September 03, 2026

00:38:44

Episode 383 Deep Dive: Sarah Sloan | It Still Runs, But Can You Defend It? The End-of-Life Tech Reckoning

Episode 383 Deep Dive: Sarah Sloan | It Still Runs, But Can You Defend It? The End-of-Life Tech Reckoning
KBKAST
Episode 383 Deep Dive: Sarah Sloan | It Still Runs, But Can You Defend It? The End-of-Life Tech Reckoning

Sep 03 2026 | 00:38:44

/

Show Notes

The tech running hospitals, power grids and government services often still works. Sarah Sloan, Cisco’s Head of Cybersecurity Policy for APAC, joins KB to explain why that’s the problem, not the reassurance it sounds like.

Drawing on a new ASPI report Cisco funded, “Past its use-by-date,” they get into why so much end-of-life tech is still in place (usually budgets and skills, not negligence), how AI and quantum turned a slow-burn risk into an urgent one, and why most organisations still can’t see the ageing gear in their own environment. Plus the upside: why moving early beats being forced by an incident.

About Sarah: Sarah Sloan is Head of Cybersecurity Policy APAC, Cisco where she leads public sector engagement on cybersecurity policy matters across the region. With over 15 years’ experience across government, industry, and consulting — including more than a decade focused on cyber and technology — Sarah has held senior roles in the Australian Government and leading global technology firms, driving policy development, public-private sector partnerships, and national cybersecurity priorities. She holds a Bachelor of Laws (Hons) and Bachelor of Asia-Pacific Studies from the Australian National University (ANU), and postgraduate qualifications in legal practice, international law, and Japanese studies. Sarah is also Chair of the Australian Industry Information Association’s (AIIA) National Security and Cyber Resilience Policy Advisory Network.

Keywords: end-of-life technology, legacy systems, critical infrastructure, cybersecurity governance, ASPI, Cisco, Legacy Five, board risk, post-quantum cryptography, AI cyber threats, SOCI Act, technology lifecycle, cost of downtime, CISO, digital resilience

View Full Transcript

Episode Transcript

Sarah Sloan [00:00:00]: most organizations actually don't have visibility of the end-of-life assets in their environment or an understanding of where they are in their product lifecycle to be able to even have the conversation around who's responsible for the assets. KB [00:00:13]: From KBI Media, I'm Karissa Breen, and this is KBKast. My guest today is Sarah Sloan, Cisco's Head of Cybersecurity Policy for APAC and one of the people behind Cisco's push on end-of-life technology. This includes the ASPI report it funded, "Past its use-by-date," and the Legacy 5 framework. Her starting point is around a system that still runs is not necessarily the same as a system you can defend. We get into why so much aging tech is still deployed for hospitals, power grids, and government services. We also cover why AI and quantum have turned that slow burn risk into something urgent. And who's actually meant to own when looking away is easier? VO: If you find these conversations useful, hit follow. It's the single best way to make sure the next one lands right into your feed, and it helps other execs find the show. KB [00:01:08]: Alrighty, let's get into it. So Sarah, I want to start— you write that functionality is not the same as defensibility. Now, if nearly 40% of most actively targeted vulnerabilities affect end-of-life devices. Why do you believe governments and boards knowingly continue operating technology that can no longer be defended? Sarah Sloan [00:01:34]: Firstly, thank you so much for having me on the program. It's great to be here and talking around the end-of-life report that the Australian Strategic Policy Institute released, which was sponsored by Cisco, a very important topic that we're keen to shine a light on. I think in answer to your question, I don't think it's a kind of deliberately malicious kind of decisions that boards are making or one that kind of ignores the risk. I think there are often legitimate reasons as to why an organization, be that government or private sector, makes the decision to continue on with some of these end-of-life and legacy devices. And they are things that, you know, many of your viewers and listeners will be very familiar with. There are budget constraints, skills constraints, and so on and so forth. And I think that's reflected in a lot of the data that we see. The government releases the annual Commonwealth Cyber Posture Report. Sarah Sloan [00:02:25]: And in that report, it did detail that the most common reason why government agencies are struggling to replace legacy and end of life is in fact dedicated budget and funding. And skills is also up there as one of the more frequently managed, you know, kind of reasons given as to why it's so challenging to replace some of these devices. So, so I think a little bit more colored there as to how organizations are approaching this challenge. But as you say, the report is really trying to shine a light on the risk and the risk profile of end-of-life devices across government and critical infrastructure and the fact that that risk is really changing. So we already saw, you know, say 6 months ago, a year ago, of course, that, you know, end-of-life devices were particularly vulnerable and targeted by our adversaries. And you highlighted there some data from the Talos ERA review report that Cisco released. Based on what we saw across 2025. So we saw, of course, as you said, end of life has been commonly targeted. Sarah Sloan [00:03:20]: We also saw a lot of older vulnerabilities still being targeted. In fact, one of the most commonly targeted vulnerabilities for 2025 was a