Sector Deep Dive · 8 October 2026

The obligation nobody is recruiting for.

Every generator, network and water utility in the country now carries a cyber risk management obligation. The engineering and the security worlds each assume the other has it covered. Neither does.

What the obligation actually is.

Australia's Security of Critical Infrastructure Act places mandatory risk management and reporting duties on responsible entities across eleven sectors, including energy, water and sewerage, transport, communications and data storage. In practice that means a documented critical infrastructure risk management program covering cyber and information security, personnel, supply chain and physical hazards, reviewed and reported on annually.

Incident reporting is tight. A significant cyber incident has to be reported within twelve hours, other reportable incidents within seventy two. Assets designated as systems of national significance carry further enhanced obligations on top.

None of that is new law. What is new is that the first full cycles of assessment have now run, boards have seen the gaps, and the remediation work has landed on operational teams that were not built to carry it.

Why operational technology is the hard part.

Corporate IT security is a mature discipline with a deep talent pool. Operational technology is not. OT is the SCADA, the protection relays, the plant control systems, the RTUs and the historians. It is the layer that actually moves electrons and water.

Securing it is a different job, and the differences are what make the hiring so hard.

  • You cannot patch on a Tuesday. Availability outranks confidentiality. A maintenance window on a generating asset may come twice a year, and the security plan has to live inside that reality.
  • The equipment is old and proprietary. Protection and control kit in service today may predate modern network security entirely. The work is compensating controls and segmentation, not patch management.
  • Getting it wrong trips plant. An aggressive scan on an OT network can take an asset offline. That consequence makes owners slow to hire anyone without operational credibility.
  • The reporting clock is operational. Twelve hours means the people who notice an incident are the control room and the field, not a corporate security operations centre watching a dashboard.

The candidate pool, honestly described.

The role needs someone who understands both a firewall rule and a protection scheme. Almost nobody is trained into that combination. They arrive from one of two directions, and each comes with a predictable gap.

From the engineering side. Control systems, protection and SCADA engineers who have picked up security through compliance work. They have the operational credibility and the plant knowledge. They usually need formal security depth: threat modelling, detection, incident response discipline. In our experience this is the easier gap to close, and it is the group most owners overlook.

From the security side. IT security specialists moving into OT. They bring the frameworks and the detection skills. What they often lack is any instinct for why an engineer will refuse a change, and that instinct is the difference between a program that lands and one that is quietly ignored. Candidates who have done a genuine OT deployment are rare and priced accordingly.

The third source is the one nobody likes to talk about: this capability can be bought as a managed service, and many owners do, because the market cannot supply enough permanent people. That works for monitoring. It does not work for the parts of the obligation that require someone accountable inside the business.

What good resourcing looks like.

From what we see across generators, networks and water utilities, the structures that work share a few features.

  1. The role reports into operations, not only into IT. Where OT security sits purely under a corporate CISO with no operational line, change requests stall and the program stays on paper.
  2. One accountable permanent hire, supported by specialists. The risk program, the regulator relationship and the internal credibility need a permanent owner. Assessments, architecture reviews and uplift projects run well on contract.
  3. Engineers trained into security, not the reverse. The owners filling these roles fastest are promoting control systems engineers and funding the security training, rather than waiting for a unicorn to appear on the market.
  4. The field is part of the plan. Technicians and operators are the detection layer for an obligation measured in hours. Their training is part of the compliance position, not an afterthought.

Why we are writing about this.

Because it is the clearest example we see of a regulatory obligation arriving years ahead of the workforce to meet it, and because almost nobody is recruiting for it deliberately. Roles get written as IT security roles, advertised to an IT audience, and then sit open for six months while the asset carries the risk.

For candidates, the message is more positive. If you are a control systems, protection or SCADA engineer, this is the most valuable adjacent skill you can add right now, and the market will pay for it well before you consider yourself an expert.

For owners, the honest position is that you will not hire your way out of this quickly. Plan on building it.


← All insights
Get in touch Salary report

Hiring into OT or control systems?

Control systems, protection, SCADA and operational technology security across Australian energy, water and infrastructure. Talk to us about what is genuinely available.

Book a briefing call →