Tech-looking background image
Tech-looking background image
Tech-looking background image
Tech-looking background image

Maintaining Continuous Monitoring During SOCI Compliance Lockdowns

Australian utilities provider

Tech-looking background image
Tech-looking background image

Company context

Company context

This water utilities provider manages critical infrastructure across 30+ dam sites, serving water services to communities and industries.

Following an audit, they needed to redesign their OT network to meet Security of Critical Infrastructure (SOCI) Act compliance requirements.

Under SOCI, their OT network and related monitoring needed to be able to operate in complete isolation from external connectivity for up to three months during lockdown events, while their IT network monitoring needed to continue as normal.

Utilities

650+ employees

1,000+ monitored entities

High-level summary

High-level summary

Main outcome

End-to-end visibility during and outside of SOCI lockdowns

Implementation time

6 months

Maturity level

From Level 2 (Responsive) to Level 4 (Predictive)

Tech-looking background image
Tech-looking background image
Tech-looking background image
Tech-looking background image

Observability maturity

Observability maturity

This project advanced monitoring from Level 2 (Responsive) to Level 4 (Predictive).

1

Reactive

Manual monitoring across multiple systems with no alerting and no dashboards set up.

2

Responsive

Basic monitoring and predefined alerts set up for some systems but no dashboards yet.

3

Proactive

Total system observability with some dashboards and automated diagnostic alerts.

4

Predictive

Full observability across all systems with leading metric tracking for predictive alerts.

5

Strategic

Observability fully integrated with intelligence systems to provide business insights.

The challenge: End-to-end visibility that survives OT network isolation

SOCI compliance requires critical infrastructure networks to operate in complete isolation from external connectivity for up to three months if a threat is detected, suspected, or a compliance failure occurs during an audit. During this lockdown period, the OT network is cut off from the internet and other internal networks.

The challenge wasn't just keeping the OT network monitored during isolation. It was maintaining unified visibility across IT and OT during normal operations, while ensuring both networks could still be monitored independently if they're suddenly cut off from each other.

This needed to be reliable because once a lockdown occurs, teams must validate whether a genuine threat exists while day-to-day operational issues still need resolving and essential water services must continue uninterrupted.

The solution: Two independent instances, one unified view

The client was considering a SaaS monitoring tool for ease of updates, but during OT isolations, cloud platforms lose visibility OT networks. The solution required on-premise monitoring that could operate independently while maintaining end-to-end visibility during normal operations.

We achieved this by deploying two independent SolarWinds instances (one for IT, one for OT) with a unified view across both during normal operations.


High-level architecture diagram


Independent instances for IT and OT

  • IT network: Azure-hosted, supporting their cloud-first strategy

  • OT network: On-premise, within the secure OT perimeter

During a SOCI lockdown, when the OT network is isolated, teams log into each instance locally. No unified dashboard during isolation, but monitoring continues uninterrupted in both environments.


Unified view through an enterprise console

The unified view comes from the Enterprise Operations Console, which sits in the DMZ between IT and OT networks. During normal operations, it aggregates data from both instances into a single pane of glass across the entire organisation.

During security events that require isolation, monitoring doesn't stop or degrade, it simply shifts from unified view to independent operation. Teams continue monitoring their respective networks without scrambling for emergency solutions or manual checks.


The final outcomes

This project:

  • Enabled SOCI compliance and audit readiness

  • Delivered end-to-end visibility during normal operations with independent monitoring during isolation

  • Maintained rapid threat detection and resolution even during isolation events

  • Advanced monitoring maturity from Level 2 (Responsive) to Level 4 (Predictive)


The key insight

The key to SOCI-compliant monitoring isn't a single monitoring instance - it's two independent SolarWinds instances connected through an enterprise console. This architecture maintains end-to-end visibility during normal operations while preserving independent monitoring during isolation events.

If you'd like to learn more about how to achieve SOCI compliance by aligning SolarWinds to a compliant architecture, we created detailed guides on how to do so with a Purdue architecture and also micro-segmentation.

Tech-looking background image
Tech-looking background image

Maximised our SolarWinds value

Intrepid has been an exceptional SolarWinds partner, providing expert guidance and hands-on support that consistently exceeded expectations. Their deep expertise, responsive support, and strategic guidance have helped us maximise the value of our SolarWinds upgrade.

Henry, Integration Engineer

Australian utilities provider