vulnerability that was 12+ years old. So our adversaries clearly know that these devices are vulnerable. There's no real defenses in many cases preventing access to them. But what has changed and what the report's trying to highlight is really that we're seeing 3 things occurring across the cyber ecosystem. The first, of course, is AI, and everyone's talking about AI and advanced cyber-capable AI models, and they're fundamentally changing the risk when it comes to end of life because, of course, they're making them more discoverable, more easily accessed. And so some of the risk profile and risk mitigations, I guess, we put in place prior to the evolution of these technologies may or may not be sufficient. So, you know, isolating them, hardening. Sarah Sloan [00:04:10]: I even had someone tell me that the code for one of their end-of-life devices was so old, nobody could, you know, nobody knew it to be able to do anything. And so that equation's fundamentally changed with some of these models coming through. The other 2 pieces I'll very briefly touch on are really quantum and quantum readiness. Of course, these aging devices will, you know, not be able to be ready for the era where quantum breaks modern-day encryption, which some put as early as 2029. So there's a real imperative here to rethink the risk of those devices to your organizations to make sure that you have devices that are able to implement quantum resilient algorithms that are quantum agile. And then the final point the report touches on is of course the IT/OT convergence, which I'm sure many of your listeners are also very familiar with. But some of these systems were just not built to be internet-facing or connected. So yeah, the report's really trying to tease out how the risk profile has changed and the imperative of reassessing these end-of-life assets in your environment going forward. KB [00:05:08]: And just on the end-of-life assets, I mean, these were conversations that when I was in industry people were having like 10+ years ago. So do you think that those, those same end-of-life devices have still been sitting there until now? And do you think like, what's, what's been the main catalyst around really focusing on this? And I, and I caveat that with saying, because every person I interview, it's like, that's a really big concern. we should, everyone should look at that. And then you interview the next person and like, that's a really big concern, we should look at that. So what do you think is really driving this behavior? Do you think it is because of what's happening around the AI and the Mythos sort of stuff? And then to your point around quantum, is it that, that people are like, now we've got to get our act together, we've got to get moving on this? Because why sort of wasn't this addressed earlier perhaps? Sarah Sloan [00:05:55]: Yeah, I think to your point, there is a lot of end-of-life kind of infrastructure floating around in the system. If you're looking at Australian government context, I think 40% of Australian federal government infrastructure is end of life or approaching legacy. Similar statistics exist for the UK where we saw, I think they've got 228 or so legacy devices in government systems. One in 4 of those is critical. So they're, you know, kind of at risk of failure and they're supporting some of those critical functions. And the US is equally the same in the sense that they have a large amount of end of life devices supporting critical functions. I think some are apparently anywhere between 8 and 51 years old, which is mind-blowing. So there is this very large amount of, you know, end-of-life devices supporting critical functions in government and of course in critical infrastructure. Sarah Sloan [00:06:41]: And I think people have been aware of it for some time that it is a risk, but the risks have been somewhat manageable. I think, you know, we've seen guidance, for instance, out of the Australian Signals Directorate and the Australian Cyber Security Centre around how you can harden and mitigate some of the risks associated with having these devices in your environment. To your point, I think what has changed is that conversation around AI and quantum and some of the technologies that are coming through are really changing the tone. And we saw that with the Five Eyes advisory that came out, I think in July, where they talked around the, you know, advancements that some of these AI, say cyber-capable AI models were making and really highlighted that this poses a risk to end-of-life devices and legacy devices in the sense that they are, as I said, more discoverable, more vulnerable than perhaps they've ever been before. And we've seen already that, you know, AI tool has scanned very old code and found vulnerabilities. It's now at that stage where it's able to find these vulnerabilities that humans haven't been able to find before and really compress that time to exploit, right? So, from finding that vulnerability to being able to exploit is that window is shrinking rapidly. So, I think it is that it's having a moment really, end of life and legacy conversations are having a moment where we've realized we really have to get on top And would you also think, just staying with the risk side of things for a moment, because even a couple of years ago, the risk maybe wasn't as prominent. KB [00:08:07]: So it was sort of that old adage, like, if it ain't broke, don't fix it sort of thing, because people got other things to do. But now they're like, actually, this is becoming quite a major risk. We probably should look into it a bit more. Do you think there was some of that? Because there's so many things people have to do each day and we can't fix everything at once. So that whole prioritization is