The New Pressure to Decommission Legacy Systems
Cyber resilience, data integrity and regulatory accountability in the age of DORA, NIS2, AI and digital evidence
Legacy systems used to be seen mainly as an IT cost problem.
They were expensive to maintain, difficult to integrate and dependent on ageing infrastructure. Many organisations accepted that cost because the systems still contained historical data that someone might need for audit, legal, regulatory or customer service reasons.
That position is becoming harder to defend.
Today, legacy systems are also a resilience problem. They increase the attack surface. They complicate recovery. They create hidden ICT risk. They are difficult to monitor, patch, test and govern. They may contain data that is still legally or operationally relevant, but whose integrity, provenance and context become harder to prove over time.
At the same time, regulations and supervisory expectations increasingly require organisations to demonstrate control over ICT risk, data integrity, recordkeeping, auditability and evidence.
The question is no longer only:
Can we afford to keep this legacy system running?
The better question is:
Can we still justify keeping this legacy risk online when the data could be preserved in a trusted archive?
Legacy is no longer only an IT cost problem
For years, legacy application retirement was mainly presented as an IT efficiency topic.
The usual arguments were familiar:
- Reduce licence costs
- Remove obsolete infrastructure
- Simplify the application landscape
- Reduce maintenance effort
- Free up scarce technical skills
- Support cloud migration or platform modernisation
Those arguments still matter.
But they are no longer the full story.
Legacy systems increasingly create risk because they remain part of the operational and security landscape even when their business function has largely disappeared.
Many are kept alive only because historical data has not been properly archived. These systems may no longer support active processes, but they still need accounts, infrastructure, backups, monitoring, security patches, access control, support contracts and recovery procedures.
If the only reason a system remains online is historical lookup, the organisation should ask whether the system is still an asset, or whether it has become an avoidable risk.
A legacy system kept alive only for historical access is not a business application. It is a risk surface.
Three pressure waves are changing the legacy system discussion
The pressure to retire and decommission legacy systems is coming from three directions.
Pressure Wave 1: Cyber and Operational Resilience
Regulations such as DORA and NIS2 push organisations to better understand, manage, protect, monitor, recover and test their ICT environment. Obsolete systems make that harder.
Pressure Wave 2: Data Integrity and Evidentiary Trust
In regulated sectors such as Life Sciences, historical records must remain complete, accurate, attributable, legible, accessible and trustworthy. A system may be retired, but the evidence must remain inspection-ready.
Pressure Wave 3: Regulatory Accountability and Data Governance
The AI Act, AML regulation, financial crime obligations and broader compliance frameworks increasingly require organisations to explain the origin, quality, context, use and integrity of data.
These three waves point to the same conclusion:
Legacy systems should not remain online simply because no one has created a trusted archival alternative.
Legacy systems can weaken resilience in several ways:
- They may run on unsupported software or operating systems.
- They may depend on outdated databases, middleware or infrastructure.
- They may be difficult to patch without breaking business logic.
- They may use weak or outdated authentication methods.
- They may contain dormant user accounts or unmanaged service accounts.
- They may not integrate well with modern monitoring and detection tools.
- They may be poorly documented.
- They may have unknown dependencies.
- They may be difficult to recover after an incident.
- They may rely on vendors or internal experts who are no longer available.
Why legacy systems weaken cyber resilience
Cyber resilience is not only about protecting active systems. It is also about reducing unnecessary exposure.
Every obsolete system that remains online adds complexity.
More systems means more assets to inventory, more vulnerabilities to manage, more access rights to control, more backups to validate, more recovery procedures to test and more incidents to investigate.
Resilience improves not only by strengthening critical systems, but also by removing unnecessary systems from the risk landscape.
DORA: legacy systems as an ICT risk management issue
The Digital Operational Resilience Act changes how financial entities need to think about ICT risk.
DORA is not only about cybersecurity incidents. It establishes a broad digital operational resilience framework covering ICT risk management, governance, identification of ICT assets and risks, protection, prevention, detection, response, recovery, backup, restoration, testing and ICT third-party risk.
This matters for legacy systems.
A legacy application that is still online for historical access remains part of the ICT environment. It must be identified, protected, monitored, governed and recoverable. If it relies on old infrastructure or a third-party vendor, it may also increase ICT third-party risk. If it is not properly included in resilience testing, backup procedures or access control reviews, it becomes a weakness in the ICT risk framework.
