Access doesn't disappear in the cloud - It just gets harder to see
What happened
SecurityBrief reports that third‑party access is one of four named hazard categories under Australia’s reformed Critical Infrastructure Risk Management Program and that visibility gaps persist across hybrid cloud and OT estates. The regulation (in force since June) requires organisations to demonstrate who currently has access, not rely on out‑of‑date inventories. Procurement should watch supplier account hygiene, time‑bound access and revocation proof as immediate contract levers
Why the category manager should care
Treat supplier admin/support accounts as contractual control points: procurement must demand proof of active access and revocation capability
Key facts
- CIRMP names third‑party access as a distinct hazard
- Regulation requires current‑state demonstrable answers about who can access what