---
title: "Managing Legacy Systems: Effective Strategies for Risk Reduction"
description: Discover how Australian government entities must manage legacy technology risks, emphasizing the importance of financial metrics for effective decision-making and planning.
image: https://www.cyquantifi.com/hubfs/legacy-stocktake-retain-or-retire-hero.png
---

[Skip to content](https://www.cyquantifi.com/blog/managing-legacy-systems-effective-strategies-for-risk-reduction#main-content)

[![cyquantifi-horizontal-light](https://www.cyquantifi.com/hubfs/cyquantifi-horizontal-light.svg)Homepage](https://www.cyquantifi.com)

- [Home](https://www.cyquantifi.com)
- [Insights](https://www.cyquantifi.com/blog)
  
    - [Product](https://www.cyquantifi.com/product)
      
          - [Cyber Risk Quantification](https://www.cyquantifi.com/transform-cyber-risk-into-financial-insights-actionable-threat-modeling-cyquantifi)
          - [Packet Capture Appliance](https://www.cyquantifi.com/cyquantifi-capture-appliance-dollarised-risk-on-site)
- Services
  
    - [Supply Chain Risk Assessment](https://www.cyquantifi.com/third-party-supply-chain-cyber-risk-quantification)
    - [IRAP and E8](https://www.cyquantifi.com/irap-assessments-essential-eight-uplift)
    - [SOCI CIRMP](https://www.cyquantifi.com/cyber-risk-quantification-for-soci-cirmp-compliance)
- CyQuantiFi vs
  
    - [Avertro](https://www.cyquantifi.com/cyquantifi-vs-avertro)
    - [Safe Security](https://www.cyquantifi.com/cyquantifi-vs-safe-security)
    - [CYE](https://www.cyquantifi.com/cyquantifi-vs-cye)
    - [6clicks](https://www.cyquantifi.com/cyquantifi-vs-6clicks)
    - [Cybercube](https://www.cyquantifi.com/cyquantifi-vs-cybercube)
- [About](https://www.cyquantifi.com/about)
  
    - [Contact Us](https://www.cyquantifi.com/contact-us)
    - [Careers](https://www.cyquantifi.com/careers)

[Book a Demo](https://www.cyquantifi.com/demo)

- [Home](https://www.cyquantifi.com)
- [Insights](https://www.cyquantifi.com/blog)
  
    - [Product](https://www.cyquantifi.com/product)
      
          - [Cyber Risk Quantification](https://www.cyquantifi.com/transform-cyber-risk-into-financial-insights-actionable-threat-modeling-cyquantifi)
          - [Packet Capture Appliance](https://www.cyquantifi.com/cyquantifi-capture-appliance-dollarised-risk-on-site)
- Services
  
    - [Supply Chain Risk Assessment](https://www.cyquantifi.com/third-party-supply-chain-cyber-risk-quantification)
    - [IRAP and E8](https://www.cyquantifi.com/irap-assessments-essential-eight-uplift)
    - [SOCI CIRMP](https://www.cyquantifi.com/cyber-risk-quantification-for-soci-cirmp-compliance)
- CyQuantiFi vs
  
    - [Avertro](https://www.cyquantifi.com/cyquantifi-vs-avertro)
    - [Safe Security](https://www.cyquantifi.com/cyquantifi-vs-safe-security)
    - [CYE](https://www.cyquantifi.com/cyquantifi-vs-cye)
    - [6clicks](https://www.cyquantifi.com/cyquantifi-vs-6clicks)
    - [Cybercube](https://www.cyquantifi.com/cyquantifi-vs-cybercube)
- [About](https://www.cyquantifi.com/about)
  
    - [Contact Us](https://www.cyquantifi.com/contact-us)
    - [Careers](https://www.cyquantifi.com/careers)

[Book a Demo](https://www.cyquantifi.com/demo)

![](https://www.cyquantifi.com/hs-fs/hubfs/legacy-stocktake-retain-or-retire-hero.png?width=1200&height=630&name=legacy-stocktake-retain-or-retire-hero.png)

cyber pspf

# Managing Legacy Systems: Effective Strategies for Risk Reduction

![Sam Keogh](https://7528315.fs1.hubspotusercontent-na1.net/hub/7528315/hubfs/raw_assets/public/mV0_d-cms-elevate-theme_hubspot/elevate/images/avatar-placeholder.jpg?width=48&height=48&name=avatar-placeholder.jpg)

