Skip to main content
CybersecurityVulnerability Management

Australia Grapples with Legacy IT Security Risks as AI Threats Escalate

Dusty, outdated computer equipment and tangled cables in a cluttered server room.

"AI is sharply reducing the time and expertise needed to find and exploit simple weaknesses in ageing, poorly maintained systems."

Home Affairs' direction: a fast stocktake, a longer fight

The Department of Home Affairs has ordered a national reckoning: all non-corporate federal agencies must complete a legacy technology stocktake and a risk management plan, the direction requires. The plan must include a reduction target and a prioritisation strategy, and it aims to "ensure agencies understand and assess their legacy technology base." That stocktake is meant to identify systems at risk; acting on the results is where the hard work begins.

Medicare statistics portal: a simple failure that exposed a bigger problem

The immediate trigger for the direction was an incident in which an OpenAI agent reached non-public files on a "decades-old Medicare Statistics portal." The portal was taken offline after the exposure — an action the article notes was straightforward once the vulnerability was recognised, and one that raises the question "why it was connected to the internet at all." The episode underlines how routine connectivity decisions can leave old systems unexpectedly open to modern threats.

Why retiring legacy systems is difficult

Retiring legacy systems, the article explains, is constrained by three realities: money, scarce skills and leverage over vendors. Old systems often persist for rational, not negligent, reasons: they embed complex business logic that must be understood and replicated; they hold data that must be migrated without loss or corruption; and they underpin public services that cannot be interrupted during a changeover. Because of finite funding, technical skills and business expertise, agencies "will therefore have to triage aggressively, prioritising the highest-risk systems while mitigating the risks of those that realistically won’t be replaced for several years."

Mitigations beyond the Essential Eight

The article cautions against reflexively prescribing the Australian Signals Directorate’s Essential Eight for ageing, bespoke systems, noting that "the directorate itself actually describes them as designed for internet-connected Windows-based IT networks." Instead, it outlines practical protections suited to legacy architectures: placing dedicated security hardware or software between the system and the wider internet; adding additional authentication before users can gain access; network isolation and segmentation to constrain attacker movement after a compromise; and enhanced logging and monitoring to improve detection. For some systems the only feasible immediate step may be disconnection from the internet; for core operational systems that cannot be disconnected, layered protection and careful transition planning are required.

Vendor support, procurement leverage and section 13.7

Commercial arrangements are central to what counts as "legacy." Under section 13.7 of Home Affairs’ direction, "a product counts as legacy only if it is out of support, including extended support, from its vendor or developer. It also must be impractical or uneconomic to maintain." That rule ties the federal government's treatment of a product to a vendor's commercial decision to end support, creating what the article calls a "perverse incentive": shorter support periods reduce vendors' maintenance costs and create opportunities to sell replacement systems.

To counter that dynamic, the article urges government coordination of vendor negotiations through whole-of-government arrangements already managed by the Digital Transformation Agency with major vendors. It recommends stronger procurement requirements in new contracts — minimum security support periods matched to a system’s expected life, disclosure of end-of-support dates at purchase, and caps on extended-support pricing. The piece notes the EU's Cyber Resilience Act as a precedent for imposing similar conditions on vendors.

What this means for technologists, procurement leaders, and the public

  • Technologists and security teams: Expect to be directed to catalogue legacy systems quickly, then to score and prioritise them by breach risk, data impact and migration effort; for many systems, enhanced network controls, authentication and monitoring will be the immediate remedies.
  • Procurement leaders and the Digital Transformation Agency: They will need to coordinate commercial negotiations with vendors, seek longer and binding support periods, require end-of-support transparency at purchase and push for caps on extended-support pricing.
  • The public and service users: Some services will be insulated by disconnection or strengthened controls, but core operational systems that cannot be migrated quickly will remain dependent on layered mitigation while replacements are planned and funded.

The stocktake will reveal what the government has and where to start. But, as the article concludes, fixing that inventory "will take funding, skills and vendors willing to share the burden." The direction sets a timetable for assessment; the harder questions — how to pay for migration, where to find the expertise, and how to reshape vendor contracts so taxpayers do not subsidise accelerated end-of-support decisions — remain to be negotiated.

https://www.aspistrategist.org.au/to-face-ai-intrusion-counting-legacy-systems-will-be-easy-fixing-them-wont/