coming back through people's minds on, well, where does this sort of sit? Sarah Sloan [00:08:28]: Yeah. KB [00:08:28]: in our threat landscape? Sarah Sloan [00:08:29]: Right. Now, I think, you know, a couple of points there. I think the first one is we have now a pretty good understanding of critical assets, at least in the Australian context and some other geographies across the region who have done mapping of what their critical infrastructure sectors are, for instance, and what they're— in an Australian context, what their systems of government significance are. So we now understand, you know, what aspects and what technologies are underpinning some of these core functions that without them we could not function as a society or we couldn't, you know, have the economic or national security stability that we need. So I think that's helped us kind of understand and come back to that risk piece because people are acutely aware that they cannot replace every legacy. If we're talking, you know, the legacy infrastructure has pretty much tripled in the last couple of years. That's a lot. And, you know, a lot of the questions I get is, are you asking me to replace every single device in my environment? Well, no. Sarah Sloan [00:09:22]: I mean, that's not, you know, that's not reasonable. And in an ideal world, of course, Sure. But the reality is that we need to overlay it with that risk of where the asset is and what systems and functions it's underpinning, and then take that approach to how we look to replace it. Because obviously for many organizations, they just don't have the skills, coming back to that original question, the skills, the resources, the people to be able to replace every single device in every environment. KB [00:09:49]: So my next question would be, You touched on it before, legacy systems that support, like, for example, hospitals, power grids, government services. What I'm curious to understand is replacing it in people's minds can be an immediate disruption. And obviously now people are very impacted by business disruption. But then also to your point, it does create that risk if we sort of don't replace the thing. So then who in your experience, Sarah, gets to decide which danger the public gets to live with? Or what— and they're both sort of bad, but is one worse than the other? Like, you know, in terms of how to move forward from this sort of scenario? Sarah Sloan [00:10:32]: I don't think it's any one individual or entity that really decides. I mean, it clearly depends on what we're talking about, where the asset is, in which sector it is. But say we're talking about, you know, end of life in critical infrastructure, that of course has a pretty strong framework around it already with our critical infrastructure reforms. that we've seen over the last couple of years or so. So in that instance, it's really, you know, not just the person who's the technical owner, it's not the person who kind of runs the device, it's not just the board. It would be a conversation, I think, between the entity as well as government as to who gets to make that decision. And the government's role really in that context is about setting the expectations, right? The policies and the frameworks by which that decision is made. I think the kind of key point there though, of course, is It has to be firstly, obviously overlaid with risk, as I talked about before, that, you know, it has to be dependent on where the asset is in the environment, what it is doing to make that decision. Sarah Sloan [00:11:27]: But of course, if the decision is made to continue to have an end-of-life device in that environment, it's critically important, and the report talks to this, to identify an owner of that asset, to be able to have a plan for when and how you're going to transition off that particular asset, for instance. And so putting in place some of these kind of governance-style arrangements can really help give clarity to the entity, but also the public, also the government around how, you know, these devices are going to be managed for the greater good. KB [00:12:00]: And you mentioned before, identify the owner of the asset. I want to talk to you a little bit more about this because a lot of conversations I'm having is around the ownership, who owns the responsibility. Who's accountable? Would you say in your experience, people may be reticent because it's like, well, I kind of don't really want to own this thing perhaps because maybe I don't have the people or the budget or the resources or the timeframe, or someone's asked me to deliver something in 3 days when it's going to take 3 years. Do you think there's that? Do you think people may be hesitant to wanting to own it? Sarah Sloan [00:12:29]: I think it is a challenge to find out, you know, who's the appropriate owner. As we know, it's very matrix within a lot of organizations. as to where the accountability kind of best sits. But I think the important part is obviously taking that first step, right? And in terms of finding out, you know, one, the visibility of assets actually, just as a side note, is one that I repeatedly get is most organizations actually don't have visibility of the end-of-life assets in their environment or an understanding of where they are in their product lifecycle to be able to even have the conversation around who's responsible for the asset. So, you know, my kind of message today would really be to take that first step, right, of understanding what you have in your environment and where it's up to in its product lifecycle. And then the kind of flow-on measures around what does good look like, who's accountable, and those kind of conversations can follow. KB [00:13:18]: And do you think, and the parallel that I'm drawing