Summary

  • APNIC says it completed a multi-year migration from end-of-life CentOS hosts to containerised platforms or RHEL9 in Q2 2026. Its 2025 Annual Report also records completed virtual-machine and virtualisation-platform migrations.
  • The same public record describes DAST, SAST, vulnerability reporting, data classification, retention, DLP and adversary emulation, but mixes completed outcomes, current activity and future targets.
  • Four privacy-safe evidence joins remain outside the public record: service inventory to retired platform, finding to remediation, classification to deletion disposition, and emulation scenario to production-detection validation.
  • A quarterly control-closure receipt could expose denominators, age bands, dispositions, exceptions and retest dates without revealing vulnerabilities, assets, personal data or live detection rules.

One unusually clear finish line

Security programmes produce verbs that sound reassuring: modernise, scan, classify, test, harden. The difficult word is finished.

APNIC used it with useful precision on 30 June 2026. Its security update said that, during the second quarter, the registry completed a multi-year programme to move core infrastructure from end-of-life CentOS Linux hosts to containerised platforms or Red Hat Enterprise Linux 9. The reason given was operational rather than ceremonial: maintained systems are easier to secure, monitor and patch.

The statement is stronger than a roadmap item. It names a legacy condition, a replacement family, a time boundary and a completion state. APNIC’s 2025 Annual Report supplies adjacent evidence. It records the migration of projects from virtual machines to Kubernetes as complete. It also says a replacement virtualisation platform was selected and implemented and that migration was complete.

None of that proves that every service has the same architecture, that no exception exists, or that a migrated workload is secure forever. APNIC does not publish a service-level denominator in these documents. But it has made a claim that can in principle be reconciled: an old platform population existed, a transition took place, and the workstream closed.

That makes the CentOS passage a useful control case. It shows what the rest of the public security narrative lacks—not more descriptions of activity, but the joins that connect an activity to a bounded population, an outcome and a later verification.

The public record contains four different kinds of statement

APNIC’s documents are not internally contradictory. They answer different questions.

The 2025 Annual Report mostly records actual outcomes. It says dynamic application security testing was implemented, that six critical vulnerabilities were identified and rectified, and that ISO 27001:2022 certification was achieved. The June 2026 blog mixes completed work with work in progress: DAST had been rolled out across the critical application portfolio; Microsoft Purview had been provisioned; enhanced data classification and DLP were being rolled out; controlled adversary emulation was being run to improve production detection.

The 2026 Activity Plan describes intended outcomes. Under Technical Infrastructure, it schedules initial scans of public WordPress sites for Q3, active-active network-edge firewalls for Q2, validated attack-detection pathways across critical infrastructure for Q2, and a more production-consistent on-premises test environment for Q3. It also sets an ongoing outcome of triaging and remediating critical vulnerabilities within 30 days.

The December 2025 Executive Council minutes record priorities rather than results: implement a Data Retention and Deletion Policy beginning with a Fellowship Application System pilot, deploy enhanced DLP, run an internal red-team programme, and scan all public web services externally.

The policies then state durable intentions. APNIC’s Information Security Policy says incidents and non-conformances will be reported, investigated and acted on systematically and promptly. Its vulnerability programme aims to reply within seven days and resolve medium-or-higher reports within 90 days. Its Privacy Statement says irrelevant or excessive personal information should be deleted or de-identified as soon as reasonably possible, and information no longer required for a legitimate business reason should be destroyed or de-identified through reasonable steps.

Outcome, current activity, target and policy are all valid evidence classes. They are not interchangeable. A target is not a result. A deployed scanner is not a closed finding. A retention schedule is not a deletion record. Certification is not a verdict on every control in every system. Public assurance becomes weak when those distinctions disappear inside one narrative of continuous improvement.

Join one: inventory to retired platform

The CentOS statement says the workstream closed. The natural audit question is not “which servers did APNIC run?” That would invite sensitive detail. It is “what denominator was closed?”

A privacy-safe reconciliation could begin with an aggregate baseline: the number of in-scope hosts, workloads or services running on the legacy platform at a defined date. It could then report migrated, retired, rebuilt and formally excepted counts. Exceptions could be grouped by broad reason and review quarter. Verification could state the method—configuration inventory, deployment attestation or independent sample—without publishing hostnames, network locations or architecture diagrams.

This join matters because “migration complete” can mean several things. The project plan may be complete. Production workloads may have moved while archival or laboratory instances remain. Hosts may have been replaced while an application dependency survives. None of these conditions is alleged here. They are simply the categories a completion receipt would distinguish.

APNIC already has the hardest part: a clear public boundary. Adding a denominator and exception count would turn the statement from an institutional assertion into a reproducible control closure.

