Skip to main content
Regulation 10 min read

What Your TSRMP Needs to Contain for Telco Assets

Telecommunications assets have specific requirements under the SOCI Act TSRMP framework. What the risk management program needs to cover and where most entities leave gaps.

Darragh Downey

Principal Consultant, O/IT Cyber


The Telecommunications Security and Risk Management Program Rules 2025 created a specialised set of obligations for responsible entities operating critical telecommunications assets. These rules largely mirror the Critical Infrastructure Risk Management Program (CIRMP) Rules but add requirements that reflect the unique risk profile of telecommunications infrastructure. If you are building or revising your RMP for a telecommunications asset, here is what it needs to contain and where the common gaps are.

Who the TSRMP Rules apply to

The obligations apply to two categories of asset. Carrier assets are telecommunications infrastructure owned or operated by a carrier. Relevant carriage service provider assets are those that meet the prescribed threshold of 20,000 active carriage services or supply services to the Commonwealth.

If your asset falls below these thresholds, the TSRMP Rules do not apply, though other SOCI obligations still do. If your asset meets these thresholds, you need a Risk Management Program that satisfies the TSRMP Rules specifically, not just the general CIRMP Rules. The TSRMP Rules introduce higher standards, and satisfying only the CIRMP is not sufficient for telecommunications assets.

There is an important nuance for entities that operate assets across multiple classes. If you are a rail operating entity that also provides telecommunications services, you can have one RMP for all assets, provided it meets the TSRMP Rules requirements for the telecommunications components. Alternatively, you can maintain separate RMPs: one under the CIRMP for transport and one under the TSRMP Rules for telecommunications. Either approach is acceptable.

The structural requirements

Section 9 of the TSRMP Rules requires that the RMP establish a process or system to accomplish several things.

Identify the operational context of the asset. This means documenting what the asset is, how it operates, what services it provides, and how it fits within the broader telecommunications ecosystem. For a telecommunications carrier, this includes the network architecture, the geographic footprint, the customer base, and the interdependencies with other carriers and service providers.

Identify material risks. The RMP must identify each hazard where there is a material risk of a relevant impact on the asset. This is not a one-time exercise. The process must be ongoing, and it must cover all five hazard vectors defined in Section 4 of the TSRMP Rules: cyber and information security, personnel, physical security, natural hazards, and supply chain.

Minimise or eliminate material risks. As far as is reasonably practicable, the RMP must establish processes to prevent hazards from occurring. This includes both proactive risk management and processes to detect and respond to threats as they are being realised.

Mitigate relevant impacts. The RMP must also establish processes to mitigate the impact of hazards that do materialise. Mitigation activities must be based on documented processes that can be activated as required. This is not about having a theoretical response plan. It is about having a documented, tested capability to manage the consequences of an incident.

Describe interdependencies. Section 10(b) of the TSRMP Rules requires that the RMP outline how the entity’s critical infrastructure assets interact or intersect with assets owned or operated by other responsible entities. For telecommunications, this is particularly important. Networks are highly interdependent. If your backbone capacity depends on another carrier’s infrastructure, that dependency is a material risk that needs to be documented and managed.

Review and update mechanisms. The RMP must include processes for regular review and for keeping the program current. This is not a suggestion. Sections 30AE and 30AF of the SOCI Act make maintenance and review a legal obligation.

The five hazard vectors for telecommunications

Each hazard vector has specific implications for telecommunications assets.

Cyber and information security. Section 11 of the TSRMP Rules adds the cyber security framework compliance requirement. You must comply with one of the listed frameworks (or an equivalent) and meet the maturity level deadlines. For telecommunications, common cyber hazards include phishing, malware, credential harvesting, and denial-of-service attacks. But the RMP should also consider hazards specific to telecommunications: signalling protocol exploitation, BGP hijacking, SS7 vulnerabilities, and attacks against the control and management plane of network infrastructure.

Your RMP needs to describe the specific cyber and information security hazards relevant to your asset, not generic hazards copied from a template. If your network runs MPLS across 50 points of presence and the control plane of those devices is your crown jewel, the RMP should say so and describe the specific risks to that environment.

Personnel. For telecommunications entities with small operational teams, personnel hazards are significant. If your team has 30 people, a shallow management structure, and one or two individuals who hold the majority of critical system knowledge, the loss or compromise of those individuals is a material risk. The RMP should identify key person dependencies and document how the entity would maintain operational capability if those individuals were unavailable.

Physical security. Telecommunications assets are geographically distributed. Transmission towers, points of interconnect, data centres, and field equipment all require physical security that is commensurate with their criticality. The TSRMP Rules require that you identify the physical critical components of the asset, control access to those components, and test the effectiveness of your security arrangements.

Natural hazards. If your network runs along the eastern seaboard of Australia, you face cyclones, flooding, storms, and bushfire. The RMP should identify which natural hazards are relevant to your geographic footprint and describe how you would maintain or restore service in each scenario. This is not hypothetical. Major weather events disrupt telecommunications infrastructure with predictable regularity.

Supply chain. Telecommunications equipment supply chains are global and concentrated. If your network relies on equipment from a single vendor, or if replacement parts for critical infrastructure have extended lead times, those dependencies are material supply chain risks. The RMP should identify critical suppliers, assess the impact of supply chain disruption, and document any over-reliance on particular vendors.

The annual report

The annual report under Section 30AG of the SOCI Act must be submitted within 90 days after the end of the relevant Australian financial year, through the CISC website. It must be approved by the entity’s board, council, or other governing body.

This board approval requirement creates a practical challenge for entities where the operational subsidiary is several layers removed from the group board. The board needs to understand what it is approving: the state of the RMP, the entity’s risk posture, progress against maturity targets, and any material gaps that remain. This is not a rubber-stamp exercise. A board that attests to compliance without understanding the substance is taking on personal liability.

The CISC does not require you to submit the RMP itself with the annual report. However, they may request and review your RMP as part of a compliance audit. Build your RMP on the assumption that someone will read it critically, because eventually someone will.

Common gaps

The most consistent gaps I see in telecommunications RMPs are interdependency documentation (entities describe their own systems but not how those systems depend on other carriers), personnel hazard assessment (the cyber section is detailed but the people section is a paragraph), and the gap between enterprise-level controls and asset-level application (the group has the capability, but it has not been deployed to the specific telecommunications environment).

Build your RMP around your actual operating environment, not around a generic template. Document what is real, not what you wish were true. And ensure the people who operate the asset every day have read it and can tell you what it says.


Darragh Downey is the principal consultant at O/IT Cyber, specialising in SOCI Act compliance for telecommunications and critical infrastructure operators across Australia.

Share LinkedIn Email