Flat OT/IT topology
No IEC 62443 zone-and-conduit segmentation between the SCADA/supervisory layer (Purdue Level 3) and the corporate domain. Dragos or Claroty asset export shows the same VLAN end to end.
Cyber and information security
No IEC 62443 zone-and-conduit segmentation between the SCADA/supervisory layer (Purdue Level 3) and the corporate domain. Dragos or Claroty asset export shows the same VLAN end to end.
Persistent jump-host accounts in the IT GRC export, no break-glass workflow for emergency vendor access, no session video tied to a change ticket.
Last backup restore test in the BCM (Business Continuity Management) register older than twelve months. Often absent. Essential Eight Maturity Level 1 requires restoration of data, applications and settings from backups to a common point in time to be tested as part of disaster recovery exercises. The same requirement is repeated word for word at Maturity Level 2 and Maturity Level 3. The export says it has not happened.
The Enhanced CIRMP Rules 2026 ask for phishing-resistant multi-factor authentication with central logging plus network segregation of critical systems, from 10 June 2028. The export shows SMS or app-push MFA only. It shows a flat path from the corporate network into the critical systems. Network segregation is the control that limits how far an attacker moves once inside. A CIRMP written before 10 June 2026 usually does not evidence either.
Personnel
HRIS export shows OT operators and admins, but no documented criteria identifying which roles meet the critical worker criteria under the CIRMP Rules 2023 personnel hazard obligations.
Active Directory shows accounts of leavers with lastLogon after termination date. Movers still hold old role groups.
The IT GRC export carries no attested access review of OT or domain admin entitlements. Essential Eight Maturity Level 2 requires privileged access to systems, applications and data repositories to be disabled after 12 months unless revalidated, and privileged access to systems and applications to be disabled after 45 days of inactivity. There is no quarterly recertification requirement at any maturity level.
The Enhanced CIRMP Rules 2026 ask entities to minimise unauthorised, unescorted or privileged access to critical components, and to gate critical-worker access to those components on an AusCheck background check with a suitability assessment, or an active Australian Government security clearance at Negative Vetting 1 or higher, redone at least every 5 years. Those personnel requirements sit at section 9A, and they apply from 10 June 2028. The export shows shared admin credentials, no privileged-access review and no critical-worker suitability record. Credential compromise itself is not a personnel control: it has its own section in the cyber block at section 8B, with lateral movement at section 8C. Neither adds a fifth hazard category.
Supply chain
Vendor list ingested, but no recorded assessment of foreign ownership, control or influence. The CIRMP supply chain hazard obligations require consideration of risks from suppliers, and FOCI is a material risk factor.
No firmware SBOM (Software Bill of Materials), no vendor-signed update channel, no hash check at install. The CMDB shows firmware versions but no provenance record.
Procurement export carries the contract list. Review shows audit, security incident notification and exit clauses missing or weak.
Physical and natural
Asset register shows no documented failover site, no tested DR runbook, no RTO/RPO validated against the last DR exercise.
No flood-zone, bushfire-rating or seismic overlay attached to the site list, no Bureau of Meteorology hazard tier per facility.
Card-reader logs reference badge IDs only. No link to HRIS for joiner-mover-leaver alignment, no escort policy enforcement evidence for visitors at the control room.
Every gap above is observable from artefacts you already produce. cirmp AI is being built to read them, name the gap, cite the obligation, and give you a board-grade fix list before the regulator does.