Skip to main content Skip to footer site map
Updates

Past its use-by-date: Turning end-of-life technology risk into national advantage : Australian Strategic Policy Institute , July 28 , 2026

July 28, 2026

Australian Strategic Policy Institute

Download PDF

From the report: “We’re quietly failing a test most don’t know we’re sitting. Across governments and industry, including critical infrastructure sectors such as energy, health and telecommunications, the everyday reality is that technology systems designed for the threat environments of the 1990s or 2000s continue to carry live operational demands into the 2030s. Some systems no longer receive security patches. Others remain operational but have no road map for post-quantum cryptography, modern identity standards, secure management protocols, secure boot, zero-trust integration or advanced telemetry. The result isn’t managed risk. It’s inherited exposure, accumulating without a named owner, a funded exit, or a threshold for action.

What’s changed isn’t the problem’s existence but the speed and scale at which vulnerable systems can now be identified, targeted and exploited. Leading cybersecurity experts suggest we’ve crossed the Rubicon on cyber risk—that the threshold between human-paced attack and machine-speed, network-scaled attack has passed a point of no return with Anthropic’s Mythos, OpenAI’s GPT-5.5 and whatever comes next. Advances in offensive artificial intelligence (AI) capability are compressing the time between vulnerability discovery and operational exploitation—in some cases to a window measured in hours, not days. Cisco Talos finds that nearly 40% of the most actively targeted vulnerabilities affect end-of-life devices. For systems that will never receive another patch, this isn’t a narrowing window; it’s no window at all. State-sponsored actors have already demonstrated persistent access to critical infrastructure through precisely this vector, and AI-enabled tooling is accelerating this asymmetry: what once required deep technical expertise is now more accessible, adaptable and deployable by a wider range of threat actors at significantly greater speed.”

Authors - Van der Schyff, Jason

Subjects

Authors

Van der Schyff, Jason

Publishers

Australian Strategic Policy Institute

Format

PDF - Download

Related Resources

s