Legacy systems are Australia's hidden security gap
The median time to exploit a newly disclosed vulnerability has fallen from 63 days to five. That number comes from a new ASPI report published this week, and it changes the maths on every unsupported system still running in your environment.
Jason Van der Schyff and James Corera, from ASPI’s Cyber, Technology and Security program, document how end-of-life technology has moved from an IT maintenance problem to a national resilience issue. Nearly 40 percent of the most actively targeted vulnerabilities now affect devices that will never receive another patch. There is no remediation window. Only exposure.
The report pulls no punches on Australia’s own situation. A Commonwealth Cyber Security Posture report from February found that 59 percent of federal entities said legacy technology was preventing them from implementing the Essential Eight at Maturity Level 2. An ANAO audit found that only five percent of Defence systems requiring authorisation had been entered into the authorisation management system by mid-2024. Of those recorded, nearly half carried an ‘Expired’ or ‘No accreditation’ status.
Those numbers describe the federal government. Private sector exposure is likely worse. Most mid-size Australian businesses have at least one system that the vendor stopped supporting two or three years ago. It runs because it still works. Nobody wants to touch it. Risk accumulates silently until a vulnerability disclosure or a breach forces the decision.
Regional examples in the report show what forced recovery looks like. A 2023 ransomware attack on Japan’s Port of Nagoya shut down operations at one of the country’s busiest logistics hubs. In the Philippines, only 10 of 19 national weather radars were operational at the end of 2024 because replacement cycles had stalled. A 2025 fire at a South Korean data centre destroyed 96 systems and exposed how much deferred maintenance sat beneath one of the world’s most advanced digital economies.
Australia has mature governance frameworks. Australia’s ASD Information Security Manual requires unsupported systems to be removed or replaced in many contexts. Its Protective Security Policy Framework includes lifecycle obligations. From June this year, critical infrastructure rules treat delayed patching and unsupported technology as material risks for specified high-risk assets.
The gap between those frameworks and operational reality is where the risk lives. And AI is making it worse. Vulnerability discovery, exploitation development, and targeting are becoming faster and cheaper. Legacy systems are now exposed to continuous machine-assisted discovery that systematically expands the attack surface. What was once a tolerable operational compromise is becoming a structural liability.
ASPI proposes a ‘Legacy Five’ governance approach: make unsupported technology visible and owned, then replaceable before failure forces the decision. That recommendation sounds obvious. Investment discipline and procurement settings are the hard part, and they determine whether governance frameworks translate into actual system change.
For Australian organisations carrying legacy systems, the practical starting point is an inventory. List every system running on unsupported operating systems or firmware. Check the last patch date. Assign an owner. Then decide whether to replace, isolate, or accept the risk with eyes open. Most businesses have never done this exercise because nothing has forced it. ASPI argues that the forcing event is now a matter of when, not if.
One approach that works: the strangler pattern. You do not rip out the system that runs the business. You wrap it, route around it piece by piece, and retire it when it is hollow. That approach is slower than a full replacement but it keeps the business running while the risk shrinks.
A window for governed renewal is narrowing. Organisations that start now have options. Those that wait for a breach or a forced recovery will have fewer.
Sources:
- “Legacy technology is a national security threat hiding in plain sight,” Jason Van der Schyff and James Corera, The Strategist (ASPI), 28 July 2026. https://www.aspistrategist.org.au/legacy-technology-is-a-national-security-threat-hiding-in-plain-sight/
- Commonwealth Cyber Security Posture report, Australian Government, February 2026.
- Australian National Audit Office, Defence authorisation management audit, mid-2024.
- Australian Signals Directorate, Information Security Manual (ISM).
- Protective Security Policy Framework (PSPF), Australian Government.
Some of the content on this site may have been generated by AI tools, with human oversight but without detailed human review. We are human and our oversight is not perfect, so there may be mistakes or inaccuracies. Please verify any critical information independently before relying on it.