The head of the Australian Signals Directorate warned in September that legacy technology is leaving the country exposed to AI-enabled intrusion and automation at scale. The warning was aimed at government and critical infrastructure, but the underlying economics land harder on small business — because what changed is not the vulnerability of old systems. It is the cost of finding them.
What AI actually changes about attacks on old systems
Legacy systems have always been soft: unpatched, unsupported, running because replacing them is expensive and they still work. What protected the average SME's forgotten server was attacker attention being scarce — human effort went to targets worth the hours.
Automation removes the scarcity. AI-assisted tooling now writes the reconnaissance scripts, triages the scan results, adapts the exploit attempt and drafts the follow-up phishing email — at a marginal cost near zero. When attacks cost nothing to attempt, "too small to bother with" stops being a defence. We put this shift in context in the top 10 cyber threat trends shaping NZ businesses in 2026, and its ransomware-specific version in why AI is making ransomware faster.
The SME legacy list looks like this
Not mainframes — mundane things:
- The Windows Server 2012 box running the job-tracking system "until we migrate"
- The unsupported NAS in the cupboard holding every file since 2016
- The VPN appliance that has not seen a firmware update since installation
- The EFTPOS or door-access PC that cannot be upgraded because the vendor is gone
- The website plugin stack nobody has audited since launch — the exact pattern from the WordPress RCE that hit NZ sites
Every one of those is internet-adjacent, automation-discoverable, and on nobody's calendar.
Triage for a business without a security team
You cannot replace everything, and you do not need to. The order of operations:
- Inventory ruthlessly. One afternoon: list every device and system, its OS or firmware, and whether it still receives updates. The list is the deliverable; do not fix while listing.
- Kill internet exposure first. A legacy system reachable from the internet is a different species of risk from one on the LAN. Remove remote access to anything that does not truly need it.
- Isolate what must stay. If the old machine cannot be replaced, wall it off — its own network segment, no path to your file server or backups.
- Patch the perimeter fastest. VPNs, firewalls, mail gateways and anything with a login page get updates within days of release, not quarters.
- Assume discovery, plan recovery. Tested, offline backups are the control that makes a legacy compromise survivable — the recovery-first logic in cloud backup against ransomware.
Where people fit in
Automation finds the door; a human usually still opens it. AI-generated phishing gives attackers volume AND quality at once, which means staff see more convincing lures more often. Technology triage and awareness training are not competing budgets — one shrinks the attack surface, the other guards the surface you cannot shrink.
Practical takeaway
- Build the legacy inventory this month — visibility is the control everything else depends on
- Remove or gate every internet-facing legacy service
- Segment what cannot be retired; patch the perimeter aggressively
- Verify offline backups by restoring, not by hoping
- Train staff for higher-volume, higher-quality AI-generated lures
SecureAZ's modules include AI-era threats — deepfakes, AI-written phishing, voice cloning — built for NZ and Australian teams. Start a free 45-day trial.