Skip to content
CAPA Intelligence

Book a briefing

A 45 min briefing with our team: first a briefing on where Australian cyber and risk policy, threat and compliance are heading, then a walkthrough of how CAPA addresses it. You should leave with something useful, regardless of whether you ever buy from us.


Request a briefing

The shape of it

  • Around 45 mins, online or in person, with experienced practitioners in the electricity and cyber sectors
  • Part one — the Australian cyber and risk picture, tailored to electricity sector asset types
  • Part two — a walkthrough of the CAPA solutions against the obligations that apply to you
  • Briefing notes and source material sent afterwards, yours to circulate internally

Part one

The Australian cyber and risk briefing

A read on where policy, adversaries and obligations are moving in Australia, drawn from the work we do across wind, solar, storage, T&D networks and adjacent critical infrastructure.

Policy and posture

Where the regulator’s expectations have shifted

  • SOCI Act direction of travel and what the consultation signals
  • What “uplift” now means in practice for boards and accountable executives
  • How Australian posture compares with the operators we work with offshore

Emerging threats

What we are actually seeing, and what it implies

  • State-linked activity against grid and DER infrastructure, with demonstrated TTPs
  • Supply chain and vendor-of-concern exposure in inverters, controllers and cloud
  • AI-accelerated intrusion tradecraft and what it changes for defenders

Incoming compliance

What lands next, and when you need to be ready

  • Enhanced CIRMP obligations and the evidence they expect you to hold
  • AESCSF, ISO 27001 and IEC 62443 — where they overlap and where they don’t
  • Realistic sequencing for the next twelve months

Part two

A walkthrough of the CAPA solutions

Here we take a solutions based approach: how we close compliance gaps across three streams, tailoring to your own architecture and obligations, and reducing ongoing complexity and costs.

Secure by Design

  • Security requirements set at project inception, carried through procurement and commissioning
  • Vendor and product assurance before the asset is on the network

Secure by Design →

Risk & Compliance

  • One site record carrying risk, controls and evidence through to reporting
  • Mapping to SOCI, CIRMP and the frameworks you already report against

Risk & Compliance →

Security Operations

  • Detection and response built for fleets of small assets, not single large plants
  • Protocol monitoring, inventory and threat intelligence across DER and OT

Security Operations →


No pitch, no obligation

Take the briefing purely as an opportunity to learn about important changes in the space, and the types of solutions that are available now and in the near future that can ease the burden of from increased risk and regulation.

Request a briefing