upon is it has to be one of these scenarios at the moment. If we look at AI, for example, people are saying, oh, but it's a risk if we do AI. But yeah, it's more of a risk if we don't do it. Is that the same sort of mindset that's coming in here with end-of-life sort of assets? Sarah Sloan [00:13:35]: Yeah, it's a great question. And absolutely, the report that we kind of issued with ASPI is really trying to tease out the opportunity here. So, you know, yes, end-of-life is often viewed as kind of like more of that, the risk equation, you know, we'll try and harden, mitigate, we'll manage it. But there is an opportunity here. And I think the opportunity really comes from firstly, of course, managing your transition. Rather than having an incident or an outage that can obviously force your transition on timeframes that are no longer really your own, you know, that you're working under pressure, all these kind of things. So there is benefit in having the ability to manage your transition off some of these end-of-life devices at your own pace and having that ability to kind of go to market in a much slower fashion and choose the right vendor and support for you. So I think there is that opportunity there really that the report is trying to tease out that this isn't just a conversation around risk management. Sarah Sloan [00:14:30]: It's a conversation around, yeah, that kind of structured transition to the new assets. KB [00:14:35]: And then with like the regulation piece, I know you mentioned SOCI and other things like that. What's your, and I know your background as well, what's your view then on that whole adage around you attract more with honey than you do with vinegar? Because some people say, yes, you know, regulation helps. get people to where we need them to get, but then other people say, yeah, but maybe I'm cutting corners because I'm time poor. Where does that sort of sit with you given your background? Sarah Sloan [00:15:00]: Yeah, you're asking a lawyer about regulation. So, I think for me, you know, regulation does have a really important role in terms of articulating the standard in which organizations are to meet. And it's funny when I talk to people, they have mixed kind of, to your point, feedback. Some organizations and some individuals really welcome regulation because it helps them have conversations internally around what they need and the resources that should be dedicated to, you know, fixing a particular thing or meeting a particular standard, for instance. So it can be really advantageous for some organizations and entities, and other entities of course would like the regulations to maintain that flexibility and agility that allows them to meet a certain standard in the way that is best for their organization or entity. So I think it's always a really you know, balanced approach that's needed that, you know, kind of articulates that standard but doesn't necessarily prescribe how organizations are to meet that standard. And I think in the Australian context, you know, I think we're doing pretty well on that. You know, when you're looking at, you know, SOCIE, for instance, it has various standards that you can meet as an entity depending on which standard is best for your organization. Sarah Sloan [00:16:07]: So we're seeing some really, I think, positive moves in the Australian landscape. And just on legacy, we actually are seeing the Australian government in particular trying to take some measures to address legacy and end of life. We saw some developments there on Horizon 2 of the Cybersecurity Strategy where they talked about managing and addressing legacy across systems of government significance, for instance, and also some measures to get organizations to turn their minds to managing legacy risk in critical infrastructure. So once again, I think, yeah, there is definitely a role for regulation and policy in this space in terms of articulating what good looks like and what standards organizations have to meet. KB [00:16:46]: And so that leads into my next question around, should critical infrastructure operators be required to report when they continue using unsupported technology rather than just be allowed to manage that risk quietly behind closed doors? Given, you know, we spoke about the regulation piece, do you think that'll be something companies need to declare then moving forward? Sarah Sloan [00:17:08]: Yeah, it's a really good question and one that the Australian Strategic Policy Institute dived into as part of their report. So they do articulate the merits of having reporting obligations around end-of-life devices. And one of the kind of more seamless ways potentially of doing it that they speak to is around incident reporting obligations. So as many organizations have incident reporting obligations across our economy, you're thinking critical infrastructure, we've got ransomware reporting, we've got notifiable data breaches, we've got a whole bunch of reporting mechanisms. The kind of argument there is around putting in a requirement to disclose whether that was related to an end-of-life device, just so we can have that transparency around how end-of-life is being impacted and clarity around and transparency of the footprint that we have and how that's playing out. The other piece that they talk to is particularly around high-risk end-of-life devices. So if you're thinking your systems of national significance, if you're thinking your systems of government significance, looking at introducing a reporting requirement there. So if it's basically responsible for keeping the lights on for our country or the banking system flowing, potentially looking at a reporting obligation to government there is what ASPI really talks to in the report. Sarah