 Sam Keogh

October 5, 2026

9 MIN READ

 

On 30 September 2026 the Department of Home Affairs issued PSPF Direction 002-2026. It orders every non-corporate Commonwealth entity to take a stocktake of its legacy technology, write a Legacy Technology Risk Management Plan, and set targets for reducing the legacy estate. The deadline is 31 March 2027, and for entities that run what the direction calls systems of government significance, the stocktake is due earlier, by 31 December 2026 ([iTnews](https://www.itnews.com.au/news/home-affairs-orders-gov-wide-legacy-system-stocktake-within-six-months-629313); [TechPartner](https://www.techpartner.news/news/govt-orders-legacy-tech-stocktake-to-counter-ai-enabled-cyber-risks-629326)).

The direction, issued under Secretary Stephanie Foster, states that the continued operation of vulnerable legacy technology systems "poses an unacceptable risk to the Australian Government" ([GovTech Review](https://www.govtechreview.com.au/content/gov-security/news/home-affairs-issues-new-pspf-direction-in-wake-of-medicare-incident-246372498)). Marles, named as Acting Home Affairs Minister in coverage of the announcement, put it more plainly: "We can't wait for an old system to fail before replacing it" ([PS News](https://psnews.com.au/home-affairs-orders-government-wide-review-of-legacy-systems-in-wake-of-ai-breach/186208/)). The trigger was the OpenAI agent incident on a Medicare data portal, which we covered in [It wasn't an attack. That's why your risk register is wrong.](https://www.cyquantifi.com/blog/it-wasnt-an-attack.-thats-why-your-risk-register-is-wrong)

This post is about the part of the direction that comes after the list. The stocktake is the easy deliverable. Every agency can produce a spreadsheet of old systems. The hard one is the plan: targets for reducing the legacy estate, strategies for prioritising the work, and mitigations for the legacy systems you keep, as the trade reports describe it ([TechPartner](https://www.techpartner.news/news/govt-orders-legacy-tech-stocktake-to-counter-ai-enabled-cyber-risks-629326)). Somebody has to decide which systems go first and which stay. On what evidence?

**Scope note.** None of the reporting on the direction mentions a dollar figure for any system. It describes reduction targets and mitigations for what is retained. Our argument is that you cannot do either defensibly without one. We could not open the primary text on protectivesecurity.gov.au when this post was researched, so the requirements above come from the trade reports cited. Check the direction itself for the exact wording.

## A stocktake can't tell you what to retire

A stocktake produces a flat list. Every row has the same status: legacy. Operating system out of support, vendor no longer patching, protocol older than the person maintaining it. The list is accurate, and it is nearly useless for the decision the direction asks next.

Consider what an agency does with it. It has finite budget and finite migration capacity. Retiring a system means funding a replacement, running both in parallel, retraining staff, and in some cases re-accrediting. So the agency retires some and keeps the rest. The direction calls the second group "retained", and expects controls around them.

The pressure in that moment is to rank by what is visible. Count the vulnerabilities, check the vendor support date, note which systems face the public. Those are reasonable inputs. They are not a measure of loss. A public-facing system holding nothing of consequence can be worth far less than an internal system that three critical services quietly depend on. Severity is not risk, and a count is not a target.

Same legacy list, two viewsThe stocktakeEvery row says the same thingA Records database, unsupportedLEGACYB Workstation fleet, end-of-life OSLEGACYC Vendor-run control gatewayLEGACYD Public portal, ageing stackLEGACYRanked by annual lossIllustrative ranges, not client data$0M$1M$2M$3M$4M$5MABCDAll four rows read "legacy". The four ranges do not look alike. CyQuantiFi · Put a dollar figure on every cyber risk — even the ones you can't scan.

Illustrative only. Four hypothetical legacy systems with made-up annual-loss ranges, to show how a flat list and a ranked view differ. Not client data.

There is a second problem with count-based targets. "Reduce legacy systems by 30 per cent" can be met by retiring the three easiest, cheapest and least consequential systems. The number goes down and the risk does not. A target set in dollars of annual loss cannot be gamed that way, because the easy retirements barely move it.

## Legacy is an unscannable asset with a different label

Here is why the ranking is hard. The defining property of a legacy system is that the tools you use to assess modern systems do not work on it. It cannot run an agent. It may not tolerate an active scan, and in some environments a scan is a safety or availability event. Its vendor may no longer publish advisories. Its logs may not exist or may not be read.

