Companies are generally aware of the risks associated with outdated software, but they continue to use it anyway, writes Raul Gil García, CEO of Unatec.
Legacy software refers
to
systems or
platforms that are used in daily operations but are
technologically outdated and no longer meet modern requirements. It could be software whose
vendor support ended long ago or that simply hasn’t been updated for years.
Failing to update a platform increases the likelihood of security vulnerabilities that can be exploited in cyberattacks or that some IT components will stop working. This is referred to as the technical risk of legacy systems. However, far less attention is paid to the business risks associated with them.
Imagine a scenario where no one has modified a company's software or added new features for years. Time passes, developers leave the company, and critical documentation remains undone. Then, if the need arises to update the business logic within the system—say, to accommodate tax changes—there might be no one left who knows how to do it on the company's platform. A completely realistic outcome in such a case is having to start developing new software from scratch.
IT departments in are usually aware of the dangers posed by legacy systems. The real issue often lies in communication or prioritization.
IT departments continuously raise alarms about legacy risks, but management either doesn’t grasp the risks or focuses solely on adding new features to address business needs. This can lead to a situation where the software meets business goals but is already outdated from a technical perspective and vulnerable in terms of security.
The reverse can also happen. When guidance doesn’t come from management, IT departments usually focus, out of habit, on managing technical risks, while the business perspective and maintaining the necessary development competence take a back seat. The result is a well-managed platform with significant money invested in it but one that is, or soon will be, dead from a business perspective because no one knows how to further develop it.
Over time, the technical and business risks associated with legacy systems grow exponentially. It’s just like with a car—if you skip one service, it might still be salvageable, but a car that hasn’t been serviced in five years will likely need a complete overhaul.
The initiative to address legacy software must come from management, as they set priorities and allocate funding for them. A good starting point is simply to define and put in writing that the IT budget has two parts—money goes toward both maintaining the existing platform and making changes. Setting clear goals and communicating them helps IT personnel decide how to allocate their time.
There are also internal company procedures that can help identify the risks associated with legacy software. A good starting point would be a sustainability audit, where all IT systems critical to the company’s operations are listed. From there, a more detailed assessment should outline what the realization of a specific risk would mean for the business, who is responsible for it, and how it can be mitigated.
During the audit and risk mapping process, it may turn out that a system previously deemed high-risk doesn’t need to be completely discarded. After a minor update, it could serve reliably for another 5-10 years. But before making such a decision, you need to go under the hood with your IT department or partner and inspect the engine. If it turns out the supposedly reliable software will need to be replaced in the coming years, you need to start addressing it now.