Skip to content
Mining, oil & gas · Australia

When the network stops, the pit stops.

Coal and metal-ore mining, oil and gas extraction, and the support services around them run on converged IT and operational technology — and much of it now sits inside Australia's critical-infrastructure regime. A ransomware hit here doesn't just leak data. It halts production, by the hour, at a cost few other sectors face.

Dossier 10 / 10

Mining, Oil & Gas

Ransomware that stops extraction stops revenue by the hour — and IT/OT convergence hands an attacker a path from the office network straight to the pit.

  • Security of Critical Infrastructure Act 2018 (SOCI), where the asset/operator is covered
  • Operational-technology (OT/ICS) security
  • Incident reporting obligations where applicable
Named obligations

What the obligation actually requires of you.

  1. 01

    Security of Critical Infrastructure Act 2018 (SOCI), where the asset/operator is covered

    SOCI obligations depend on the asset class and the entity's role. Where a mining, energy or gas business is covered, it may need to identify assets, maintain a risk-management program and meet registration or reporting duties.

  2. 02

    Operational-technology (OT/ICS) security

    Operational technology — the SCADA, PLCs and control systems that run extraction and processing — was built for uptime, not for the internet it's now connected to. Securing the IT/OT boundary is the single most important control between an office phishing email and a stopped production line.

  3. 03

    Incident reporting obligations where applicable

    For a responsible entity or other covered participant whose critical-infrastructure asset is affected, a qualifying cyber incident carries mandatory reporting timeframes to the Australian Signals Directorate / ACSC. Meeting that clock under pressure requires a rehearsed process agreed long before the incident, not improvised on the day.

7

controls to review

Use this sector-specific set of practical prompts to identify owners, evidence and the next control to verify.

Illustrative scenario · Resources-support contractor, WA

An office breach approaching the control network.

Illustrative scenario — In this example, A contractor servicing a mine site was compromised through a phishing email on the corporate network. Because the corporate and operational networks shared flat, unsegmented infrastructure, the attacker was a single lateral move away from systems that touched site operations.

Example response — A suitable response is to isolate corporate access from OT, preserve evidence, confirm whether a regulated asset is affected and follow the applicable reporting plan.

What to verify — Confirm the relevant control is configured, tested and evidenced for this scenario; record the owner, review date and any exception before treating the risk as addressed.

Control evidence to collect

Configuration, test evidence, an accountable owner and a review date for the controls described in this scenario.

Illustrative scenario only. It is not a client case study, endorsement, zero-loss claim or proof of a security outcome.

The compliance checklist

Run it yourself, before we ever speak.

  • Corporate IT and operational technology (OT/ICS) segmented, with every crossing monitored
  • Your critical assets identified and a risk-management program maintained under SOCI
  • MFA enforced on remote access to both corporate and operational environments
  • Where applicable, a rehearsed incident-response plan that meets ASD/ACSC mandatory reporting timeframes
  • Tested, immutable, offline-capable backups for systems that keep the site running
  • Third-party and contractor access to your network scoped, logged and time-limited
  • Staff and site crews trained to recognise phishing and supplier-impersonation attempts

These are practical control prompts, not a legal compliance determination. Exact obligations vary by entity, asset, contract and jurisdiction.

Get the Mining, Oil & Gas compliance checklist

A practical web checklist for your sector’s controls and obligations. No call. No obligation.

Before you call us

The questions this vertical always asks.

Find out exactly where your operation’s IT/OT boundary is exposed.

The Cyber Readiness Assessment is the forensic starting point, backed by a 100% refund guarantee. Enquire for scope and terms.

Melbourne VIC · Australia · gmanit.com.au