A company can carry millions of dollars in future cash obligations that appear nowhere in its published accounts. Those obligations are not concealed through any wrongdoing; they are absent because of how accounting standards are built.
The annual report gives you a depreciation schedule and a capital expenditure line. What it does not tell you is whether the infrastructure generating that depreciation is two years from a forced replacement or already running four years past the point where its vendor stopped supporting it.
That distance between what is reported and what is actually owed is the subject here. What follows is a framework for reading a capex figure critically, understanding the number that never makes the statements, and knowing what to do with that gap as an investor.
Why the annual report goes quiet on this kind of spending
Accounting standards require capital expenditure to be recorded when it happens, not when it becomes foreseeable. A refresh cycle that everyone inside the business knows is coming does not appear anywhere until the money is actually spent.
That is the whole mechanism. Deferred IT spending sits outside the financial statements not because a company chose to hide it, but because the rules have no line for an obligation that has not yet materialised.
Off-balance-sheet obligations are not unique to IT infrastructure: an estimated $1.1 trillion in unrecognised data-centre lease commitments and $1.5 trillion in unconditional purchase obligations sit outside the balance sheets of major technology companies, invisible to the standard leverage screens most equity investors apply.
You can observe plenty from the accounts. Capitalised assets sit on the balance sheet, depreciation schedules show you the wear-down of what was bought, and the stated capex figure tells you what was spent in the period.
What you cannot see is the share of the estate running past its supported life, the timing of the next big licence renewal, or the size of the refresh bill quietly building on the horizon.
What compounds in the background
The scale of ongoing maintenance is the part most investors underestimate. Multiple 2026 modernisation and budgeting analyses, drawing on Gartner, Forrester, and Deloitte, place legacy maintenance at 60 to 80 percent of total enterprise IT spend before a single refresh even begins.
Between 60% and 80% of enterprise IT budgets go to keeping existing systems running, leaving only the remainder for anything new.
Deferral does not freeze the bill. It grows it. Postpone a hardware or software refresh and more of the estate ages out at the same time, while migrating from an older baseline becomes more complex and more expensive than it would have been on schedule.
End-of-life operation is not a fringe scenario either. A June 2024 network scan found that 26% of observed enterprise Linux servers were running CentOS 7, a distribution that reached the end of its supported life that very month.
The read for you is straightforward. A capex line tells you what a company spent, not what it owes, and the accounting structure that keeps the obligation invisible is the same structure that keeps it off the page as a foreseeable liability.
When big ASX news breaks, our subscribers know first
What happens when deferred spending meets unsupported software
The first cost of deferral is the replacement you eventually have to fund. The second cost is the one that arrives while you wait.
Running systems past vendor end-of-support does more than push out a capital decision. It converts the infrastructure into a permanent attack surface, because security patches stop arriving while known vulnerabilities keep piling up against systems that will never be fixed.
This is not a theoretical framing. It is codified in the frameworks Australian organisations are expected to work within.
- The Australian Cyber Security Centre (ACSC) states that once devices, operating systems, or software reach end of support, they stop receiving updates and stay persistently exposed to attacks through known bugs.
- NIST SP 800-53 control SA-22 requires organisations to replace components once support ends, or to put documented alternative support arrangements in place.
- NIST SP 800-171 warns of the same open vulnerability window that unsupported components create.
- The NIST Cybersecurity Framework mappings ID.AM-2 and PR.PS-02 require that only currently supported software be authorised in enterprise inventories, with any exception needing formal risk acceptance.
The ACSC’s position is blunt: end-of-support systems no longer receive updates and remain persistently vulnerable to cyber-attacks through known software bugs.
The CentOS 7 figure from earlier makes the point concrete. More than a quarter of scanned servers were already running past a support cutoff, which is the state the frameworks warn against, happening at scale in the real world.
Here is why this matters to you as an investor rather than to an IT department. In sectors where security posture affects contract eligibility or the terms of cyber insurance, the condition of the infrastructure estate stops being a cost question and becomes a revenue one.
End-of-support infrastructure in a regulated or compliance-sensitive business is not a problem confined to a server room. It can decide whether a contract is won or renewed, and whether an insurance policy holds when it is needed. That is a direct line to earnings, not an operational footnote.
In sectors where security posture affects contract eligibility, Australian procurement teams and insurers have increasingly hardened that gate into a commercial absolute, disqualifying vendors without documented controls regardless of product quality or pricing.
How private buyers put a dollar figure on infrastructure nobody discloses
Private acquirers do not treat infrastructure condition as a mystery. They treat it as a number, and they go and find it through a repeatable sequence.
- Automated discovery. Instead of relying on whatever asset register the target provides, the acquirer deploys automated discovery tools across the full estate to produce a verified picture of everything that is actually operating.
- Lifecycle aging. Each discovered device and software installation is mapped to its vendor’s published lifecycle data, identifying items already beyond end-of-support, those approaching it within the review window, and upcoming licence renewal dates.
- Translation into a forward estimate. The aged inventory becomes a dollar figure, typically covering a 12-to-24-month window, expressed as a “must-spend” technology investment.
Self-reported registers get skipped for a reason: they undercount. A register reflects formal procurement channels, so it routinely misses shadow IT, legacy systems inherited through past acquisitions, and devices that were simply never logged. Discovery captures what the paperwork does not.
The resulting number is not academic. Practitioner materials point to mandatory one-time costs such as a £3.0m legacy ERP migration or an illustrative $2m remediation charge as the kind of figure involved. In a deal model, that becomes a “Deficit CAPEX” or “Tech Debt Adjustment” and is deducted directly from enterprise value or purchase price.
