SecurityBrief Australia - Technology news for CISOs & cybersecurity decision-makers
Australia
Filigran warns boards on ageing tech cyber controls

Filigran warns boards on ageing tech cyber controls

Tue, 22nd Sep 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Filigran has warned that Australian organisations are relying too heavily on untested cyber controls for ageing technology, arguing that boards and insurers need continuous evidence those protections still work.

The warning comes amid growing concern about legacy systems still used across government and business. Recent reporting has highlighted the risk that artificial intelligence could help attackers exploit outdated technology more quickly, while industry data shows vulnerability exploitation has become a leading path into breached systems.

Damian Skeeles, Senior Manager, Solution Engineering, Filigran, said many organisations assume a compensating control remains effective long after it is first put in place. That assumption can leave businesses exposed if a change elsewhere weakens the protection without being noticed.

Security controls can often be configured to reduce the risk posed by older systems that cannot easily be updated or replaced. These measures can act as a form of virtual patching, but their effectiveness can diminish over time as configurations change, exceptions are added, or the surrounding environment shifts.

That creates a blind spot for boards seeking assurance that cyber risks are understood and managed. It also complicates insurance renewals, as underwriters increasingly want current information on an organisation's exposure rather than a static assessment made at a single point in time.

Changing threat picture

Broader market data points to a faster, less forgiving threat environment. Verizon's 2026 Data Breach Investigations Report found attackers are using AI to accelerate the exploitation of known vulnerabilities, shrinking response windows from months to hours. It also found vulnerability exploitation had overtaken stolen credentials as the main entry point for breaches for the first time in the report's 19-year history.

In Australia, concerns about outdated systems have also been raised at the national level. Abigail Bradshaw, Director-General of the Australian Signals Directorate, recently warned that AI-enabled attacks could exploit the country's ageing technology estate.

Against that backdrop, Filigran is advocating a continuous approach to exposure management rather than periodic reviews. It points to Continuous Threat Exposure Management, or CTEM, which Gartner describes as a way to continuously assess how accessible, exposed and exploitable an organisation's assets are.

In practical terms, that means tracking the threat landscape, reviewing current weaknesses, identifying the threats most likely to cause harm and testing whether existing controls can resist them. The aim is to give security teams a current view of exposure instead of relying on outdated configuration assumptions.

Boardroom gap

The issue is not only technical. Filigran's State of Threat Management research found 48% of Australian security teams cited a lack of executive support as their biggest barrier to improving exposure management. According to the research, that was more than twice the proportion recorded in Singapore.

The finding suggests many security teams still struggle to secure backing for work that does not always produce immediate or visible business outcomes. Yet that same gap can leave boards with limited visibility into whether risks linked to older systems are shrinking, holding steady or growing.

Aon's Head of Cyber Solutions for Australia, Quinton Kotze, has described ageing technology as a business resilience exposure. That framing broadens the issue beyond information security and places it within wider questions of operational continuity, governance and risk transfer.

For insurers, the quality of evidence matters. Underwriters assessing cyber risk often need to understand not just which controls are supposed to exist, but whether they are functioning as intended and how that position is changing over time.

Skeeles said continuous validation can provide that evidence in a form boards and insurers can use. "Continuous validation gives boards and underwriters up-to-date evidence and metrics of that risk: which exposures matter, whether controls are as effective as proposed, and where additional improvement is required," he said.