For financial institutions, the question becomes:
Can we demonstrate that every legacy system still online is necessary, controlled, recoverable and proportionate to its risk?
If the answer is no, archive-only access may be a better strategy.
NIS2: cybersecurity risk management across essential and important entities
NIS2 expands the cybersecurity risk management discussion beyond the financial sector.
It applies to a broad set of essential and important entities across sectors such as energy, transport, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, space, postal services, waste management, chemicals, food, manufacturing and digital providers.
The Directive increases the focus on technical, operational and organisational cybersecurity risk management measures.
Legacy systems are relevant because they often sit at the edge of governance. They may not be business-critical anymore, but they still contain sensitive data. They may not receive the same attention as active core systems, but they still create cyber exposure.
For organisations in NIS2-relevant sectors, the legacy question becomes:
Why keep obsolete systems online if their only remaining purpose is historical access?
Trusted archiving can help reduce the active system landscape while preserving access to the information that still needs to be retained.
The hidden risk of keeping systems alive for historical access
Many legacy systems are not kept alive because they are still operationally valuable.
They are kept alive because someone may one day need to look something up.
This creates a dangerous compromise.
The organisation carries the cost and risk of an operational system, but only receives the value of a historical archive.
That is inefficient and risky.
Yet it may not receive the same governance attention as a modern core system.
This creates a gap between perceived risk and actual exposure.
If a system is only needed for historical lookup, the safer pattern is archive-only access, not permanent read-only legacy access.
A legacy system kept alive for historical access may still require:
- User accounts
- Privileged access
- Service accounts
- Network connectivity
- Database administration
- Backup and restore procedures
- Vulnerability management
- Monitoring
- Vendor support
- Incident response planning
- Disaster recovery testing
Data integrity: when old data still needs to be proven
Cyber resilience is only one part of the pressure.
In many regulated sectors, the bigger issue is evidentiary trust.
Historical data must not only exist. It must remain understandable, complete, traceable and trustworthy.
Organisations may need to prove:
- Where data came from
- Which system created it
- Who entered or approved it
- Whether it was changed
- Which version is authoritative
- Whether the record is complete
- Which audit trail applies
- Which metadata explains the record
- Which retention rule applies
- Whether the data was migrated or transformed
- Whether the evidence can be relied upon in an audit, inspection, investigation or legal dispute
A database export without context may not be enough. A backup may not be enough. A file share may not be enough.
The more regulated the environment, the more important provenance, auditability and integrity become.
Data that cannot be verified cannot be trusted. In regulated environments, data that cannot be trusted may become unusable.
Life Sciences: data integrity can become a regulatory blocker
Life Sciences provides a clear example of why historical data cannot be treated as ordinary legacy data.
Clinical trials, laboratory data, quality records, validation evidence, regulatory submissions, pharmacovigilance records and batch records may remain relevant long after the systems that created them have changed or disappeared.
In this sector, data integrity principles such as ALCOA++ are central. Records must remain attributable, legible, contemporaneous, original, accurate, complete, consistent, enduring and available.
A useful recent example is the Applied Therapeutics case. The FDA issued a Warning Letter after a pre-approval inspection linked to a clinical trial, and the company also received a Complete Response Letter for its new drug application. Public reporting and the FDA letter point to clinical application deficiencies and inspection findings. The case should not be oversimplified, but it illustrates how clinical data integrity, electronic records, auditability and inspection findings can directly affect regulatory approval risk.
The lesson is broader than one company.
If a sponsor or regulated organisation cannot reconstruct, explain, verify and trust the records behind a regulated activity, it may face inspection risk, approval risk, litigation risk or remediation cost.
In Life Sciences, legacy system retirement must preserve inspection readiness, not merely historical access.
AI Act: historical data becomes regulated AI input
The AI Act creates another reason to take legacy data seriously.
Historical data is increasingly used for analytics, automation, model development, validation, testing and decision support. In regulated contexts, this means old data may become an input into new AI systems.
For high-risk AI systems, data governance becomes a formal requirement. Organisations need to understand the origin of data, data collection processes, preparation operations, suitability, limitations, bias risks, completeness and relevance. Logging and traceability also become important for accountability across the AI lifecycle.
This creates a direct link with legacy data preservation.
This is not a traditional archive problem. It is a data governance and evidence problem.
