The credibility test

What we catch. Fourteen gaps a real responsible entity has, when nobody is looking.

A CIRMP report is only worth the gaps it surfaces. Across the four hazard domains, here are fourteen common shortfalls cirmp AI is being built to flag from the artefacts you already export. The terms are technical. Your CISO will recognise every one.

Cyber and information security

The digital systems that run the asset.

Flat OT/IT topology

No IEC 62443 zone-and-conduit segmentation between the SCADA/supervisory layer (Purdue Level 3) and the corporate domain. Dragos or Claroty asset export shows the same VLAN end to end.

Vendor remote access without PAM, MFA or session recording

Persistent jump-host accounts in the IT GRC export, no break-glass workflow for emergency vendor access, no session video tied to a change ticket.

Backups present, integrity untested

Last backup restore test in the BCM (Business Continuity Management) register older than twelve months. Often absent. Essential Eight Maturity Level 1 requires restoration of data, applications and settings from backups to a common point in time to be tested as part of disaster recovery exercises. The same requirement is repeated word for word at Maturity Level 2 and Maturity Level 3. The export says it has not happened.

No phishing-resistant MFA or network segregation for critical systems

The Enhanced CIRMP Rules 2026 ask for phishing-resistant multi-factor authentication with central logging plus network segregation of critical systems, from 10 June 2028. The export shows SMS or app-push MFA only. It shows a flat path from the corporate network into the critical systems. Network segregation is the control that limits how far an attacker moves once inside. A CIRMP written before 10 June 2026 usually does not evidence either.

Personnel

The trusted insiders who can disrupt the asset.

Critical-worker register undefined

HRIS export shows OT operators and admins, but no documented criteria identifying which roles meet the critical worker criteria under the CIRMP Rules 2023 personnel hazard obligations.

Joiner-mover-leaver gaps on privileged access

Active Directory shows accounts of leavers with lastLogon after termination date. Movers still hold old role groups.

Privileged access never revalidated or aged out

The IT GRC export carries no attested access review of OT or domain admin entitlements. Essential Eight Maturity Level 2 requires privileged access to systems, applications and data repositories to be disabled after 12 months unless revalidated, and privileged access to systems and applications to be disabled after 45 days of inactivity. There is no quarterly recertification requirement at any maturity level.

Credentials and privileged access not controlled to the enhanced standard

The Enhanced CIRMP Rules 2026 ask entities to minimise unauthorised, unescorted or privileged access to critical components, and to gate critical-worker access to those components on an AusCheck background check with a suitability assessment, or an active Australian Government security clearance at Negative Vetting 1 or higher, redone at least every 5 years. Those personnel requirements sit at section 9A, and they apply from 10 June 2028. The export shows shared admin credentials, no privileged-access review and no critical-worker suitability record. Credential compromise itself is not a personnel control: it has its own section in the cyber block at section 8B, with lateral movement at section 8C. Neither adds a fifth hazard category.

Supply chain

The vendors and dependencies the asset rests on.

Material supplier register without FOCI assessment

Vendor list ingested, but no recorded assessment of foreign ownership, control or influence. The CIRMP supply chain hazard obligations require consideration of risks from suppliers, and FOCI is a material risk factor.

OT firmware updates without provenance verification

No firmware SBOM (Software Bill of Materials), no vendor-signed update channel, no hash check at install. The CMDB shows firmware versions but no provenance record.

No contractual right to audit on material OT suppliers

Procurement export carries the contract list. Review shows audit, security incident notification and exit clauses missing or weak.

Physical and natural

The buildings, sites and weather the asset sits in.

Single-site dependency for a critical asset

Asset register shows no documented failover site, no tested DR runbook, no RTO/RPO validated against the last DR exercise.

Natural-hazard exposure not mapped to the asset register

No flood-zone, bushfire-rating or seismic overlay attached to the site list, no Bureau of Meteorology hazard tier per facility.

Physical access logs not tied to identity

Card-reader logs reference badge IDs only. No link to HRIS for joiner-mover-leaver alignment, no escort policy enforcement evidence for visitors at the control room.

Every gap above is observable from artefacts you already produce. cirmp AI is being built to read them, name the gap, cite the obligation, and give you a board-grade fix list before the regulator does.

Ready to look inside

See cirmp AI run on a real CIRMP cycle.

Three minutes inside the demo. A live walkthrough on request. You will see what the next CIRMP attestation looks like when it writes itself.

See the live demo Back to overview