Why are we letting yesterday’s systems fight tomorrow’s threats?

A decade of under-investment has left government networks exposed to AI-driven attacks

Australia’s public sector has become one of the most valuable targets for cybercriminals, with bad actors escalating both the speed and sophistication of their campaigns. From ransomware and phishing campaigns to insider threats and supply-chain compromises, government networks are being targeted on multiple fronts. Attackers are looking to exploit vulnerabilities in legacy software, compromise credentials, and leverage social engineering to infiltrate critical systems. These are tactics that have already led to the exposure of sensitive legal records, health data, and student information across Australia’s public institutions.

The consequences are immense: disrupted essential services, eroded public trust, and billions in economic cost. And yet, we continue to rely on systems designed for a different era. Recent reports show that only 10% of federal government IT spending goes towards public cloud, and more than 70% of agencies still operate on legacy infrastructure. These antiquated on-premises environments are hunting grounds for cybercriminals who are attacking legacy systems at machine speed. Servers that may be more than a decade old and running out-of-support operating systems are no match for the AI-driven attacks of the modern threat actor.

The challenge is not only technical but strategic

As Andrew Shearer, Director-General of the Office of National Intelligence, warned, Australia is already operating in the “grey zone”, the space between genuine peace and overt war, where cyberattacks are a key tool of influence. State-aligned groups, like Lazarus, and organised crime actors are probing for weaknesses across government and critical infrastructure. Add to this the complexity of massive outsourcing agreements and third-party software environments, like what exposed Qantas, and we have an attack surface that is both vast and unevenly defended.

Modern solutions for modern problems

With such a fragmented IT landscape, visibility and correlation are everything. It’s critical that government security teams can unify signals across endpoint, cloud, and identity to detect, investigate, and respond to threats in real time. Government agencies need to leverage AI to combat the very AI attacks being deployed by our adversaries. This means moving beyond manual processes and stagnant defences to modern, intelligent systems that can operate autonomously at the same speed as attackers.

The answer lies in robust cloud security, AI-driven detection, and automated response capabilities. Solutions like AI-enhanced Security Information and Event Management (SIEM) offer real-time visibility, automated workflows, and integrated threat intelligence, enabling teams to shorten dwell time and strengthen resilience while maintaining compliance with local data residency requirements.

We must also address the skills gap and resource pressures facing Security Operations Centres (SOCs). By using AI to triage alerts, streamline workflows, and automate low-value tasks, analysts can focus on the strategic work of safeguarding citizens’ data and ensuring continuity of government services.

The reality is simple

Every day we delay replacing outdated systems, the risk compounds. We’re asking legacy infrastructure to defend against threats it was never built to withstand. Modernisation is a necessity if we want to protect citizens’ data and maintain trust in the public institutions that serve them. Otherwise, every breach chips away at public confidence and diverts taxpayer dollars from progress to repair. The government has a narrow window to act before “outdated” becomes “unrecoverable”.

Brad Perriott
Area Vice President and Country Manager at  | Website |  + posts

Brad Perriott is the Area Vice President for Australia and New Zealand at SentinelOne, a leading AI-powered cybersecurity firm. With over 20 years of experience in information technology and business leadership, Brad is recognised for driving market expansion and building high-performing teams across the Asia-Pacific region.

Before SentinelOne, he was Senior Director, APAC at New Relic, where he significantly contributed to the company's regional market growth. Earlier in his career, Brad held sales, marketing, and alliance roles at major tech companies, including Dell, Optus, and Sun Microsystems.

Leave a Reply

Your email address will not be published. Required fields are marked *