Back to Resources

Beyond Legacy MPLS: Building Government Networks That Can’t Afford to Fail

Key Takeaways

  • Tech in Gov 2026, held 4–5 August at the National Convention Centre, Canberra, brought together around 3,000 public sector technology leaders at a moment when government agencies are under sustained pressure to modernise citizen-facing services without compromising security.
  • Government agencies accounted for 33 per cent of all cyber incidents ASD responded to in 2024–25, making the sector one of the most heavily targeted in the country.
  • Legacy MPLS architectures were not designed for the distributed, high-availability, zero-trust requirements now expected of government networks.
  • The Protective Security Policy Framework (PSPF) sets the mandatory security baseline for non-corporate Commonwealth entities, with IRAP-endorsed assessment underpinning how systems are validated against it.
  • Auditing and hardening citizen-facing digital portals is one of the most immediate, practical steps agencies can take to reduce their exposure.

Modernisation Under Pressure

Tech in Gov, Australia’s leading public sector technology event, was held at the National Convention Centre in Canberra on 4 and 5 August 2026, bringing together around 3,000 delegates, CIOs, CTOs, CISOs and senior leaders from federal, state and local government, across sessions spanning AI and automation, cyber security, data and analytics, critical infrastructure and service delivery.

The event lands at a genuine inflection point for government technology leaders. Citizen expectations for fast, reliable digital services keep rising, while the operating environment those services run on is under some of the most sustained attack pressure of any sector in the country. Agencies are being asked to modernise continuously: to retire legacy systems, extend services to new channels, and support an increasingly distributed workforce, all while meeting security expectations that are considerably higher than those faced by most private sector organisations. That tension does not need dramatising. It is well understood by anyone working inside government technology, and it is the backdrop against which this year’s Tech in Gov conversations will play out.

Where Legacy Architecture Becomes a Liability

Much of the network infrastructure underpinning Australian government was built for a different operating model: centralised, perimeter-defended, and designed around predictable traffic patterns between a handful of major sites. MPLS served that model well for a long time. It does not serve a government workforce that is now distributed across ministerial offices, regional service centres, remote field operations and an expanding footprint of citizen-facing digital channels, all of which need consistent performance and rigorous access control regardless of location.

The shift underway across government is toward secure, high-performance architectures built for that distributed reality. SD-WAN gives agencies centralised policy management across geographically dispersed sites, while supporting the traffic prioritisation that mission-critical applications need when citizen-facing services and back-end administrative systems share the same network. SASE extends security controls out to the network edge, enforcing identity-verified, zero-trust access for remote workers and regional offices without forcing every session to hairpin back through a centralised data centre. Neither of these is a theoretical upgrade path. They are the practical answer to a workforce and service delivery model that has already moved past what MPLS-era architecture was built to support.

Evidence Snapshot

  • Government agencies accounted for 408 cyber security incidents responded to by ASD in 2024–25, representing 33 per cent of all incidents handled nationally (ASD/ACSC Annual Cyber Threat Report 2024–25)
  • Notifiable data breaches involving Australian Government agencies made up 17 per cent of all breaches reported to the OAIC in the second half of 2024 (OAIC Notifiable Data Breaches Report, Jul–Dec 2024)
  • ASD’s proactive notifications to entities of potentially malicious activity increased 83 per cent in 2024–25 (ASD/ACSC Annual Cyber Threat Report 2024–25)
  • Essential Eight Maturity Level 2 has been mandatory for non-corporate Commonwealth entities since 1 July 2022 under PSPF Policy 10, yet the proportion of entities reaching that standard has declined (ASD Commonwealth Cyber Security Posture in 2025)

The Regulatory Backbone: PSPF and IRAP

Underpinning all of this is the Protective Security Policy Framework, the standing Australian Government policy that non-corporate Commonwealth entities are required to apply. PSPF Release 2026 took effect in July 2026 and is organised across six security domains: governance, risk, information, technology, personnel and physical. It sets expectations agencies cannot treat as optional, and it is reviewed annually to keep pace with the threat environment.

Protective Security Policy Framework (PSPF)

Governing body: Attorney-General’s Department, established as Australian Government policy under the Directive on the Security of Government Business.

What it requires: Mandatory application across six security domains (governance, risk, information, technology, personnel and physical), including specific technical and procedural controls such as Essential Eight Maturity Level 2 under PSPF Policy 10 and Information Security Manual (ISM) alignment under PSPF Policy 11.

Who it applies to: All non-corporate Commonwealth entities subject to the Public Governance, Performance and Accountability Act 2013. It represents better practice for corporate Commonwealth entities and wholly-owned Commonwealth companies, and state and territory agencies are required to apply it when holding or accessing Commonwealth-classified material under agreed arrangements.

Consequence of non-compliance: Adverse findings in Australian National Audit Office reviews and PSPF Assessment Reports tabled in Parliament, alongside increased operational and reputational exposure if a security incident follows an unaddressed gap.

Validating a system against the PSPF and the ISM is where the Infosec Registered Assessors Program (IRAP) comes in. IRAP assessors, endorsed by ASD, independently assess how well a system’s security controls align with government requirements, giving agencies and their technology partners a defensible basis for procurement and risk decisions rather than a self-reported claim.

The Public-Facing Attack Surface

Every additional citizen-facing digital channel is also an additional entry point, and it is one of the more immediately actionable areas for agencies to address. ASD’s guidance on hardening internet-facing services and gateway devices is explicit about the risk edge devices pose when they are not consistently patched, monitored and configured, and government’s own incident data reflects that exposure. Auditing citizen-facing portals against that guidance, understanding what is exposed, how it is monitored, and where responsibility for remediation sits, is a concrete step agencies can take now rather than waiting for the next audit cycle to surface the gap.

This is also where the wider theme of operational resilience across government converges with observability. Knowing a portal is up is not the same as knowing it is secure, performant and behaving as expected under load, a distinction covered in more depth in Orro’s recent piece on managed observability.

Where Orro Fits

Orro works with Commonwealth, state and territory, and local government to build the network foundations, cybersecurity capability and operational resilience that modern service delivery demands, with Australian-owned governance and IRAP-aligned architecture underpinning that work. As an Australian-owned partner with Australian-based support escalation and 24/7 global operations capability, Orro supports agencies navigating exactly the tension Tech in Gov 2026 spent two days discussing: how to modernise without compromise.


Sources and Further Reading

  • Australian Signals Directorate’s Australian Cyber Security Centre (2025) – Annual Cyber Threat Report 2024–25
  • Australian Signals Directorate (2025) – Commonwealth Cyber Security Posture in 2025
  • Office of the Australian Information Commissioner (2024) – Notifiable Data Breaches Report, July–December 2024
  • Attorney-General’s Department – Protective Security Policy Framework (protectivesecurity.gov.au)
  • Australian Signals Directorate’s Australian Cyber Security Centre – Infosec Registered Assessors Program (IRAP)
  • Australian Signals Directorate’s Australian Cyber Security Centre – Guidance on hardening internet-facing services and edge devices