Avatar

At Cisco, we believe secure connectivity is foundational to economic resilience, national security and public trust. The networks and digital systems supporting governments, critical infrastructure, businesses and communities are no longer just operational assets. They are strategic infrastructure — underpinning how countries deliver essential services, protect data, enable innovation and participate in the digital economy. That is why their lifecycle matters. 

Each successive generation of technology is becoming more secure. As they are adopted and used, they can help organisations become more secure too. Each new wave of innovation brings stronger capabilities: richer telemetry, better encryption, stronger identity, automated detection, secure-by-design architectures and more resilient ways to connect users, data, applications and infrastructure. These advances give organisations greater visibility, control and confidence — but only when they are deployed, maintained and governed over their full lifecycle. 

Across many governments and critical infrastructure, however, systems designed for earlier threat environments continue to carry essential services into the 2030s — often without security patches, modern identity controls, advanced monitoring or a viable path to future security standards. That is now a strategic risk. 

The Growing Risk of Legacy Systems

This is the central challenge examined in the Australian Strategic Policy Institute’s new report, “Past its use-by-date: Turning end-of-life technology risk into national advantage”, funded by Cisco. The report argues that end-of-life technology is not simply a technical problem. It is a governance problem — and, if addressed well, a strategic opportunity. Importantly, the report also launches the “Legacy Five”: a practical framework for governments and enterprises to make lifecycle risk visible, accountable and actionable. 

The report’s message is clear: functionality is not the same as defensibility. A system may still operate, but if it can no longer be patched, monitored, segmented, upgraded or integrated into modern security architectures, it creates exposure defenders can no longer afford. 

Cisco Talos’ 2025 Year-in-Review findings sharpen the point. Talos found that nearly 40 percent of the most actively targeted vulnerabilities affect end-of-life devices. It also observed that threat actors continue to exploit vulnerabilities that are many years old, including flaws more than a decade old, particularly in networking and edge infrastructure. Unsupported and ageing systems remain attractive, practical and persistent pathways into critical environments. 

Across the Indo-Pacific, countries are confronting the same lifecycle challenge from different starting points.  

  • In South Korea, rapid digitisation has created deep dependency on legacy systems that can be difficult and costly to unwind.  
  • In the Philippines, procurement, budget and capacity constraints can make it difficult to maintain support or fund timely replacement.  
  • In India, lifecycle governance is progressing unevenly, with stronger controls emerging in power and financial services, while broader fragmentation still poses risk.  
  • In Australia, robust frameworks — including Horizon 2 of the Cyber Security Strategy, the Protective Security Policy Framework, and Security of Critical Infrastructure reforms — show the importance of turning policy maturity into measurable execution. 

The problem is accelerating. AI-enabled cyber capability is compressing the time between vulnerability discovery and exploitation. At the same time, post-quantum cryptography, IT–OT convergence and growing dependency on digital infrastructure are widening the consequences of delay.  

Legacy technology risk is often the result of rational choices made over time: prioritising new capability, continuity and limited resources while deferring replacement of systems that still function. But as the threat environment accelerates, those choices can compound quickly, forcing action later under greater pressure and on less favourable terms.

This is where ASPI’s report makes its most important contribution. It reframes end-of-life technology by highlighting gaps such as unclear ownership, unfunded exits, weak procurement signals, and no enforceable threshold for action, governance gaps that are inherent in all digitizing countries. The Legacy Five provides a practical way to respond — with parallel actions for government policymakers and enterprises.

The Legacy Five: A Framework for Action

For government policymakers, the priority is to make lifecycle governance visible, enforceable and embedded into regulation and procurement. The Legacy Five for governments includes: 

  1. Requiring lifecycle registers for high-consequence systems — so governments and regulators know which technologies are approaching or past end of support, who owns the risk and what transition plan is in place.
  2. Setting consequence-based standards — ensuring the most critical systems, including those supporting essential services, public safety or national security, are subject to stronger requirements to replace, isolate or mitigate unsupported technology. 
  3. Embedding lifecycle obligations into procurement — requiring vendors to disclose support timelines, end-of-support dates, and transition pathways at the point of acquisition.
  4. Requiring accountability and funded transition plans — linking lifecycle exposure to assurance, audit and incident-reporting processes, and ensuring high-consequence unsupported systems have a funded pathway to replace, remediate or manage the risk.
  5. Enabling transition through incentives and coordination — providing guidance, co-funding where appropriate, and coordinated programs that help operators modernise without disrupting essential services. 

For enterprises, end-of-life risk needs to be governed as an enterprise risk — not left as an IT issue. The Legacy Five for enterprises means: 

  1. Knowing what technology they have — including which systems are unsupported or nearing end of support. 
  2. Prioritising action based on consequence — not just age or maintenance cost, but the potential impact on essential services, safety, customers, data and operations.
  3. Requiring formal “replace-or-mitigate” decisions — before systems reach end-of-support milestones.
  4. Assigning clear accountability — so unsupported systems do not continue by default, but are owned by a named decision-maker with responsibility for residual risk, compensating controls and transition planning.
  5. Funding transition before crisis forces action — treating modernisation as part of long-term resilience and capability-building, not as an emergency response after an incident. 

Modernisation as a Catalyst for Resilience

This is not only a risk agenda; it is an opportunity agenda. Modernisation gives defenders greater visibility, stronger control and the foundation for responsible AI-enabled defence — helping organisations identify exposure, prioritise remediation and respond faster. 

The choice before decision-makers is not whether to invest. It is whether to invest deliberately, before incidents, outages or adversaries force the terms of transition. End-of-life technology risk is not inevitable. It is governable — and with the right leadership, standards and partnerships, it can become a catalyst for resilience and long-term strategic advantage.

Read the report: here.

Authors

Sarah Sloan

Head of Cybersecurity Policy, Asia and the Pacific (APAC)

Government Affairs