Sloan [00:18:21]: And I think that is, you know, a strong catalyst in terms of that transparency around what is in these organizations. where the assets are sitting, what functionality they underpin. But that, that first step, I guess, would logically flow to a conversation around some of the other measures we talked through around accountability, for instance, around a funded transition path or around clarity around how that asset's going to be managed in lieu of it being replaced. So yeah, the report really touches on the merits of a reporting obligation. KB [00:18:50]: Okay. So there's a couple of things in there that I want to explore. Number one would be because of the requirement around end of life, Do you think that as a result, the risk of our critical infrastructure would avoid like any issues with it going down and downstream impacts and flow-on effects? Because I've spoken to people a lot on the show about something happens, how much it impacts just our everyday society. So do you envision that it'll just overall reduce that risk collectively? Sarah Sloan [00:19:21]: Well, nothing's 100% perfect, right? It will help, I think, to identify the risks and manage and mitigate those risks. So if an organization, for instance, has visibility of what end-of-life assets are in their environment, if they understand how they're being hardened, how they're being protected, and then have a clear pathway of like how we're going to transition off, I think that would absolutely help organizations to drive down risk. As I said, we do know that adversaries are targeting end-of-life devices, and we do know that the emerging technologies coming through, whether that's AI or quantum, are going to make these devices even more vulnerable. than they were yesterday. So there is a need to move at speed here to kind of understand those vulnerabilities, manage them, and transition onto more modern infrastructure. The other piece, of course, that we haven't talked through is, you know, the procurement side here, right? So we're talking about, you know, when you have an end-of-life device already in your assets, already in your environment, rather. So there is obviously a need to get on the front foot here around procurement and to identify at the procurement stage when a device is going to be end-of-life and also have an understanding of your budget cycle. So in 3 years, 5 years, 10 years, whatever it is, you're going to need funding to replace that device and you're going to need to prepare for the transition of that, you know, device, you know, in terms of those budget cycles and board-level conversations and the like. Sarah Sloan [00:20:41]: So yeah, some measures really to think about there in terms of driving down that risk. KB [00:20:45]: We'll come back to that in a moment after a quick word from our sponsor. When you're building a startup, every hour counts and so does trust. Whether you're chasing your first enterprise deal or just trying to stay ahead of the compliance curve, Vanta helps you prove your security posture fast by automating up to 90% of the work for SOC 2, ISO 27001, GDPR, and more. Vanta gets you audit ready without the late nights and spreadsheets. Visit vanta.com/KBKast. Sarah Sloan [00:21:15]: V-A-N-T-A.com/KBKast. KB [00:21:22]: So on that last point there, Sarah, I interviewed a lawyer here in the US earlier this week and he sort of touched around, we're going to start seeing businesses re-architecting their contracts, what their procurement strategy looks like. Okay, this was more talking about AI, but now to your point around end-of-life assets, do you envision that companies now are looking at how they're working with external vendors, how they're working internally, suppliers, contractors, et cetera? just in totality on how do we address this overall? Because it's probably coming to that point in time where businesses need to look at all of these new elements, or old from the end of life perspective, but new elements on the AI front. It's just something that I'm starting to see trickle through in the media now. Sarah Sloan [00:22:07]: I assume you mean organizations going to be putting in, you know, requirements to disclose end of life dates or things like that into contracts. I think that's entirely possible going forward that organizations would want to have some level of understanding about the product lifecycle upfront at the point of procurement, once again, so that they can, you know, fully understand the budget cycles and they can, you know, prepare for the transition. I mean, some of these devices that we're talking about in end of life underpinning critical systems are very hard to replace. So it requires a fair amount of work to get ready to look at transitioning off these devices onto the new, new infrastructure there. So Yeah, I think getting that understanding at the stage of procurement would be particularly helpful for organizations going forward. KB [00:22:51]: And then just going back to your comment around sort of if there was an outage or an incident happened and then it was identified that it was in relation to an end-of-life device, what does that do then to the whole trust piece? Because again, it's another thing that's— trust has always been there, but it's, it's got like a different definition at the moment according to different people that I'm interviewing. So do you think that's there's going to be a distrust if it's like, oh, well, there was a major outage and something happened, but it was because this X company didn't, they still had end-of-life assets that they were leveraging and that's what caused the outage, for example. Sarah Sloan [00:23:25]: Yeah, I think we're, you know, I always think that we need to approach everything with a