Skip to content
Mining, oil & gas · Australia

When the network stops, the pit stops.

Coal and metal-ore mining, oil and gas extraction, and the support services around them run on converged IT and operational technology — and much of it now sits inside Australia's critical-infrastructure regime. A ransomware hit here doesn't just leak data. It halts production, by the hour, at a cost few other sectors face.

Dossier 10 / 10

Mining, Oil & Gas

Ransomware that stops extraction stops revenue by the hour — and IT/OT convergence hands an attacker a path from the office network straight to the pit.

  • Security of Critical Infrastructure Act 2018 (SOCI), where the asset/operator is covered
  • Operational-technology (OT/ICS) security
  • Incident reporting obligations where applicable
Named obligations

What the obligation actually requires of you.

  1. 01

    Security of Critical Infrastructure Act 2018 (SOCI), where the asset/operator is covered

    SOCI obligations depend on the asset class and the entity's role. Where a mining, energy or gas business is covered, it may need to identify assets, maintain a risk-management program and meet registration or reporting duties.

  2. 02

    Operational-technology (OT/ICS) security

    Operational technology — the SCADA, PLCs and control systems that run extraction and processing — was built for uptime, not for the internet it's now connected to. Securing the IT/OT boundary is the single most important control between an office phishing email and a stopped production line.

  3. 03

    Incident reporting obligations where applicable

    For a responsible entity or other covered participant whose critical-infrastructure asset is affected, a qualifying cyber incident carries mandatory reporting timeframes to the Australian Signals Directorate / ACSC. Meeting that clock under pressure requires a rehearsed process agreed long before the incident, not improvised on the day.

7

controls to review

Use this sector-specific set of practical prompts to identify owners, evidence and the next control to verify.

Illustrative scenario · Resources-support contractor, WA

An office breach approaching the control network.

Illustrative scenario — In this example, A contractor servicing a mine site was compromised through a phishing email on the corporate network. Because the corporate and operational networks shared flat, unsegmented infrastructure, the attacker was a single lateral move away from systems that touched site operations.

Example response — A suitable response is to isolate corporate access from OT, preserve evidence, confirm whether a regulated asset is affected and follow the applicable reporting plan.

What to verify — Confirm the relevant control is configured, tested and evidenced for this scenario; record the owner, review date and any exception before treating the risk as addressed.

Control evidence to collect

Configuration, test evidence, an accountable owner and a review date for the controls described in this scenario.

Illustrative scenario only. It is not a client case study, endorsement, zero-loss claim or proof of a security outcome.

The compliance checklist

Run it yourself, then see the priorities.

Review each practical control, assign an owner, and get an educational action list before you request a prepared follow-up.

These are practical control prompts, not a legal compliance determination. Exact obligations vary by entity, asset, contract and jurisdiction.

Mining, Energy & Resources Cybersecurity Checklist

0 / 7 reviewed0%

Corporate IT and operational technology (OT/ICS) segmented, with every crossing monitored

Verify the setting or process in your environment, record its accountable owner, and retain current evidence for review: Corporate IT and operational technology (OT/ICS) segmented, with every crossing monitored.

Your critical assets identified and a risk-management program maintained under SOCI

Verify the setting or process in your environment, record its accountable owner, and retain current evidence for review: Your critical assets identified and a risk-management program maintained under SOCI.

MFA enforced on remote access to both corporate and operational environments

Verify the setting or process in your environment, record its accountable owner, and retain current evidence for review: MFA enforced on remote access to both corporate and operational environments.

Where applicable, a rehearsed incident-response plan that meets ASD/ACSC mandatory reporting timeframes

Verify the setting or process in your environment, record its accountable owner, and retain current evidence for review: Where applicable, a rehearsed incident-response plan that meets ASD/ACSC mandatory reporting timeframes.

Tested, immutable, offline-capable backups for systems that keep the site running

Verify the setting or process in your environment, record its accountable owner, and retain current evidence for review: Tested, immutable, offline-capable backups for systems that keep the site running.

Third-party and contractor access to your network scoped, logged and time-limited

Verify the setting or process in your environment, record its accountable owner, and retain current evidence for review: Third-party and contractor access to your network scoped, logged and time-limited.

Staff and site crews trained to recognise phishing and supplier-impersonation attempts

Verify the setting or process in your environment, record its accountable owner, and retain current evidence for review: Staff and site crews trained to recognise phishing and supplier-impersonation attempts.

Complete each control to see your prioritised plan before submitting.

Request a prepared action plan

Share business details so GMAN IT can prepare a useful follow-up by email and with the team.

Optional business context

Your submitted details and checklist answers are shared with GMAN IT to prepare the plan and follow up. Read our Privacy Policy. If a delivery link is generated, it expires after 7 days.

Before you call us

The questions this vertical always asks.

Find out exactly where your operation’s IT/OT boundary is exposed.

The Cyber Readiness Assessment is the forensic starting point, backed by a 100% refund guarantee. Enquire for scope and terms.

Melbourne VIC · Australia · gmanit.com.au