Australia's Cyber Chief: Legacy Tech Is the AI Attack Surface
ASD's Bradshaw warned this week that Australia sits on 'an enormous legacy technology debt' — the door AI-powered attacks come through. What SMEs check first.
The warning, in the ASD chief's own words
On Monday, at ASPI's Sydney Dialogue AI Masterclass in Canberra, the head of Australia's Signals Directorate delivered a sentence Australian business owners should read twice. "We are sitting on, in Australia, an enormous legacy technology debt," Abigail Bradshaw said, as reported by ABC News on 15 September 2026.
Her framing was binary. "AI will either do one or the other — it'll be a catalyst for decisions about replacing legacy technology; or, if we don't move fast enough, almost certainly the legacy technology will be the first to be compromised in a major AI-enabled attack." She was speaking to policymakers about state-scale risk. She was also, whether she meant to or not, describing the average Australian SME's tech stack. Bradshaw's second call — for a formal AI "early warning system" of the sort Australia already has in a cyber context — sits on top of that. The government does not yet know how many AI agents are operating on the internet at any moment. Neither does anyone else.
What 'legacy tech' actually looks like inside an SME
The word "legacy" sounds like a mainframe problem. It isn't. Legacy is the accounting software that stopped getting security patches two versions back. The CRM you can't migrate off because the export function was never finished. The on-premises PBX still in the cupboard because the port took a fortnight and nobody wanted the outage. The Windows 10 machine on reception. Each one is a public-facing service running yesterday's assumptions about what an attacker could reach at scale.
The OECD's 2026 D4SME survey found 46 per cent of SMEs have no meaningful digital security — while 61 per cent are already using AI tools that touch their business data. Bradshaw's binary lands on that group first. The ASD's own numbers, from its Annual Cyber Threat Report 2024–25, sharpen the picture: the average self-reported cybercrime cost per small-business report is now $56,600 — up 14 per cent year on year — and the agency logs one cybercrime report every six minutes. Those numbers predate AI-augmented attackers running phishing generation, credential stuffing and vulnerability scans at machine speed against exactly the unpatched software Bradshaw named.
$56,600
Average cyber cost per small-business report
ASD Annual Cyber Threat Report 2024–25 · up 14% YoY
46%
SMEs with no meaningful digital security
OECD D4SME survey 2026
1 / 6 min
Cybercrime reports to ASD
84,700 across 2024–25
Want to know what this means for your business? We'll map it in one call.
Book a call →AI is the attack and the defence — pick fast
The other half of Bradshaw's message got quieter coverage. She wants Australian organisations to use AI defensively too, and she was blunt about how well it works inside her own agency: "What would have taken cybersecurity experts in ASD weeks and weeks of work has been done in hours." ASD is running specialist tools — Bradshaw named Anthropic's Mythos and OpenAI's cyber variants. Your business is not. But the commercial versions of those capabilities are now inside every serious business platform you would migrate to — modern accounting, modern field service, modern email — as anomaly detection, phishing filters and automatic patching. That is the compound benefit hiding in her speech.
It also changes the calculus. Every legacy retirement you complete this quarter kills an attack surface and swaps it for an AI-defended one. The cheapest AI adoption most SMEs can make is often the one that also unloads a decade-old exposure. Framed that way, replacing the on-prem accounting install with a supported cloud version is not a discretionary upgrade — it is the security move Bradshaw is asking for. If you'd like to see where the exposures live in your own business, and where AI would earn you more than it costs, check your business's AI exposure.
What to do this week
Bradshaw made the specific ask herself: "set some legacy technology reduction targets and move towards those." For an SME, that is five moves, in order. First, run the free Cyber Health Check at cyber.gov.au — anonymous, roughly 15 minutes, produces a tailored action plan. Second, inventory the stack and list anything past end-of-support or more than two versions behind. Third, prioritise whatever holds customer data, financial records or supplier payment details — those are where the $56,600 average comes from. Fourth, turn on the AI-native security features in the platforms that already offer them; they are usually a checkbox, not a purchase. Fifth, when the next piece of software comes up for renewal, treat built-in security AI as a specification, not a nice-to-have. The businesses that come out of the next 18 months intact will be the ones that stopped budgeting for legacy software's last renewal.
Key takeaways
Common questions
What did Australia's ASD chief say about legacy tech and AI?
At ASPI's Sydney Dialogue AI Masterclass on 14 September 2026, ASD Director-General Abigail Bradshaw warned that Australia sits on "an enormous legacy technology debt" and that outdated systems will almost certainly be the first compromised in a major AI-enabled cyber attack. She called for organisations to set legacy technology reduction targets, and for Australia to build a formal AI early warning system.
What is the Cyber Health Check, and does it cost anything?
The Cyber Health Check is a free, anonymous ~15-minute self-assessment run by the Australian Cyber Security Centre at cyber.gov.au. It produces a tailored action plan for small business based on your current controls. It is the same tool ASIC has been recommending to AFS licensees in its 2026 cyber-resilience letter.
How much does a cyber attack cost an Australian small business on average?
The ASD's Annual Cyber Threat Report 2024–25 puts the average self-reported cybercrime cost per report at $56,600 for small businesses — up 14% year on year. Medium businesses averaged $97,200 across the same period. Those figures are before AI-augmented attackers scale up.
Sources
Cyber Daily — ASD chief says Aussie companies' ageing tech a growing concern in the age of AI
▶Assumptions & methodology
- Bradshaw's remarks were delivered at ASPI's Sydney Dialogue AI Masterclass in Canberra on Monday 14 September 2026 and reported by the ABC on 15 September 2026 and by Cyber Daily the same week. The direct quotes on "legacy technology debt" and the binary framing ("catalyst… or first to be compromised") are as reported.
- The $56,600 average small-business cybercrime cost, the 14% year-on-year increase, the 84,700 total cybercrime reports and the one-report-every-six-minutes figure are from the ASD Annual Cyber Threat Report 2024–25 (published October 2025 — the most recent full annual report at time of writing).
- The 46% no-meaningful-security and 61% AI-using figures are from the OECD's 2026 D4SME survey of more than 2,000 SMEs across 12 OECD countries — a global figure with Australian SMEs in the sample, not an Australia-only measurement.
- The named defensive tools (Anthropic's Mythos, OpenAI's specialised cyber versions) reflect Bradshaw's own remarks about ASD's capabilities; they are not commercially available to SMEs. Commercial equivalents inside modern SaaS platforms are the addressable substitute.
- Last reviewed 18 September 2026. General information, not legal or security advice.
Field Notes are general commentary on AI trends for Australian businesses. They don’t constitute professional advice. Talk to your accountant, lawyer, or IT adviser before acting on anything specific to your situation — or talk to us if you want help working out where AI fits.
Subscribe
Don't miss the next one
Get each new Field Note in your inbox as it publishes — short, practical AI intelligence for business owners.
Which piece of your stack would Bradshaw call "legacy"?
Every SME has one — the accounting install nobody wants to migrate, the CRM two versions behind, the phone system still on-premises. The businesses that come out of the next 18 months in one piece are the ones that stopped renewing that software and replaced it with a modern, AI-defended equivalent. A short conversation is enough to work out which one to move first. Book a call.
Book a call →