A USD500K Java Licensing Trap: How One Power Company Escaped Before Audit Season
- By CDOTrends editors
- December 14, 2025

Ausgrid runs the kind of infrastructure that cannot afford surprises. The utility keeps electricity flowing to 1.8 million customers across Sydney and New South Wales.
So when Ausgrid’s IT team kicked off a routine Windows 11 migration, they weren’t expecting to uncover a ticking time bomb in their application stack.
Buried across the organization were Oracle Java installations, some running in applications managed by operational teams outside central IT, others embedded in systems so legacy they’d become invisible. For most companies, this would be mildly annoying. For a utility subject to NERC CIP compliance requirements and ESCC cybersecurity standards, it was a full-blown crisis waiting to happen.
Because Oracle had just rewritten the rules.
In 2023, Oracle ditched its instance-based Java licensing model for per-employee headcount pricing. One single Java installation anywhere in your organization, even in some forgotten SCADA integration, triggers fees for every employee, contractor, and consultant on your payroll. When Java is used or not or is touched a company device, the meter runs regardless.
For Ausgrid’s 4,000-person operation, that meant potential annual costs north of USD500,000. For maintaining software they barely knew they had.
“Oracle’s license subscription model was very aggressive, and I was aware of their ability to move the goalposts again at any time,” says Glen Parker, Ausgrid’s senior partner solutions manager. “This represented a risk we simply weren’t willing to carry forward.”
The perils of vendor lock-in
But the licensing nightmare was not over. Oracle Java was also creating security vulnerabilities, a catastrophic problem when you’re managing critical infrastructure. Energy utilities live in a world where patching cycles must balance security imperatives against operational stability. You can’t just reboot a substation to apply updates.
Ausgrid needed an exit strategy that addressed three problems simultaneously: eliminating audit exposure, closing security gaps, and avoiding operational disruption. That’s a hell of a tightrope walk for mission-critical systems.
Enter Azul Platform Core, an OpenJDK-based alternative that promised compatibility without the licensing challenges. But Ausgrid wasn’t about to swap out foundational runtime environments on vendor promises alone. They demanded proof.
Azul ran three proof-of-concept deployments across Ausgrid’s operational applications and infrastructure environments, stress-testing real-world compatibility against grid operations requirements.
The results: zero disruption. And a 99% reduction in Java-related vulnerabilities.
“The Azul Platform Core POCs gave us confidence that migrating to an OpenJDK alternative was the right approach,” Parker says. “We saw first-hand that moving off Oracle Java wouldn’t cause any disruption. In addition, we were able to reduce our large volume of outstanding Java-related vulnerabilities by 99%.”
Two months later, the migration was complete. Ausgrid had eliminated audit risk, slashed potential licensing costs by 80%, and closed virtually every Java security hole, all while keeping the grid running without a flicker.
“Ausgrid’s proactive approach shows how critical it is for enterprises to address Java licensing and security risks before they become compliance crises,” says Dean Vaughan, Azul’s APAC vice president.
The takeaway for energy sector tech leaders? A vendor’s licensing pivot transformed Java and added unpredictable liability to an otherwise predictable infrastructure. When vendor licensing models can reshape your cost structure overnight, especially in operational technology environments where hidden dependencies lurk, the smartest move is finding the exit before audit season arrives.
Image credit: iStockphoto/z_wei