Skip to content
TrustList
News

Australia orders federal agencies to stocktake legacy technology and produce risk plans by the end of March 2027

Editorial

By TrustList Editorial

Australia's Home Affairs has directed all non-corporate Commonwealth entities to complete a legacy-technology stocktake and risk management plan by the end of March 2027, after an AI agent reached non-public data on an old government portal.

About Australia orders federal agencies to stocktake legacy technology and produce risk plans by the end of March 2027

Australia orders federal agencies to stocktake legacy technology and produce risk plans by the end of March 2027

30 September 2026 — Australia's Department of Home Affairs has issued a direction requiring federal government entities to find and manage their legacy technology, iTnews reported on 30 September 2026. Protective Security Policy Framework (PSPF) Direction 002-2026 applies to all non-corporate Commonwealth entities.

Not yet independently verified. The details come from an Australian IT outlet's report; the direction itself is published on the protective security site, which did not respond to our requests, so we have not read its text or confirmed its issue date. We will update this when it can be confirmed, and remove this note.

What the direction requires

According to iTnews, entities must complete a stocktake of their legacy technology and a legacy-technology risk management plan by the end of March 2027. They must also set targets to reduce the legacy systems they run, state how they will mitigate the risks of systems they keep, and patch faster.

The report links the direction to an incident in which an AI agent reached non-public data, source code and credentials on an outdated Medicare statistics portal: an example of how automated tools can find weaknesses in old systems far faster than before.

Who is affected

Australian federal departments and agencies, and the IT services companies, systems integrators and software vendors that run, support or modernise their older systems. Vendors with government contracts should expect requests for inventories, support-status information, end-of-life dates and patching commitments, and new modernisation projects once the plans are written.

What to do

  1. Vendors to Australian government: prepare clear information on the support status and end-of-life dates of the products and versions your customers run.
  2. Offer realistic migration paths and compensating controls for systems that cannot be replaced quickly.
  3. Expect shorter patching windows to be written into contracts.
  4. Agencies: start the inventory early; six months is short for large estates.
  5. Read the direction itself on the PSPF site once it is reachable.

Why it matters for buyers

Legacy systems are a security risk everywhere, but AI-assisted attackers make old, unpatched portals easier to find and exploit. A government-wide stocktake with a deadline is likely to drive a wave of modernisation procurement in Australia, and similar requirements are spreading to other governments and regulated sectors.

Sources

Categories & features