ASD Warns Legacy Technology Will Be First Hit in AI-Enabled Attacks
The head of the Australian Signals Directorate has said that legacy technology will almost certainly be the first thing compromised in a major AI-enabled attack, unless organisations replace it first. Director-General Abigail Bradshaw made the remarks at the Sydney Dialogue in September 2026, describing Australia as sitting on "an enormous legacy technology debt" and suggesting that the most meaningful response would be to set legacy technology reduction targets and work towards them, as reported by Cyber Daily. The warning is about Australia. The reasoning applies anywhere.
What ASD actually means by "legacy"
"Legacy" is often used loosely for anything old. ASD's practitioner guidance on managing the risks of legacy IT uses a precise definition from the Australian Government's Protective Security Policy Framework. A product, which can be hardware, software, a service, a protocol or a system, is legacy when it meets at least one condition from each group:
| Category A: its support status | Category B: its place in the organisation |
|---|---|
| It is an end-of-life product, or it is out of support, including extended support from the manufacturer, vendor or developer | It is impractical to update or support, or it is no longer cost-effective, or it is above the current acceptable risk threshold, or it offers diminishing business use, or it obstructs the organisation's IT strategy |
The first test is a matter of fact with a date attached: has the vendor ended support, or not. That is the part that can be measured across a whole estate, and it is where a reduction target has to start, because a target needs a number.
What ASD tells organisations to do
- Replace it before it becomes legacy. The guidance calls this the most effective way to mitigate the risk.
- Know your environment. Keep an accurate IT register, and support it with a Software Bill of Materials where possible.
- Monitor depreciation continuously. Vendors usually give advance notice of end of life; ASD asks for a systematic process that tracks when each product will reach it, and which already have.
- Plan for the end at purchase. Treat replacement as part of the whole-of-life cost.
- Report the aggregate. The guidance says the combined risk of legacy IT across an organisation is significantly higher than any single system suggests, and that security leaders should convey that total to management.
- Mitigate only as a stopgap. Where replacement is not yet possible ASD lists low-cost mitigations, and states that they reduce risk only temporarily.
"Replace or mitigate legacy technologies" is also the first item on ASD's list of critical actions for its Cyber Action Year 2026; "prepare for AI-enabled cyber threats" is on the same list.
Turning a reduction target into something you can count
- List what runs. Operating systems, databases, runtimes, frameworks, network devices. An asset inventory or an SBOM is enough to start.
- Attach a support end date to every line. Our EOL Checker does this one product at a time; the API does it for a whole list, and accepts a CycloneDX or SPDX SBOM. Every date carries its source, which matters when the number goes to a board or an auditor.
- Count three groups: already past end of support; ending within twelve months; supported beyond that. The first group is the legacy technology debt in ASD's Category A sense. The second is the debt you can still avoid.
- Rank by exposure, not age. An end-of-life system with a vulnerability that attackers are already using comes first. Our Exploited & Unpatchable list tracks exactly that overlap, and the end-of-support edge device list covers the firewalls, VPN gateways and routers that sit on the internet.
- Set the target as a date and a number, and report the count each quarter.
What becomes legacy next
A few widely deployed products whose support ends in the coming weeks, from our tracked data:
| Product | Support ends |
|---|---|
| FortiOS 7.2 | September 30, 2026 |
| Microsoft Office 2021 | October 13, 2026 |
| Next.js 15 | October 21, 2026 |
| Python 3.10 | October 31, 2026 |
| .NET 8 | November 10, 2026 |
Everything else reaching end of life this year is on the 2026 end-of-life calendar.
Frequently Asked Questions
What did the Australian Signals Directorate say about legacy technology and AI?
Speaking at the Sydney Dialogue in September 2026, ASD Director-General Abigail Bradshaw said Australia carries a very large legacy technology debt, and that AI will either prompt organisations to replace legacy technology or, if they move too slowly, legacy technology will almost certainly be the first thing compromised in a major AI-enabled attack. She suggested setting legacy technology reduction targets.
What does ASD count as legacy IT?
Under the Protective Security Policy Framework definition that ASD's guidance uses, an IT product is legacy when it meets at least one condition from each of two groups. The first group is about support: it is an end-of-life product, or it is out of support including extended support. The second is about the organisation: it is impractical to update or support, no longer cost-effective, above the acceptable risk threshold, of diminishing business use, or an obstacle to the IT strategy.
What does ASD tell organisations to do about legacy IT?
Replace it before it becomes legacy, which ASD calls the most effective mitigation. To do that, keep an accurate IT register, supported by a Software Bill of Materials where possible, and systematically monitor when products will reach end of life or go out of support. Where replacement is not yet possible, ASD lists temporary, low-cost mitigations, and says they reduce risk only temporarily.
Related
- What is EOL? End of life software, every term and key dates
- Exploited & Unpatchable — exploited vulnerabilities on software that will never be fixed
- Auditing an SBOM for end-of-life components
- How we verify our dates