AESCSF — Australian Energy Sector Cyber Security Framework
The national cyber security standard for Australia's electricity and gas sectors, managed by AEMO. Based on the US C2M2 model with Australian-specific additions covering critical infrastructure obligations and cross-sector information sharing.
See where NodeZero appliesWhat is the AESCSF?
The Australian Energy Sector Cyber Security Framework is the national cyber security standard for Australia's electricity and gas sectors, managed by the Australian Energy Market Operator (AEMO). Based on the US Department of Energy's C2M2 model, the AESCSF adds Australian-specific practices covering critical infrastructure obligations, cross-sector information sharing, and alignment with ASD guidance. Energy market participants complete annual self-assessments against the framework, with results reported to AEMO and used to benchmark sector-wide maturity.
The framework assesses 10 domains at Security Profile levels determined by the criticality of the entity's role in the energy market. Generators, transmission network service providers, and market operators typically face higher profile requirements than smaller participants. While the AESCSF shares C2M2's governance-heavy structure, the Australian additions place stronger emphasis on incident reporting to AEMO and the Australian Cyber Security Centre, OT/IT convergence risks, and alignment with SOCI Act obligations.
Where NodeZero applies
NodeZero addresses the IT side of AESCSF compliance by testing the same three domains where technical evidence is critical: Identity and Access Management, Threat and Vulnerability Management, and Situational Awareness. Importantly, NodeZero operates exclusively in IT environments and does not exploit OT or SCADA systems -- where the inherited control mappings mention OT, NodeZero's role is enumerating reachable OT assets from the IT side and testing whether the IT/OT segmentation boundary holds, a distinction that matters in the energy sector where IT/OT boundaries are a key assessment focus. For governance domains and OT-specific practices, we map what sits outside autonomous testing so your self-assessment covers both environments accurately.
This mapping reflects our best-effort analysis of where NodeZero's autonomous pentesting produces relevant technical evidence against each requirement. It is intended to help you focus security effort on the controls NodeZero can test — not to serve as a compliance certification. You remain responsible for your own compliance assessment, for validating applicability to your environment, and for evidencing the requirements NodeZero does not directly test.
Please note the following require separate evidence: Risk management, Event and incident response, continuity of operations, Workforce management and Cybersecurity programme management.
Showing coverage grouped by compliance category.
Asset, change, and configuration management
Partial coverage. NodeZero discovers assets and identifies configuration weaknesses.
Internal pentestingCore
Enumerates every reachable host and service from the attacker perspective — often surfacing assets the inventory doesn't track.
High-Value TargetingElite only
Infers which assets carry the most business risk and prioritises attack paths to them — supporting input to the documented asset-prioritisation criteria this practice asks you to define and apply.
Identity and access management
Strong coverage. NodeZero directly tests IAM controls and credential security.
AD Password AuditCore
First AI to solve GOAD in 14 minutes (Horizon3-reported); audits password strength and reuse on privileged, service, and break-glass accounts — it is not uncommon for NodeZero to crack more than 50% of the passwords it tests on a first audit.
Phishing Impact TestingCore
Takes a phished credential and demonstrates its blast radius — what an attacker reaches when a single factor is enough — surfacing higher-risk access where a stronger or multifactor credential is not actually required.
Internal pentestingCore
Proves end-to-end paths from initial access to domain compromise — evidence of whether least-privilege is actually enforced.
BloodHound (integrated)Core
Built-in attack-graph visualisation — surfaces the higher-risk, over-privileged relationships ACCESS-2g (MIL2) requires extra scrutiny on.
Cloud pentestingCore
Extends privileged-credential validation into cloud IAM and tests whether those credentials are tightly scoped across on-prem and cloud.
Threat and vulnerability management
Strongest alignment. This domain is exactly what autonomous pentesting produces evidence for.
Internal pentestingCore
Returns proof of which vulnerabilities are actually exploitable in your environment — vulnerability information interpreted for the function, not theoretical CVSS lists.
Rapid ResponsePro & Elite
Rapid Response tests are delivered often within hours of disclosure, and in some cases ahead of the public patch — attacker-first assessment inside the detection window.
Vulnerability Risk IntelligenceElite only
Ingests existing scanner exports and classifies each CVE-asset pair as Confirmed Exploitable, Contextually Exploitable, or Threat Actor Pressure — attacker-first prioritisation of the scanner backlog.
Threat Actor IntelligenceElite only
Maps your real attack paths to MITRE ATT&CK and named threat-actor behaviour — produces environment-specific threat intelligence alongside external sources.
Vulnerability Management HubCore
Findings flow to Jira and ServiceNow through existing integrations, tracked through an Open → Mitigated → Regressed lifecycle, with Quick Verify to confirm a mitigation actually held.
High-Value TargetingElite only
Concentrates discovery and exploitation effort on the assets that carry the most business risk — vulnerability information that explicitly addresses the higher-priority subset.
Quick VerifyCore
Re-tests the exact attack chain after a remediation is applied and reports whether the action actually closed the vulnerability — direct effectiveness review built into the workflow.
Situational awareness
Direct coverage via deception, EDR effectiveness measurement, and attacker-behaviour generation.
