound (integrated)Core

Built-in attack-graph visualisation — surfaces the higher-risk, over-privileged relationships ACCESS-2g (MIL2) requires extra scrutiny on.

Cloud pentestingCore

Extends privileged-credential validation into cloud IAM and tests whether those credentials are tightly scoped across on-prem and cloud.

7 controls mapped

Threat and vulnerability management

Strongest alignment. This domain is exactly what autonomous pentesting produces evidence for.

Internal pentestingCore

Returns proof of which vulnerabilities are actually exploitable in your environment — vulnerability information interpreted for the function, not theoretical CVSS lists.

Rapid ResponsePro & Elite

Rapid Response tests are delivered often within hours of disclosure, and in some cases ahead of the public patch — attacker-first assessment inside the detection window.

Vulnerability Risk IntelligenceElite only

Ingests existing scanner exports and classifies each CVE-asset pair as Confirmed Exploitable, Contextually Exploitable, or Threat Actor Pressure — attacker-first prioritisation of the scanner backlog.

Threat Actor IntelligenceElite only

Maps your real attack paths to MITRE ATT&CK and named threat-actor behaviour — produces environment-specific threat intelligence alongside external sources.

Vulnerability Management HubCore

Findings flow to Jira and ServiceNow through existing integrations, tracked through an Open → Mitigated → Regressed lifecycle, with Quick Verify to confirm a mitigation actually held.

High-Value TargetingElite only

Concentrates discovery and exploitation effort on the assets that carry the most business risk — vulnerability information that explicitly addresses the higher-priority subset.

Quick VerifyCore

Re-tests the exact attack chain after a remediation is applied and reports whether the action actually closed the vulnerability — direct effectiveness review built into the workflow.

12 controls mapped

Situational awareness

Direct coverage via deception, EDR effectiveness measurement, and attacker-behaviour generation.

NodeZero TripwiresPro & Elite

Honeytoken decoys on high-risk assets alert the moment an attacker interacts — routed via Splunk, Sentinel, or webhook into the same monitoring programme SITUATION-2 expects.

Internal pentestingCore

Every NodeZero action is timestamped with proofs and commands — correlate with your SIEM to validate whether your defined indicators actually fire.

Endpoint Security EffectivenessCore

Per-host and per-vendor EDR block/allow data mapped to MITRE ATT&CK — concrete effectiveness metrics for the monitoring layer.

3 controls mapped

Supply chain and external dependencies management

Minimal coverage. NodeZero tests the technical boundary where a supplier compromise would land.

Segmentation testingCore

Proves whether a supplier-side compromise would be contained at the interconnect or cascade into your critical assets — direct evidence that the controls protecting against third-party risk actually hold.

Phishing Impact TestingCore

Where a supplier credential or interconnect can be tested, proves how far that access reaches into your environment — one input to your supplier risk assessment, not the assessment itself.

High-Value TargetingElite only

Discovery + High-Value Targeting flag third-party connections that carry privileged reach into critical assets — direct evidence of which suppliers warrant the escalated-prioritisation tier.

3 controls mapped

Cybersecurity architecture

Direct coverage — tests whether architectural security controls actually hold.

Segmentation testingCore

Enumerates IPs, ports, services, and applications across the network to prove whether the security-zone boundaries hold the way the architecture says they should.

Internal pentestingCore

Proves end-to-end attack paths that cross architectural boundaries — evidence that the boundary-enforcement controls are not holding in practice. Whether a cybersecurity architecture is documented and maintained remains governance work.

Cloud pentestingCore

Hybrid architectures are where pentesters find the most gaps; cloud pentesting tests privilege-escalation paths between on-prem and AWS/Azure/K8s boundaries.

BloodHound (integrated)Core

Attack-graph visualisation surfaces every over-privileged user and service account — the gap between policy and practice that ARCHITECTURE-3c (MIL2) requires you to close.

Endpoint Security EffectivenessCore

Reports per-host EDR and host-firewall block/allow outcomes across 40+ vendors — direct evidence of which assets actually have the required security applications enforced.

Web application pentestingPriced separately

Runs the penetration-testing element of this practice against in-house-developed and in-house-tailored applications — OWASP Top 10 weaknesses, access-control failures and business-logic flaws, in pre-production and production, on a periodic or change-triggered cadence. Static, dynamic-code and fuzz testing remain separate activities.

External pentestingCore

Exercises internet-facing applications and services from the attacker's perspective, on a continuous cadence and after changes — the perimeter half of the security testing this domain expects, alongside the application-layer testing above.

11 controls mapped
AESCSF kit

See every control mapped to NodeZero

The full control-by-control coverage map — every AESCSFrequirement matched to the NodeZero capability that produces evidence for it, with maturity-level grouping and source citations. We'll email you the link and a downloadable copy.

Who does this apply to?

The AESCSF applies to participants in Australia's National Electricity Market (NEM) and gas markets. This includes electricity generators, transmission network service providers (TNSPs), distribution network service providers (DNSPs), electricity retailers, gas pipeline operators, gas retailers, and the Australian Energy Market Operator (AEMO) itself. Market participants complete an annual self-assessment against the framework, with results reported to AEMO.

The required Security Profile level -- which determines how many practices your organisation must implement -- is based on the criticality of your role in the energy market. Large generators, transmission operators, and market operators typically face higher profile requirements. Smaller retailers and non-critical participants may have lower thresholds, but all participants are expected to complete the self-assessment.

The AESCSF is also approved as one of five cyber frameworks under the SOCI CIRMP rules, making it the natural choice for energy sector entities that need to satisfy both their AEMO reporting obligations and their SOCI Act CIRMP requirements with a single framework. If you operate in Australia's energy sector, this is likely your primary cyber security compliance obligation.

Security profiles

Three profiles, assigned by criticality

AESCSF assigns each market participant a required Security Profile (SP-1 to SP-3) based on the criticality of their role in the National Electricity Market and gas markets. Higher-criticality entities must implement more of the framework's practices and meet them at higher Maturity Indicator Levels. Your profile is determined by AEMO, not self-selected.

SP-1
Lower criticality

Applies to smaller retailers and lower-criticality participants. A narrower set of practices is required, focused on foundational cyber security activities across the ten AESCSF domains.

AEMO reference
SP-2
Moderate criticality

Applies to mid-tier participants including some retailers, smaller generators, and distribution network service providers. Broader practice coverage and higher MIL expectations in domains exposed to cyber attack.

AEMO reference
SP-3
High criticality

Applies to large generators, transmission network service providers, and AEMO itself. Comprehensive practice coverage with the highest MIL expectations, particularly across identity, vulnerability management, and situational awareness.

AEMO reference
Trusted by 7,013 organisations worldwide
Powers the NSA's CAPT program310,332 pentests4.7 Gartner

Close the gaps before your next assessment

See how NodeZero generates audit-ready evidence for your compliance obligations. We'll walk you through where NodeZero applies for your specific framework.