Legacy technology exposure gives brokers a new placement question
A client who cannot map their legacy technology exposure presents a different risk at placement. Australia’s peak signals intelligence body has now stated publicly why that gap is becoming more consequential – and the data behind the warning gives brokers something specific to raise.
The Australian Signals Directorate’s (ASD) chief made the assessment at the Australian Strategic Policy Institute’s Sydney Dialogue AI Masterclass last week. Security and risk leaders who responded were consistent: artificial intelligence has not created a new threat category. It has closed the window between a known vulnerability and an active attack.
For clients running systems they cannot quickly patch or replace, that window is now narrower than most boards appreciate.
The evidence is already in the ASD’s own numbers
The ASD’s Annual Cyber Threat Report 2024-25 recorded more than 1,200 cybersecurity incidents responded to by the Australian Cyber Security Centre (ACSC) last financial year – an 11% year-on-year rise. The number of proactive notifications to critical infrastructure entities of potentially malicious cyber activity increased 111%. Publicly reported common vulnerabilities and exposures rose 28%, with the report identifying legacy IT explicitly among the systems “most difficult for network defenders to secure effectively.”
The report’s four recommendations to Australian network operators include a direct instruction to “replace legacy IT” – not manage around it, but replace it.
The business harm is also widening. The Australian Institute of Criminology’s (AIC) Cybercrime in Australia 2025 report found one in four small and medium businesses reported being a victim of cybercrime in the past year. The share reporting that cybercrime caused staffing consequences nearly doubled in 12 months.
Read next: APRA’s chair just linked AI to cyber risk. World’s top regulator just said the same thing
The placement question this raises
Aon’s head of cyber solutions for Australia, Quinton Kotze, put the issue in terms that connect directly to broker conversations. “Ageing technology should be viewed as a business resilience exposure, not simply an IT maintenance issue. Boards need visibility of these exposures and a clear plan to manage and reduce them over time,” Kotze said.
“The choice is often between investing in modernisation today or accepting greater cyber risk in the future,” he added.
A client who can demonstrate active remediation – mapped exposures, documented controls, a sequenced modernisation plan – is a different submission than one who cannot. That distinction is becoming more material as claims activity rises in sectors where legacy infrastructure is common.
Fortinet’s Glenn Maiden, chief security officer and director of threat intelligence for Australia and New Zealand, described how the threat dynamic has shifted. “AI is compressing the time organisations have to deal with existing cyber risk. AI-assisted attackers can exploit known vulnerabilities, weak access controls, insecure configurations, and exposed legacy systems at far greater speed and scale,” Maiden said.
On what the response requires: “There is no single technology that solves this challenge. The response remains defence in depth: maintaining visibility of assets and exposures, patching where possible, rigorously managing identities and access, segmenting networks, monitoring continuously, and putting compensating controls around systems that cannot be immediately remediated.”
Where the exposure is most concentrated
For operators of essential services – utilities, healthcare, transport – the problem is structural. Taking systems offline is often not operationally viable, which means risk accumulates around infrastructure that cannot be remediated on a standard timeline.
Kinetic IT’s chief transformation officer, Kishore Jayaram, said the priority is consequence-mapping rather than wholesale replacement. “It means identifying which systems and dependencies would carry the greatest consequence if compromised or disrupted, strengthening controls around them, and sequencing modernisation so security and resilience improve while essential services remain available,” he said.
The healthcare figures from the ASD report make the stakes plain. Malicious actors succeeded in 95% of healthcare and social assistance incidents the ACSC responded to last financial year, compared with around 52% across all sectors. Ransomware incidents targeting healthcare doubled in the same period.
Australian cyber premiums fell approximately 10% through 2025, according to EBM Insurance and Risk’s May 2026 market outlook. Australian Prudential Regulation Authority (APRA) data shows three consecutive quarters of positive underwriting results for the cyber class.
Lower prices have not driven take-up. The AIC’s 2025 survey put cyber insurance uptake at 3.7% of respondents – down from 4.6% the prior year.
The Insurance Council of Australia (ICA) has identified risk literacy as the barrier. In its September 2025 submission to the federal government on Australia’s Cyber Security Strategy, ICA CEO Andrew Hall said: “While large businesses generally understand cyber risks well, our challenge now is improving cyber hygiene among individual Australians and small businesses.”
Hall added: “Improving cyber literacy will help SMB decision-makers balance insurance costs with preventive measures, which can positively influence their insurance premiums.”
That is the opening for brokers. The ASD warning, the AIC data on SMB harm, and mandatory ransomware reporting – in force since May 30, 2025, for businesses with annual turnover of $3 million or more under the Cyber Security Act 2024 – provide three concrete talking points for clients who have deferred the conversation.
Read next: AI cyberattacks outpace Australian firms’ defences
A coverage question worth raising at renewal
Jayaram raised a further issue: agentic AI – automated systems operating inside business workflows with reduced human oversight – as an exposure existing policy language may not have been written to address. “AI is increasingly becoming part of an organisation’s operational fabric, creating new dependencies across data, workflows, identity, platforms, and controls. Those harnesses should be engineered from the ground up to ensure humans are not just in the loop; human oversight should remain in control, so accountability is never delegated,” he said.
Policy wordings drafted before autonomous processes became common in day-to-day operations may contain gaps around liability when an automated system causes or enables a breach – including questions of who is accountable when no person made the relevant decision. For brokers, it is a specific question worth putting to underwriters at renewal, particularly for clients in sectors moving quickly to automate.
Related Stories
Technology
Munich-based Arcos raises €5.5 million to build and operate civil safety infrastructure across Europe
34 seconds ago
Technology
Uzbekistan, S.Korean KISED explore soft
37 seconds ago
Technology
SUNY funding to advance tech that could improve patient care
1 minute ago
Technology
Revealed: how Russia uses mobile ‘super
1 hour ago
Technology
Finvolve marks Rs 90 crore first close of Rs 250 crore fund to back defence, aerospace and deeptech startups
2 hours ago
Technology
UPI MDR puts payment fintech startups back on investors’ radar, VCs brace for higher valuations
2 hours ago
Technology
Guernsey, Jersey and Isle of Man issue smart glasses warning
3 hours ago
Technology
Why planners need to be proactive about drones
3 hours ago