Legacy equipment has been linked to cyberattacks against utility organisations. It’s a problem well beyond utilities: old, unsupported hardware and software no longer receive security updates, leaving known holes wide open for attackers to walk through.

The Foresight take

End-of-life kit is a security liability, not just an operational one. Once a vendor stops issuing patches, every newly discovered flaw in that device is permanent — and attackers actively hunt for exactly these forgotten systems.

Keep a live inventory of your hardware and software, track end-of-support dates, and plan replacements before they become risks. Where legacy systems can’t be retired yet, isolate them behind segmentation and tight controls. We help clients build and manage that lifecycle.

The hidden scale of the problem

Legacy technology is far more widespread than most organisations realise. It is not just ageing industrial controllers; it is the old Windows server nobody dares reboot, the line-of-business application that only runs on an unsupported operating system, the firewall three versions behind, and the “if it works, leave it” culture that surrounds them all. The moment a vendor ends support, every flaw discovered afterwards becomes permanent, and attackers specifically scan the internet for these forgotten, unpatchable systems because they know a fix will never come.

Managing the lifecycle

The answer is to treat technology lifecycle as a security control, not just a budgeting exercise. Keep a live inventory of hardware and software with their end-of-support dates, and plan and fund replacements before those dates arrive rather than after an incident forces the issue. Where a legacy system genuinely cannot be retired yet, isolate it behind network segmentation, restrict who and what can reach it, and wrap it in compensating controls and close monitoring. We help clients build and manage exactly this lifecycle, so ageing kit is retired on your timetable rather than an attacker’s.

Source: ITPro, 19 June 2026.