Why the Capex Line Hides the Obligation That Actually Matters

Hidden capex obligations worth millions can sit entirely off a company's balance sheet without any wrongdoing, and this framework shows investors exactly how to spot the gap, what private buyers do about it, and which three questions to raise at the next investor call.
By Ryan Dhillon -
Annual report casting a server-rack shadow — hidden capex obligations invisible in financial statements
  • Between $1.1 trillion in unrecognised data-centre lease commitments and $1.5 trillion in unconditional purchase obligations sit off the balance sheets of major technology companies, invisible to standard leverage screens.
  • Legacy maintenance consumes 60 to 80 percent of total enterprise IT budgets before a single refresh begins, and deferring a refresh grows the eventual bill by aging more of the estate out simultaneously.
  • A June 2024 network scan found 26 percent of observed enterprise Linux servers running CentOS 7 past its end-of-support date, confirming that end-of-life operation is a widespread real-world condition, not a fringe scenario.
  • Private acquirers convert infrastructure condition into a hard dollar deduction from purchase price using automated discovery and vendor lifecycle mapping, a method the article describes as replicable and well understood, giving them an information advantage over public market investors.
  • Three indicators in annual reports can flag potential deferred capex: persistent capex-to-depreciation deficits over multiple years, acquisition-led growth with no integration plan, and sudden unexplained capex step-ups with no accompanying growth narrative.
Summarise with AI:

A company can carry millions of dollars in future cash obligations that appear nowhere in its published accounts. Those obligations are not concealed through any wrongdoing; they are absent because of how accounting standards are built.

The annual report gives you a depreciation schedule and a capital expenditure line. What it does not tell you is whether the infrastructure generating that depreciation is two years from a forced replacement or already running four years past the point where its vendor stopped supporting it.

That distance between what is reported and what is actually owed is the subject here. What follows is a framework for reading a capex figure critically, understanding the number that never makes the statements, and knowing what to do with that gap as an investor.

Why the annual report goes quiet on this kind of spending

Accounting standards require capital expenditure to be recorded when it happens, not when it becomes foreseeable. A refresh cycle that everyone inside the business knows is coming does not appear anywhere until the money is actually spent.

That is the whole mechanism. Deferred IT spending sits outside the financial statements not because a company chose to hide it, but because the rules have no line for an obligation that has not yet materialised.

Off-balance-sheet obligations are not unique to IT infrastructure: an estimated $1.1 trillion in unrecognised data-centre lease commitments and $1.5 trillion in unconditional purchase obligations sit outside the balance sheets of major technology companies, invisible to the standard leverage screens most equity investors apply.

You can observe plenty from the accounts. Capitalised assets sit on the balance sheet, depreciation schedules show you the wear-down of what was bought, and the stated capex figure tells you what was spent in the period.

What you cannot see is the share of the estate running past its supported life, the timing of the next big licence renewal, or the size of the refresh bill quietly building on the horizon.

What compounds in the background

The scale of ongoing maintenance is the part most investors underestimate. Multiple 2026 modernisation and budgeting analyses, drawing on Gartner, Forrester, and Deloitte, place legacy maintenance at 60 to 80 percent of total enterprise IT spend before a single refresh even begins.

Between 60% and 80% of enterprise IT budgets go to keeping existing systems running, leaving only the remainder for anything new.

The Hidden IT Burden: Maintenance vs. Innovation

Deferral does not freeze the bill. It grows it. Postpone a hardware or software refresh and more of the estate ages out at the same time, while migrating from an older baseline becomes more complex and more expensive than it would have been on schedule.

End-of-life operation is not a fringe scenario either. A June 2024 network scan found that 26% of observed enterprise Linux servers were running CentOS 7, a distribution that reached the end of its supported life that very month.

The read for you is straightforward. A capex line tells you what a company spent, not what it owes, and the accounting structure that keeps the obligation invisible is the same structure that keeps it off the page as a foreseeable liability.

What happens when deferred spending meets unsupported software

The first cost of deferral is the replacement you eventually have to fund. The second cost is the one that arrives while you wait.

Running systems past vendor end-of-support does more than push out a capital decision. It converts the infrastructure into a permanent attack surface, because security patches stop arriving while known vulnerabilities keep piling up against systems that will never be fixed.

This is not a theoretical framing. It is codified in the frameworks Australian organisations are expected to work within.

  • The Australian Cyber Security Centre (ACSC) states that once devices, operating systems, or software reach end of support, they stop receiving updates and stay persistently exposed to attacks through known bugs.
  • NIST SP 800-53 control SA-22 requires organisations to replace components once support ends, or to put documented alternative support arrangements in place.
  • NIST SP 800-171 warns of the same open vulnerability window that unsupported components create.
  • The NIST Cybersecurity Framework mappings ID.AM-2 and PR.PS-02 require that only currently supported software be authorised in enterprise inventories, with any exception needing formal risk acceptance.

