Cyber Security Services You’ve Never Thought to Commission

polygon-right

You wouldn't commit capital to unassessed ground. That's not how this industry works. 

Before the first dollar goes in, you want a feasibility study. You want to know what's actually there, what the risk looks like, what you're working with. That discipline is so fundamental to how mining and energy businesses operate that it barely gets said out loud anymore. 

I find it interesting, then, that the same attention rarely gets applied to cyber security. 

The controls do exist. There's a firewall, some software on the laptops, something keeping an eye on the network. But if I ask you whether that covers the systems actually running your operation, then your answer gets less certain.  

If I ask when any of it was last properly assessed against the current shape of your business, the answer is usually never, or not recently enough to matter. 

You're running a business where a cyber attack doesn't just mean a data breach or a week of IT headaches. It can mean production stops. It can mean the systems controlling your plant behave in ways nobody intended. It can mean you're sitting on regulatory obligations you didn't know about and haven't met. 

Most cyber security was built for offices. Yours wasn't built for that, and that's one thing worth fixing. 

Aerial view of open cut mine representing risk assessment in Australian resources operations.

What Cyber Security Does My Mining or Energy Business Actually Need Covered? 

The cyber security solutions a resources business actually needs cover two environments. Most operations I walk into have only properly looked at one of them. 

The first is your corporate IT network. The laptops, the email systems, the software your finance and admin teams use. This is the environment most cyber security is designed for. Firewalls, software that watches for threats on devices, controls around who can access what, a process for what happens if something goes wrong. These matter and they should be in place. 

The second is your operational technology. The systems that actually run the physical side of your business. The controls managing your plant. The monitoring is telling you what's happening across your sites. The equipment your operation depends on to keep producing. 

These two environments are increasingly connected. Data flows from the operational side into the corporate side for reporting, planning, and maintenance. That connection is useful. It's also where most resource businesses have a gap they haven't formally looked at.

Getting both environments assessed and understanding exactly where they touch each other is the difference between cyber security that covers your business and cyber security that covers your office. 

Why Doesn't My IT Security Cover My Operational Technology? 

Because they were built for completely different jobs. 

Your corporate IT security is built around protecting information. Locking things down, controlling access, containing anything that gets through. 

Your operational technology is built around keeping things running. These systems often can't tolerate the same interventions. A patch applied at the wrong time can stop production entirely. 

Here's the part that catches most operations out. 

A lot of this equipment was installed before anyone was thinking about cyber security. It was never designed to connect to anything external. It's connecting now, because your business needs the data it generates. That happened gradually, site by site, as the business modernised. 

Nobody went back and assessed what that meant. 

What If Your IT Review Missed Half the Operation? 

I've seen this more than once. A gas operation, three remote sites, corporate network recently reviewed and signed off. 

 The IT side was genuinely well managed. When I asked about the operational systems, the plant controls, the remote monitoring, the infrastructure that had been quietly connecting to the corporate network over two years, the answer was that they weren't in scope for the review. 

Nobody decided to leave them out on purpose. They just weren't part of the conversation. Twelve months later, a formal review found an exposure that had been sitting there since the digital integration was completed. 

For a clearer picture of how we approach both sides of this for resource businesses, our cyber security services cover the details. 

What Compliance Obligations Is My Business Actually Sitting On? 

More than most CFOs in this sector realise. And the gap between what applies and what people think applies has grown considerably in the last couple of years. 

If your operation owns or operates infrastructure that the Australian Government classifies as critical, you're carrying formal obligations under the Security of Critical Infrastructure Act 2018. A documented risk management program, board-approved, reported annually. Significant incidents reported to the Australian Cyber Security Centre within 12 hours. 

That's not a soft obligation. 

The Cyber Security Act 2024 added mandatory reporting of ransomware payments within 72 hours for any business turning over more than $3 million a year. That pulls in most of the resources sector. 

I'd say half the CFOs I speak to haven't had that conversation with their legal team yet. 

The compliance picture has shifted. Most businesses in this sector are sitting on obligations they haven't fully mapped. That's a board-level exposure, not just an IT problem. 

Are My Remote Sites as Secure as My Head Office Thinks They Are? 

The assumption that remote sites are lower risk made sense when they were genuinely cut off. That was a reasonable picture fifteen years ago. 

It's not the picture now. 

Most remote sites are connected to corporate systems for reporting, maintenance, and monitoring. That connectivity is what makes them manageable from a distance. It also makes them part of your network. 

What I find on remote sites is a device problem that's quietly grown out of control. Laptops belonging to contractors, personal phones, gear from a dozen different vendors, all connecting to site networks and nobody's got a handle on what's coming in. No IT person on the ground four hours from the nearest regional centre checking what's plugging in. 

You have to know what's connecting to what before you can secure it. The same thing you'd do before committing capital to anything else.

Cyber Security Services device problem quietly growing out of control.

How Do I Know If My Cyber Security Was Built for the Business I'm Running Now? 

Ask yourself when your cyber security strategy was last properly reviewed. Not tweaked. Properly reviewed against the current shape of your operation. 

If the answer is more than two or three years ago, it probably wasn't built for the business you're running now. Sites added, systems connected, the operation has grown. The security hasn't kept pace. 

Absence of incidents isn't evidence that you're covered. 

It might mean the controls are working. It might mean you haven't been targeted yet. It might mean something is sitting in your environment right now that nobody's found. 

The feasibility study that worked for the original pit doesn't automatically cover the expansion. Nobody commissions a new one. They just assume it still applies. 

What Are the Signs I've Outgrown My Current Cyber Security Setup? 

A few things I see consistently.  

  • The operational systems have never had a formal security review. The IT side has controls, someone can point to them. But nobody's mapped what's running on the operational side or how it connects to the broader network. That's unassessed ground. 
  • Contractor device management has quietly got away from people. No clear picture of what's connecting to site networks, who approved their access, or what those devices are carrying with them. 
  • The security setup reflects a version of the business that no longer exists. The operation has moved on. The architecture was done once and assumed to still apply. 

Any of those land? 

The starting point is the same in every case. Do the assessment. Know what ground you're standing on before you decide what to do about it. 

Summary 

A mining or energy business wouldn't sink capital into ground that hasn't been assessed. 

The same logic applies here. And the businesses that treat it that way are the ones that don't get caught out. 

Your operational systems carry a different risk profile from your office network. The compliance obligations are real and getting more specific. Your remote sites are connected in ways that may not have been assessed. And the cyber security you have was probably designed for a smaller, simpler version of this operation. 

The businesses managing this well have done the work. They know what they're standing on. 

That's where it starts. 

If you'd like to understand what that looks like for a resources business, take a look at our cyber security services. 

Send us a message!

Fill out the form below and we will be in contact with you within 24 hours.

This field is for validation purposes and should be left unchanged.
Name(Required)
Type of enquiry*(Required)
Subscribe
Support

Chat with our team

Want to learn more about what we offer and how we can help? Fill out the form below and our friendly team will get back to you and give you a buzz!

If you're an existing client in need of support, please head to the contact us page.

This field is for validation purposes and should be left unchanged.
Name(Required)
Subscribe