The two parties are simply looking at different amounts of information.
| Information type | Private acquirer view | Public investor view |
|---|---|---|
| Asset inventory | Reconciled discovery across the full estate | None disclosed |
| Estate age and support status | Age-stratified, checked against vendor lifecycles | Depreciation schedule only |
| Forward spending obligation | Dollar estimate over 12-24 months | Not visible |
| Effect on valuation | Deducted from purchase price | Cannot be assessed |
The takeaway is not that anyone is hiding anything. The gap between what an acquirer knows and what you can see is a difference in access, not honesty, and the acquirer’s figure rests on a method that is both replicable and well understood. The information is knowable. It just takes someone going to look.
What software can surface and what it still cannot tell you
If the acquirer’s advantage is access, then the tool that provides that access matters. ASX-listed FirstWave Cloud Technology produces one such tool, the Open-AudIT platform, positioned within a competitive segment of asset discovery products.
Open-AudIT works without installing software agents on individual endpoints, which lets it build an inventory across on-premise, cloud, and hybrid environments from a single deployment. Its capabilities cover the ground a due diligence team needs.
- Agentless discovery across on-premise, cloud, and hybrid estates.
- Flagging of systems running past vendor end-of-support dates.
- Licence status tracking across the estate.
- Surfacing of shadow IT that formal registers miss.
- Configuration validation against NIST, ISO 27001, the ACSC’s Essential Eight, and the CIS Controls.
The most recent version, Open-AudIT v6, adds contextual vulnerability management, narrowing the universe of published vulnerabilities down to those that actually apply to the specific devices it discovers. The platform has an open-source heritage, and a free community edition remains available alongside the commercial tiers, so the capability is not locked behind one vendor.
More than 150,000 organisations were estimated to be using Open-AudIT across FY25 and FY26 updates, up from over 130,000 disclosed in FY24.
FirstWave and analyst commentary tie that installed base to a $30 million annual recurring revenue opportunity through the conversion of free users into paying subscribers, framed as management and analyst expectation rather than a firm forecast. Early v6 metrics reported in Q3 FY26 showed 5,991 downloads since launch, a 6.09% commercial trial conversion rate, and 194 open leads in the sales funnel, with the active free base spread across roughly 20,000 users on Open-AudIT.com and 19,000 on Open-AudIT.org.
Now the counterweight, because the tool solves less than it first appears. Discovery tells you what exists and its lifecycle status; it does not tell you what remediation is required or what it will cost. Converting an aged inventory into a credible budget requires specialists who can assess the environment, evaluate realistic migration options, and apply current commercial pricing.
Not every end-of-life system is an active risk either, particularly where a system is genuinely isolated from external networks, and this remains a category where several vendors offer comparable capability. What matters for you is structural, not technical: the existence of a systematic tool, run at scale by a listed company, confirms that infrastructure condition is measurable. The public market blind spot is a product of access, not of the information being fundamentally unknowable.
Three questions worth raising at the next investor call
You cannot run discovery on a listed company’s network, and this piece does not pretend otherwise. What you can do is know what to look for and what to ask. Three indicators are worth raising directly.
- Capex running persistently below depreciation. Australian annual reports set out depreciation under AASB standards, so you can watch the relationship over several periods. Capex sitting below depreciation for multiple consecutive years may reflect genuine efficiency, or it may signal replacement spending being deferred and quietly stacking up.
- Acquisition-led growth with no stated integration program. A company that has grown by buying others, without a described rationalisation or integration plan, has a higher chance of carrying parallel, unconsolidated infrastructure estates across its former subsidiaries, each with its own refresh clock.
- Sudden, unexplained capex step-ups. A jump in capital expenditure with no accompanying growth or expansion story may be catch-up spending on deferred maintenance rather than investment in something new.
None of these is a conclusion on its own. Each is a reason to ask a question, on an analyst call, at an AGM, or in writing to an investor relations contact.
The private market context from earlier is why this is worth your time even though you cannot conduct the due diligence yourself. When a deal involves a technology-heavy target, the price negotiated already reflects infrastructure condition, even when the accounts stay silent on it.
Capital allocation signals embedded in annual reports carry more information than the headline capex figure suggests; Russell 1000 data from Q1 2026 shows a 27.1% year-on-year surge in aggregate capital expenditure, concentrated in infrastructure and AI, which makes distinguishing genuine investment from deferred maintenance catch-up a more consequential analytical task than in prior cycles.
The point of all this is that you can ask something more precise than whether management takes technology seriously. You can ask what a persistently low capex-to-depreciation ratio is actually signalling, which is a far harder question to wave away.
This article is for informational purposes only and should not be considered financial advice. Investors should conduct their own research and consult with financial professionals before making investment decisions.
Knowing the gap exists is already half the work
There is a class of future cash obligation that is real, dateable, and invisible in financial statements. Private buyers price it into their deals. Public market investors cannot see it directly. That asymmetry is the condition you now understand, and understanding it changes how you read a capex line.
None of this implies that any particular listed company carries this exposure. A persistently low capex line is a question to raise, not a diagnosis to reach. The indicators point you toward a conversation, not a conclusion.
What may shift over time is the size of the gap itself. As automated discovery tools spread and infrastructure condition becomes easier to measure, the distance between what acquirers know and what public investors can reasonably infer may narrow, even if the formal disclosure rules never change. The obligation was always there. The difference is that more people are now able to go and find it.
Technology adoption signals visible before analyst coverage arrives, including job postings requiring specific tools and developer standardisation patterns, follow a similar informational logic to infrastructure condition: the underlying reality is knowable to those who know where to look, and it typically precedes any formal disclosure by twelve to eighteen months.

