CI Security Assessment
Vulnerability and gap evaluation across the IT/OT boundary, cloud workloads, and IoT edge — aligned to SOCI, AESCSF, and IEC 62443.
Overview
Most security assessments stop at the IT estate or treat OT as a footnote. For a critical-infrastructure operator, that leaves the most consequential exposure unexamined: the cloud-connected OT and IoT systems that, if compromised, could affect service continuity, safety, or regulatory standing.
The xCIRT CI Security Assessment evaluates posture across the entire cloud-to-edge path, in the regulatory context that applies to your sector.
What’s included
- Cloud workload review — Identity, network exposure, key-management, logging, and any cloud-to-OT integration paths.
- IT/OT boundary assessment — Segmentation, firewall rules, remote-access mechanisms, jump hosts, and shared service exposure.
- OT environment review — PLC, SCADA, RTU, historian, and engineering-workstation posture, including patch state and known-vulnerable firmware.
- IoT edge review — IIoT gateway configuration, telemetry pathways, and update mechanisms.
- Regulatory alignment — Mapped to SOCI Act / CIRMP obligations, AESCSF (energy), IEC 62443, and ISM/Essential Eight where applicable.
- Prioritised remediation roadmap — Findings ranked by likely impact and sector context, with realistic effort estimates.
How it works
- Scoping — Define the in-scope environments, the regulatory frame, and any sensitivities (safety-critical systems, change windows).
- Discovery — A mix of documentation review, configuration analysis, interviews, and (where authorised and safe) targeted technical validation.
- Findings and report — Board-grade summary plus technical detail, with prioritised remediation.
- Walkthrough and Q&A — Live debrief with your team to align on the next steps.
Outcomes
A clear, sector-appropriate picture of where the cyber risk concentrates in your critical-infrastructure estate, mapped to obligations you must meet, with a remediation roadmap your board and operations team can both act on.
Need an Australian responder, now?
Retainer engagements, scoped pilots, and SOCI-readiness packages. Talk to us about what your critical-infrastructure estate needs.