← Blog

Can your board honestly sign that the programme was up to date?

The Security of Critical Infrastructure Act makes a board put its name, once a year, to a risk management programme being up to date. Here is why that signature is a point-in-time claim over a programme that drifts — and what a board would need in order to sign it honestly.

Once a year, a board does something it does for almost nothing else in the security programme: it signs its name to it.

Under the Security of Critical Infrastructure Act 2018 (Cth), a responsible entity for a critical infrastructure asset has to maintain a critical infrastructure risk management programme, review it regularly, and give an annual report on it — one its board, or council, or equivalent governing body, has to approve. Within ninety days of the end of the financial year, the entity lodges that report with the relevant regulator, usually the Cyber and Infrastructure Security Centre, and the report carries an attestation the board has signed off: that the programme was up to date. Miss the lodgement and the Act sets a civil penalty of 150 penalty units — up to five times that, 750 units, for a body corporate, which runs well into six figures of dollars.

Most of the compliance conversation stops there. Lodge on time, attest, avoid the penalty. But the penalty for not lodging is the least interesting thing in the obligation. The interesting thing is the sentence the board is signing — that the programme was up to date — and whether anyone in the room could see whether it was.

The signature is a point in time. The programme is not.

The board approves the report in, say, September, and the report says the programme is up to date. The programme it describes is a fair one: someone competent assembled it, the hazards are named, the controls are described, the review happened. Then the meeting ends, and the programme starts doing what every programme does — drifting away from the page that describes it. A supplier the plan leaned on changes its offering. A segmentation control is relaxed to get a release out, on the understanding that someone will revisit it. A role turns over and an access review slips a quarter. Nobody has done anything wrong, and nothing on the signed attestation moves; it will say exactly the same thing the following winter as it said on the day of the vote.

We have written before about the eleven months your certificate isn’t watching — the stretch between one point-in-time assessment and the next, during which the document keeps making its claim and nobody is checking whether the claim still holds. The board attestation is the same shape, raised to the altitude where the signature carries a name and a penalty. The board is not asked whether the programme is up to date now. It is asked to put its name, once a year, to a programme it can see only through a papered summary — and then to carry that signature through twelve months it cannot see.

”Up to date” is a state, not a document

The words doing the work in the obligation are up to date. They describe a state: the programme as it stands today, against the hazards as they stand today. But the artefact the board signs is a document, and a document records a state on the day it was written. The gap between those two is not a technicality — it is the whole risk. A programme can be entirely up to date on the September afternoon the board approves it and materially out of date by the time the hazard it was written against actually arrives. The attestation cannot tell the difference, because it was built to record that a review happened, not to report whether the state that review found still holds.

The question comes back after the incident

Boards sign these attestations in calm weather. They are read back in a storm. When an incident lands on a critical infrastructure asset, the annual report is one of the first documents pulled, and the board’s approval is read back to the people who now have to account for it — the regulator, the responsible minister’s office, the entity’s own shareholders. In that room, “the governing body signed that the programme was up to date” is offered as diligence and heard as exposure, for the same reason “we were compliant at the time” is: everyone present can now see the distance between attesting a programme was up to date and being in the state the programme described. The signature meant to demonstrate oversight becomes the record of what the board attested to without being able to see it.

That is the job the board actually has, underneath the lodgement deadline: to be able to survive that question. Not to have signed on time — to have signed something it could stand behind when it was read back.

What a board can actually sign over

Writing a better annual report does not help, because the quality of the report was never the problem. However well it is drafted, it is still accurate on its date and still followed by twelve unwatched months. What the board needs is something current to sign over: a live account of where the programme stands, rather than a once-a-year snapshot of where it stood.

This is the gap Frank was built for. Every posture Frank publishes is a coverage assertion: a stated posture, against a named scope, with an expiry and the evidence basis it rests on — we stand behind this, for this asset, until this date, on this evidence. It is meant to be read in February as easily as in September. Because confidence decays whether or not anyone writes it down, the expiry moves as the evidence does, and an attestation has nothing indefinite to inherit.

That changes the question in the boardroom. “Is the programme up to date?” stops being a matter of trust in a summary and becomes something the board can look at: what stands today, against which obligations, and — the question no annual report answers — what expires before the next attestation is due. A board that can see the expiry dates is a board that can sign honestly, because it is signing over a state it can read.

Frank does not replace the programme, the annual review, or the governing body’s judgement. It gives that judgement something current to exercise itself on, so that when the signature is read back, it describes the state the entity was in, not just the day the board happened to meet.

Before the vote

Somebody at the table should ask what would visibly change, between this meeting and the next annual report, if the programme stopped being up to date in the meantime. Where the only artefact is a document that reads the same the day after a control fails as the day before, the annual signature measures the calendar rather than the programme, and the board ends up attesting that a review took place — which is not what the Act asks it to attest to.

You can read the current state of one scope — what it covers, what it assumes, what has lapsed, and the date each claim stops being defensible — before you ever put a name to it. Start with obligation visibility. There is no green tick in it for the board to take comfort from, only what the programme holds today and the date each part of that stops being true.