degree of understanding, right? We've talked a lot about the cybersecurity community around, you know, victim blaming, you know, you shouldn't have clicked on the link and you did click on the link and you had an incident. I mean, I think we've tried to change our culture, and I think we're doing a great job of doing that when it comes to cybersecurity issues, of having that understanding of these are really complex environments that we're talking about. These are really complex challenges. If it was easy, we would have solved it. So when it comes to things like end of life and public trust, you know, in an ideal world, absolutely, that we wouldn't have end of life devices. But in the world we live in, unfortunately, there are those constraints that exist for organizations. Be that financial pressure, be that skills, be that resourcing, or just the sheer complexity of the device that we're talking about. So I think we need to have a degree of understanding around that. Sarah Sloan [00:24:16]: When it comes to, you know, like we were talking before about a reporting regime, the idea of that wouldn't be to apportion blame. It's really about to get an understanding, once again, coming back to visibility of where some of these assets are, but also to help work together on having that transition plan, right? That, that clarity around, are we doing enough to mitigate the risks associated with that device? And, you know, trying to look at how we can align funding cycles and, you know, that transition period so that we are in a more resilient posture than we were prior. KB [00:24:48]: So that part I get. It was probably just more like everyday sort of people that may not understand the constraints because you're right, these things are complex, not as easy. Do you think that businesses are starting to think through that strategy on how to approach it? Just, just in case something were to happen. Because as we know, people are less forgiving nowadays and highly visible and critical on social media the second something goes wrong. It's just more like an observation from my point of view, like looking at all angles of this sort of conundrum. Sarah Sloan [00:25:19]: Yeah, I think it's an interesting point. Now that you mentioned the public trust kind of component and the social media component, I think there is. a degree here though also of unpacking the need to have points of friction as a way of doing business when it comes to technology, for instance. So I think there is a need to kind of build up that maybe public resilience there around, you know, when, when we have to have MFA or, you know, when we have to have these various interventions in our everyday interactions online that help make us more secure. There is also a piece here which the report does talk to around government and to a degree the public needing to understand that if we're going to be replacing some of these end-of-life devices, we may need to have some flexibility around operational requirements. So if you think about the need, there's, you know, various regulations that, you know, organizations need to have continuous service, continuous operations, and if they don't, they may have to have reporting obligations to government. But part of this conversation around replacing end of life is, well, some of these systems are underpinning such critical functions. If you want to replace them, you kind of got to take some of them offline, or there is a risk that they may be taken offline. Sarah Sloan [00:26:26]: And so having an appreciation that that is a necessary kind of risk in order to replace it, I think is really a critical component. And that's a risk that needs to be understood, I guess, by government as regulators and policymakers as much as it is by the public. KB [00:26:42]: And then would you say it'd be more of an iterative process and that sort of is underpinned by like a holistic sort of approach? So it's like, okay, well, if we've got X amount of hospitals in New South Wales that are leveraging these end-of-life assets, obviously we can't all turn them off at once. So Is that then informed by government and regulators on how they would do this operationally so nothing was impacted and there's still that seamless sort of flow? Sarah Sloan [00:27:04]: Yeah, I think that is the role that government can play, particularly when we're talking about systems of national significance, which is kind of what you've alluded to there. When those systems are so critical that they will impact, you know, the public and hospital care and energy and all these kind of things if they're taken offline. So, I think that is where government could have a role in terms of coordinated communication and making sure that, you know, not everyone's replacing these core systems all at once and that we're stuck with a severe impact to critical services, for instance. KB [00:27:35]: So now I want to switch gears and talk to you about the Legacy 5 Requires Named Accountability. So, from my understanding, this is a practical framework for governments and enterprises to make lifecycle risk Visible, accountable, and actionable, which is outlined in your recent report, the ASPI one. So, I want to understand what consequences perhaps should an executive actually face if they repeatedly accept legacy risk and then that system is later exploited? Now, I know you mentioned before there's constraints, there's complexity, there's all that sort of stuff, but if someone continuously perhaps is Negligence is not the word I want to use, but accepts the risk and then something does happen. Is there consequences for that? Sarah Sloan [00:28:21]: For the Australian context, we actually do have a raft of, you know, kind of obligations that are at the director