"The problem with legacy technology is not that organisations do not know the risks. It is that no mechanism forces a decision," the new ASPI report warns, and then makes the case that that governance failure has become a national security problem.
How fast exploits and AI reshape exposure
The arithmetic of risk has changed. The report documents that the median time to exploit a newly disclosed vulnerability has fallen from 63 days to as little as five. Nearly 40 percent of the most actively targeted vulnerabilities affect end‑of‑life devices. For systems that will never receive another patch, the report says, "there is only exposure."
Machine assistance is accelerating that exposure. ASPI points to faster, cheaper and more accessible vulnerability discovery, exploitation‑mechanism development and targeting — and notes debate around Anthropic’s Mythos model as evidence of how quickly many cyber practitioners believe "we are moving towards machine‑speed offence." That trend, the report adds, changes the economics of cyber risk and will be sharpened by the coming transition to post‑quantum cryptography, especially for systems that cannot be upgraded at all.
Operational technology now carries real‑world risk
Unsupported systems are not an IT convenience problem; they live in the operational baseline for critical services. The report lists health, telecommunications, energy and government services as sectors carrying systems vendors stopped supporting years ago. It also points out that operational technology underpins power grids, ports, water infrastructure, hospitals and telecommunications networks — and that when those systems fail the consequences "move quickly beyond data loss into real‑world disruption."
Indo‑Pacific examples: Nagoya, the Philippines radars, and South Korea's data‑centre fire
ASPI uses regional incidents to show how deferred decisions become crises. In Japan, a 2023 ransomware attack on the Port of Nagoya disrupted operations across one of the country’s busiest logistics nodes. In the Philippines, only 10 of 19 national Doppler weather radars were operational at the end of 2024 because repair and replacement cycles had stalled — a resilience gap with direct consequences for disaster warning capability. And in South Korea, a 2025 fire at a national data centre destroyed 96 systems and "exposed how deeply deferred maintenance had accumulated."
Australia: rules on paper, compliance in practice
Australia, the report says, possesses "one of the region’s most mature governance architectures" for legacy risk. The Australian Signals Directorate’s Information Security Manual requires unsupported systems to be removed or replaced in many contexts, and the Protective Security Policy Framework now includes explicit lifecycle obligations. In June, Australia’s critical‑infrastructure rules began explicitly treating delayed patching and unsupported technology as material risks for specified high‑risk assets.
Yet the compliance picture is stark. The Commonwealth Cyber Security Posture report in February found that 59 percent of federal entities said legacy technology was preventing them from implementing the Essential Eight at Maturity Level 2. An Australian National Audit Office audit found that only around five percent of Defence systems requiring authorisation had been entered into Defence’s authorisation management system by mid‑2024 — and of those recorded, nearly half carried an "Expired" or "No accreditation" status.
The report contrasts those operational realities with the financial logic elsewhere: the US government, it notes, still directs around four‑fifths of its IT budget towards maintaining existing systems rather than replacing them. The more organisations spend preserving ageing infrastructure, the less capacity they retain to invest in secure architectures, AI‑enabled defence, post‑quantum readiness or operational resilience.
What this means for technologists, policymakers, and the public
- Technologists and security teams: face a compression of the remediation window — "as little as five" days in some cases — and a rising burden to keep unsupported systems online while machine‑assisted tools continuously expand the attack surface.
- Policymakers and procurement leaders: must shift from drafting policy to enforcing investment discipline, procurement settings and accountability — the report emphasizes these are the decisions that determine whether governance frameworks "translate into actual system change."
- Affected enterprises and public services: will see continuing trade‑offs between short‑term operational continuity and long‑term resilience; the report frames deliberate replacement as a way to unlock trapped operational data, reduce long‑term costs and create demand for sovereign capability in secure infrastructure and post‑quantum transition support.
ASPI proposes a 'Legacy Five' governance approach to make unsupported technology visible, owned and progressively replaceable before failure forces the decision. The report stresses that modernisation is not merely defensive: it can improve resilience, lower operating costs over time and position countries as trusted partners in regional infrastructure transitions.
Unsupported technology, the report concludes, is now accumulated strategic risk. In a threat environment defined by AI‑enabled exploitation, contested infrastructure and growing digital dependence, the window for "governed renewal" is narrowing — and the hard choices about what to sustain, replace or defer are shaping national resilience itself.




