TL;DR: Australia’s updated SOCI rules now require phishing-resistant authentication, least privilege, and access review capability that continues to work for up to 90 days in isolated critical infrastructure environments, according to RSA Security’s analysis. The governance shift is bigger than MFA selection: cloud-only identity assumptions no longer satisfy resilience, recovery, or audit expectations.
NHIMG editorial — based on content published by RSA Security: Multi-Factor Authentication Addressing SOCI 8B and 8C Obligations for Critical Infrastructure
By the numbers:
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities , 46% confirmed, 26% suspected.
Questions worth separating out
Q: What breaks when cloud-only MFA is used for isolated critical infrastructure?
A: Cloud-only MFA breaks the continuity of identity assurance when the environment is disconnected.
Q: Why does SOCI 8C make least privilege a recovery issue?
A: Because lateral movement risk rises during isolation and rebuild, when privileged access can expand the blast radius of compromise.
Q: How can security teams tell whether their phishing-resistant MFA model is actually compliant?
A: They need to test whether the authenticators, directories, and policy services remain available without external cloud access and still support the required user and admin flows.
Practitioner guidance
- Map every authentication dependency to isolation behaviour Document whether MFA, directory, and governance services still operate when cloud connectivity is removed for up to 90 days.
- Re-test phishing-resistant MFA against OT recovery conditions Validate that phishing-resistant authentication works for privileged, unprivileged, and remote access paths when critical infrastructure is segmented or air-gapped.
- Rebuild access review for lateral movement resistance Tie access certification to the accounts that can reach critical systems during restoration.
What's in the full article
RSA Security's full post covers the operational detail this post intentionally leaves for the source:
- The clause-by-clause mapping of SOCI 8B and 8C obligations to identity and governance controls.
- The specific deployment model for phishing-resistant MFA in on-premises, air-gapped, and semi air-gapped environments.
- The access review and least-privilege implications for critical systems during recovery and isolation.
- The practical rationale behind hybrid failover for maintaining authentication during cloud outages.
👉 Read RSA Security’s analysis of SOCI 8B and 8C identity obligations for critical infrastructure →
SOCI 8B and 8C: is your MFA model ready for isolation?
Explore further
Identity controls designed for connected environments fail when regulation assumes isolation. SOCI 8B and 8C make a simple point that many IAM programmes have avoided: authentication is not complete unless it survives the disconnected state. The governance assumption that cloud services are always available is no longer acceptable in high-risk critical infrastructure. Practitioners should treat survivable identity control as a design constraint, not an exception path.
A few things that frame the scale:
- 85% of organisations lack full visibility into third-party vendors connected via OAuth apps, according to The State of Non-Human Identity Security.
- 72% of organisations have experienced or suspect they have experienced a breach of non-human identities, according to The 2024 ESG Report: Managing Non-Human Identities.
A question worth separating out:
A: Authentication continuity, least privilege, and access review matter most because recovery is when identity weaknesses become operationally visible. Teams need controls that keep users authenticated, restrict lateral movement, and prove entitlement scope while rebuild work is underway. That is the governance model SOCI is pushing toward.
👉 Read our full editorial: SOCI 8B and 8C turn MFA into an isolation requirement