Home Politics Legacy technology is a national security threat hiding in plain sight
Politics

Legacy technology is a national security threat hiding in plain sight

Share
Legacy technology is a national security threat hiding in plain sight
Share

The problem with legacy technology is not that organisations do not know the risks. It is that no mechanism forces a decision. Ownership is distributed across operators, boards, procurement teams, regulators and ministers until responsibility effectively disappears and unsupported systems keep running, carrying live demand, long after the last security patch.

That governance failure is now a national security problem.

A new ASPI report documents how end-of-life technology has moved from the information-technology maintenance queue into the national resilience ledger. The median time to exploit a newly disclosed vulnerability has fallen from 63 days to as little as five. Nearly 40 percent of the most actively targeted vulnerabilities affect end-of-life devices. For systems that will never receive another path, there is no remediation window. There is only exposure.

In many organisations, unsupported systems aren’t the exception. They are part of the operational baseline. Health, telecommunications, energy and government services are all carrying systems that vendors stopped supporting years ago. At the same time, operational technology now underpins power grids, ports, water infrastructure, hospitals and telecommunications networks. When those systems fail, the consequences move quickly beyond data loss into real-world disruption.

AI is accelerating the exposure. Vulnerability discovery, exploitation-mechanism development and targeting are becoming faster, cheaper and more accessible. Legacy systems are now exposed not only to known weaknesses but to continuous machine-assisted discovery processes that systematically expand the attack surface. Debate around Anthropic’s Mythos model has reinforced how quickly many cyber practitioners believe we are moving towards machine-speed offence. That changes the economics of cyber risk entirely. What once looked like a tolerable operational compromise is becoming a structural liability. The coming transition to post-quantum cryptography will only sharpen the problem, particularly for systems that cannot be upgraded at all.

The financial logic compounds the problem. Organisations are spending heavily to keep unsupported systems alive while simultaneously reducing their capacity to modernise. According to its IT dashboard, the US government still directs around four-fifths of its IT budget towards maintaining existing systems rather than replacing them. The more organisations spend preserving ageing infrastructure, the less capacity they retain to invest in secure architectures, AI-enabled defence, post-quantum readiness or operational resilience.

The report calls this the difference between ‘forced recovery’ and ‘governed renewal’. The Indo-Pacific provides instructive examples of what forced recovery looks like in practice.

In Japan, a 2023 ransomware attack on the Port of Nagoya disrupted operations across on of the country’s busiest logistics nodes. In the Philippines, only 10 of 19 national Doppler weather radars were operational at the end of 2024 because repair and replacement cycles had stalled – a resilience gap with direct consequences for disaster warning capability. South Korea offers perhaps the sharpest warning. A fire at a national data centre in 2025 destroyed 96 systems and exposed how deeply deferred maintenance had accumulated beneath one of the world’s most advanced digital economies.

Australia is not immune, and the report’s findings on this point are worth reading carefully.

Australia possesses one of the region’s most mature governance architectures for managing legacy technology risk. The Australian Signals Directorate’s Information Security Manual already requires unsupported systems to be removed or replaced in many contexts. The Protective Security Policy Framework now includes explicit lifecycle obligations.

In June, Australia’s critical-infrastructure rules began explicitly treating delayed patching and unsupported technology as material risks for specified high-risk assets – an important but still targeted step..

Yet compliance data tells a different story.

The Commonwealth Cyber Security Posture report in February found that 59 percent of federal entities said legacy technology was preventing them from implementing the Essential Eight cybersecurity framework at Maturity Level 2. An audit by the Australian National Audit Office found that only around five percent of Defence systems requiring authorisation had even been entered into Defence’s authorisation management system by mid-2024. Of those recorded, nearly half carried an ‘Expired’ or ‘No accreditation’ status.

The gap between policy settings and operational reality is significant. The challenge is no longer primarily about drafting better cyber policy. It is about investment discipline, procurement settings, operational continuity and accountability – the decisions that determine whether governance frameworks translate into actual system change.

ASPI’s new report proposes a ‘Legacy Five’ governance approach designed to make unsupported technology visible, owned and progressively replaceable before failure forces the decision instead.

The report doesn’t frame modernisation solely as a defensive exercise, and that framing matters.

Deliberate replacement of legacy systems can unlock operational data trapped inside closed architectures, improve resilience and reduce long-term operating costs. It also creates demand for sovereign capability in areas such as secure infrastructure, assurance services and post-quantum transition support. Countries that establish credible lifecycle governance frameworks early will shape supplier behaviour, influence regional standards and position themselves as trusted partners for critical digital infrastructure transitions across the Indo-Pacific.

The systems governments choose to sustain, replace or defer are shaping national resilience itself. In a threat environment defined by AI-enabled exploitation, contested infrastructure and growing digital dependence, unsupported technology is no longer simply ageing infrastructure. It is accumulated strategic risk, and the window for governed renewal is narrowing.

Source link

Share

Leave a comment

Leave a Reply

Your email address will not be published. Required fields are marked *