The SOCI obligation reaches further into IT than most operators assume
Critical infrastructure risk programs concentrate on operational technology. The corporate endpoint that reaches into it is usually nobody's responsibility.
When an operator builds a critical infrastructure risk management program, the attention goes where the risk is most obvious: the operational technology, the control systems, the network boundary between corporate and operations.
That is the right place to start. It is not the whole boundary, and the part that gets left out is consistent.
The device that crosses the line
A technician carries a handset. On it: their identity, their multi-factor authentication, the work management application that tells them what to do, the documentation for the asset they are standing in front of, the camera they photograph it with, and the mail client that receives the instruction.
That device is corporate IT by ownership and management. It is operational by function. It crosses the boundary several times a day, physically and logically, and in most risk programs it appears in neither column.
The exposure is not usually a direct path into a control system — the segmentation is generally sound. It is that the device holds the credentials, the context and the access that a person uses to act on operational systems, and it is the least monitored thing in the chain.
Where it actually goes wrong
Identity is the pivot. Compromise the phone and you have the technician’s authentication, including the MFA approval prompt. The device is both the credential and the second factor, which is convenient and is also a single point of failure.
Field devices are the least managed. Office endpoints get EDR, patching and monitoring. Field handsets are frequently a year behind on OS version, outside the compliance reporting, and connected to whatever network is available at site — which at a remote location is often somebody’s hotspot.
Documentation and imagery leave. Asset photographs, site documentation and network diagrams end up in a camera roll, synchronised to a personal cloud service, indefinitely. This is not an exotic attack path; it is the default behaviour of a phone.
Contractors are outside everything. Much field work is contracted. The contractor’s device is not yours, their offboarding is not yours, and their access frequently outlives the engagement.
What the obligation actually implies
The regulatory language is about a risk management program covering cyber and information security hazards, with material risks identified and mitigated. It does not enumerate device classes, which is precisely why the mobile estate slips through — nothing names it, so nothing prompts anyone to include it.
The test to apply is simple: if this device were compromised, what could an adversary reach, and how quickly would we know? Run that question against a field technician’s handset and the answer is usually uncomfortable and always specific.
What to do about it
Put field endpoints in scope, explicitly. Named in the program, with the same expectations as any other endpoint: managed, patched to a minimum version, monitored, and able to lose access automatically when it falls out of policy.
Make compliance an access condition. A field device below the minimum OS version, or flagged as compromised, should lose access to the work management system without a human deciding. This is the step that turns monitoring into control.
Detect on the device. Field sites have poor connectivity by nature, so detection that depends on a cloud lookup is not detection at the moments that matter. On-device analysis keeps working, and reports when the link returns.
Control field data capture. Operational imagery captured inside an application that delivers it to an approved repository, rather than into a camera roll that synchronises to a consumer service. This is a small change with a disproportionate effect on what leaves the organisation.
Bring contractors into the model. Either their devices meet your standard and are enrolled, or they access your systems through a boundary that assumes they do not. Both are defensible. Neither is what usually happens.
Make the reporting continuous. The obligation carries timeframes. Evidence assembled under deadline is worse and more expensive than evidence produced monthly as a by-product of running the environment properly.
The short version
The corporate endpoint is inside the boundary of a critical infrastructure risk program whether or not the program mentions it. The field handset is the version of that endpoint with the most access, the least management and the worst connectivity.
Name it, manage it, and make its compliance state change what it can reach.
More on security services and how we work with critical infrastructure operators.