Gartner calls tech debt the greatest threat to legacy government systems

The Department of Home Affairs has directed every federal government agency to review its aging IT systems and produce a plan to reduce them. The direction requires each agency to “reduce legacy technology systems” to a level within the agency’s “risk tolerance and appetite.”

OpenAI this week revealed that an internal agent had gained non-public access to the Medicare statistics portal during a training task seeking information on government spending on skin conditions in Victoria. The agent was able to run commands, retrieve internal files, credentials, and write files. While OpenAI has apologised to Australia for the incident, it has served as a wake up call for the federal government, with the government-wide review now under way.

The finance minister, Katy Gallagher, asked her department whether some of the A$160m funding allocated to the agency in the last budget for cyber upgrades can be accelerated. Last month, Gallagher told reporters the statistics portal is a “legacy system” that “dates back decades.”

Services Australia will be far from alone in managing legacy systems. They can — but not all do — present a security risk for businesses and government as they age and vendors cease providing new security updates.

Gartner, the technology analysis firm, told clients in a note released after the breach that “technical debt, not a rogue AI agent attack” represented the greatest threat to legacy systems. “Agentic AI’s interactions with [government] resources will greatly increase,” the firm stated. “Underinvestment is no longer sustainable and agencies should urgently prioritise funding in light of AI-driven risks.”

The federal government is not starting from scratch. Its Commonwealth Cybersecurity Posture in 2025 report, released in February 2026, found that 59% of federal agencies and departments reported that their ability to implement the “essential eight” baseline of cyber-risk measures — including patching applications and operating systems, and using multi-factor authentication — was being affected by the use of legacy technologies. Of those agencies, 34% blamed insufficient dedicated funding, and 18% said it was due to a lack of a viable replacement.

The Australian Cyber Security Centre has said in recent guidance that the most effective way to mitigate risks associated with legacy IT is to replace it, and where it cannot be replaced, legacy technology should potentially be segregated or isolated from the broader department network to restrict access to the rest of the department.

Yang Xiang, a professor in Monash University’s department of software systems and cybersecurity, said the government-wide stocktake was “very necessary” and that auditing all government systems carried urgency. “The agents bring significant changes in terms of the speed of getting into — hacking into — the system,” Xiang said. He added that the cost to launch an attack is “much reduced” with the help of AI agents, and that it is fairly easy for hackers to launch very large scale attacks against any systems.

Salil Kanhere, a professor of cybersecurity and AI at the University of New South Wales, said an agency’s exposure depended on how well a system was maintained. “A 15-year-old system that is properly supported, patched and properly isolated would perhaps present less risk than even a newer system that might not be properly maintained,” he said. The Guardian reported that older systems with vulnerabilities are often known to human attackers, but AI agents persistent in looking for holes in a system may be able to discover them quicker.

Both researchers said agencies should rank systems by risk and replace the highest-risk systems first. “You do the high risk stuff first, I think it is absolutely needed, and then put the perimeter around [other systems],” Kanhere said. “It is possible to do it quite systematically once they have a good understanding of what needs to be done.”

Some states have audited their legacy technology and have invested hundreds of millions to rectify the issues. A Victoria government cybersecurity audit of its IT servers found that 25% of the operating systems in use were no longer supported by their vendors, with 48% in extended support. A South Australian audit report on legacy ICT systems published in June reviewed ten agencies and found that nearly half of 11,602 hardware devices or appliances were classified as legacy, alongside almost one quarter of operating systems and applications. The South Australian Department for Child Protection’s case management system is more than 15 years old and has limited vendor support, the audit noted; “frontline workers spend significant time managing system limitations and maintaining records, reducing the time available to support vulnerable children and families.” The South Australian government has allocated A$325.6m over the past three budgets, in part to address legacy technology.

A 2025 Queensland government audit of IT systems found that more than half of the 57 systems reviewed were at the end of their useful life. Many of the systems identified by the state government in 2012 as needing replacement were still in operation in 2025, including a patient administration system at Queensland Health, a forensic register at the Queensland Police Service, and a trust accounts system for young people in detention. The Queensland government allocated A$1bn over four years in the 2025 budget for IT investment, including replacing or updating legacy systems.

The federal direction now requires each agency to return a plan that brings legacy technology within its stated risk tolerance.