ARTICLE

The Risk You Sign Your Name To

The Risk You Sign Your Name To

Compliance tells you the minimum. Leadership decides what you will defend, what you will accept, and who answers for it.

Boards in critical infrastructure are increasingly asking a question that sounds simple, responsible and necessary:

Are we secure?

It is an understandable question. It is also one that no organisation can answer with absolute certainty.

No organisation can mitigate every cyber risk. Even national defence organisations with significant resources are constantly adjusting their posture as threats, technologies and operating environments change. Managing cyber risk has never meant eliminating risk. It means understanding the impacts that could disrupt operations, deciding which risks should be mitigated, and consciously accepting those that remain.

That word, deciding, is central.

Leadership in operational cyber security is not about receiving reassurance that everything is under control. It is about seeing risks clearly, apportioning them honestly and understanding which decisions the organisation is prepared to stand behind.

In critical infrastructure, that matters because cyber risk is no longer only a technical issue. It is a question of operational resilience, service continuity, public trust and governance.

 

The floor is not the level

It is worth starting with what compliance actually provides.

Compliance frameworks establish a baseline. They define minimum expectations and help industries lift their collective standard of protection. They create consistency, support accountability and give organisations a common language for discussing controls and obligations.

Those things are valuable.

But compliance is not the same as resilience.

A compliance framework is, by design, a floor. It is a minimum level set for a broad group of organisations at a point in time. It cannot fully reflect the asset profile, threat exposure, operational dependencies, risk appetite or consequences of failure within a specific organisation.

The challenge emerges when the floor is mistaken for the level an organisation has chosen to hold.

A compliant organisation may still carry risks that are material to its operations. A resilient organisation understands those risks, has made deliberate decisions about them and has the capability to respond when controls are tested.

Resilience is the ability to continue operating and hold an acceptable level of service under pressure, whether that pressure comes from a sudden incident or a sustained campaign over time. No external framework can fully define that level on behalf of a board. It is a business and governance decision.

  • Where does the organisation need to stand?

  • What does it cost to stand there?

  • What risks will be reduced, transferred, monitored or accepted?

  • And who has the authority to make those decisions?

Compliance contributes to resilience, but it does not create it on its own.

Compliance is the floor someone else set. Resilience is the level an organisation chooses to hold under pressure. The gap between them is not only technical. It is a series of leadership decisions.

 

Nothing changed, and everything did

Operational cyber risk has always extended beyond IT because the consequences of failure are operational, physical and often public.

The assets that treat water, generate power, move trains and support industrial production have always needed protection. What has changed is the level of connectivity, the capability of adversaries and the extent to which cyber disruption can affect the services communities and economies rely on.

As industrial environments digitised, responsibility for cyber security often sat naturally with IT because IT held much of the organisation's technical capability. That made sense for many years.

Today, the picture is more complex.

Modern compute power, automation and AI-enabled capabilities are lowering the barriers to cyber intrusion.

Activities that once required significant expertise, patience and resources are becoming increasingly accessible. At the same time, operational environments have become more connected, more data-driven and more dependent on digital systems.

As the cost and complexity of attacking critical infrastructure changes, the question of who owns the risk becomes more than an organisational structure issue. It becomes a governance decision.

Regulators are moving in the same direction.

In Australia, the Security of Critical Infrastructure framework and associated risk management obligations continue to place greater emphasis on operational resilience, asset accountability and demonstrable risk management. The Australian Signals Directorate has also signalled a move from the Essential Eight toward a broader, domain-specific Essentials series, including guidance for operational technology.

Across other jurisdictions, similar themes are emerging. Boards, executives and asset owners are being asked to take a more active role in understanding cyber risk and ensuring organisations can demonstrate the effectiveness of their security posture. The direction is clear.

Accountability is moving upward to leadership and outward to the asset owner. Adequacy is becoming less about whether controls can be attested to, and more about whether a risk position can be understood, evidenced and defended.

Organisations do not need to wait for every framework or regulatory detail to be finalised before acting. The direction of travel is already visible. Those that prepare now will be better placed to adapt as expectations continue to mature.

 

There are no green dashboards

Most boards want the dashboard to be green.

That is understandable. Boards are asked to oversee risk across a wide range of complex areas, and clear reporting matters.

But in cyber security, especially in operational environments, an entirely green dashboard should prompt further questions.

 

engineer-looking-at-a-tablet-with-dashboard

There is no such thing as a risk-free critical infrastructure environment. There should be areas of strength, areas of progress and areas where risk is being actively managed. But if every indicator is green, the board may not be seeing the full picture.

What boards need is not reassurance for its own sake. They need visibility.

  • Clear sight of the organisation's actual exposure.

  • Clear sight of where controls are working.

  • Clear sight of where assumptions remain untested.

  • Clear sight of the actions being taken to close the gap between current state and desired resilience.

This can be difficult in cyber security because the discipline has an understandable instinct toward secrecy. Organisations are cautious about discussing vulnerabilities, weaknesses or potential attack paths. That caution is valid.

But boards cannot make good decisions without meaningful visibility.

The reporting challenge is to provide enough clarity for decision-making without creating unnecessary exposure. Strong cyber governance does not require every director to become a technical specialist. It does require boards to be given information they can use to understand risk, challenge assumptions and make informed decisions.

The request should not be:

“Tell us everything is okay.”

The request should not be:

“Show us the risk clearly enough that we can decide what to do about it.”

 

Four sectors, one pattern

Across water, energy, transport and resources, the operational realities differ. The leadership pattern is often similar.

  • The organisations that move beyond compliance tend to do three things well.

