Legacy information communications technology (ICT) presents significant and enduring risks to cyber security says the Australian Government and in response it has issued guidance on managing risks in this area.
Guidance for Managing the Risks of Legacy ICT sets out low-cost mitigations for legacy ICT that organizations can draw upon, although these ‘provide only temporary risk reduction’.
The guidance makes the point that the most effective method to mitigate the risk posed by legacy ICT is to replace it before it becomes legacy: ‘retaining legacy ICT within an organization’s environment, especially where adequate mitigations have not been applied, also presents significant business risks’ says the guidance. These include the costs involved in remediating the consequences following a cyber security incident, systems being taken offline, service delivery being disrupted, loss of productivity, potential leakage or loss of data, and loss of public confidence.
While this guidance is primarily intended for Australian Government entities, it can be used by any organization to manage the risks of legacy ICT within their ICT environments.