Join two: finding to remediation

The application-security chain has more entrances. The June update says DAST scans running web applications and APIs across the critical application portfolio, complementing SAST and external discovery managed through HackerOne and APNIC’s vulnerability-reporting programme. The Annual Report says six critical vulnerabilities were identified and rectified. The public reporting page sets response and resolution aims for externally reported issues.

These statements show discovery capacity and at least one set of completed remediations. They do not expose a common denominator. How many findings entered through each channel? How old were they when closed? How many were duplicates, accepted risks, false positives, mitigations pending replacement, or reopened after retest? Did the 30-day critical target and the 90-day medium-or-higher external-report aim apply to different populations?

The safe answer is not a vulnerability list. It is an aggregate closure table. For each discovery channel and severity band, APNIC could publish opening backlog, new findings, closed findings, median or banded age, overdue count, accepted-risk count and reopened count. A retest column would show whether “rectified” means a change was made or that the original failure condition was no longer observable.

This would also preserve organisational boundaries. A report about an APNIC product, an incident affecting APNIC itself and an abuse complaint involving an APNIC Member are not the same queue. APNIC’s security page treats them separately. Public metrics should do the same.

Join three: classification to deletion disposition

Data governance creates a subtler gap. APNIC says Microsoft Purview has been provisioned and is being used to apply sensitivity classifications and define retention schedules. The June update frames efficient removal of historical information no longer required as the goal. The EC minutes identify implementation of a new retention-and-deletion policy, beginning with a Fellowship Application System pilot, as a 2026 priority.

Classification is a prerequisite for defensible deletion. It is not deletion.

A public closure record need not reveal what any fellowship applicant submitted or how long a sensitive category is retained. It could report the population assessed, the share assigned a retention class, the volume or count that reached an eligible-disposition date, and aggregate outcomes: deleted, de-identified, legally held, extended after review, or awaiting owner action. An exception can be counted without being exposed.

The distinction is material. A data catalogue proves visibility. A sensitivity label proves a decision about handling. A retention schedule proves a rule. A disposition record proves that the rule reached an object and produced an outcome. Without that last join, the public sees a control architecture but cannot tell whether historical risk is actually shrinking.

The Annual Report says APNIC completed its data-warehouse project, catalogued the information in it and implemented query capability. That is useful context, not proof of the broader deletion chain. The proposed receipt should resist the temptation to turn one well-bounded data estate into a proxy for all APNIC information.

Join four: exercise to production detection

Controlled adversary emulation is valuable because it tests the receiving system rather than merely generating another finding. APNIC says it is running such a programme to inform improvements to production-detection tooling. Its stated aim is to verify that monitoring and response operate as expected and identify areas for improvement. The Activity Plan separately names validated attack-detection pathways across critical infrastructure as a Q2 outcome.

The public record does not say which objectives were observed, missed, tuned and retested. It should not publish the techniques, attack paths or live rules needed to recreate them.

An aggregate result can remain useful. APNIC could publish scenario class, control objective, validation status—pass, partial or fail—remediation state and retest quarter. It could show the proportion of objectives that produced a timely signal, reached the intended response role and were confirmed after tuning. It could exclude every operational detail that would help an attacker.

The key is to join the exercise to production evidence. “Red team conducted” measures activity. “Detection objective observed and retested” measures a control. Those statements are related, but they should never be treated as synonyms.

Certification is a frame, not the missing join

APNIC’s ISO/IEC 27001:2022 certification matters. Its policy says the ISMS provides a foundation for continual improvement, and the Annual Report notes that the 2022 standard added controls compared with the previous edition. The EC minutes record a successful recertification audit in August 2025.

Certification supports governance: scope, responsibility, review and corrective action. It does not publish the four operational reconciliations described here. Nor should the absence of those public tables be misread as evidence that the underlying controls failed. The correct conclusion is narrower. The management system and the outside reader operate at different levels of access. A public closure receipt would translate selected aggregate outcomes across that boundary.

A quarterly control-closure receipt

APNIC can close the evidence joins without opening its security perimeter.

For each selected workstream, a quarterly receipt would name the in-scope denominator, the control or activity, the evidence class—target, deployed, tested, closed or retested—the aggregate outcome, exception count, verification date, responsible role and next review date. It would define material changes from the previous receipt and preserve corrected versions.

The first four lines almost write themselves: legacy-platform estate; application-security findings; retention-eligible records; and adversary-emulation objectives. The document should explicitly say that it excludes asset identities, vulnerabilities, personal information, exact retention schedules, exercise techniques and live detection rules.

This is not a request for radical transparency. It is a request to make carefully chosen public claims conserve their meaning as they move from plan to operation. APNIC has already shown that it can publish a clear finish line. The next step is to make the route to that line visible in aggregate.

Sources