Each year, we review how well Queensland public sector entities are managing the information technology (IT) systems that support their delivery of public services.
Through our information systems audit program across entities, we form opinions about the security and integrity of key IT systems to ensure the financial data entities’ use for their financial reporting is reliable. Our first of a new yearly report to parliament Information systems 2025 (Report 6: 2025–26) provided our findings and recommendations.
This blog reminds entities about our advice in this report and shares some actions all entities should prioritise.
Strengthening IT defences remains essential
From our audit work, we are finding most public sector entities generally maintain effective IT controls over the financial systems they use for financial reporting. However, we have identified ongoing weaknesses across several fundamental areas of entities’ IT security. These issues increase entities’ exposure to cyber security risks at a time when attacks are becoming more sophisticated and frequent.
The most common control issues we found relate to:
- system access management – gaps in timely removal of system access for terminated staff and access and dormant accounts, and restricting/monitoring users with elevated access
- passwords and authentication – further progress is needed to implement contemporary methods of authentication to improve security
- security configuration – outdated or inconsistently applied security configuration in systems that are not in line with better practice or security requirements
- monitoring and detection – insufficient security logging or alerts identifying unusual or high‑risk activity
- third-party risk management – service providers are receiving broad access to IT systems without adequate oversight of their security controls.
What entities need to do
- Regularly test and strengthen all aspects of system access controls, including elevated access and system accounts.
- Fully implement robust authentication practices, such as multi‑factor authentication or passwordless authentication.
- Ensure security configuration standards are current and applied consistently across all systems.
- Improve monitoring and ability to detect security incidents, especially where preventative controls are not possible to implement.
- Strengthen oversight of third‑party service providers by defining security requirements and verifying compliance.
Legacy systems continue to create risks and inefficiencies
Half of the systems we audited are legacy systems that are operating beyond their supported lifespan. These legacy systems can no longer receive critical security updates, integrate effectively with newer technologies, or support efficient business processes. Some require manual workarounds, and others cannot provide sufficient audit or activity logs.
We also found that:
- entities do not have a complete and accurate understanding of the number and condition of their legacy systems
- entities reported inconsistent information in their datasets about the inventory of their IT systems, systems requiring attention (at-risk systems), and IT projects to the Department of Customer Services, Open Data and Small and Family Business.
- entities identified some systems for replacement more than a decade ago, but they remain in use
- the Queensland Government’s $1 billion digital fund over the next 4 years is expected to support improvements, but its impact on reducing legacy system risks will take time to assess.
What entities need to do next
- Maintain accurate, complete, and up‑to‑date registers of all of their IT assets and all at‑risk systems.
- Apply consistent risk assessment approaches when reporting on systems requiring attention (at-risk systems) to the Department of Customer Services, Open Data and Small and Family Business.
- Prioritise system upgrades or replacements based on whole‑of‑government risk and investment visibility.
- Implement mitigating controls where legacy systems must remain in service, or formally accept the residual risks.
Overall, these findings reinforce that entities need to manage their IT risks and put in place coordinated actions to address deficiencies in IT controls. Strengthening cybersecurity fundamentals and addressing ageing systems will improve the resilience and reliability of public sector service-delivery.
We encourage entities to focus on timely action of the recommendations we made in our report to parliament Information systems 2025 (Report 6: 2025–26), disciplined risk management, and improved reporting to support better whole‑of‑government decision‑making.
Resources
Reports:
- Information systems 2025 (Report 6: 2025–26)
- Managing third-party cyber security risks (Report 13: 2025–26)
- Responding to and recovering from cyber attacks (Report 12: 2023–24)
Better practice guides:
- Guidelines for implementing new systems
- Checklist for managing third-party cyber security risks
- Role capability checklist for cyber attack response and recovery
- Cyber response and recovery governance checklist
- Risk management maturity model
Blogs:
- Do you understand your third-party cyber security risks?
- Strengthening your internal controls against emerging fraud risks
- Is your Information Security Management System helping you mitigate cyber risk?
- Access controls for information technology systems
For more resources, check out our cyber and digital resources page, which brings together resources from QAO’s large body of work on digital, data, and cyber-related topics drawn from our work across Queensland public sector entities and local governments.