DrochaidHorizon3.ai
NodeZero/Industries/Critical Infrastructure
The state of play — Critical Infrastructure, 2026

Critical Infrastructure is now the primary ransomware target.

ASD recorded a 280% year-on-year jump in DDoS activity against Australian CI. Supply chain and legacy edge services remain the recurring entry points — from default-password PLCs on US water utilities to the Jaguar Land Rover cascade that the UK Cyber Monitoring Centre estimates at £1.9 billion in economic loss.

50%
of all ransomware incidents tracked between January and September 2025 targeted critical sectors — manufacturing, healthcare, energy, transport, and financial services.
KELA — Escalating Ransomware Threats to National Security
280%
year-on-year increase in DDoS activity against Australian critical infrastructure — now accounting for almost a third of all CI incidents ASD responded to in FY2024–25.
ASD Annual Cyber Threat Report 2024–25
62%
of water and electricity operators reported a cyberattack in the past year; 67% of those incidents involved compromise of identity systems such as Active Directory, Entra ID, or Okta.
Semperis utilities sector study
The trend

Why Critical Infrastructure is in the crosshairs

Five shifts shaping the CI threat environment — what attackers are doing, and what regulators now expect operators to prove.

Critical infrastructure has become the primary ransomware target

KELA's 2025 data shows 50% of all tracked ransomware attacks hit critical sectors, with the absolute number of CI attacks rising 34% year-on-year. CI operators face the greatest downtime pressure and the highest public and regulatory scrutiny — and attackers are targeting that pressure deliberately.

State-sponsored actors are pre-positioning

ASD's 2024–25 report is explicit that state actors target Australian CI for "state goals". The CyberAv3ngers (IRGC) campaign against US water utilities, Volt Typhoon's activity against US CI, and the Viasat KA-SAT attack at the outset of the Ukraine invasion illustrate the same pattern: establishing footholds now, preserving disruption options for later.

OT is the front line, and it is behind IT

Many OT systems — water treatment PLCs, solar inverters, building management, pipeline SCADA — predate modern security. Default passwords, unencrypted protocols, and direct internet exposure persist. CyberAv3ngers compromised at least 34 US water utilities by finding internet-exposed Unitronics PLCs with default passwords. Forescout's SUN:DOWN research found 80% of disclosed solar-inverter vulnerabilities over the past three years were high or critical severity.

The supply chain is the weakest link

JLR, Colonial Pipeline, and Synnovis were not compromised via their OT — attackers entered through IT systems, third-party IT providers, or legacy edge services and cascaded from there. Verizon's 2025 DBIR confirms third-party involvement in breaches doubled to 30% globally.

Regulation is moving from "controls in place" to "evidence of effectiveness"

Australia's SOCI amendments, the UK's proposed ransomware payment ban for public sector and CI operators, the EU's NIS2 directive, and US EPA moves on water utility cybersecurity all point the same way — regulators want evidence that controls are working, not just that they exist on paper.

On the record

What regulators and experts are saying

We cannot just rely on voluntary measures. We need to use every tool we have… We've needed to move to mandatory.
Anne Neuberger
Then-US Deputy National Security Advisor for Cyber and Emerging Technology
2021
Cybersecurity threats are a serious concern for our nation's water infrastructure, including the communities, businesses, hospitals, and other critical infrastructure sectors that rely on these critical lifeline services.
Jess Kramer
EPA Assistant Administrator for Water — joint EPA/FBI/CISA/NSA advisory
2025
At £1.9 billion of financial loss, this incident appears to be the most economically damaging cyber event to hit the UK, with the vast majority of the financial impact being due to the loss of manufacturing output at JLR and its suppliers.
Cyber Monitoring Centre
UK systemic-risk body — on the Jaguar Land Rover incident
October 2025
What is now required

Cyber Security Act 2024 is now in force

Since 30 May 2025, mandatory 72-hour ransomware payment reporting applies to all entities over $3M turnover. CIRB post-incident forensic reviews are now law.

The Security of Critical Infrastructure Act 2018 (SOCI Act) requires responsible entities for critical infrastructure assets to maintain a Critical Infrastructure Risk Management Program (CIRMP). The CIRMP must address four hazard vectors: cyber and information security, personnel, supply chain, and physical security. For the cyber hazard vector, entities must adopt and comply with one of five approved frameworks — ASD Essential Eight, NIST Cybersecurity Framework, ISO/IEC 27001, C2M2, or AESCSF. The choice of framework should reflect the entity's risk profile and operational context. CIRMP annual reports must be submitted to the board and to CISC within 90 days of financial year end.

Legislation
SOCI Act — Critical Infrastructure Risk Management Program

Federal legislation covering 11 sectors including energy, water, transport, communications, and data storage. Responsible entities must maintain a CIRMP addressing four hazard vectors: cyber, personnel, supply chain, and physical security. NodeZero directly validates controls under the cyber hazard vector and tests supplier network segmentation under the supply chain vector. For the cyber vector specifically, entities must also adopt one of five approved frameworks which define the detailed technical controls.

Your chosen CIRMP cyber frameworkSelect one
Also in effect

A cascade of new obligations

Multiple new regulatory requirements are hitting simultaneously — each increasing the compliance burden and the consequences of failure.

Cyber Security Act 2024 -- ransomware reporting

30 May 2025

Mandatory ransomware payment reporting to ASD within 72 hours for entities over $3M turnover. The reporting obligation carries a civil penalty of 60 penalty units (a 5x multiplier applies to bodies corporate). NodeZero Tripwires and Rapid Response validate detection within this critical window.

Cyber Incident Review Board

30 May 2025

Independent post-incident review board with authority to examine significant cyber incidents affecting critical infrastructure. Organisations must provide forensic evidence at law-enforcement standards. NodeZero generates timestamped attack documentation that supports post-incident review.

TSRMP Rules 2025

4 Apr 2025

Telecommunications security obligations restructured under the SOCI Act framework, expanding asset scope to include CPE, OSS/BSS, and cloud infrastructure. All carriers and CSPs must now develop CIRMPs under the unified critical infrastructure framework.

Smart Device Cyber Security Standards

4 Mar 2026

Mandatory minimum security standards for internet-connected devices sold or deployed in Australia. Critical infrastructure operators cannot procure non-compliant devices. NodeZero identifies non-compliant devices on networks and validates isolation controls.

CIRMP cyber risk uplift (proposed)

Dec 2026

Proposed semi-annual vulnerability assessments for 9 high-risk asset classes including energy, water, transport, and broadcasting. Expanded scope of critical systems and mandatory threat modelling exercises. Expected to commence December 2026.

Enhanced Response and Prevention Act 2024

20 Dec 2024

Expanded government intervention powers for "seriously deficient" CIRMPs. Regulators can now compel specific remediation actions. Board directors face personal liability for inadequate risk management programs.

Platform credentials

The only autonomous pentesting platform that is:

SOCI / CIRMP
Control-by-control
Board attestation
Essential Eight
Mapped ML1–3
ASD baseline
NSA CAPT
Powered by NodeZero
US defence industrial base program
310,332
Pentests run
7,013 orgs
Trusted by 7,013 organisations worldwide
Powers the NSA's CAPT program310,332 pentests4.7 Gartner

Prove your controls work before regulators ask

See how NodeZero maps to your SOCI Act CIRMP obligations and Essential Eight requirements across your critical infrastructure environment