Govt orders legacy tech stocktake to counter AI-enabled cyber risks

By Staff Writer on Sep 30, 2026 3:55PM
Govt orders legacy tech stocktake to counter AI-enabled cyber risks

In summary

  • The Australian Government has directed all non-corporate Commonwealth entities to complete a legacy technology stocktake and risk management plan by 31 March 2027.
  • PSPF Direction 002-2026 cites frontier AI capabilities already targeting the Commonwealth's technology estate, warning that legacy systems combined with unpatched vulnerabilities pose an unacceptable risk.
  • Entities operating Systems of Government Significance face an earlier deadline, needing a stocktake completed and SoGS Risk Reduction Measures incorporated by 31 December 2026.

The Australian Government has directed all non-corporate Commonwealth entities to conduct a full legacy technology stocktake and develop a risk management plan by 31 March 2027, as part of a new protective security directive aimed at reducing cyber security risks posed by outdated government systems.

PSPF Direction 002-2026, issued under the Protective Security Policy Framework by the Secretary of the Department of Home Affairs, requires affected entities to identify all legacy technology systems across their estates, develop strategies to reduce them, and implement mitigations where legacy systems remain in use.

The direction cites frontier AI capabilities as having already targeted the Commonwealth's technology estate, with the Department of Home Affairs warning that the combination of legacy systems and unpatched vulnerabilities now represents an unacceptable risk to Australian Government operations.

Entities operating Systems of Government Significance  the government's most critical digital services - face an earlier deadline.

Those systems must have a legacy technology stocktake completed and SoGS Risk Reduction Measures incorporated by 31 December 2026, with measures to be detailed in a forthcoming Policy Explanatory Note 002-2026 due by 13 October 2026.

Under the direction, each entity's Legacy Technology Risk Management Plan must include a target to reduce legacy systems in line with the entity's risk tolerance, prioritisation strategies to meet that target, mitigations for systems that remain, and procedures to rationalise the broader technology estate.

The plan must be incorporated into the entity's existing cyber security strategy and uplift plan.

The direction also instructs entities to strengthen vulnerability and patch management across their entire technology estate, citing a shortened window between vulnerability discovery and exploitation. Vendors' critical-severity vulnerability designations, as well as internal processes, should trigger rapid patching responses, the direction states.

Entities are also directed to balance system availability with security, particularly for public-facing systems, and should prioritise those services when scoping their legacy technology assessments.

The Department of Home Affairs said it will conduct policy advisory sessions to support implementation, and pointed entities to Policy Advisory 001-2026 - Cyber Security Readiness in the Frontier AI Era - for supplementary guidance.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © nextmedia Pty Ltd. All rights reserved.

Add techpartner.news as your trusted source

Tags:

Log in

Email:
Password:
  |  Forgot your password?