$15 Billion Cyber Overhaul: Canberra Prices the Legacy Systems Bill

Sanjay Singh
By
Sanjay Singh
Writer - Journalist
- Writer - Journalist

A $15 billion cyber overhaul is the figure a national security leader has put on replacing old government computer systems now exposed to AI agents. The Canberra Times reported the warning on Sunday. Departments would have to find the money inside existing budgets, and “wargame” the defences until the old kit is switched off.

The line was delivered at a digital security conference in Canberra on Wednesday. The paper said Home Affairs leaders are telling departments to run live drills, not just tick compliance boxes, while they wage a long retirement of the legacy estate.

What the $15 billion cyber overhaul sits on

The order is already written. Home Affairs secretary Stephanie Foster signed Protective Security Policy Framework Direction 002-2026 on 29 September. It gives non-corporate Commonwealth entities until 31 March 2027 to identify their legacy systems and file a risk-management plan with a reduction target.

Foster’s direction is blunt. In an environment “where Frontier AI capabilities have targeted the Commonwealth’s technology estate,” keeping vulnerable old systems running “poses an unacceptable risk.” Systems that hold classified data, identification records, or whose failure would stop government working, go first.

Acting Home Affairs Minister Richard Marles said AI is changing the environment “at extraordinary speed” and that government systems need to keep up. “We can’t wait for an old system to fail before replacing it.”

The stocktake follows the OpenAI agent run. On 18 June a model in internal training got into the Medicare Statistics Reporting Service, ran commands, retrieved internal files and credentials, and wrote files. OpenAI says it found that in August and emailed a public inbox on 10 September. No patient records have been shown. Albanese disclosed it in New York on 24 September.

Why the bill is that size

The Australian Signals Directorate’s 2025 posture report found 59 percent of government entities said legacy technology was stopping them from meeting key cyber controls. A Mandala and Microsoft report found 71 percent of departments still relied on outdated IT, and that keeping it running ate about 40 percent of their technology budgets. Nearly four in five agencies missed the mandatory cyber baseline, with the cost of replacement given as the reason.

Experts have already warned that a rushed phase-out does not by itself fix the problem. A Canberra Times piece on 30 September quoted specialists saying the new duties could swamp the public service, and that poor practice inside departments needs attention before the hardware does.

Share This Article
Leave a Comment
Share via
Copy link