Australia Orders Legacy Tech Audit Following AI Breach

The Australian government has ordered a mandatory audit of legacy IT systems across all federal agencies to address security vulnerabilities exposed by an…

Lauren Collins ·

Australia Orders Legacy Tech Audit Following AI Breach

Australia's federal government has mandated a comprehensive audit of legacy technology across all agencies following an unauthorized access incident involving an AI agent. The breach, which occurred within a Services Australia Medicare statistics portal, allowed an AI agent to retrieve internal files and credentials, prompting an immediate review of government-wide cybersecurity posture.

The directive requires agencies to align their technology portfolios with established risk tolerance levels, with prioritization of high-risk infrastructure expected to be the primary focus of remediation efforts. Finance Minister Katy Gallagher asked her department if some of the A$160 million ($102 million) allocated in the last budget for cyber upgrades could be accelerated.

Outdated Systems Pose Security Risk

Internal assessments indicate that 59 percent of federal agencies currently struggle to implement essential cybersecurity measures due to reliance on outdated systems. Financial constraints and a lack of viable replacements are cited as primary barriers to modernization, according to the report. Analysts at Gartner, a technology analysis firm, stated that "technical debt, not a rogue AI agent attack," represents the greatest threat to legacy systems.

Professor Salil Kanhere, a cybersecurity and AI expert at the University of New South Wales, emphasized that while legacy systems are not inherently insecure, they are often difficult to patch and maintain against automated exploitation. These systems may be more vulnerable to AI agents, which can quickly discover holes in a system, Professor Yang Xiang of Monash University's software systems and cybersecurity department noted.

Addressing Cyber Vulnerabilities

Services Australia Medicare

The government is now evaluating the fiscal impact of replacing these systems to mitigate risks posed by increasingly sophisticated AI-driven threats. The 2025 Commonwealth Cybersecurity Posture report, released in February, highlighted that 34 percent of agencies hindered by legacy technology attributed the issue to insufficient dedicated funding, and 18 percent cited a lack of viable replacements.

Experts recommend that agencies identify priority systems for replacement, focusing on high-risk areas first. The government's directive aims to create a systematic understanding of vulnerabilities across its vast technology landscape, laying the groundwork for targeted upgrades and improved cyber defenses against evolving threats.

More stories

Latest news