That is the same set of constraints that defines an unscannable asset: operational technology, air-gapped networks, classified systems, embedded devices. We wrote about what happens when the air gap turns out not to be one in [When the air gap stopped existing](https://www.cyquantifi.com/blog/when-the-air-gap-stopped-existing). Legacy sits in the same family. The scanner-driven risk programme cannot see it, so it either gets rated by gut or gets left off the register.

Ask a scanner-based tool for a risk figure on a legacy records system and you get silence. Ask a room of people who know the system, and you get strong, disagreeing opinions. The second source is the only one available, so the question becomes how to use it well.

## Retained systems share weather

The direction speaks of retained systems as a group. They should be modelled as a group too, because legacy systems rarely fail independently. They share a vendor whose support ended, a network segment nobody has reorganised since it was built, a service account that unlocks three of them, a patch window that nobody can open.

Risk registers record each of those as a separate line with its own "likelihood". That treats every system as rolling its own dice. In practice, when a threat actor develops reliable access to one family of ageing software, every system running it is exposed in the same season. We call that shared weather. A calm season costs little. A stormy one hits many systems at once, and the loss at the bad end of the range is larger than the sum of independent estimates would suggest.

This is why the total across the retained estate matters more than any single line. A board or a secretary signing the plan is accepting a combined position, not forty separate ones. If your method adds up independent numbers, it will understate the worst year, which is the year the plan exists for.

## What a defensible number looks like

A number for a legacy system has to survive one test: someone senior, sceptical and informed asks "why that?" and you can answer in the room. Three properties help.

| Property | What it means | Why it matters for legacy |
| --- | --- | --- |
| A range, not a point | Low, most likely, and high annual loss, with a stated confidence | There is no telemetry to narrow it. Pretending to precision is the first thing a reviewer will attack. |
| Calibrated experts | Estimates from people who know the system, weighted by how well their past estimates held up | The only data source is people. Their track record is the only quality control available. |
| Assumptions on the page | Each estimate carries the scenario, the dependencies and the reasoning, so it can be challenged and updated | A number that cannot be re-run when a fact changes is a guess with decimals. |

None of this needs a new framework. FAIR gives you a respectable vocabulary: how often a loss event happens and how much it costs. The difference is where the inputs come from when the asset cannot be instrumented. Structured expert elicitation, with calibration tracked over time, is the approach behind a risk quantification framework I built at Defence, one the Royal Australian Navy uses. The CyQuantiFi platform is a different build, but that is the lineage it comes from.

> *If a reduction target cannot be expressed in dollars, it can be met without reducing anything.*

Then the plan almost writes itself. Rank retained and retiring systems by combined annual loss. Spend retirement budget where the number falls fastest. Put mitigations around what stays, and show the number before and after the control. When the secretary, the audit committee or Parliament asks why system D went first, the answer is a range, a reason and a name, not a heatmap colour.

## Five things worth doing before 31 December

The 31 December date applies to stocktakes for systems of government significance. Everyone else has until 31 March. Either way, the work that decides whether the plan is any good happens early.

1

#### Split the stocktake by what you can and cannot measure

Tag every legacy system as scannable or unscannable at the start. The unscannable group needs a different method, and finding that out in March is too late.

2

#### Name the people who actually know each system

For each retained system, list the two or three people who can describe how it fails. They are your evidence base. If that list is one person, that is itself a finding.

3

#### Write targets in dollars of annual loss, not counts of systems

A count rewards easy retirements. A dollar target forces the conversation about which systems carry the loss.

4

#### Map what the retained systems share

Vendors, network paths, credentials, patch windows. Shared dependencies are where several systems move together, and where your worst year comes from.

5

#### Pre-write the retain decision

For every system kept, record the range, the confidence, who contributed, the controls, and a review date. When the number changes, the decision gets reopened on a schedule, not by an incident.

## The bottom line

Home Affairs has done the useful thing of making legacy technology a named, dated obligation across government. A stocktake is the right first step, and agencies will deliver it.

The difficulty is what follows. A flat list tells you what is old. It does not tell you what is expensive to keep, and the direction asks agencies to make precisely that call on systems that cannot be scanned, queried or easily replaced. The honest answer is a calibrated range from people who know the system, aggregated across the estate so the worst year is not understated.

Private operators with legacy OT and ageing records platforms are watching this direction as a signal of where regulators are heading. The same method applies to them, with the same constraint: the systems that carry the most consequence are often the ones with the least data.