Legacy data is not just old data. In the AI era, it may become regulated input data.
If historical data is used to train, validate, test or justify AI-assisted decisions, the organisation must be able to explain:
- Where the data came from
- Why it was collected
- Whether it is complete
- Whether it is representative
- Whether it was cleaned, labelled, enriched or transformed
- Which version was used
- Whether it contains bias or gaps
- Whether it may lawfully be reused
- How its provenance and integrity are documented
This is relevant for legacy system retirement because AML and customer due diligence records are often spread across multiple systems:
- Onboarding platforms
- KYC systems
- Case management tools
- Transaction monitoring systems
- Document management systems
- Customer communication archives
- Core banking systems
- CRM platforms
- Legacy databases
AMLR: regulatory accountability requires controlled recordkeeping
Anti-money laundering regulation also reinforces the need for trustworthy recordkeeping.
Under the EU AML Regulation, obliged entities must retain customer due diligence information, records of certain assessments, supporting evidence and transaction records. These records must be available for competent authorities and must support financial crime prevention, detection, investigation and prosecution.
When these systems are replaced, consolidated or decommissioned, organisations must ensure that the retained records remain accessible, complete, controlled and trustworthy.
The combination of customer due diligence obligations and record retention requirements creates a clear need for governed preservation.
Financial crime records must not disappear into obsolete systems. They must remain accessible, reliable and controlled for regulatory purposes.
Why backup is not evidence preservation
Backups are essential for recovery. They are not the same as long-term evidence preservation.
A backup answers a recovery question:
Can we restore the system or data after an incident?
An archive answers an evidence question:
Can we find, understand, trust and prove the information after the original system is gone?
Backups are usually system-centric. They are designed for restoration, not for governed historical access. They may be difficult to search. They may not preserve business context in a usable way. They may not support retention rules, legal hold, audit trails or controlled access for business and regulatory users.
A regulated archive must do more.
It should preserve:
- Data
- Documents
- Metadata
- Relationships
- Provenance
- Integrity evidence
- Audit trails
- Access rules
- Retention rules
- Legal holds
- Evidence of migration or transformation
Backup helps you recover a system. Trusted archiving helps you preserve evidence when the system should no longer exist.
Why full migration is not always the answer
Some organisations respond to legacy risk by migrating everything into a new operational system.
That may be right for active data. It is not always right for historical evidence.
Full migration can create new problems:
- The new system becomes overloaded with inactive data
- Historical records do not fit the new data model
- Context is lost during transformation
- Historical evidence is changed or simplified
- Old data becomes active again without a business need
- Privacy and discovery exposure increase
- Retention rules become harder to enforce
- Migration costs rise sharply
- The new system inherits legacy data quality issues
- Legal holds
- Evidence of migration or transformation
For inactive, closed, historical or evidentiary data, archive-only access is often more resilient than full migration.
Migration is for active data. Trusted archiving is for historical evidence.
Archive-only access as a resilience pattern
Archive-only access is a strategic pattern for reducing legacy risk
without losing historical value.
It allows organisations to decommission obsolete systems while
preserving the information that still matters.
Archive-only access reduces:
- Active systems
- User accounts
- Privileged access
- Obsolete infrastructure
- Unsupported software
- Unmanaged databases
- Legacy vendor dependency
- Backup and recovery complexity
- Monitoring burden
- Attack surface
At the same time, it preserves:
- Historical data
- Documents
- Metadata
- Relationships
- Business context
- Auditability
- Provenance
- Integrity
- Legal hold
- Retention
- Controlled access
This makes archive-only access relevant not only for cost reduction,
but also for cyber resilience, operational resilience and regulatory
accountability.
How to decommission legacy systems without losing evidence
A resilient application retirement programme should
follow a controlled sequence.
Identify legacy systems
Create an inventory of systems that are no longer
strategically or operationally required.
01
Classify risk and value
Determine which systems create cyber, operational,
regulatory, legal or data integrity risk.
02
Assess data and records
Identify which data is active, historical, regulated,
sensitive, redundant or legally relevant.
03
Define retention and legal hold
Decide what must be kept, what may be deleted and
what must be preserved because of legal or regulatory
constraints.
04
Separate active data from historical evidence
Migrate only what remains operational. Archive what
must remain accessible and trustworthy.
05
Extract data, documents and metadata
Preserve the content, structure, relationships and
context needed to understand the records.