level, at the entity level, for instance. And we've touched on the Security of Critical Infrastructure Act, for example, which, you know, has obligations around having a risk management plan and having that signed off on a board level, right? We also have, of course, the Corporations Act, which imposes obligations. So I think there are a raft of obligations that would apply potentially to that scenario that you've just kind of walked me through. The other thing though, I would say is that I think boards are becoming more acutely aware of the financial costs, right? It's not just the kind of impact of regulations and policies. That's kind of one component. But when we're looking at the full cost of downtime or the full cost of an incident, I think that awareness of actually the financial impacts is kind of growing. And we've done some research in the cost of downtime. where we basically surveyed a number of companies globally and found that amongst the larger companies, the annual cost of an outage was $400 million and the cost of downtime per minute was around $9,000. Sarah Sloan [00:29:23]: So, a lot of kind of understanding, I think, of that financial impact when you have an outage. And that, of course, is comprised of all kinds of things. We're talking operational disruption, lost revenue, recovery costs. Alongside the regulatory scrutiny and, you know, the reputational damages that can flow. So I think that awareness of the impact and the cost of some of these outages is really acute and important when we're talking about consequences for organizations. It's not, not just the regulatory and the policy kind of consequence. It's much more than that. And it is coming at a very large cost to organizations. KB [00:29:58]: And sorry, Sarah, you said $9,000 per hour? Sarah Sloan [00:30:02]: No, no, $9,000 per minute and $400 billion annually is the downtime cost to the world's largest companies. So, and that is a holistic, we tried to get obviously a holistic kind of view of costs. So not, as I said, not just regulatory, but that is the operational disruption, the recovery costs, the regulatory scrutiny, reputational, et cetera, et cetera. So the kind of when we're talking about impacts to executives, it's quite a significant financial impact that outages and security incidents can have. And in actual fact, that research found that 54% of executives reported leaving some of the root causes unaddressed to avoid the legacy and remediation. So legacy did come through in that report, in that downtime, cost of downtime report. So really demonstrating why end of life is a risk to organizations that needs to be managed. KB [00:30:50]: Yeah, that's interesting. And that there's a big number. So do you think as well, even back in the day when I was like doing reports for what could happen and the impact, But now a lot of these numbers that you just discovered, we didn't really have data on that back then, but now we do. So would you say that's a very big driving factor for these businesses to make sure that, hey, we've got stuff sorted, we've looked at our end of life sort of strategy, because that also leads into, yes, the regulatory and all of that, but then also just the trust that is today in customers, but also that long, long tail impact. Like, is it going to take 20 years for people to stop saying, oh, well, remember that time that so-and-so had the outage? Because I'm still sort of hearing people talk about businesses all over the world when they've had that, that it's just potentially going to follow them for a long time. So it's even probably more than just those outage numbers. So what does that look like long-term for these companies? Sarah Sloan [00:31:46]: Yeah, I think there's a growing awareness of the cost of some of these incidents. as I said, in terms of not just obviously the regulatory side, but that reputational point, which you kind of cut to. And admittedly, there is some research out there that kind of indicates for organizations that have been impacted, they're actually in a better posture than the organizations that haven't, right? It's that old age-old kind of saying that we say, it's not about, you know, if you're impacted, it's when you're impacted. So when these organizations have been impacted, they usually actually get on top of these issues as a result of being impacted because they've had to live this cost and have that lived experience, I guess, has informed how they're going to minimize those risks going forward. So I think there is this growing awareness that these costs are really quite significant and can be quite long-lasting. And that's why organizations are taking kind of more measures to get on top of some of these risks after they've been kind of impacted. KB [00:32:38]: So the only question that I have is around, and probably people have as well, is around procurement. So in some instances, people would say procurement rewards the cheapest compliant bid. While cybersecurity inherits the consequences potentially 10 years down the road. So would you say government procurement is structurally designed to create the legacy problem or walk me through this scenario? Sarah Sloan [00:33:04]: Yeah, I think it's a really interesting point to tease out is how procurement kind of manages end of life. I wouldn't say that government procurement policies does reward the cheapest bid. We've seen a lot of movement in this space in the recent couple of years or so. I think, you know, value for money, of course, is a really important principle that government organisations kind of have to follow, particularly when we're talking about, you know, public money, right, public funds. But we have seen the government move to look at other factors when it's looking at