Photo: Origin EnergyOrigin Energy executives argued against tougher new cybersecurity obligations earlier this year, labelling proposed changes to critical infrastructure rules “overly prescriptive” months before a major data breach that affected almost a million of its 4.8 million customers. And while it’s not yet clear whether the breach was due to vulnerable systems, social engineering or a supply chain breach at a trusted third party, Origin recently pushed back against changes to critical infrastructure (CI) security requirements addressing these risks. In June, authorities released updates to the Security of Critical Infrastructure (SOCI) Act’s Critical Infrastructure Risk Management Program (CIRMP), adding new requirements that Clayton Utz experts called “a material step-change in risk management.” CIRMP mark 1, Home Affairs conceded, had “proven to be inadequate in repelling and preventing the compromise of critical infrastructure networks from state-sponsored and cyber-criminal threat actors.” The Origin Energy breach affected almost a million current and former customers.