Tech Obsolescence: Turning Risk Into National Gain

ASPI

End-of-life technology is no longer simply an IT management problem. Across governments and critical infrastructure, unsupported systems are becoming a structural risk to national security, economic resilience and the continuity of essential services.

Systems designed for the threat environments of the 1990s and 2000s continue to support energy networks, telecommunications, healthcare, public administration and other essential functions. Many no longer receive security updates, cannot support modern identity and zero-trust standards, and have no credible pathway to post-quantum cryptography. They may continue to operate, but they can no longer be adequately defended.

The threat environment is also changing faster than the systems themselves. Artificial intelligence is accelerating vulnerability discovery and exploit development, compressing the time available to identify, patch and mitigate weaknesses. For technology that will never receive another patch, the problem is not a narrowing response window. It is the absence of one.

This report argues that the persistence of unsupported technology is fundamentally a governance failure. Legacy systems continue not simply because replacement is technically difficult or expensive, but because decision rights are blurred, ownership is unassigned and no mechanism forces a formal decision before vendor support ends. The result is inherited exposure that accumulates without a named owner, a funded transition pathway or a defined date for review.

Drawing on case studies from South Korea, the Philippines and India, alongside a spotlight on Australia, the report identifies different pathways to the same strategic problem. South Korea demonstrates how rapid digitisation and government technology mandates can create policy-driven lock-in. The Philippines shows how procurement constraints can leave systems effectively unsupported even where current technology remains available. India illustrates the difficulty of managing lifecycle risk across fragmented institutions and infrastructure at national scale.

Australia has comparatively mature cybersecurity and technology-governance frameworks, but those protections do not yet extend consistently across all critical-infrastructure operators whose systems carry national-security consequences.

The report argues that modernisation should not be treated solely as a compliance cost. Planned technology transition can reduce operational risk, strengthen sovereign capability, improve procurement leverage, unlock the value of operational data and create new commercial opportunities. The real choice is not between spending and not spending, but between investing proactively on terms governments and operators can control or spending reactively after failure, under pressure and at greater cost.

To support that transition, the report proposes the 'Legacy Five': a practical governance framework covering lifecycle visibility, consequence-based standards, procurement reform, accountable decision-making and transition enablement. Its central principle is straightforward: no unsupported system should continue by default. Continued operation should require a named decision-maker, documented compensating controls, a funded exit pathway and a defined review date.

/Public Release. This material from the originating organization/author(s) might be of the point-in-time nature, and edited for clarity, style and length. Mirage.News does not take institutional positions or sides, and all views, positions, and conclusions expressed herein are solely those of the author(s).View in full here.