Why critical infrastructure boards can no longer delegate cyber security, and what accountability actually looks like.
Most boards want a green dashboard.
It is an understandable thing to want. It is also a misunderstanding.
There is no such thing as a completely green dashboard in any organisation that operates real infrastructure, and there should not be. There should be a great deal of green. There should never be all of it. A board that is being shown all green is unlikely to be seeing the full picture.
The expectation that cyber risk can be reduced to a reassuring colour often sits behind some of the most difficult governance challenges facing critical infrastructure organisations today.
The role of a board is not to be reassured. It is to have sufficient visibility to:
Understand risk
Challenge assumptions
Make informed decisions
And oversee the actions required to strengthen resilience
It is tempting to describe operational cyber security as a new challenge. In reality, it is not.
Protecting the assets that produce water, energy and movement has always mattered. What has changed is the extent to which cyber risk now affects operational outcomes. As a result, responsibility can no longer sit solely within IT. It increasingly requires direct oversight from asset owners, operational leaders and boards.
Technology has altered the landscape significantly.
Greater computing power, increased connectivity and the rapid emergence of AI-enabled capabilities have lowered the barriers to conducting sophisticated cyber attacks. Activities that once required significant expertise, time and resources are becoming increasingly accessible to a wider range of threat actors.
As the barrier to entry falls, the question of ownership becomes more important. Cyber security is no longer simply an operational issue delegated to technical specialists. It has become a question of organisational accountability.
Part of the challenge is that operational technology and enterprise IT are fundamentally different environments.
Enterprise systems are typically designed to support productivity. They can often tolerate updates, outages and periodic change. Most of us have experienced an unexpected software update or a reboot in the middle of a busy day. Frustrating, certainly, but fairly inconsequential.
Operational technology operates under a different set of assumptions. Systems are frequently designed to run for long periods with minimal change. Communications may remain quiet for months because nothing has exceeded an operational threshold. Assets often evolve over decades, with layers of integrations, modifications and operational knowledge built into the environment over time.
When an IT system fails, you lose productivity. When an operational system fails, you can lose water, power or transport services.
In some environments, lives may be affected.That difference in consequence demands a different approach to governance.
Boards and executive teams are being asked to absorb a significant amount of change.
Availability, reliability and safety have traditionally been the dominant governance considerations within critical infrastructure. Today, cyber resilience sits alongside them as a fundamental component of organisational risk management.
The regulatory landscape reflects this shift.
In Australia, obligations introduced through the Security of Critical Infrastructure (SoCI) framework and Critical Infrastructure Risk Management Programs continue to elevate expectations around cyber governance and operational resilience.
At the same time, the Australian Signals Directorate has announced its intention to transition from the Essential Eight to a broader Essentials framework, including domain-specific guidance for operational technology and emerging technologies such as agentic AI.
Internationally, the direction is consistent. Regulators and governments are increasingly reinforcing the principle that cyber risk is not solely an IT responsibility. It is a business and operational risk that requires active oversight from leadership teams, asset owners and governing bodies.
The common theme across jurisdictions is clear.
Compliance is becoming less about demonstrating the existence of controls and more about understanding, owning and defending a risk position.
Accountability is moving upward through the organisation and outward to those responsible for critical assets and services.
As cyber security matures, it is important to distinguish between compliance and resilience.
Compliance provides a baseline. It establishes a minimum standard that organisations are expected to meet. It creates consistency, improves accountability and helps industries lift their overall security posture.
Those are valuable outcomes.
However, compliance was never intended to eliminate risk entirely.
No framework can do that because every organisation operates different assets, faces different threats and accepts different levels of operational risk.
The challenge arises when compliance becomes confused with resilience.
An organisation can satisfy a compliance requirement and still remain exposed to material operational risks. Equally, an organisation may exceed compliance expectations in some areas while continuing to manage known and accepted risks in others.
Resilience is different.
