Wednesday, July 29, 2026

Introducing the Legacy 5: Turning Finish-of-Life Know-how Threat into Nationwide Benefit

At Cisco, we consider safe connectivity is foundational to financial resilience, nationwide safety and public belief. The networks and digital programs supporting governments, important infrastructure, companies and communities are not simply operational belongings. They’re strategic infrastructure — underpinning how international locations ship important companies, defend information, allow innovation and take part within the digital economic system. That’s the reason their lifecycle issues.

Every successive era of know-how is turning into safer. As they’re adopted and used, they may help organisations grow to be safer too. Every new wave of innovation brings stronger capabilities: richer telemetry, higher encryption, stronger id, automated detection, secure-by-design architectures and extra resilient methods to attach customers, information, functions and infrastructure. These advances give organisations larger visibility, management and confidence — however solely when they’re deployed, maintained and ruled over their full lifecycle.

Throughout many governments and significant infrastructure, nevertheless, programs designed for earlier risk environments proceed to hold important companies into the 2030s — usually with out safety patches, trendy id controls, superior monitoring or a viable path to future safety requirements. That’s now a strategic threat.

The Rising Threat of Legacy Techniques

That is the central problem examined within the Australian Strategic Coverage Institute’s new report, “Previous its use-by-date: Turning end-of-life know-how threat into nationwide benefit”, funded by Cisco. The report argues that end-of-life know-how isn’t merely a technical drawback. It’s a governance drawback — and, if addressed effectively, a strategic alternative. Importantly, the report additionally launches the “Legacy 5”: a sensible framework for governments and enterprises to make lifecycle threat seen, accountable and actionable.

The report’s message is evident: performance isn’t the identical as defensibility. A system should function, but when it might probably not be patched, monitored, segmented, upgraded or built-in into trendy safety architectures, it creates publicity defenders can not afford.

Cisco Talos’ 2025 Yr-in-Evaluation findings sharpen the purpose. Talos discovered that just about 40 % of probably the most actively focused vulnerabilities have an effect on end-of-life units. It additionally noticed that risk actors proceed to use vulnerabilities which might be a few years previous, together with flaws greater than a decade previous, notably in networking and edge infrastructure. Unsupported and ageing programs stay enticing, sensible and chronic pathways into important environments.

Throughout the Indo-Pacific, international locations are confronting the identical lifecycle problem from completely different beginning factors.

  • In South Koreafast digitisation has created deep dependency on legacy programs that may be tough and dear to unwind.
  • Within the Philippinesprocurement, price range and capability constraints could make it tough to keep up assist or fund well timed alternative.
  • In Indialifecycle governance is progressing erratically, with stronger controls rising in energy and monetary companies, whereas broader fragmentation nonetheless poses threat.
  • In Australiasturdy frameworks — together with Horizon 2 of the Cyber Safety Technique, the Protecting Safety Coverage Framework, and Safety of Essential Infrastructure reforms — present the significance of turning coverage maturity into measurable execution.

The issue is accelerating. AI-enabled cyber functionality is compressing the time between vulnerability discovery and exploitation. On the identical time, post-quantum cryptography, IT–OT convergence and rising dependency on digital infrastructure are widening the results of delay.

Legacy know-how threat is usually the results of rational decisions remodeled time: prioritising new functionality, continuity and restricted sources whereas deferring alternative of programs that also operate. However because the risk surroundings accelerates, these decisions can compound shortly, forcing motion later below larger strain and on much less beneficial phrases.

That is the place ASPI’s report makes its most vital contribution. It reframes end-of-life know-how by highlighting gaps equivalent to unclear possession, unfunded exits, weak procurement indicators, and no enforceable threshold for motion, governance gaps which might be inherent in all digitizing international locations. The Legacy 5 gives a sensible option to reply — with parallel actions for presidency policymakers and enterprises.

The Legacy 5: A Framework for Motion

For presidency policymakers, the precedence is to make lifecycle governance seen, enforceable and embedded into regulation and procurement. The Legacy 5 for governments contains:

  1. Requiring lifecycle registers for high-consequence programs — so governments and regulators know which applied sciences are approaching or previous finish of assist, who owns the danger and what transition plan is in place.
  2. Setting consequence-based requirements — making certain probably the most important programs, together with these supporting important companies, public security or nationwide safety, are topic to stronger necessities to exchange, isolate or mitigate unsupported know-how.
  3. Embedding lifecycle obligations into procurement — requiring distributors to reveal assist timelines, end-of-support dates, and transition pathways on the level of acquisition.
  4. Requiring accountability and funded transition plans — linking lifecycle publicity to assurance, audit and incident-reporting processes, and making certain high-consequence unsupported programs have a funded pathway to exchange, remediate or handle the danger.
  5. Enabling transition by means of incentives and coordination — offering steering, co-funding the place applicable, and coordinated applications that assist operators modernise with out disrupting important companies.

For enterprises, end-of-life threat must be ruled as an enterprise threat — not left as an IT problem. The Legacy 5 for enterprises means:

  1. Realizing what know-how they’ve — together with which programs are unsupported or nearing finish of assist.
  2. Prioritising motion primarily based on consequence — not simply age or upkeep price, however the potential affect on important companies, security, prospects, information and operations.
  3. Requiring formal “replace-or-mitigate” choices — earlier than programs attain end-of-support milestones.
  4. Assigning clear accountability — so unsupported programs don’t proceed by default, however are owned by a named decision-maker with duty for residual threat, compensating controls and transition planning.
  5. Funding transition earlier than disaster forces motion — treating modernisation as a part of long-term resilience and capability-building, not as an emergency response after an incident.

Modernisation as a Catalyst for Resilience

This isn’t solely a threat agenda; it is a chance agenda. Modernisation offers defenders larger visibility, stronger management and the muse for accountable AI-enabled defence — serving to organisations determine publicity, prioritise remediation and reply quicker.

The selection earlier than decision-makers isn’t whether or not to speculate. It’s whether or not to speculate intentionally, earlier than incidents, outages or adversaries drive the phrases of transition. Finish-of-life know-how threat isn’t inevitable. It’s governable — and with the suitable management, requirements and partnerships, it might probably grow to be a catalyst for resilience and long-term strategic benefit.

Learn the report: right here.

Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles