When the network stops, the pit stops.
Coal and metal-ore mining, oil and gas extraction, and the support services around them run on converged IT and operational technology — and much of it now sits inside Australia's critical-infrastructure regime. A ransomware hit here doesn't just leak data. It halts production, by the hour, at a cost few other sectors face.
Dossier 10 / 10
Mining, Oil & Gas
Ransomware that stops extraction stops revenue by the hour — and IT/OT convergence hands an attacker a path from the office network straight to the pit.
- Security of Critical Infrastructure Act 2018 (SOCI), where the asset/operator is covered
- Operational-technology (OT/ICS) security
- Incident reporting obligations where applicable
What the obligation actually requires of you.
- 01
Security of Critical Infrastructure Act 2018 (SOCI), where the asset/operator is covered
SOCI obligations depend on the asset class and the entity's role. Where a mining, energy or gas business is covered, it may need to identify assets, maintain a risk-management program and meet registration or reporting duties.
- 02
Operational-technology (OT/ICS) security
Operational technology — the SCADA, PLCs and control systems that run extraction and processing — was built for uptime, not for the internet it's now connected to. Securing the IT/OT boundary is the single most important control between an office phishing email and a stopped production line.
- 03
Incident reporting obligations where applicable
For a responsible entity or other covered participant whose critical-infrastructure asset is affected, a qualifying cyber incident carries mandatory reporting timeframes to the Australian Signals Directorate / ACSC. Meeting that clock under pressure requires a rehearsed process agreed long before the incident, not improvised on the day.
controls to review
Use this sector-specific set of practical prompts to identify owners, evidence and the next control to verify.
An office breach approaching the control network.
Illustrative scenario — In this example, A contractor servicing a mine site was compromised through a phishing email on the corporate network. Because the corporate and operational networks shared flat, unsegmented infrastructure, the attacker was a single lateral move away from systems that touched site operations.
Example response — A suitable response is to isolate corporate access from OT, preserve evidence, confirm whether a regulated asset is affected and follow the applicable reporting plan.
What to verify — Confirm the relevant control is configured, tested and evidenced for this scenario; record the owner, review date and any exception before treating the risk as addressed.
Control evidence to collect
Configuration, test evidence, an accountable owner and a review date for the controls described in this scenario.
Illustrative scenario only. It is not a client case study, endorsement, zero-loss claim or proof of a security outcome.
Run it yourself, before we ever speak.
- Corporate IT and operational technology (OT/ICS) segmented, with every crossing monitored
- Your critical assets identified and a risk-management program maintained under SOCI
- MFA enforced on remote access to both corporate and operational environments
- Where applicable, a rehearsed incident-response plan that meets ASD/ACSC mandatory reporting timeframes
- Tested, immutable, offline-capable backups for systems that keep the site running
- Third-party and contractor access to your network scoped, logged and time-limited
- Staff and site crews trained to recognise phishing and supplier-impersonation attempts
These are practical control prompts, not a legal compliance determination. Exact obligations vary by entity, asset, contract and jurisdiction.
The questions this vertical always asks.
It depends on your assets and sector, but the regime now reaches well beyond the obvious energy giants. If you're unsure, that uncertainty is itself the risk — we help you determine your obligations and build the risk-management program the Act expects.
That's the norm in OT, and it's exactly why segmentation matters more than patching here. If the control network can't be updated safely, we wall it off and monitor the boundary to reduce lateral-movement paths, then validate the design.
Increasingly, yes — operators push critical-infrastructure security requirements down their supply chain. Being able to prove your network is hardened is fast becoming a condition of winning and keeping the work.
Find out exactly where your operation’s IT/OT boundary is exposed.
The Cyber Readiness Assessment is the forensic starting point, backed by a 100% refund guarantee. Enquire for scope and terms.
Melbourne VIC · Australia · gmanit.com.au