procurement, particularly around some of the technology space. So we're, we're seeing measures around supply chain, we're seeing measures around managing foreign ownership control and influence risks. So I think we've got a little bit more color when it comes to procurement in government circles around, you know, not just looking at the cheapest cost. But when it comes to procurement, the report obviously does touch on this. Sarah Sloan [00:33:57]: And as I said before, the real important part around trying to have that visibility in the procurement lifecycle around procurement stage around the product lifecycle. So understanding when you're buying the product, When it's going to transition to end of life, what kind of support and transition support could you be, you know, leveraging in helping you transition off these end of life technologies? And then of course, as I said, factoring that into your budget processes and your governance and all the other kind of measures that flow through. So procurement is a really important lever that I think organizations can use to try and help get on top of any, you know, kind of new acquisitions. And helping manage end of life. KB [00:34:36]: And then, Sarah, as we look forward now, so you've obviously— we've touched on a range of different things today, but what do you sort of think, what's happening in the market in Australia? What are people doing? Is this becoming very front of mind? Is AI potentially taking a bit of a back seat? Is end of life now coming to sort of the top of the laundry list? What's, what's your sort of sense here? Sarah Sloan [00:34:56]: I don't think AI is going away anytime soon. I think, yeah, I think end of life is having its moment in terms of, you know, organizations becoming more acutely aware, as I said, of, of the risks, the security and operational risks that some of these devices now pose to environments and the fact that emerging technologies are really changing that equation for them, that, you know, you've got AI, you've got quantum coming through, that you cannot really afford to sit on some of these legacy devices and just, you know, kind of harden and manage them, that you are going to need to kind of come to terms with you know, some kind of transition path, particularly for those high-risk end-of-life devices in particular environments. So I think it is having this moment. I think the opportunity side is very worth highlighting. As I said, there is an opportunity here if you do have end-of-life devices in particularly high-risk areas. By doing that transition early on and not having to do it when you're experiencing an incident or an outage is advantageous for the organization. You do get that choice that you can make. You have time, you can you know, do testing, all these things that kind of flow from having your own, you know, timeframe to manage end-of-life transition has been really important. Sarah Sloan [00:36:06]: The other thing that is really important to understand here is that some data is trapped in some of these end-of-life and legacy devices that can be particularly advantageous for your organization going forward. If you're thinking about, you know, CRM, you know, your databases there, they could be particularly old and not connecting in with newer systems. You might be able to access and have an advantage by modernizing your infrastructure. Sarah Sloan [00:36:28]: we're really trying to talk through some of those advantages as well, that this isn't just a risk to be managed, that there are advantages for organizations in terms of managing them. So, we've really, with end-of-life, got these 2 kind of things happening at once. We've got the kind of the risk equation ramping up with AI and quantum, and we've got the opportunity side where, you know, AI and other tools and organizations can really benefit from unlocking the data that might be trapped in end-of-life devices. KB [00:36:55]: Now my final question would be, do you think that now companies are going to embark on this journey? So AI is still there on the side, maybe they operate in lockstep, but then this end-of-life conversation will also be there. Like you said, it's not just about the risk, it's also about getting a competitive advantage perhaps from some of this data that's sitting there. Is that what we're going to start to see come through in the Australian market now as you move forward? Sarah Sloan [00:37:16]: I would hope so. I would hope that we're going to see more traction on end-of-life and We're going to see organizations kind of really turn their mind to, as you articulated, that risk and opportunity piece and that, you know, organizations will just, I mean, start really is kind of my piece is just move in the direction of addressing this, obviously encouraging people to read the report that we've released with the Australian Strategic Policy Institute. But really we can't, you know, secure or manage what we can't see. So of all the things to do, that visibility piece I think rings true, understanding what you have in your environment. What devices are end of life, and then kind of taking the next steps from there, obviously overlaying it all with that risk lens as well as being critically important. KB [00:38:03]: That was Sarah Sloan, everybody. The line I keep coming back to is that end of life tech is finally in the spotlight. Organizations that move now get to do it on their own terms instead of in the middle of an incident. If you're a CEO listening to this, The question for your next board meeting is whether you'd rather pay for the transition on your schedule or an attacker's. VO: I read every reply. If you've got some thoughts on this one, send me a message on LinkedIn. KBKast - Cyber For The C-suite.

Other Episodes