It reflects an organisation's ability to continue operating, respond effectively and recover from disruption while maintaining critical services.
Compliance is the floor. Resilience is the ability to keep operating when conditions become difficult.
The bridge between the two is not additional documentation. It is a clear understanding of risk, meaningful preparedness and well-defined accountability.
Boards receive a vast amount of information about cyber security.
Policies, procedures, frameworks, controls, maturity models and assessment reports all have a role to play. The challenge is identifying which information genuinely supports better decision-making.
Not all risk assessments deliver the same value.
Some provide a useful compliance snapshot. Others are designed to help organisations understand how a capable adversary might target their environment and what practical actions should follow.
Both approaches can be valuable, but they serve different purposes.
For boards, the more useful question is often not whether an assessment was completed, but whether the assessment provides meaningful insight into the organisation's actual exposure and the actions required to improve resilience.
The objective should not be reassurance.
The objective should be clarity.
That distinction matters because critical infrastructure organisations serve more than shareholders.
A board's fiduciary duty in critical infrastructure extends beyond commercial outcomes to the communities that rely on the services it provides.
The people who depend on water, power, transport and other essential services are ultimately affected by decisions made in boardrooms. That is why cyber security governance has become a leadership issue, not simply a technical one.
Across water, energy, transport and resources organisations, different operational realities create different risks. Yet the leadership challenge is remarkably consistent.
The strongest organisations are not necessarily the ones with the most technology. They are the organisations willing to seek clarity, challenge assumptions and make deliberate decisions about risk.
For water utilities, the challenge is often distinguishing between compliance and operational resilience.
In one example, an organisation had received positive assurance regarding its cyber posture for many years. When assessed through a more operational lens, the findings revealed a more complex picture. The issue was not non-compliance. The issue was that the organisation lacked sufficient visibility into how a determined adversary might exploit dependencies within the environment.
The leadership response proved more important than the finding itself. Rather than focusing on whether the organisation was compliant, attention shifted toward understanding which risks could be reduced, which could be monitored and which would ultimately need to be accepted.
The rapid expansion of renewable generation, battery storage and distributed energy resources has increased the digital footprint of many operators.
The governance challenge is ensuring cyber security is considered as part of the overall operating model rather than as a project requirement attached to individual investments.
Leading organisations are increasingly treating cyber resilience as a core business capability, alongside reliability and generation performance, rather than a technology cost to be managed in isolation.
Transport operators have undertaken significant digital transformation over the past decade. Telecommunications, connectivity, remote monitoring and integrated operational systems have altered how infrastructure is managed and maintained.
In some organisations, governance structures evolved more slowly than the technology itself.
Leadership often means recognising when risk has shifted. The assets may remain physical, but the consequences of a digital disruption can now be just as significant as a mechanical failure. Boards that acknowledge that change are generally better positioned to allocate resources and oversee risk effectively.
Mining and resource organisations frequently operate distributed assets across remote environments while relying on extensive contractor and third-party access.
The assumption that remoteness provides protection can be misleading.
Leading organisations focus on visibility, governance and consistent control across their asset base. Cyber security is treated as an enterprise risk requiring board-level oversight, rather than a series of isolated challenges managed independently at each site.
Boards often ask:
“Are we compliant?” or “Are we secure?”
Both are reasonable questions but not the most useful ones.
Instead, consider asking:
“If our next audit, regulatory review or major cyber incident started tomorrow, would we be relying on evidence or assumptions?“
That distinction matters.
Evidence enables informed decision-making, clear accountability and confident governance. Assumptions create blind spots.
The role of a board is not to eliminate every risk. No board can do that. Its role is to:
Understand the organisation's exposure
Determine which risks are acceptable
Ensure management is appropriately addressing those that are not
And establish confidence that critical controls and resilience measures will perform when required
There may never be a completely green dashboard.
But there should always be a clear view of reality.
And in critical infrastructure, that visibility may be one of the most important responsibilities a board has.