TelcoNews US - Telecommunications news for ICT decision-makers
United States
Certificate failures cost Australian firms over USD $250,000

Certificate failures cost Australian firms over USD $250,000

Wed, 16th Sep 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

DigiCert has published research on the cost of certificate failures for Australian organisations. The survey found that nearly one in ten respondents linked their most serious incident to losses of more than USD $250,000.

The findings point to recurring disruption from expired or mismanaged digital certificates, which authenticate systems and secure online services. Among Australian organisations surveyed, 43.6% said they had suffered a service outage caused by an expired certificate over the past year.

Certificate-related downtime was also prolonged in many cases. Nearly one-third of respondents, or 31.6%, said they had experienced at least five hours of certificate-related downtime, while 12.4% said the disruption lasted 25 hours or more.

The study suggests many companies no longer see certificate failures solely as a security issue. More than half of Australian respondents, or 51.2%, classified certificate outages as infrastructure issues, indicating that the operational impact now extends beyond cybersecurity teams.

Automation gap

Automated certificate lifecycle management now ranks fourth among cybersecurity priorities for the organisations surveyed. It placed ahead of post-quantum cryptography deployment, efforts to standardise internet of things security, broader Zero Trust programs, and privacy-first initiatives.

Yet adoption remains limited. Only 8% of respondents said they already had automation in place.

Budget constraints were the most commonly cited obstacle, named by 24.4% of respondents. A further 22% pointed to incompatibility with legacy technology systems.

Mike Nelson, Global Vice President, Field CTO at DigiCert, said the operational burden is likely to rise as certificate validity periods shrink and the number of certificates in use increases.

"An expired certificate can shut down a critical service just as quickly as any other infrastructure failure," Nelson said.

"With certificate lifecycles shrinking to 47 days, spreadsheets and calendar reminders simply won't scale. Organisations need to know every certificate they have, where it is, who owns it, and then automate the lifecycle before an overlooked expiration becomes a business outage," he said.

Rising volumes

Nearly three-quarters of organisations surveyed expect certificate volumes to increase over the next two years. More than half already manage more than 1,000 certificates.

Under planned industry rules from 2029, public TLS certificates will be limited to 47 days and domain validation reuse to 10 days. Companies would therefore need to renew and validate certificates far more often than they do now.

For an organisation managing 1,000 public TLS certificates, DigiCert estimated this could mean roughly 8,000 certificate issuances and 40,000 domain validations each year. The figures illustrate the administrative load facing large estates if processes remain manual.

The report also found that 37.6% of organisations are still not actively preparing for shorter certificate lifecycles. In Australia, 62.4% said they were actively preparing, compared with 71% in the UK and 74% in the US.

Service disruption linked to certificate mismanagement was also widely reported. Some 41.6% of respondents said they had experienced service downtime for that reason, and more than half said they were very or extremely concerned about certificate expiration.

Survey scope

The research was based on a survey of 1,001 IT and cybersecurity decision-makers across Australia, the United States, and the United Kingdom. Propeller Insights conducted the survey on behalf of DigiCert.

The Australian findings add to a broader debate over digital infrastructure resilience as more organisations depend on certificates to run customer-facing services, internal systems, and machine-to-machine communications. As certificate volumes rise and validity periods shorten, the risk shifts from isolated oversight to a recurring operational problem with measurable financial consequences.

Among the clearest findings in Australia was the concentration of larger losses in a minority of incidents, with 9.2% of organisations saying their most significant certificate incident cost more than USD $250,000.