Learn how to assess, benchmark, and strengthen the maturity of the security effect of your CIRMP.
Summary
This workshop helps critical infrastructure entities assess, benchmark, and strengthen the maturity of the security effect of their Critical Infrastructure Risk Management Program (CIRMP) in line with the Security of Critical Infrastructure Act 2018. Learn how to evaluate your organisation’s protective security capabilities, identify areas for improvement, and demonstrate defensible, evidence-based assurance to Boards and regulators of the effort made to improve protective security performance viewed through the CIRMP.
Event description
A mature Critical Infrastructure Risk Management Program does not just exist — it evolves.
Under the Security of Critical Infrastructure Act 2018 (SOCI Act) and its subordinate Rules, responsible entities must ensure their protective security arrangements are both effective and defensible. This workshop introduces a structured approach to measuring and improving CIRMP maturity, providing Boards and executives with a transparent, evidence-based understanding of how well their organisation’s security controls align with regulatory obligations, and guiding decision-making about future investment in response to evolving threats.
Drawing on Pentagram Advisory’s tailored CIRMP Security Maturity Assessment and Evaluation Model, this session will guide participants through the principles of assessing current state, identifying gaps, prioritising uplift, and demonstrating compliance through measurable outcomes.
What you will learn
• The purpose and value of a security maturity model for CIRMP assessment
• How to evaluate organisational maturity across key protective security domains
• How CIRMP maturity levels link to compliance with the SOCI Act and subordinate Rules
• Approaches for benchmarking, setting improvement goals, and tracking progress
• How to communicate maturity results effectively to Boards and regulators
• How to embed continuous improvement and business-as-usual resilience practices
Key takeaway
By the end of the session, participants will understand how to assess and determine how best to improve their CIRMP maturity in a structured, repeatable, and transparent way. The framework supports critical infrastructure entities in meeting regulatory expectations, building stakeholder confidence, and driving continuous improvement across governance, assurance, and protective security functions. This approach informs CIRMP-aligned investment planning.
To register for this event - click here.