NSW Audit Office finds agency legacy system cybersecurity risk

By Joshua Gliddon on Aug 14, 2026 8:17AM
NSW Audit Office finds agency legacy system cybersecurity risk

The NSW Audit Office has issued a report into internal controls and governance covering consultants, purchasing cards and technology within 26 of the NSW government’s largest agencies.

Key findings of the report include that there are significant gaps in cybersecurity policy compliance, with some agencies failing to assess legacy system risks, as well as the strategic use and assurance of AI is limited.

The Audit Office found many agencies have limited visibility over AI use as they did not consistently register all AI use cases or centrally track costs. Additionally, the AO reports governance is not keeping pace with the speed at which agencies are adopting AI.

With the cybersecurity policy adherence, the AO discovered less than half of the agencies examined reported compliance with requirements to protect and govern their risk exposure.

Agencies are also not effectively engaging or reporting on consultants, while 13 percent of sampled engagements did not include clauses relating to confidentiality to protect government information.

The report makes several recommendations, including agencies strengthening their stewardship of public funds for their grant programs; improve their cybersecurity by assessing legacy system risk; and strengthening AI governance by assessing all AI solutions against the NSW AI Assurance Framework.

Got a news tip for our journalists? Share it with us anonymously here.
Copyright © nextmedia Pty Ltd. All rights reserved.

Add techpartner.news as your trusted source

Tags:

Log in

Email:
Password:
  |  Forgot your password?