Critical Infrastructure is now the primary ransomware target.
ASD recorded a 280% year-on-year jump in DDoS activity against Australian CI. Supply chain and legacy edge services remain the recurring entry points — from default-password PLCs on US water utilities to the Jaguar Land Rover cascade that the UK Cyber Monitoring Centre estimates at £1.9 billion in economic loss.
Why Critical Infrastructure is in the crosshairs
Five shifts shaping the CI threat environment — what attackers are doing, and what regulators now expect operators to prove.
Critical infrastructure has become the primary ransomware target
KELA's 2025 data shows 50% of all tracked ransomware attacks hit critical sectors, with the absolute number of CI attacks rising 34% year-on-year. CI operators face the greatest downtime pressure and the highest public and regulatory scrutiny — and attackers are targeting that pressure deliberately.
State-sponsored actors are pre-positioning
ASD's 2024–25 report is explicit that state actors target Australian CI for "state goals". The CyberAv3ngers (IRGC) campaign against US water utilities, Volt Typhoon's activity against US CI, and the Viasat KA-SAT attack at the outset of the Ukraine invasion illustrate the same pattern: establishing footholds now, preserving disruption options for later.
OT is the front line, and it is behind IT
Many OT systems — water treatment PLCs, solar inverters, building management, pipeline SCADA — predate modern security. Default passwords, unencrypted protocols, and direct internet exposure persist. CyberAv3ngers compromised at least 34 US water utilities by finding internet-exposed Unitronics PLCs with default passwords. Forescout's SUN:DOWN research found 80% of disclosed solar-inverter vulnerabilities over the past three years were high or critical severity.
The supply chain is the weakest link
JLR, Colonial Pipeline, and Synnovis were not compromised via their OT — attackers entered through IT systems, third-party IT providers, or legacy edge services and cascaded from there. Verizon's 2025 DBIR confirms third-party involvement in breaches doubled to 30% globally.
Regulation is moving from "controls in place" to "evidence of effectiveness"
Australia's SOCI amendments, the UK's proposed ransomware payment ban for public sector and CI operators, the EU's NIS2 directive, and US EPA moves on water utility cybersecurity all point the same way — regulators want evidence that controls are working, not just that they exist on paper.
What regulators and experts are saying
We cannot just rely on voluntary measures. We need to use every tool we have… We've needed to move to mandatory.
Cybersecurity threats are a serious concern for our nation's water infrastructure, including the communities, businesses, hospitals, and other critical infrastructure sectors that rely on these critical lifeline services.
At £1.9 billion of financial loss, this incident appears to be the most economically damaging cyber event to hit the UK, with the vast majority of the financial impact being due to the loss of manufacturing output at JLR and its suppliers.
Cyber Security Act 2024 is now in force
Since 30 May 2025, mandatory 72-hour ransomware payment reporting applies to all entities over $3M turnover. CIRB post-incident forensic reviews are now law.
The Security of Critical Infrastructure Act 2018 (SOCI Act) requires responsible entities for critical infrastructure assets to maintain a Critical Infrastructure Risk Management Program (CIRMP). The CIRMP must address four hazard vectors: cyber and information security, personnel, supply chain, and physical security. For the cyber hazard vector, entities must adopt and comply with one of five approved frameworks — ASD Essential Eight, NIST Cybersecurity Framework, ISO/IEC 27001, C2M2, or AESCSF. The choice of framework should reflect the entity's risk profile and operational context. CIRMP annual reports must be submitted to the board and to CISC within 90 days of financial year end.
Federal legislation covering 11 sectors including energy, water, transport, communications, and data storage. Responsible entities must maintain a CIRMP addressing four hazard vectors: cyber, personnel, supply chain, and physical security. NodeZero directly validates controls under the cyber hazard vector and tests supplier network segmentation under the supply chain vector. For the cyber vector specifically, entities must also adopt one of five approved frameworks which define the detailed technical controls.
Prescriptive and technically focused. Eight specific mitigation strategies with clear pass/fail controls. Common for government-adjacent entities, defence industry, and smaller organisations adopting ASD guidance.
Where NodeZero appliesBroad lifecycle coverage from governance through recovery without mandating specific technologies. Suited to entities operating across jurisdictions or mapping existing controls into a flexible structure.
Where NodeZero appliesInternational management system standard with formal certification. Chosen by larger entities with mature security programs, international operations, or existing ISO certification investment.
Where NodeZero appliesMaturity model assessing organisational capability across 10 domains. Originally built for the US electricity sector. Process and governance oriented -- less about specific controls, more about repeatable capability.
Where NodeZero appliesSector-specific to energy. Derived from C2M2 and NIST CSF with Australian privacy additions. Managed by AEMO. The default for electricity and gas market participants with OT/ICS environments.
Where NodeZero appliesCritical infrastructure operators often hold personal information of customers, employees, and stakeholders subject to the Australian Privacy Principles.
Where NodeZero appliesRelevant for infrastructure operators providing managed or shared services, particularly in water, energy, and transport sectors.
Where NodeZero appliesApplies to infrastructure operators that process customer payments — utilities, transport, and port authorities handling card transactions.
Where NodeZero appliesMandatory ransomware reporting and minimum security standards for all critical infrastructure entities under the SOCI Act.
Where NodeZero appliesA cascade of new obligations
Multiple new regulatory requirements are hitting simultaneously — each increasing the compliance burden and the consequences of failure.
Cyber Security Act 2024 -- ransomware reporting
30 May 2025Mandatory ransomware payment reporting to ASD within 72 hours for entities over $3M turnover. The reporting obligation carries a civil penalty of 60 penalty units (a 5x multiplier applies to bodies corporate). NodeZero Tripwires and Rapid Response validate detection within this critical window.
Cyber Incident Review Board
30 May 2025Independent post-incident review board with authority to examine significant cyber incidents affecting critical infrastructure. Organisations must provide forensic evidence at law-enforcement standards. NodeZero generates timestamped attack documentation that supports post-incident review.
TSRMP Rules 2025
4 Apr 2025Telecommunications security obligations restructured under the SOCI Act framework, expanding asset scope to include CPE, OSS/BSS, and cloud infrastructure. All carriers and CSPs must now develop CIRMPs under the unified critical infrastructure framework.
Smart Device Cyber Security Standards
4 Mar 2026Mandatory minimum security standards for internet-connected devices sold or deployed in Australia. Critical infrastructure operators cannot procure non-compliant devices. NodeZero identifies non-compliant devices on networks and validates isolation controls.
CIRMP cyber risk uplift (proposed)
Dec 2026Proposed semi-annual vulnerability assessments for 9 high-risk asset classes including energy, water, transport, and broadcasting. Expanded scope of critical systems and mandatory threat modelling exercises. Expected to commence December 2026.
Enhanced Response and Prevention Act 2024
20 Dec 2024Expanded government intervention powers for "seriously deficient" CIRMPs. Regulators can now compel specific remediation actions. Board directors face personal liability for inadequate risk management programs.
Find your organisation
See how the changes affect you specifically
Energy utilities
Transmission, distribution, and generation operators. SoNS-designated entities with dual IT/OT environments and AESCSF obligations.
View details →Water authorities
State water authorities and regional utilities. SoNS-designated for major urban supply systems. Ageing OT alongside modern IT creates segmentation complexity.
View details →Transport operators
Roads, rail, aviation, and port authorities. Increasingly software-defined systems with high ransomware risk and operational resilience requirements.
View details →The only autonomous pentesting platform that is:
Prove your controls work before regulators ask
See how NodeZero maps to your SOCI Act CIRMP obligations and Essential Eight requirements across your critical infrastructure environment


