There are machines in the hallways of Canberra’s government buildings that are running software that was no longer supported by the companies who created it. This is not exclusive to Australia, nor is it a secret. Every developed country’s government environments continue to use legacy systems for a variety of reasons: replacing them is costly, integrating replacements with current infrastructure is challenging, and the urgency of doing so before something goes wrong tends to be subordinated to more pressing budgetary priorities. Until anything goes awry.
No one working in professional cybersecurity today would suggest Windows Mobile, the Microsoft platform that drove enterprise smartphones thru the mid-2000s, as a platform for secure communications after it was formally retired. In the security community, this is not a subtle point. Security patches are not applied to unsupported operating systems. Any vulnerability found after the end-of-life date remains permanently exploitable on any software-running device. A Windows Mobile device is more like an open door than a locked one for a contemporary attacker with access to public vulnerability databases.

Canberra’s cybersecurity experts actually rely on a far cry from anything that resembles mobile encryption from the analog era. Under its Essential Eight framework, the Australian Signals Directorate, which establishes the cybersecurity requirements that federal government institutions must adhere to, releases comprehensive technical guidance. This advice requires multi-factor authentication, application control, timely operating system patching, and encryption standards based on the most recent peer-reviewed cryptographic algorithms.
The real tools that ASD-certified practitioners utilize and suggest include end-to-end encrypted communication platforms with auditable security frameworks, TLS 1.3 for data in transit, and AES-256 encryption. Because they are unable to meet the fundamental condition of being patchable against contemporary threats, legacy mobile systems are not included in that list.
The actual security discussion takes place in the gap between what government agencies formally prescribe and what still functions in reality. Agencies with limited funding occasionally operate systems much into their maintenance lifecycle—not because anybody thinks the outdated platform is safe, but rather because the migration effort keeps getting put off. If the application was never migrated and the successor was not financed, an agency that developed a specialized application on a legacy platform in 2008 might still be using it in 2026. The risk is acknowledged, the security vulnerability is known, and it is currently on someone’s repair queue. Agencies take a risk more frequently than their public-facing security postures indicate regarding whether it remains there long enough to be exploited.
Retention of old platforms is not just annoying but really risky due to the zero-day problem. Since then, cryptographic flaws that were unknown during the active development of Windows Mobile have been published in scholarly works and vulnerability databases, which both attackers and defenders closely examine. Vulnerabilities are persistently carried by a platform that is unable to get updates. If legacy systems are in use, an attacker targeting a particular government network doesn’t need new methods because they already exist, are well-documented, and function dependably against unsupported software.