The ACSC’s position is blunt: end-of-support systems no longer receive updates and remain persistently vulnerable to cyber-attacks through known software bugs.

The CentOS 7 figure from earlier makes the point concrete. More than a quarter of scanned servers were already running past a support cutoff, which is the state the frameworks warn against, happening at scale in the real world.

Here is why this matters to you as an investor rather than to an IT department. In sectors where security posture affects contract eligibility or the terms of cyber insurance, the condition of the infrastructure estate stops being a cost question and becomes a revenue one.

End-of-support infrastructure in a regulated or compliance-sensitive business is not a problem confined to a server room. It can decide whether a contract is won or renewed, and whether an insurance policy holds when it is needed. That is a direct line to earnings, not an operational footnote.

In sectors where security posture affects contract eligibility, Australian procurement teams and insurers have increasingly hardened that gate into a commercial absolute, disqualifying vendors without documented controls regardless of product quality or pricing.

How private buyers put a dollar figure on infrastructure nobody discloses

Private acquirers do not treat infrastructure condition as a mystery. They treat it as a number, and they go and find it through a repeatable sequence.

  1. Automated discovery. Instead of relying on whatever asset register the target provides, the acquirer deploys automated discovery tools across the full estate to produce a verified picture of everything that is actually operating.
  2. Lifecycle aging. Each discovered device and software installation is mapped to its vendor’s published lifecycle data, identifying items already beyond end-of-support, those approaching it within the review window, and upcoming licence renewal dates.
  3. Translation into a forward estimate. The aged inventory becomes a dollar figure, typically covering a 12-to-24-month window, expressed as a “must-spend” technology investment.

Self-reported registers get skipped for a reason: they undercount. A register reflects formal procurement channels, so it routinely misses shadow IT, legacy systems inherited through past acquisitions, and devices that were simply never logged. Discovery captures what the paperwork does not.

The resulting number is not academic. Practitioner materials point to mandatory one-time costs such as a £3.0m legacy ERP migration or an illustrative $2m remediation charge as the kind of figure involved. In a deal model, that becomes a “Deficit CAPEX” or “Tech Debt Adjustment” and is deducted directly from enterprise value or purchase price.

The two parties are simply looking at different amounts of information.

The Infrastructure Information Gap

Information type Private acquirer view Public investor view
Asset inventory Reconciled discovery across the full estate None disclosed
Estate age and support status Age-stratified, checked against vendor lifecycles Depreciation schedule only
Forward spending obligation Dollar estimate over 12-24 months Not visible
Effect on valuation Deducted from purchase price Cannot be assessed

The takeaway is not that anyone is hiding anything. The gap between what an acquirer knows and what you can see is a difference in access, not honesty, and the acquirer’s figure rests on a method that is both replicable and well understood. The information is knowable. It just takes someone going to look.

What software can surface and what it still cannot tell you

If the acquirer’s advantage is access, then the tool that provides that access matters. ASX-listed FirstWave Cloud Technology produces one such tool, the Open-AudIT platform, positioned within a competitive segment of asset discovery products.

Open-AudIT works without installing software agents on individual endpoints, which lets it build an inventory across on-premise, cloud, and hybrid environments from a single deployment. Its capabilities cover the ground a due diligence team needs.

  • Agentless discovery across on-premise, cloud, and hybrid estates.
  • Flagging of systems running past vendor end-of-support dates.
  • Licence status tracking across the estate.
  • Surfacing of shadow IT that formal registers miss.
  • Configuration validation against NIST, ISO 27001, the ACSC’s Essential Eight, and the CIS Controls.

The most recent version, Open-AudIT v6, adds contextual vulnerability management, narrowing the universe of published vulnerabilities down to those that actually apply to the specific devices it discovers. The platform has an open-source heritage, and a free community edition remains available alongside the commercial tiers, so the capability is not locked behind one vendor.

More than 150,000 organisations were estimated to be using Open-AudIT across FY25 and FY26 updates, up from over 130,000 disclosed in FY24.

FirstWave and analyst commentary tie that installed base to a $30 million annual recurring revenue opportunity through the conversion of free users into paying subscribers, framed as management and analyst expectation rather than a firm forecast. Early v6 metrics reported in Q3 FY26 showed 5,991 downloads since launch, a 6.09% commercial trial conversion rate, and 194 open leads in the sales funnel, with the active free base spread across roughly 20,000 users on Open-AudIT.com and 19,000 on Open-AudIT.org.

Now the counterweight, because the tool solves less than it first appears. Discovery tells you what exists and its lifecycle status; it does not tell you what remediation is required or what it will cost. Converting an aged inventory into a credible budget requires specialists who can assess the environment, evaluate realistic migration options, and apply current commercial pricing.

Not every end-of-life system is an active risk either, particularly where a system is genuinely isolated from external networks, and this remains a category where several vendors offer comparable capability. What matters for you is structural, not technical: the existence of a systematic tool, run at scale by a listed company, confirms that infrastructure condition is measurable. The public market blind spot is a product of access, not of the information being fundamentally unknowable.

