How DOLIUM meets the SOCI Act’s Core Obligations for critical infrastructure

The Security of Critical Infrastructure Act does not treat Australia as a single system. it treats it as eleven of them.

Energy, water & sewerage, transport, food & grocery, communications, data storage & processing, financial services & markets, health care & medical, defence industry, higher education & research and space technology. Each sector has its own failure modes, its own regulators, its own definition of what counts as a significant impact.

What they share is three Positive Security Obligations that every responsible entity must satisfy regardless of what they operate: a risk management program that covers all hazards, mandatory reporting of cyber incidents within statutory timeframes and an accurate register of what they own and control.

Most organisations meet these obligations sector by sector because that is how the compliance function is usually built. A different team, a different spreadsheet, a different set of controls for the pipeline. That approach works until the auditor asks how the risk program adapts when the ownership structure changes or how the incident report reached the regulator inside twelve hours or why the register was three weeks out of date when the transaction settled.

At that point the gaps between sector-specific compliance efforts become the story, not the compliance itself.

DOLIUM does not solve this by building eleven versions of the same system. It solves it by encoding one operating logic that governs how the obligations are met and letting each sector’s operational reality run through it. The System of Work does not change, what changes is the risk the entity is managing today.

The Critical Infrastructure Risk Management Program, wherever the hazard sits

An electricity transmission operator, a water utility, a freight and logistics operator and a food distribution network have almost nothing in common operationally. One worries about grid stability during extreme weather. One worries about contamination and supply continuity. One worries about port congestion and insider access to freight manifests. One worries about cold chain failure and the speed at which a recall has to move.

Under the SOCI Act, each of them needs a CIRMP that takes an all-hazards approach across physical, personnel, supply chain and cyber vectors and each needs to prove the program is not a document sitting in a shared drive but something staff use to perform their duties.

DOLIUM’s embedded assistant, AiDA, reads the legislative and sector-specific requirements relevant to each asset class and maps them against the entity’s actual operating procedures, not a generic template borrowed from a compliance vendor. The risk program is enforced at the point of action.

When a field technician at the water utility tries to skip a mandated inspection step to hit a deadline, DOLIUM’s business logic stops the shortcut because it breaches the embedded risk policy, not because someone flags it after the fact in a quarterly review. When the freight operator’s dispatch system attempts to route a shipment through an unvetted subcontractor, the same logic intervenes before the exposure exists. The CIRMP stops being a document produced for the regulator and becomes the way the operation actually runs. That is the difference between compliance as evidence and compliance as behaviour, and it is the only version of a risk management program that survives an audit under real pressure.

Mandatory cyber incident reporting, at the speed the Act requires

A data storage and processing facility, a national communications carrier, a financial market infrastructure provider, and a hospital network operate in sectors where the cyber threat is constant rather than occasional, and where the twelve-hour reporting clock for a significant impact incident starts the moment the threshold is met, not the moment someone notices. The gap between those two points is where most organisations lose the time they cannot get back.

Because DOLIUM sits as a trust anchor across the enterprise’s transaction and system layer, it recognises a qualifying incident in real time rather than waiting for a security team to piece together what happened from logs after the fact. AiDA verifies the event against the statutory threshold, assembles the technical detail the Australian Signals Directorate requires, and produces a report with a validated audit trail attached, ready for a human to authorise rather than draft from scratch under pressure. A hospital network facing a ransomware attempt on patient systems and a payments provider facing a targeted intrusion on settlement infrastructure are different crises in every respect except one: both need an accurate, defensible report in the regulator’s hands well inside the statutory window, and both need to be able to show, months later, exactly what was known and when. DOLIUM produces that record as a byproduct of how the incident was handled, not as a separate exercise reconstructed afterwards.

The Register of Critical Infrastructure Assets, kept current by the transaction, not the memory of the person who should have updated it

Defence industry, higher education and research, and space technology sit under scrutiny that goes beyond operational resilience into ownership, control and foreign interest. A defence manufacturer restructuring its capital base, a university onboarding an international research partner, a space technology operator bringing in a new investor all trigger the same underlying obligation: the Register of Critical Infrastructure Assets has to reflect who owns and controls the asset within the mandated window, and it has to be right.

DOLIUM separates the governance layer from the transactional systems, which means it does not depend on a person remembering to file an update after the legal team closes the deal. When the corporate registry reflects a change in equity or control, DOLIUM detects the structural shift, updates the internal register, and generates the documentation the Cyber and Infrastructure Security Centre requires to stay informed. For sectors where national security and research integrity sit this close to the surface, that is not an administrative convenience. It is the difference between a register that is accurate because someone remembered, and one that is accurate because the system cannot let it drift.

The point of building it once

None of this works if DOLIUM has to be rebuilt for every sector it touches. The value is that it does not. The same operating logic that stops a shortcut on a pipeline stops one in a hospital supply chain. The same real-time detection that produces a defensible cyber incident report for a bank produces one for a university research network. The same structural awareness that keeps a defence contractor’s register current keeps a space technology operator’s register current. Eleven sectors, twenty-two asset classes, one System of Work.

That is the argument for treating a System of Work as infrastructure rather than software. Software gets selected for a use case and retired when the use case changes. Infrastructure gets built once and everything downstream depends on it working the same way every time, regardless of which sector is asking. Under the SOCI Act, that consistency is not a convenience. It is the only version of compliance that holds up when the regulator, the auditor, or the incident itself arrives without warning.

Start the conversation.

Tell us about your operating model and we will show you where DOLIUM fits. We respond within one business day.