At Cisco, we consider safe connectivity is foundational to financial resilience, nationwide safety and public belief. The networks and digital programs supporting governments, vital infrastructure, companies and communities are now not simply operational property. They’re strategic infrastructure — underpinning how international locations ship important providers, shield information, allow innovation and take part within the digital financial system. That’s the reason their lifecycle issues.
Every successive technology of know-how is turning into safer. As they’re adopted and used, they will help organisations change into safer too. Every new wave of innovation brings stronger capabilities: richer telemetry, higher encryption, stronger id, automated detection, secure-by-design architectures and extra resilient methods to attach customers, information, functions and infrastructure. These advances give organisations higher visibility, management and confidence — however solely when they’re deployed, maintained and ruled over their full lifecycle.
Throughout many governments and demanding infrastructure, nonetheless, programs designed for earlier risk environments proceed to hold important providers into the 2030s — typically with out safety patches, trendy id controls, superior monitoring or a viable path to future safety requirements. That’s now a strategic danger.
The Rising Threat of Legacy Techniques
That is the central problem examined within the Australian Strategic Coverage Institute’s new report, “Previous its use-by-date: Turning end-of-life know-how danger into nationwide benefit”, funded by Cisco. The report argues that end-of-life know-how just isn’t merely a technical drawback. It’s a governance drawback — and, if addressed effectively, a strategic alternative. Importantly, the report additionally launches the “Legacy 5”: a sensible framework for governments and enterprises to make lifecycle danger seen, accountable and actionable.
The report’s message is obvious: performance just isn’t the identical as defensibility. A system should function, but when it could now not be patched, monitored, segmented, upgraded or built-in into trendy safety architectures, it creates publicity defenders can now not afford.
Cisco Talos’ 2025 12 months-in-Assessment findings sharpen the purpose. Talos discovered that almost 40 p.c of probably the most actively focused vulnerabilities have an effect on end-of-life units. It additionally noticed that risk actors proceed to take advantage of vulnerabilities which might be a few years outdated, together with flaws greater than a decade outdated, significantly in networking and edge infrastructure. Unsupported and ageing programs stay enticing, sensible and protracted pathways into vital environments.
Throughout the Indo-Pacific, international locations are confronting the identical lifecycle problem from totally different beginning factors.
- In South Korea, fast digitisation has created deep dependency on legacy programs that may be troublesome and dear to unwind.
- Within the Philippines, procurement, price range and capability constraints could make it troublesome to keep up help or fund well timed substitute.
- In India, lifecycle governance is progressing inconsistently, with stronger controls rising in energy and monetary providers, whereas broader fragmentation nonetheless poses danger.
- In Australia, sturdy frameworks — together with Horizon 2 of the Cyber Safety Technique, the Protecting Safety Coverage Framework, and Safety of Essential Infrastructure reforms — present the significance of turning coverage maturity into measurable execution.
The issue is accelerating. AI-enabled cyber functionality is compressing the time between vulnerability discovery and exploitation. On the similar time, post-quantum cryptography, IT–OT convergence and rising dependency on digital infrastructure are widening the results of delay.
Legacy know-how danger is usually the results of rational selections remodeled time: prioritising new functionality, continuity and restricted assets whereas deferring substitute of programs that also perform. However because the risk setting accelerates, these selections can compound shortly, forcing motion later beneath higher strain and on much less beneficial phrases.
That is the place ASPI’s report makes its most vital contribution. It reframes end-of-life know-how by highlighting gaps similar to unclear possession, unfunded exits, weak procurement alerts, and no enforceable threshold for motion, governance gaps which might be inherent in all digitizing international locations. The Legacy 5 offers a sensible technique to reply — with parallel actions for presidency policymakers and enterprises.
The Legacy 5: A Framework for Motion
For presidency policymakers, the precedence is to make lifecycle governance seen, enforceable and embedded into regulation and procurement. The Legacy 5 for governments consists of:
- Requiring lifecycle registers for high-consequence programs — so governments and regulators know which applied sciences are approaching or previous finish of help, who owns the chance and what transition plan is in place.
- Setting consequence-based requirements — making certain probably the most vital programs, together with these supporting important providers, public security or nationwide safety, are topic to stronger necessities to interchange, isolate or mitigate unsupported know-how.
- Embedding lifecycle obligations into procurement — requiring distributors to reveal help timelines, end-of-support dates, and transition pathways on the level of acquisition.
- Requiring accountability and funded transition plans — linking lifecycle publicity to assurance, audit and incident-reporting processes, and making certain high-consequence unsupported programs have a funded pathway to interchange, remediate or handle the chance.
- Enabling transition by incentives and coordination — offering steerage, co-funding the place acceptable, and coordinated packages that assist operators modernise with out disrupting important providers.
For enterprises, end-of-life danger must be ruled as an enterprise danger — not left as an IT problem. The Legacy 5 for enterprises means:
- Understanding what know-how they’ve — together with which programs are unsupported or nearing finish of help.
- Prioritising motion primarily based on consequence — not simply age or upkeep value, however the potential impression on important providers, security, clients, information and operations.
- Requiring formal “replace-or-mitigate” choices — earlier than programs attain end-of-support milestones.
- Assigning clear accountability — so unsupported programs don’t proceed by default, however are owned by a named decision-maker with accountability for residual danger, compensating controls and transition planning.
- Funding transition earlier than disaster forces motion — treating modernisation as a part of long-term resilience and capability-building, not as an emergency response after an incident.
Modernisation as a Catalyst for Resilience
This isn’t solely a danger agenda; it is a chance agenda. Modernisation provides defenders higher visibility, stronger management and the inspiration for accountable AI-enabled defence — serving to organisations establish publicity, prioritise remediation and reply sooner.
The selection earlier than decision-makers just isn’t whether or not to speculate. It’s whether or not to speculate intentionally, earlier than incidents, outages or adversaries pressure the phrases of transition. Finish-of-life know-how danger just isn’t inevitable. It’s governable — and with the proper management, requirements and partnerships, it could change into a catalyst for resilience and long-term strategic benefit.
