At Cisco, we consider safe connectivity is foundational to financial resilience, nationwide safety and public belief. The networks and digital methods supporting governments, vital infrastructure, companies and communities are now not simply operational belongings. They’re strategic infrastructure — underpinning how nations ship important companies, shield information, allow innovation and take part within the digital financial system. That’s the reason their lifecycle issues.
Every successive technology of know-how is changing into safer. As they’re adopted and used, they might help organisations turn into safer too. Every new wave of innovation brings stronger capabilities: richer telemetry, higher encryption, stronger identification, automated detection, secure-by-design architectures and extra resilient methods to attach customers, information, functions and infrastructure. These advances give organisations higher visibility, management and confidence — however solely when they’re deployed, maintained and ruled over their full lifecycle.
Throughout many governments and important infrastructure, nevertheless, methods designed for earlier risk environments proceed to hold important companies into the 2030s — typically with out safety patches, trendy identification controls, superior monitoring or a viable path to future safety requirements. That’s now a strategic danger.
The Rising Danger of Legacy Programs
That is the central problem examined within the Australian Strategic Coverage Institute’s new report, “Previous its use-by-date: Turning end-of-life know-how danger into nationwide benefit”, funded by Cisco. The report argues that end-of-life know-how isn’t merely a technical downside. It’s a governance downside — and, if addressed effectively, a strategic alternative. Importantly, the report additionally launches the “Legacy 5”: a sensible framework for governments and enterprises to make lifecycle danger seen, accountable and actionable.
The report’s message is evident: performance isn’t the identical as defensibility. A system should still function, but when it might now not be patched, monitored, segmented, upgraded or built-in into trendy safety architectures, it creates publicity defenders can now not afford.
Cisco Talos’ 2025 12 months-in-Evaluation findings sharpen the purpose. Talos discovered that just about 40 % of probably the most actively focused vulnerabilities have an effect on end-of-life gadgets. It additionally noticed that risk actors proceed to use vulnerabilities which can be a few years outdated, together with flaws greater than a decade outdated, significantly in networking and edge infrastructure. Unsupported and ageing methods stay engaging, sensible and chronic pathways into vital environments.
Throughout the Indo-Pacific, nations are confronting the identical lifecycle problem from totally different beginning factors.
- In South Korea, speedy digitisation has created deep dependency on legacy methods that may be troublesome and expensive to unwind.
- Within the Philippines, procurement, funds and capability constraints could make it troublesome to take care of assist or fund well timed alternative.
- In India, lifecycle governance is progressing inconsistently, with stronger controls rising in energy and monetary companies, whereas broader fragmentation nonetheless poses danger.
- In Australia, sturdy frameworks — together with Horizon 2 of the Cyber Safety Technique, the Protecting Safety Coverage Framework, and Safety of Crucial Infrastructure reforms — present the significance of turning coverage maturity into measurable execution.
The issue is accelerating. AI-enabled cyber functionality is compressing the time between vulnerability discovery and exploitation. On the identical time, post-quantum cryptography, IT–OT convergence and rising dependency on digital infrastructure are widening the results of delay.
Legacy know-how danger is usually the results of rational selections revamped time: prioritising new functionality, continuity and restricted assets whereas deferring alternative of methods that also operate. However because the risk setting accelerates, these selections can compound shortly, forcing motion later beneath higher stress and on much less beneficial phrases.
That is the place ASPI’s report makes its most vital contribution. It reframes end-of-life know-how by highlighting gaps resembling unclear possession, unfunded exits, weak procurement indicators, and no enforceable threshold for motion, governance gaps which can be inherent in all digitizing nations. The Legacy 5 supplies a sensible strategy to reply — with parallel actions for presidency policymakers and enterprises.
The Legacy 5: A Framework for Motion
For presidency policymakers, the precedence is to make lifecycle governance seen, enforceable and embedded into regulation and procurement. The Legacy 5 for governments consists of:
- Requiring lifecycle registers for high-consequence methods — so governments and regulators know which applied sciences are approaching or previous finish of assist, who owns the chance and what transition plan is in place.
- Setting consequence-based requirements — making certain probably the most vital methods, together with these supporting important companies, public security or nationwide safety, are topic to stronger necessities to interchange, isolate or mitigate unsupported know-how.
- Embedding lifecycle obligations into procurement — requiring distributors to reveal assist timelines, end-of-support dates, and transition pathways on the level of acquisition.
- Requiring accountability and funded transition plans — linking lifecycle publicity to assurance, audit and incident-reporting processes, and making certain high-consequence unsupported methods have a funded pathway to interchange, remediate or handle the chance.
- Enabling transition by way of incentives and coordination — offering steering, co-funding the place acceptable, and coordinated applications that assist operators modernise with out disrupting important companies.
For enterprises, end-of-life danger must be ruled as an enterprise danger — not left as an IT challenge. The Legacy 5 for enterprises means:
- Figuring out what know-how they’ve — together with which methods are unsupported or nearing finish of assist.
- Prioritising motion based mostly on consequence — not simply age or upkeep price, however the potential affect on important companies, security, prospects, information and operations.
- Requiring formal “replace-or-mitigate” choices — earlier than methods attain end-of-support milestones.
- Assigning clear accountability — so unsupported methods don’t proceed by default, however are owned by a named decision-maker with accountability for residual danger, compensating controls and transition planning.
- Funding transition earlier than disaster forces motion — treating modernisation as a part of long-term resilience and capability-building, not as an emergency response after an incident.
Modernisation as a Catalyst for Resilience
This isn’t solely a danger agenda; it is a chance agenda. Modernisation provides defenders higher visibility, stronger management and the inspiration for accountable AI-enabled defence — serving to organisations establish publicity, prioritise remediation and reply quicker.
The selection earlier than decision-makers isn’t whether or not to take a position. It’s whether or not to take a position intentionally, earlier than incidents, outages or adversaries drive the phrases of transition. Finish-of-life know-how danger isn’t inevitable. It’s governable — and with the correct management, requirements and partnerships, it might turn into a catalyst for resilience and long-term strategic benefit.
