A programme can be up to date and still not name the risk
A critical infrastructure risk management programme can be current, reviewed and lawfully attested, and still not contain the hazard that takes the asset down.
In July we wrote about the signature the Security of Critical Infrastructure Act asks a board to put its name to once a year, and asked whether a board can honestly sign that the programme was up to date. That argument was about time: an attestation is accurate on its date and then carries twelve months it cannot see.
There is a harder question sitting underneath it, and a review published this month has put it on the record. Up to date against what?
What the review found
On 2026-07-08, starting at 02:50, a national mobile network failed across Australia. Roughly 45% of calls and data sessions were affected. Six hundred and twelve Triple Zero calls failed to connect, eight more than had first been disclosed. The independent review by Technology Audit Partners, reported on 2026-09-02, traced it to a replacement power supply that reset a GPS card’s date to 2006, which then cascaded through network time protocol across the estate.
Three findings in that review matter more than the mechanism. Alarms that would ordinarily have raised the error were monitored only during business hours, by what the review described as a limited number of people. Two key engineers were on mandatory leave. And there was, in the review’s own words, “insufficient clarity of responsibility regarding NTP ownership and support” — alongside a finding that the timing system had not been treated as a high risk function.
The failure was not novel. In October 2025 a clock in Melbourne repeatedly lost connectivity to a clock in Sydney and raised the same class of alarm. It was not investigated. Government agencies had been issuing warnings through 2024 and 2025 about national dependence on positioning, navigation and timing systems.
So this is not a story about an unforeseeable event. Every component of it was visible somewhere in the organisation before it happened.
The legal turn, which cuts both ways
Dr Jill Slay, who conducted the government’s independent review of the SOCI Act, said in July that the law as drafted left gaps meaning the entity may not have been legally required to address that specific timing issue.
That statement is usually read as criticism of the entity. It is at least as much a defence of it, and it should be written as both. If the obligation did not reach positioning, navigation and timing, then a programme that omitted it was not deficient in the terms the Act set. The regulator’s own process is still running; whether any rule was broken is not settled and is not the point being made here.
The point is what remains true regardless of how that lands. A risk management programme can be current, properly reviewed, approved by a governing body and lawfully attested — and the hazard that takes the asset down can still be nowhere in it. Compliance was never the same thing as coverage. This is the same gap we described as the eleven months your certificate isn’t watching, arriving from the other direction: not a claim that has gone stale, but a claim that was never made about the thing that mattered.
Ownership is the quietest thing that decays
Of everything the review found, “insufficient clarity of responsibility” is the finding worth carrying into your own programme, because it is the one that leaves no trace.
A control with no clear owner still appears in the register. It still has a description, a mapped obligation, a status. What it does not have is anybody whose job it is to notice when the alarm fires at three in the morning, or to investigate the smaller version of the same fault nine months earlier, or to argue that this function should be classified as high risk. Ownership does not fail visibly. It thins out through a reorganisation, a resignation, a handover that covered the systems and not the responsibilities — and the register reads exactly as it did before.
That is why the annual attestation does not, by itself, show it. The Act separately requires the programme to be reviewed regularly and kept up to date, and a review done properly might notice that a function has lost its owner. But the attestation is a statement about the programme as documented, and the document is unchanged by the departure of the person who was quietly holding one part of it together. Nothing in the artefact moves. The board signs the same sentence it signed last year, and the sentence is still, on its face, accurate.
What can actually be seen
Frank will not tell you about a hazard nobody in your organisation ever wrote down. We are direct about that limit, because a tool that invented hazards to look thorough would be manufacturing exactly the confidence it exists to test, and because the inferences would be ours rather than yours.
What Frank does is narrower and more useful than that. Every posture it publishes is a coverage assertion: a stated posture, a named scope, an expiry, and the evidence basis underneath it. Which means the things your programme does name get tested against what your own records actually say about them — whether a control has a named owner, whether the justification states a cadence and a scope or only asserts that something is handled, whether the evidence supporting it has an author and a date or ran out some time ago. Where there is nothing, Frank shows nothing. It does not fill the gap with a plausible guess, and it does not award a green status for a claim that has never been observed.
A control whose entire justification is that a vendor product is in place, with no cadence, no scope and no named activity, is not evidence that the function operates. It reads as covered on the page. It is one of the cheapest findings in any assessment to fix and one of the easiest to leave alone for years, because nothing about it looks urgent until the morning it does.
Before the next attestation
The useful question for a board is not whether the programme is up to date. It is which parts of the programme currently rest on nobody, and which claims in it have never been checked against anything.
Ask what would have to be visible, between this meeting and the next annual report, for the answer to change. If the only artefact is a document that reads identically whether or not a function still has an owner, the attestation is measuring the calendar.
You can look at one scope — what it covers, what it assumes, what has lapsed, and the date each claim stops being defensible. Start with obligation visibility. There is no green tick in it, only what your programme holds today and what is holding it up.