  • They build an evidence-based understanding of operational risk.

  • They invest according to consequence rather than audit findings alone.

  • And they place accountability for resilience with the people who own and operate the assets.

 

Water: 

 

Water

 

For water utilities, cyber security is closely tied to public health, service reliability and community confidence.

In one major water environment, the organisation had extensive compliance artefacts and established assurance processes. However, when the environment was examined through the lens of operational consequence, the picture became more nuanced.

The work focused on what genuinely depended on control systems and communications networks, where manual fallback existed, and what would happen to service delivery if visibility or control was degraded.

Some assumptions were validated. Others needed to be reconsidered.

The important lesson was not that compliance lacked value. It was that compliance alone could not demonstrate resilience. A deeper understanding emerged when risks were examined from the perspective of service delivery and operational consequence.

 

Energy: 

 

energy

 

Energy operators are managing a rapidly changing landscape. Renewable generation, battery storage and distributed assets are expanding the connected footprint of the sector, often faster than traditional governance models were designed to accommodate.

In one distributed generation environment, the organisation had assurance that specific controls existed, but less visibility of whether assets could withstand or respond to a modern threat scenario.

The shift was from periodic assurance toward more continuous evidence. This included improving detection across operating sites, aligning risk activity to sector-specific expectations and assessing capability in terms of operational effectiveness rather than reporting comfort.

The most useful outcome was not a single technology decision. It was a more defensible operational model that gave executives better evidence of risk, capability and exposure.

That evidence enabled more deliberate decisions about what to mitigate, what to monitor and what to accept.

 

Transport:

 

Transport

 

Major transport infrastructure depends on interconnected signalling, station systems, communications, building management and operational support technologies.

Historically, cyber security has sometimes entered the delivery process late, often at commissioning or after an asset has already gone live. At that point, remediation can be more expensive, more disruptive and harder to implement.

In one transport environment, cyber security requirements were carried through design, factory acceptance, site acceptance and commissioning. Monitoring was integrated into central security operations from the beginning.

The leadership lesson is economic as much as technical.

Security that is embedded during delivery can often be addressed through design and configuration decisions. Security added after commissioning may require outages, change boards, additional cost and operational disruption.

For boards, this reinforces the importance of seeing cyber security as part of asset delivery and lifecycle governance, not simply as a later-stage technology control.

 

Resources: 

 

Resources

 

Resources and mining operators often manage remote, distributed and ageing assets, with significant reliance on contractors, third parties and specialist vendors.

In this environment, remoteness can create a false sense of protection. Distributed assets may be physically distant, but they are often digitally connected through systems used for monitoring, maintenance, optimisation and support.

In one mining environment, the organisation needed to modernise and segment an OT network without interrupting continuous production. The work was staged carefully, with preparation, testing and validation completed before each production cutover.

Production continued throughout the program.

The key point is that the objective was not cyber risk reduction in the abstract. The objective was operational reliability, safety and business continuity, with security enabling those outcomes.

Across all four sectors, the pattern is consistent.

The artefacts matter. The controls matter. But the differentiator is evidence, ownership and the willingness to make decisions based on operational consequence.

 

Moving beyond reassurance

 

Boards receive a significant volume of information about cyber security: assessments, dashboards, maturity ratings, policies, controls, exceptions and audit findings.

The volume of information is not the same as clarity.

 

AdobeStock_208648754

Not all assessments are designed to answer the same question. Some are designed to demonstrate compliance. Others are designed to help organisations understand how a capable adversary might approach their environment and what practical actions should follow.

Both can be useful, but they serve different purposes.

For boards and executive teams, the important question is whether the advice being received improves understanding and supports better decisions.

  • Does it show what is known and what remains uncertain?

  • Does it identify the consequences that matter most?

  • Does it explain which assumptions have been tested?

  • Does it provide options that can be assessed, prioritised and funded?

  • And does it help the organisation decide what it will mitigate, what it will monitor and what it will accept?

This is the point at which cyber security becomes a leadership conversation.

The goal is not to avoid difficult information. The goal is to ensure the board has a clear enough view to govern effectively.

 

The decision you cannot delegate

Fiduciary duty in critical infrastructure extends beyond commercial performance. It also reaches the communities, customers and industries that rely on the services these organisations provide.

The people on the other end of the pipe, the wire, the track or the supply chain may never see the board papers. But they are affected by the decisions made in boardrooms, whether the full impact of those decisions is immediately visible or not.

That is why accountability matters.

A useful place to start is the risk register.

 

Cyber-security-risk-comprehension

Boards should have confidence that risks can be raised without fear, challenged constructively and closed only through an accountable decision-making process. Every organisation will carry risk. The important question is whether those risks are visible, understood and deliberately accepted by the right people.

If risks can disappear without clear ownership or documented rationale, the organisation loses an important part of its governance foundation.

A stronger approach is to ask:

  • Who can raise a risk?

  • Who can accept a risk?

  • Who can close a risk?

  • What evidence is required to support that decision?

  • How is accepted risk reviewed over time?

These questions cost nothing to ask, but they reveal a great deal about how risk is actually governed.

Then comes the harder question:

 

If our next audit, regulatory review or cyber incident began tomorrow, would we be relying on evidence or assumptions?

 

That question matters because leadership is not defined by the absence of risk. It is defined by the ability to understand risk, make deliberate decisions about it and accept accountability for those decisions.

In critical infrastructure, that responsibility cannot be delegated entirely to a framework, a dashboard, an adviser or a technical team.

Every organisation will carry risk.

The question is whether those risks are understood, owned and consciously accepted.

That is the risk you sign your name to.