<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
  xmlns:atom="http://www.w3.org/2005/Atom"
  xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd"
  xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>The Critical Path</title>
    <link>https://insights.ot-it-cyber.com/</link>
    <description>Practical OT/IT cyber security guidance for critical infrastructure operators in Australia.</description>
    <language>en-au</language>
    <!-- Not canonicalPageUrl: /feed.xml is an endpoint served as a file, and
         /feed.xml/ 404s. The self-reference must be the unslashed form. -->
    <atom:link href="https://insights.ot-it-cyber.com/feed.xml" rel="self" type="application/rss+xml" />

    <item>
      <title>Essentials for Operational Technology: What We Know, and Why It Matters</title>
      <link>https://insights.ot-it-cyber.com/blog/essentials-for-operational-technology/</link>
      <guid isPermaLink="true">https://insights.ot-it-cyber.com/blog/essentials-for-operational-technology/</guid>
      <pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate>
      <description>ASD is replacing the Essential Eight with a domain-split Essentials series, and one chapter is written for operational technology. No draft exists yet. What is confirmed, what is not, why an outcomes-based model fits OT better than a maturity ladder, and what to do before it lands.</description>
    </item>

    <item>
      <title>The Essential Eight Is Being Retired: What It Means for Your CIRMP Nomination</title>
      <link>https://insights.ot-it-cyber.com/blog/essential-eight-retirement-cirmp/</link>
      <guid isPermaLink="true">https://insights.ot-it-cyber.com/blog/essential-eight-retirement-cirmp/</guid>
      <pubDate>Sat, 08 Aug 2026 00:00:00 GMT</pubDate>
      <description>ASD will retire the Essential Eight within about two years, replacing it with a domain-split Essentials series that includes an operational technology chapter. The Enhanced CIRMP Rules give you until June 2028 to comply with a nominated framework. Those two clocks overlap, and it changes what you should nominate.</description>
    </item>

    <item>
      <title>What Your TSRMP Needs to Contain for Telco Assets</title>
      <link>https://insights.ot-it-cyber.com/blog/tsrmp-telco-assets/</link>
      <guid isPermaLink="true">https://insights.ot-it-cyber.com/blog/tsrmp-telco-assets/</guid>
      <pubDate>Wed, 24 Jun 2026 00:00:00 GMT</pubDate>
      <description>Telecommunications assets have specific requirements under the SOCI Act TSRMP framework. What the risk management program needs to cover and where most entities leave gaps.</description>
    </item>

    <item>
      <title>Three Things Called &quot;Enhanced&quot; in Your SOCI Obligations</title>
      <link>https://insights.ot-it-cyber.com/blog/positive-obligation-vs-enhanced/</link>
      <guid isPermaLink="true">https://insights.ot-it-cyber.com/blog/positive-obligation-vs-enhanced/</guid>
      <pubDate>Wed, 13 May 2026 00:00:00 GMT</pubDate>
      <description>The regime now has three obligation layers and two of them are called enhanced. They apply to different populations, are triggered differently, and demand different things. Which ones you can look up today, and which one arrives privately.</description>
    </item>

    <item>
      <title>AESCSF Security Profile 2: What the Enhanced CIRMP Rules Now Require</title>
      <link>https://insights.ot-it-cyber.com/blog/aescsf-sp2-requirements/</link>
      <guid isPermaLink="true">https://insights.ot-it-cyber.com/blog/aescsf-sp2-requirements/</guid>
      <pubDate>Wed, 29 Apr 2026 00:00:00 GMT</pubDate>
      <description>The AESCSF has two scales and people mix them up. Maturity Indicator Levels measure where you are; Security Profiles say where you must be. The Enhanced CIRMP Rules move named energy asset classes to SP-2 by June 2028, and cumulative profiles make that further than it looks.</description>
    </item>
  </channel>
</rss>