Biphoo.eu - Guest Posting Services

collapse
Home / Daily News Analysis / Australian government cloud mandate sparks migration warnings

Australian government cloud mandate sparks migration warnings

Jul 28, 2026  Twila Rosenbaum  4 views
Australian government cloud mandate sparks migration warnings

Australia's whole-of-government cloud policy comes into effect on 1 July 2026, establishing cloud as the default when modernising IT infrastructure. The policy document, prepared by the Digital Transformation Agency (DTA), sets out five broad requirements. They include prioritising cloud technologies for IT modernisation, leveraging cloud to drive innovation including artificial intelligence (AI), adopting cloud securely and responsibly, actively managing and optimising cloud costs, and nurturing cloud skills across the Australian Public Service (APS).

The first specific requirement is for agencies to adopt cloud solutions for all new digital and ICT initiatives and upgrades unless an alternative is justified. However, industry experts have raised significant concerns about the blanket nature of this mandate. Gartner director-analyst Adrian Wong warned that a one-size-fits-all approach overlooks the reality that some applications or workload components are simply poor fits for cloud. Legacy applications, for example, often fail to fully utilise cloud computing capabilities, making them technically mismatched and sometimes unexpectedly more expensive to run in the cloud than in a local datacentre.

Wong pointed out that while the policy frames this as a transition away from ageing systems, aggressive timelines can drive poor decision-making. If organisations feel rushed, especially lacking adequate cloud planning and architectural expertise, they are more likely to pursue poorly conceived lift-and-shift migrations. These hurried efforts frequently fail to meet expectations and form the basis for cloud project failures. According to a Gartner report on handling cloud project failures, common reasons include workloads inappropriate for cloud, poorly chosen providers, bad design or implementation, inaccurate cost estimates, and integration issues.

Wong noted several factors that make workloads inherently more suited to on-premise deployment: high sensitivity to latency; strict data residency, compliance, or sovereignty mandates that cannot be satisfied with public cloud solutions; unique service-level agreements that cloud providers might not meet; and environments requiring enterprise-controlled assets. According to Wong, “Ultimately, avoiding cloud dissatisfaction requires agencies to have the time and flexibility to perform a detailed application portfolio analysis. While prioritising modern cloud solutions is a strong strategic aspiration, enforcing rigid decommissioning pressures risks forcing bad long-term fits just to satisfy policy requirements.”

Vinayak Sreedhar, country manager for Australia and New Zealand (ANZ) at ManageEngine, an IT management and monitoring provider that serves federal, state, and local government customers, said agencies shouldn't underestimate the complexity of what lies ahead. Migrating away from legacy systems while ensuring ongoing compliance is no easy feat. “The agencies most at risk are those without a clear picture of what's being retired, when, and what is dependent on it. Moving fast without that clarity is how outages occur,” Sreedhar said.

AI and interoperability

Cloud platforms are seen as a way of creating a more connected, responsive, and data-driven public sector, partly through adoption of artificial intelligence. While government entities are required to design for interoperability and portability to minimise supplier lock-in, they are only encouraged to ensure cloud services support open standards and APIs and allow for data portability. SUSE ANZ general manager Ben Henshall suggested the language in the policy indicates the DTA wants to avoid another “mother of all lock-in” situation that repeats historical problems with mainframes. Once data is locked into a particular cloud, it becomes very hard and costly to extract it into a format deployable elsewhere.

Henshall warned that public clouds are designed as a “land grab” to capture as many departmental workloads as possible. “They're not making it easy to get out because why would they? It's not in their commercial interest to be open, interoperable, more standard spaces.” For example, hyperscalers each have their own domain-specific languages for creating templates that specify operating systems and software for virtual machines. The government cloud policy highlights design and procurement principles of selecting architectures that are open, interoperable, contestable, and portable, but that remains a challenge.

According to Henshall, a vast amount of money is spent simply keeping the lights on rather than on innovation. Replatforming with low cost and effort is the “secret sauce” of open source and of companies like SUSE because they remain agnostic, allowing agencies to spend more time deploying new features rather than draining budgets on system upgrades. While cloud provider partners offer utility, Henshall admitted they also pose risks and add cost because they rely on proprietary technology stacks, creating complications for multicloud environments. Departments such as education, health, defence, home affairs, and Services Australia are complex organisations with vast use cases, and cannot source all capabilities from a single provider. This makes interoperability, portability, and integration vital.

Agentic AI is also gaining attention as a way to automate workflows. Different systems within a process will use different large language models (LLMs) of varying sizes, meaning data processing needs will be highly varied. At one extreme, soldiers have disconnected, intermittent, and limited access to remote systems, so processing must be local. At the other extreme, the health department processes large volumes of records to determine benefits or treatments. With many LLMs available, both open source and proprietary, Henshall said it is incredibly important for governments to retain sovereign control over their data and models. Governments are looking to open source LLMs to access code, ensure explainability, and govern the models.

