The SOCI Act reforms and maturing RSNL obligations have fundamentally changed what adequate security looks like for critical infrastructure owners and operators. Demonstrating compliance is no longer sufficient — practitioners must prove that residual risk has been reduced to SFAIRP and produce documented evidence that is defensible under independent assurance review. Drawing on live application across the $11B Sydney Metro Western Sydney Airport program, this session unpacks Security Cases, Goal Structuring Notation, and RVTM — and what risk-based, evidence-led security practice demands of the profession.