top of page

Security of Critical Infrastructure Act 2018 

Surveillance Cameras Outdoors

We are a market leader in the complete lifecycle management of SOCI compliance

Team

Complying with the SOCI legislation involves navigating a complex collection of highly legal and technical interdependencies. That's why we're legal experts with strong regulatory and operational experience, backed by a proven track record of interpreting and responding to new laws in a targeted, efficient way. There are no juniors at Rangecroft - we are all seasoned professionals that work collaboratively with our clients at the coalface.

Legally Robust and Defensible

Helping Responsible Entities comply with the SOCI Act isn't part our business - it is our business. We've critically assessed the legal obligations under the legislation, prescribed cyber security frameworks and ancillary rules to ensure the systems and processes we develop for clients address all mandatory requirements, are fit for purpose and achieve compliance.

Quick and Effective

We maintain a reference Critical Infrastructure Risk Management Program that includes all necessary policies and procedures aligned with the evolving requirements under SOCI. Tailored for individual critical infrastructure sectors and customisable for any particular asset, our turnkey artefacts help clients quickly and effectively minimise material risks and mitigate relevant impacts across the prescribed hazard domains while reducing the burden of operationalisation.

Knowledge

Hitting the required compliance goals without overloading teams or blowing budgets requires an intimate understanding of how critical infrastructure assets work. We can quickly assimilate your specifications, design files and as-built SLDs in building an accurate picture of your critical infrastructure asset. We use the invaluable information you already have, consider it against legislative requirements and work with you in developing a strategy that maximizes effectiveness, contains costs and minimizes disruption to your organisation.

Market Liaison

We know at a granular, technical level how critical infrastructure assets are configured and assist stakeholders across the supply chain align their processes to ensure the Responsible Entity can achieve and maintain compliance. We have an established track record of leading complex change management, helping to reduce the complexity, potential relationship impacts and resource demands of complying with the SOCI legislation and cyber security frameworks.

Defray Risk

We happily accept responsibility on behalf of our clients for performing the prescribed relevant positions identified for developing, reviewing and updating their Critical Infrastructure Risk Management Programs. We can engage with stakeholders, advise on how to ensure their processes, technologies and workforce are aligned with your legal obligations, and negotiate to ensure the best interests of your business are secured. We proudly stand behind our work and will defend it before any audit with the regulator.

Our suite of SOCI services

Site Audits and

Component Mapping

Cyber Framework Assessment

Compliance Methodology

Sense Check

Risk Management Program Creation and Maintenance

Cyber Framework

Policies

Strategic Compliance

Advice

Risk Register Creation and Maintenance

Critical Worker Register Creation and Maintenance

Asset Transaction

Due Diligence

Mandatory Policies

Stakeholder Liaison

ELT / Board Assurance

Risk Management

Operationalisation

Risk Management

Program Audit

All-Hazard Policy

Development (Govt)

bottom of page