Energy sector cyber security advisory helps electricity, gas and liquid fuel organisations understand their cyber maturity, meet the Australian Energy Sector Cyber Security Framework (AESCSF) and SOCI Act obligations, and protect the operational technology that keeps the lights on. Security Solution Consultants (SSC) works with energy utilities, generators, network operators, retailers and distributed energy providers across Australia and New Zealand, from AESCSF self-assessments to SCADA and OT security reviews.

Smart grids, distributed energy resources, electric vehicle charging and digital substations are changing how energy is generated and delivered. Every new connection brings efficiency and flexibility, and also new paths for attackers into systems that were never designed to be online. Our job is to help you modernise without increasing systemic risk.
The AESCSF is the energy sector’s cyber security maturity framework, developed with industry and government and run with the Australian Energy Market Operator (AEMO). Version 2, released in 2023, aligned the framework with the US Cybersecurity Capability Maturity Model (C2M2) version 2.1, added a cyber security architecture domain and refreshed third-party risk management.
| Concept | What it means |
|---|---|
| Domains | Eleven domains covering areas such as asset, change and configuration management; threat and vulnerability management; risk; identity and access; situational awareness; incident response and continuity; third-party risk; workforce; architecture; program management; and Australian privacy management. |
| Maturity Indicator Levels (MIL) | Each practice sits at a maturity level, from MIL-1 (initiated) through MIL-2 (performed) to MIL-3 (managed), building on the level below. |
| Security Profiles (SP-1 to SP-3) | Target states that bundle practices into a single goal matched to an organisation’s criticality. Higher criticality means a higher target profile. |
| Criticality assessment | Determines which Security Profile applies, based on the organisation’s role and impact in the energy system. |
| AESCSF Lite | A simplified version for smaller and lower-criticality participants, including distributed and consumer energy resource providers. |
We help you confirm your criticality and target profile, assess each practice with evidence, identify the anti-patterns that hold back maturity, and turn results into a roadmap your board can track. Read our AESCSF compliance guide for Australian energy firms for more detail.
Electricity, gas and liquid fuel assets are among the critical infrastructure asset classes covered by the Security of Critical Infrastructure Act 2018. Depending on the asset, responsible entities may need to:
As SOCI compliance consultants, we link your AESCSF assessment and CIRMP so one body of evidence supports both. See also our enterprise risk management and CIRMP advisory and CIRMP enhancements article.

Operational technology protects physical processes, so availability and safety come first and change has to be managed carefully. Our OT assessments are designed for that reality. We review documentation and architecture, interview engineers and operators, and use passive techniques where possible rather than active scanning of live control systems.
Findings are mapped to ISA/IEC 62443, AESCSF practices and your CIRMP, so each recommendation shows which obligation it supports. Our industrial cyber security article explains why uptime alone is no longer the measure of resilience.

Visibility is the foundation of resilience. We help energy organisations plan OT-aware monitoring, integrate OT security events with the enterprise security operations centre, centralise log management and align threat intelligence with sector-specific threats, so unusual activity in control environments is seen and acted on quickly.
Credential misuse and insecure remote access remain among the most common ways into operational environments. We review role-based access, privileged access management, vendor accounts, multi-factor authentication and access reviews across substations, control rooms and enterprise systems. See our identity and access management advisory.
As Australia and New Zealand add rooftop solar, community batteries, grid-scale storage, electric vehicle charging and smart meters, more control decisions are made by software, often through third-party platforms and cloud services. That creates new dependencies: aggregators that can switch thousands of devices at once, vendors with remote access to many sites, and data flows between market systems and field equipment. We help organisations assess these new dependencies, set security requirements in contracts and designs, and extend their AESCSF and CIRMP coverage to new assets before they go live rather than after.
An AESCSF assessment is a snapshot; sustained maturity needs structure. GRCLens, the GRC platform built by SSC, tracks Maturity Indicator Levels by practice, Security Profile progress, control gaps, evidence and remediation actions, links them to your CIRMP risk register, and produces executive dashboards for the board. Your IEC 62443 program can run alongside it.
Related services: cyber security maturity assessment, incident response and recovery and certification and accreditation. To discuss an AESCSF assessment, contact our energy team.
The Australian Energy Sector Cyber Security Framework is the energy sector's cyber security maturity framework, run with AEMO. It assesses practices across eleven domains by Maturity Indicator Level and compares results with a target Security Profile based on the organisation's criticality.
Version 2, released in 2023, aligned the framework with C2M2 version 2.1, added a cyber security architecture domain, refreshed third-party risk management and expanded coverage across electricity, gas and liquid fuels.
SP-1, SP-2 and SP-3 are target maturity states. Each bundles a set of practices at specific Maturity Indicator Levels. Organisations with higher criticality are expected to reach a higher profile.
The CIRMP rules require responsible entities to comply with a recognised cyber security framework, and the AESCSF at the relevant profile is one of the recognised options. Other options include the Essential Eight, ISO/IEC 27001 and the NIST Cybersecurity Framework.
Within 90 days of the end of the Australian financial year, which is 28 September for a year ending 30 June. The report must be approved by the entity's board, council or other governing body.
Only when it is safe and agreed with your engineers. Our OT assessments rely mainly on documentation, architecture review, interviews and passive analysis, because availability and safety come first in operational environments.

Secure your cloud environments & ensure safe migration with compliance-ready.
Stay informe with the latest cybersecurity news, expert tips.
Copyright © 2026 All Rights Reserved.