Three questions worth raising at the next investor call

You cannot run discovery on a listed company’s network, and this piece does not pretend otherwise. What you can do is know what to look for and what to ask. Three indicators are worth raising directly.

  1. Capex running persistently below depreciation. Australian annual reports set out depreciation under AASB standards, so you can watch the relationship over several periods. Capex sitting below depreciation for multiple consecutive years may reflect genuine efficiency, or it may signal replacement spending being deferred and quietly stacking up.
  2. Acquisition-led growth with no stated integration program. A company that has grown by buying others, without a described rationalisation or integration plan, has a higher chance of carrying parallel, unconsolidated infrastructure estates across its former subsidiaries, each with its own refresh clock.
  3. Sudden, unexplained capex step-ups. A jump in capital expenditure with no accompanying growth or expansion story may be catch-up spending on deferred maintenance rather than investment in something new.

None of these is a conclusion on its own. Each is a reason to ask a question, on an analyst call, at an AGM, or in writing to an investor relations contact.

The private market context from earlier is why this is worth your time even though you cannot conduct the due diligence yourself. When a deal involves a technology-heavy target, the price negotiated already reflects infrastructure condition, even when the accounts stay silent on it.

Capital allocation signals embedded in annual reports carry more information than the headline capex figure suggests; Russell 1000 data from Q1 2026 shows a 27.1% year-on-year surge in aggregate capital expenditure, concentrated in infrastructure and AI, which makes distinguishing genuine investment from deferred maintenance catch-up a more consequential analytical task than in prior cycles.

The point of all this is that you can ask something more precise than whether management takes technology seriously. You can ask what a persistently low capex-to-depreciation ratio is actually signalling, which is a far harder question to wave away.

This article is for informational purposes only and should not be considered financial advice. Investors should conduct their own research and consult with financial professionals before making investment decisions.

Knowing the gap exists is already half the work

There is a class of future cash obligation that is real, dateable, and invisible in financial statements. Private buyers price it into their deals. Public market investors cannot see it directly. That asymmetry is the condition you now understand, and understanding it changes how you read a capex line.

None of this implies that any particular listed company carries this exposure. A persistently low capex line is a question to raise, not a diagnosis to reach. The indicators point you toward a conversation, not a conclusion.

What may shift over time is the size of the gap itself. As automated discovery tools spread and infrastructure condition becomes easier to measure, the distance between what acquirers know and what public investors can reasonably infer may narrow, even if the formal disclosure rules never change. The obligation was always there. The difference is that more people are now able to go and find it.

Technology adoption signals visible before analyst coverage arrives, including job postings requiring specific tools and developer standardisation patterns, follow a similar informational logic to infrastructure condition: the underlying reality is knowable to those who know where to look, and it typically precedes any formal disclosure by twelve to eighteen months.

Frequently Asked Questions

What is hidden capex and why does it not appear in financial statements?

Hidden capex refers to future capital spending obligations, particularly IT infrastructure refresh costs, that accounting standards do not require companies to record until the money is actually spent, meaning a known replacement cycle can build for years without appearing anywhere in published accounts.

How much of enterprise IT budgets goes to maintaining legacy systems?

Research from Gartner, Forrester, and Deloitte places legacy maintenance at 60 to 80 percent of total enterprise IT spend before any refresh begins, leaving only a small share of budgets available for new investment.

How do private equity buyers account for deferred IT spending in acquisitions?

Private acquirers run automated discovery across the target's full estate, map every asset against vendor lifecycle data, and translate the result into a forward dollar estimate covering 12 to 24 months, which is then deducted directly from enterprise value or purchase price as a deficit capex or tech debt adjustment.

What are the warning signs of deferred IT capex in an annual report?

Three indicators are worth watching: capex running persistently below depreciation over multiple consecutive years, acquisition-led growth with no stated integration or rationalisation program, and sudden unexplained step-ups in capital expenditure that have no accompanying growth story.

Why does running software past end-of-support matter for investors beyond the IT cost?

In regulated or compliance-sensitive sectors, infrastructure running past vendor end-of-support creates a permanent attack surface with no incoming security patches, which can disqualify a company from winning or renewing contracts and may invalidate cyber insurance cover, making it a direct earnings risk rather than an operational footnote.

Ryan Dhillon
By Ryan Dhillon
Head of Marketing
Bringing 14 years of experience in content strategy, digital marketing, and audience development to StockWire X. Ryan has delivered growth programs for global brands including Mercedes-AMG Petronas F1, Red Bull Racing, and Google, and applies that same rigour to helping Australian investors access fast, accurate, and well-structured market intelligence.
Learn More
Companies Mentioned in Article

Breaking ASX Alerts Direct to Your Inbox

Join +20,000 subscribers receiving alerts.

Join thousands of investors who rely on StockWire X for timely, accurate market intelligence.

About the Publisher