According to Sreedhar, the explicit push to embed AI readiness across cloud platforms is forward thinking and necessary, but it isn't a switch organisations can simply flip post-migration. “How is the data structured, governed, and stored? How much compute is being provisioned? And how will models eventually be deployed? These questions require deliberate architectural decisions from day one. Those that treat AI as a future add-on rather than a current design requirement will be hit with expensive infrastructure rebuilds in a few years' time. The time to get this right is during the transition, not after,” Sreedhar said.

Security considerations

Henshall pointed out that federal government agencies will have to navigate the cloud transition whether it proves hard or easy, especially when it comes to security. “No one wants to be on the front page of the newspaper. Nobody wants to be the person who accidentally put information out into a public AI system that caused a whole lot of sovereign angst,” he said. A modern, defensible architecture is an essential, non-negotiable requirement for hosting and running AI workloads safely and securely. As a supplier, part of SUSE's job is to help government departments apply a modern defensible architecture, adhering to Essential Eight principles, the Australian Signals Directorate's information security manual, and ISO 27001. This ensures a zero-trust architecture that is portable, composable, and interoperable. Without this, federal agencies will lag in their ability to tap the technical benefits of AI.

Sreedhar warned that the sheer scale of the transition creates a much larger attack surface. Recent cyber security legislative reforms have sharpened obligations for critical infrastructure operators to protect business-critical data, but agencies should treat those obligations as a mere baseline. “The vulnerability we see most often in cloud transitions isn't technical – it's the gap between IT teams and security teams during the migration itself. Security architects need to be part of the transition from procurement through to go-live and beyond,” Sreedhar said.

Skills uplift

A policy framework is only as good as the people who put it into practice, Sreedhar observed. The DTA has been clear that agencies must build the skills, infrastructure, and governance required to meet community expectations, yet workforce capability is almost always the most underfunded component of digital transformation. Agencies should be evaluating their internal capability right now, well ahead of the 1 July deadline, and investing in genuine skills uplift where gaps exist. “Getting the technology right matters, but so does building a public service that understands and owns what it's building,” Sreedhar said. This is especially vital for the policy's fifth requirement, which explicitly demands agencies nurture cloud skills across the APS.

“Agencies won't be able to satisfy the policy simply by pointing to cloud deployments. That's the easy part. Agencies need genuine workforce development strategies and plans to close identified skills gaps. One of the ways we're addressing this at ManageEngine is at the operational layer, helping staff build fluency with hands-on training and tools spanning infrastructure, security, and FinOps – the disciplines the DTA has specifically and rightly called out,” Sreedhar said. Reflecting on the skills mandate, Henshall described this aspect of the policy as a strong starting point that offers good principles and guidelines. “It's there not as a stick, but as a compass,” he said.

In the broader context, the cloud mandate represents a significant shift for Australian government IT. The policy aims to drive consistency, security, and innovation across all federal entities. However, the risks are real. The experience of other governments worldwide – such as the United States' Cloud Smart strategy and the United Kingdom's cloud-first policy – shows that success depends on careful planning, vendor diversification, and building internal capabilities. Without those foundations, the transition could lead to cost blowouts, security incidents, and service disruptions. Australian agencies would be wise to learn from international examples and invest in thorough application portfolio analysis before rushing into migration.

Moreover, the push for AI readiness adds another layer of complexity. While AI can transform service delivery, it also introduces new challenges around data governance, model explainability, and ethical use. The DTA's requirement for agencies to design for interoperability and portability is a crucial guardrail against lock-in, but as Henshall noted, hyperscalers design their platforms to capture and retain workloads. Agencies must actively negotiate open standards and ensure they can move data and applications between providers without prohibitive cost. This will require sustained investment in technical expertise and procurement skills.

Finally, the security dimension cannot be overlooked. The Australian Cyber Security Centre (ACSC) has repeatedly warned about the risks of misconfigured cloud services, unsecured APIs, and inadequate identity management. As agencies accelerate cloud adoption, they must embed security into every phase of the migration lifecycle. The gap between IT and security teams that Sreedhar identified is a common failure point. A collaborative approach involving CISO, CIO, and cloud architects from the start can mitigate many of these risks. The message from industry experts is clear: the cloud mandate is ambitious and necessary, but it must be executed with caution, foresight, and a commitment to building the right skills and processes.


Source: ComputerWeekly.com News


Share:

Your experience on this site will be improved by allowing cookies Cookie Policy