← SecureAZ Blog

Security Awareness · 6 min read · Published 14 July 2026 · Reviewed 17 August 2026

Australia Is Rewriting Its Critical Infrastructure Laws Because of AI Attacks — What NZ Businesses Should Know

Australia CISC is consulting on 21 measures to modernise the SOCI Act in response to AI-enabled cyber threats. NZ businesses with Australian operations or supply chain relationships need to understand what is changing.

Australia's Cyber and Infrastructure Security Centre (CISC) is currently seeking industry feedback on 21 proposed measures to streamline and modernise the Security of Critical Infrastructure Act 2018 — specifically in response to the growing threat of AI-enabled cyber attacks against critical infrastructure.

For NZ businesses, this matters in two ways. First, if you operate in Australia or supply to Australian regulated entities, you will be affected by these changes. Second, NZ's own regulatory direction tends to follow Australian precedent with a short lag — the Cyber Security Resilience Bill currently before the NZ Parliament draws heavily on the Australian model.

What the SOCI Act Does and Why It Is Being Updated

The Security of Critical Infrastructure Act applies to organisations in 11 critical infrastructure sectors in Australia: communications, data storage and processing, defence industry, education, energy, financial services, food, health, space technology, transport, and water. Regulated entities must meet security obligations, register assets, report incidents, and maintain risk management programmes.

The 2024-2026 period has seen a significant increase in AI-assisted attacks targeting critical infrastructure globally. Attack tools using AI to conduct reconnaissance, generate targeted phishing content, identify vulnerabilities, and adapt to defensive controls in real-time have accelerated the threat landscape in ways the 2018 Act did not anticipate.

The CISC's 21 proposed measures aim to address this by streamlining compliance requirements while strengthening protections against the specific capabilities that AI-enabled threat actors now bring.

The Key Proposed Changes

While the full list of 21 measures is subject to consultation, the areas of greatest change that have been signalled include:

AI-specific threat provisions. The proposed changes would introduce explicit obligations for regulated entities to assess and manage AI-enabled threats as a distinct risk category. This goes beyond generic cyber risk management to require that entities specifically consider how AI tools change the nature of attacks against their systems.

Supply chain security expansion. The proposed measures would extend SOCI obligations further into supply chains, requiring regulated entities to impose minimum security requirements on suppliers whose products or services form part of critical infrastructure operations. This has direct implications for NZ technology companies that supply to Australian regulated entities — they may face new contractual security requirements as a result.

Incident response uplift. The proposals include strengthening mandatory incident response requirements, including shorter reporting timelines for significant incidents and requirements for tested (not just documented) incident response plans.

Simplified compliance pathways. The CISC has acknowledged that the current framework creates compliance complexity that disproportionately burdens smaller entities within regulated sectors. Several of the 21 measures aim to create tiered compliance pathways based on asset criticality.

What This Means for NZ Businesses

### If you operate in Australia

If your business operates in any of the 11 critical infrastructure sectors in Australia, SOCI obligations already apply to your Australian operations. The proposed changes will increase the specificity of those obligations — particularly around AI threat risk assessment and supply chain security. Start reviewing your current SOCI compliance posture now rather than waiting for the final regulations.

### If you supply to Australian regulated entities

This is the group most likely to be caught off-guard. If your NZ business supplies technology, software, managed services, or data processing to Australian entities in regulated sectors, you may face new downstream security requirements as those entities update their supplier contracts to meet the expanded SOCI supply chain provisions.

Specifically, expect Australian clients to ask for evidence of: your own incident response capability, your vulnerability disclosure and patching practices, your security awareness training programme, and potentially your risk management documentation.

### If you are watching NZ regulatory direction

The NZ Cyber Security Resilience Bill is the domestic parallel to Australia's SOCI evolution. NZ's critical infrastructure sectors are likely to face mandatory security obligations within the next 12-18 months under this legislation. The Australian model gives you a reasonably reliable preview of what those obligations will look like. Organisations that build SOCI-aligned security programmes now will be well-positioned for NZ regulatory requirements when they arrive.

The AI Threat Dimension

The CISC's focus on AI-enabled threats deserves attention beyond the regulatory context. The reason Australia is updating its laws is that AI has materially changed what threat actors can do at scale.

Reconnaissance that previously required hours of manual work — identifying exposed systems, mapping network topology, profiling staff for social engineering — can now be conducted in minutes using AI tools. Phishing content that previously required native language skills and cultural knowledge can be generated in fluent, contextually appropriate New Zealand English at volume. Vulnerability analysis that required specialist knowledge can be automated.

None of this means AI attacks are unstoppable. It means the speed and scale at which attacks can be conducted has increased, and the baseline security posture required to defend against them has correspondingly risen. The CISC is updating the law because the threat environment has changed — and the law needs to reflect that, whether or not your business is a regulated entity.

See our post on the NCSC Minimum Cyber Security Standards for NZ businesses for the current NZ baseline that applies regardless of regulated status.

Preparing Now

Whether or not your business is directly affected by the SOCI Act, the regulatory direction is clear: governments in both Australia and New Zealand are moving toward mandatory cyber security obligations for a widening category of businesses. Organisations that treat security as a compliance box to tick when regulations arrive will face a harder transition than those that build capability now.

The specific areas the CISC is strengthening — AI threat awareness, supply chain security, incident response, and risk management — are exactly the areas where investment now delivers both security benefit and regulatory readiness.

Build your team's security awareness with SecureAZ

Sources & references