At Cisco, we imagine safe connectivity is foundational to financial resilience, nationwide safety and public belief. The networks and digital programs supporting governments, vital infrastructure, companies and communities are not simply operational belongings. They’re strategic infrastructure — underpinning how nations ship important companies, defend knowledge, allow innovation and take part within the digital economic system. That’s the reason their lifecycle issues.
Every successive era of expertise is turning into safer. As they’re adopted and used, they might help organisations develop into safer too. Every new wave of innovation brings stronger capabilities: richer telemetry, higher encryption, stronger identification, automated detection, secure-by-design architectures and extra resilient methods to attach customers, knowledge, purposes and infrastructure. These advances give organisations better visibility, management and confidence — however solely when they’re deployed, maintained and ruled over their full lifecycle.
Throughout many governments and significant infrastructure, nevertheless, programs designed for earlier menace environments proceed to hold important companies into the 2030s — typically with out safety patches, fashionable identification controls, superior monitoring or a viable path to future safety requirements. That’s now a strategic danger.
The Rising Threat of Legacy Programs
That is the central problem examined within the Australian Strategic Coverage Institute’s new report, “Previous its use-by-date: Turning end-of-life expertise danger into nationwide benefit”, funded by Cisco. The report argues that end-of-life expertise will not be merely a technical downside. It’s a governance downside — and, if addressed nicely, a strategic alternative. Importantly, the report additionally launches the “Legacy 5”: a sensible framework for governments and enterprises to make lifecycle danger seen, accountable and actionable.
The report’s message is evident: performance will not be the identical as defensibility. A system should still function, but when it could possibly not be patched, monitored, segmented, upgraded or built-in into fashionable safety architectures, it creates publicity defenders can not afford.
Cisco Talos’ 2025 Yr-in-Overview findings sharpen the purpose. Talos discovered that just about 40 % of probably the most actively focused vulnerabilities have an effect on end-of-life gadgets. It additionally noticed that menace actors proceed to take advantage of vulnerabilities which might be a few years outdated, together with flaws greater than a decade outdated, significantly in networking and edge infrastructure. Unsupported and ageing programs stay enticing, sensible and chronic pathways into vital environments.
Throughout the Indo-Pacific, nations are confronting the identical lifecycle problem from completely different beginning factors.
In South Korea, fast digitisation has created deep dependency on legacy programs that may be troublesome and expensive to unwind.
Within the Philippines, procurement, finances and capability constraints could make it troublesome to take care of assist or fund well timed alternative.
In India, lifecycle governance is progressing inconsistently, with stronger controls rising in energy and monetary companies, whereas broader fragmentation nonetheless poses danger.
In Australia, strong frameworks — together with Horizon 2 of the Cyber Safety Technique, the Protecting Safety Coverage Framework, and Safety of Important Infrastructure reforms — present the significance of turning coverage maturity into measurable execution.
The issue is accelerating. AI-enabled cyber functionality is compressing the time between vulnerability discovery and exploitation. On the identical time, post-quantum cryptography, IT–OT convergence and rising dependency on digital infrastructure are widening the results of delay.
Legacy expertise danger is usually the results of rational decisions remodeled time: prioritising new functionality, continuity and restricted sources whereas deferring alternative of programs that also perform. However because the menace atmosphere accelerates, these decisions can compound shortly, forcing motion later below better stress and on much less beneficial phrases.That is the place ASPI’s report makes its most essential contribution. It reframes end-of-life expertise by highlighting gaps akin to unclear possession, unfunded exits, weak procurement indicators, and no enforceable threshold for motion, governance gaps which might be inherent in all digitizing nations. The Legacy 5 supplies a sensible method to reply — with parallel actions for presidency policymakers and enterprises.
The Legacy 5: A Framework for Motion
For presidency policymakers, the precedence is to make lifecycle governance seen, enforceable and embedded into regulation and procurement. The Legacy 5 for governments consists of:
Requiring lifecycle registers for high-consequence programs — so governments and regulators know which applied sciences are approaching or previous finish of assist, who owns the danger and what transition plan is in place.
Setting consequence-based requirements — guaranteeing probably the most vital programs, together with these supporting important companies, public security or nationwide safety, are topic to stronger necessities to switch, isolate or mitigate unsupported expertise.
Embedding lifecycle obligations into procurement — requiring distributors to reveal assist timelines, end-of-support dates, and transition pathways on the level of acquisition.
Requiring accountability and funded transition plans — linking lifecycle publicity to assurance, audit and incident-reporting processes, and guaranteeing high-consequence unsupported programs have a funded pathway to switch, remediate or handle the danger.
Enabling transition by way of incentives and coordination — offering steering, co-funding the place acceptable, and coordinated applications that assist operators modernise with out disrupting important companies.
For enterprises, end-of-life danger must be ruled as an enterprise danger — not left as an IT challenge. The Legacy 5 for enterprises means:
Realizing what expertise they’ve — together with which programs are unsupported or nearing finish of assist.
Prioritising motion based mostly on consequence — not simply age or upkeep price, however the potential impression on important companies, security, prospects, knowledge and operations.
Requiring formal “replace-or-mitigate” choices — earlier than programs attain end-of-support milestones.
Assigning clear accountability — so unsupported programs don’t proceed by default, however are owned by a named decision-maker with duty for residual danger, compensating controls and transition planning.
Funding transition earlier than disaster forces motion — treating modernisation as a part of long-term resilience and capability-building, not as an emergency response after an incident.
Modernisation as a Catalyst for Resilience
This isn’t solely a danger agenda; it is a chance agenda. Modernisation provides defenders better visibility, stronger management and the muse for accountable AI-enabled defence — serving to organisations establish publicity, prioritise remediation and reply quicker.
The selection earlier than decision-makers will not be whether or not to take a position. It’s whether or not to take a position intentionally, earlier than incidents, outages or adversaries power the phrases of transition. Finish-of-life expertise danger will not be inevitable. It’s governable — and with the precise management, requirements and partnerships, it could possibly develop into a catalyst for resilience and long-term strategic benefit.







.png)