**A legacy system you cannot retire is a number you have not priced yet.**

### Bring one asset you can't scan.

We'll put a number on it in 30 minutes. Or come to the talk on crowd forecasting for cyber risk at AISA CyberCon on 16 October.

[Book a 30-minute conversation →](https://cyquantifi.com/demo) [See the platform →](https://cyquantifi.com/product)

### Related reading

- [PSPF Direction 002-2026, Strengthening Commonwealth Cyber Posture Against AI-Enabled Risks](https://www.protectivesecurity.gov.au/publications-library/direction-002-2026-strengthening-commonwealth-cyber-posture-against-ai-enabled-risks) (Protective Security Policy Framework; not rendered in this run, so read the source directly)
- [Home Affairs orders gov-wide 'legacy' system stocktake within six months](https://www.itnews.com.au/news/home-affairs-orders-gov-wide-legacy-system-stocktake-within-six-months-629313) (iTnews)
- [Home Affairs issues new PSPF Direction in wake of Medicare incident](https://www.govtechreview.com.au/content/gov-security/news/home-affairs-issues-new-pspf-direction-in-wake-of-medicare-incident-246372498) (GovTech Review)
- [When the air gap stopped existing](https://www.cyquantifi.com/blog/when-the-air-gap-stopped-existing) (CyQuantiFi)
- [The CyQuantiFi platform](https://cyquantifi.com/product)

## Share this post

<https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fwww.cyquantifi.com%2Fblog%2Fmanaging-legacy-systems-effective-strategies-for-risk-reduction><https://twitter.com/intent/tweet?url=https%3A%2F%2Fwww.cyquantifi.com%2Fblog%2Fmanaging-legacy-systems-effective-strategies-for-risk-reduction><https://www.linkedin.com/shareArticle?mini=true&url=https%3A%2F%2Fwww.cyquantifi.com%2Fblog%2Fmanaging-legacy-systems-effective-strategies-for-risk-reduction><https://pinterest.com/pin/create/button/?url=https%3A%2F%2Fwww.cyquantifi.com%2Fblog%2Fmanaging-legacy-systems-effective-strategies-for-risk-reduction>[mailto:https%3A%2F%2Fwww.cyquantifi.com%2Fblog%2Fmanaging-legacy-systems-effective-strategies-for-risk-reduction](mailto:https%3A%2F%2Fwww.cyquantifi.com%2Fblog%2Fmanaging-legacy-systems-effective-strategies-for-risk-reduction)

## Keep reading

### [![](https://www.cyquantifi.com/hs-fs/hubfs/1000010594.png?width=1200&height=630&name=1000010594.png) cyber It wasn't an attack. That's why your risk register is wrong.](https://www.cyquantifi.com/blog/it-wasnt-an-attack.-thats-why-your-risk-register-is-wrong)

### [![](https://www.cyquantifi.com/hs-fs/hubfs/CyberCon.png?width=1280&height=720&name=CyberCon.png) CyQuantiFi at AISA CyberCon 2026](https://www.cyquantifi.com/blog/cyquantifi-at-aisa-cybercon-2026)

[![cyquantifi-horizontal-dark](https://www.cyquantifi.com/hubfs/cyquantifi-horizontal-dark.svg "cyquantifi-horizontal-dark")](https://www.cyquantifi.com)

<https://www.linkedin.com/company/cyquantifi>

---

[Privacy Policy](https://www.cyquantifi.com/privacy-policy) · [Legal](https://www.cyquantifi.com/terms-of-use)· [Patents Pending](https://www.cyquantifi.com/patents) · CyQuantiFi Pty Ltd © 2026. All rights reserved.

[☎️ 02 5747 4163](tel:+61257474163)

ABN: 67 697 329 105

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Sam Keogh",
    "url" : "https://www.cyquantifi.com/blog/author/sam-keogh"
  },
  "dateModified" : "2026-10-05T01:56:49.673Z",
  "datePublished" : "2026-10-05T01:56:49.000Z",
  "headline" : "Managing Legacy Systems: Effective Strategies for Risk Reduction",
  "image" : [ "https://www.cyquantifi.com/hubfs/legacy-stocktake-retain-or-retire-hero.png" ],
  "mainEntityOfPage" : {
    "@id" : "https://www.cyquantifi.com/blog/managing-legacy-systems-effective-strategies-for-risk-reduction",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://www.cyquantifi.com/hubfs/cyquantifi.png"
    },
    "name" : "CyQuantiFi Pty Ltd"
  }
}
```