NodeZero TripwiresPro & Elite
Honeytoken decoys on high-risk assets alert the moment an attacker interacts — routed via Splunk, Sentinel, or webhook into the same monitoring programme SITUATION-2 expects.
Internal pentestingCore
Every NodeZero action is timestamped with proofs and commands — correlate with your SIEM to validate whether your defined indicators actually fire.
Endpoint Security EffectivenessCore
Per-host and per-vendor EDR block/allow data mapped to MITRE ATT&CK — concrete effectiveness metrics for the monitoring layer.
Supply chain and external dependencies management
Minimal coverage. NodeZero tests the technical boundary where a supplier compromise would land.
Segmentation testingCore
Proves whether a supplier-side compromise would be contained at the interconnect or cascade into your critical assets — direct evidence that the controls protecting against third-party risk actually hold.
Phishing Impact TestingCore
Where a supplier credential or interconnect can be tested, proves how far that access reaches into your environment — one input to your supplier risk assessment, not the assessment itself.
High-Value TargetingElite only
Discovery + High-Value Targeting flag third-party connections that carry privileged reach into critical assets — direct evidence of which suppliers warrant the escalated-prioritisation tier.
Cybersecurity architecture
Direct coverage — tests whether architectural security controls actually hold.
Segmentation testingCore
Enumerates IPs, ports, services, and applications across the network to prove whether the security-zone boundaries hold the way the architecture says they should.
Internal pentestingCore
Proves end-to-end attack paths that cross architectural boundaries — evidence that the boundary-enforcement controls are not holding in practice. Whether a cybersecurity architecture is documented and maintained remains governance work.
Cloud pentestingCore
Hybrid architectures are where pentesters find the most gaps; cloud pentesting tests privilege-escalation paths between on-prem and AWS/Azure/K8s boundaries.
BloodHound (integrated)Core
Attack-graph visualisation surfaces every over-privileged user and service account — the gap between policy and practice that ARCHITECTURE-3c (MIL2) requires you to close.
Endpoint Security EffectivenessCore
Reports per-host EDR and host-firewall block/allow outcomes across 40+ vendors — direct evidence of which assets actually have the required security applications enforced.
Web application pentestingPriced separately
Runs the penetration-testing element of this practice against in-house-developed and in-house-tailored applications — OWASP Top 10 weaknesses, access-control failures and business-logic flaws, in pre-production and production, on a periodic or change-triggered cadence. Static, dynamic-code and fuzz testing remain separate activities.
External pentestingCore
Exercises internet-facing applications and services from the attacker's perspective, on a continuous cadence and after changes — the perimeter half of the security testing this domain expects, alongside the application-layer testing above.
See every control mapped to NodeZero
The full control-by-control coverage map — every AESCSFrequirement matched to the NodeZero capability that produces evidence for it, with maturity-level grouping and source citations. We'll email you the link and a downloadable copy.
Who does this apply to?
The AESCSF applies to participants in Australia's National Electricity Market (NEM) and gas markets. This includes electricity generators, transmission network service providers (TNSPs), distribution network service providers (DNSPs), electricity retailers, gas pipeline operators, gas retailers, and the Australian Energy Market Operator (AEMO) itself. Market participants complete an annual self-assessment against the framework, with results reported to AEMO.
The required Security Profile level -- which determines how many practices your organisation must implement -- is based on the criticality of your role in the energy market. Large generators, transmission operators, and market operators typically face higher profile requirements. Smaller retailers and non-critical participants may have lower thresholds, but all participants are expected to complete the self-assessment.
The AESCSF is also approved as one of five cyber frameworks under the SOCI CIRMP rules, making it the natural choice for energy sector entities that need to satisfy both their AEMO reporting obligations and their SOCI Act CIRMP requirements with a single framework. If you operate in Australia's energy sector, this is likely your primary cyber security compliance obligation.
Three profiles, assigned by criticality
AESCSF assigns each market participant a required Security Profile (SP-1 to SP-3) based on the criticality of their role in the National Electricity Market and gas markets. Higher-criticality entities must implement more of the framework's practices and meet them at higher Maturity Indicator Levels. Your profile is determined by AEMO, not self-selected.
Applies to smaller retailers and lower-criticality participants. A narrower set of practices is required, focused on foundational cyber security activities across the ten AESCSF domains.
AEMO reference →Applies to mid-tier participants including some retailers, smaller generators, and distribution network service providers. Broader practice coverage and higher MIL expectations in domains exposed to cyber attack.
AEMO reference →Applies to large generators, transmission network service providers, and AEMO itself. Comprehensive practice coverage with the highest MIL expectations, particularly across identity, vulnerability management, and situational awareness.
AEMO reference →Applies to smaller retailers and lower-criticality participants. A narrower set of practices is required, focused on foundational cyber security activities across the ten AESCSF domains.
AEMO reference →Applies to mid-tier participants including some retailers, smaller generators, and distribution network service providers. Broader practice coverage and higher MIL expectations in domains exposed to cyber attack.
AEMO reference →Applies to large generators, transmission network service providers, and AEMO itself. Comprehensive practice coverage with the highest MIL expectations, particularly across identity, vulnerability management, and situational awareness.
AEMO reference →Close the gaps before your next assessment
See how NodeZero generates audit-ready evidence for your compliance obligations. We'll walk you through where NodeZero applies for your specific framework.