Modernising legacy technology is a strategic opportunity for resilience. This report provides a practical governance framework for governments and enterprises to manage system lifecycles and build a secure, innovative digital future.
At Cisco, we believe secure connectivity is foundational to economic resilience, national security and public trust. The networks and digital systems supporting governments, critical infrastructure, businesses and communities are no longer just operational assets. They are strategic infrastructure — underpinning how countries deliver essential services, protect data, enable innovation and participate in the digital economy. That is why their lifecycle matters.
Each successive generation of technology is becoming more secure. As they are adopted and used, they can help organisations become more secure too. Each new wave of innovation brings stronger capabilities: richer telemetry, better encryption, stronger identity, automated detection, secure-by-design architectures and more resilient ways to connect users, data, applications and infrastructure. These advances give organisations greater visibility, control and confidence — but only when they are deployed, maintained and governed over their full lifecycle.
Across many governments and critical infrastructure, however, systems designed for earlier threat environments continue to carry essential services into the 2030s — often without security patches, modern identity controls, advanced monitoring or a viable path to future security standards. That is now a strategic risk.
The Growing Risk of Legacy SystemsThis is the central challenge examined in the Australian Strategic Policy Institute’s new report, “Past its use-by-date: Turning end-of-life technology risk into national advantage”, funded by Cisco. The report argues that end-of-life technology is not simply a technical problem. It is a governance problem — and, if addressed well, a strategic opportunity. Importantly, the report also launches the “Legacy Five”: a practical framework for governments and enterprises to make lifecycle risk visible, accountable and actionable.
The report’s message is clear: functionality is not the same as defensibility. A system may still operate, but if it can no longer be patched, monitored, segmented, upgraded or integrated into modern security architectures, it creates exposure defenders can no longer afford.
Cisco Talos’ 2025 Year-in-Review findings sharpen the point. Talos found that nearly 40 percent of the most actively targeted vulnerabilities affect end-of-life devices. It also observed that threat actors continue to exploit vulnerabilities that are many years old, including flaws more than a decade old, particularly in networking and edge infrastructure. Unsupported and ageing systems remain attractive, practical and persistent pathways into critical environments.
Across the Indo-Pacific, countries are confronting the same lifecycle challenge from different starting points.
The problem is accelerating. AI-enabled cyber capability is compressing the time between vulnerability discovery and exploitation. At the same time, post-quantum cryptography, IT–OT convergence and growing dependency on digital infrastructure are widening the consequences of delay.
Legacy technology risk is often the result of rational choices made over time: prioritising new capability, continuity and limited resources while deferring replacement of systems that still function. But as the threat environment accelerates, those choices can compound quickly, forcing action later under greater pressure and on less favourable terms.
This is where ASPI’s report makes its most important contribution. It reframes end-of-life technology by highlighting gaps such as unclear ownership, unfunded exits, weak procurement signals, and no enforceable threshold for action, governance gaps that are inherent in all digitizing countries. The Legacy Five provides a practical way to respond — with parallel actions for government policymakers and enterprises.
For government policymakers, the priority is to make lifecycle governance visible, enforceable and embedded into regulation and procurement. The Legacy Five for governments includes:
For enterprises, end-of-life risk needs to be governed as an enterprise risk — not left as an IT issue. The Legacy Five for enterprises means:
This is not only a risk agenda; it is an opportunity agenda. Modernisation gives defenders greater visibility, stronger control and the foundation for responsible AI-enabled defence — helping organisations identify exposure, prioritise remediation and respond faster.
The choice before decision-makers is not whether to invest. It is whether to invest deliberately, before incidents, outages or adversaries force the terms of transition. End-of-life technology risk is not inevitable. It is governable — and with the right leadership, standards and partnerships, it can become a catalyst for resilience and long-term strategic advantage.
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | Modernizing U.S. Critical Infrastructure for the AI Era: Strengthening Security In an Evolving Threat Landscape | 0 | 9.47 | 24-03-2026 |
| 2 | Continuous Authority to Operate Will Transform Cybersecurity for National Defense. Here’s How to Transition Successfully. | 0 | 7.09 | 13-07-2026 |
| 3 | AI-generated code has made security debt a governance problem | 0 | 8.78 | 13-07-2026 |
| 4 | Why “Managing Storage” Is No Longer Enough | 0 | 7.35 | 28-07-2026 |
| 5 | Beyond the Hype: How AI Can Reshape Government Operations | 0 | 10 | 28-05-2026 |
| 6 | Ransomware Is About Leverage: Return on Risk Takes It Away | 0 | 5 | 30-06-2026 |
| 7 | Responsible AI governance in 2026: Frameworks and failures | 0 | 5 | 12-01-2026 |
| 8 | Squaring the circle - digital sovereignty’s big picture versus its operational details | 0 | 8.68 | 30-07-2026 |
| 9 | From PDFs to Public Trust: Why Documents Are the Front Door to Government | 5 | 7 | 17-06-2026 |
| 10 | Cloud Exchange 2026: Splunk’s Jonathan Gines on tackling post-migration challenges | 0 | 5 | 18-06-2026 |