06
Validate completeness and integrity
Prove that the archive contains what it should contain
and that the evidence remains reliable.
07
Enable governed archive-only access
Provide controlled access for authorised users, auditors,
regulators, legal teams or business stakeholders.
08
Decommission the source system
Remove infrastructure, accounts, interfaces, licences
and obsolete dependencies after the evidence is
preserved.
09
Govern the archive over time
Apply retention, legal hold, access control, integrity
checks, auditability and controlled export.
10
Docbyte Vault: reducing legacy risk while preserving evidence
Docbyte Vault helps organisations move from legacy system
dependency to trusted archive-only access.
It enables organisations to decommission obsolete applications
while preserving the data, documents, metadata, relationships
and business context that still matter.
Docbyte Vault helps preserve:
- Structured data
- Documents
- Metadata
- Relationships
- Business context
- Audit trails
- Retention rules
- Legal holds
- Provenance
- Integrity evidence
- Controlled access
It helps organisations reduce:
- Reliance on obsolete systems
- Attack surface from legacy applications
- Unmanaged access to historical data
- Recovery complexity
- Dependency on ageing infrastructure
- Long-term maintenance burden
- Evidentiary risk caused by incomplete or untrusted exports
Docbyte Vault should not be positioned as a cybersecurity tool, an
AI compliance tool or a complete DORA, NIS2, AI Act or AMLR
compliance solution.
It should be positioned as:
The trusted archival layer that allows organisations to reduce
legacy system risk while preserving the evidence regulators,
auditors and business users still expect.
Decommission the system. Preserve the evidence. Reduce the risk.
Continue the application retirement series
This page explains why the pressure to decommission
legacy systems is increasing. For a broader understanding
of the terminology and sector-specific use cases, read the
other guides in this series.
Part 1: Application Retirement, Decommissioning, Sunsetting or Archiving?
Part 2: When the Business Moves On, the Evidence Must Remain
Frequently Asked Questions
Why are legacy systems a cyber resilience risk?
Legacy systems may run on unsupported software, use outdated authentication, contain unmanaged accounts, depend on old infrastructure and be difficult to monitor, patch or recover. Even if they are no longer operationally important, they still increase the active risk surface.
What is the connection between DORA and legacy system decommissioning?
DORA requires financial entities to manage ICT risk in a structured way. Legacy systems that remain online for historical access are still ICT assets and must be governed, protected, monitored, recoverable and proportionate to their risk. Decommissioning obsolete systems can help reduce unnecessary ICT complexity.
What is the connection between NIS2 and legacy systems?
NIS2 increases cybersecurity risk management expectations across essential and important entities in many sectors. Legacy systems may create exposure if they are poorly governed, unsupported or kept online only for historical lookup.
Why is backup not enough for regulatory evidence?
Backup is designed for recovery. Regulatory evidence preservation requires searchable, governed, contextual and trustworthy access to records, metadata, relationships, audit trails, retention rules, legal holds and provenance.
Why not migrate all legacy data into the new system?
Historical data may not fit the new operational model and may no longer need to be active. Migrating everything can increase cost, complexity, privacy exposure and data quality risk. Archive-only access is often more appropriate for historical evidence.
How does data integrity relate to legacy system retirement?
When legacy systems are retired, organisations must ensure that the records remain complete, trustworthy, traceable and accessible. This is especially important in regulated sectors such as Life Sciences, finance, healthcare, chemicals and manufacturing.
How is the AI Act relevant to legacy data?
Historical data may be reused for AI training, validation, testing or decision support. In high-risk AI contexts, organisations need strong data governance, including understanding the origin, suitability, completeness and limitations of data.
How is AML regulation relevant to legacy data archiving?
AML obligations require certain customer due diligence information, transaction evidence and assessment records to be retained and made available to competent authorities. If those records are stored in legacy systems, decommissioning must preserve accessibility, integrity and control.
What is archive-only access?
Archive-only access allows authorised users to consult historical records through a governed archive instead of keeping the original legacy system online.
How does Docbyte Vault help?
Docbyte Vault preserves structured data, documents, metadata, relationships, audit trails, retention rules, legal holds, provenance and integrity evidence in a governed archive. This enables organisations to reduce dependency on obsolete systems while maintaining trustworthy access to historical records.
Still keeping legacy systems online for historical access?
If an obsolete system remains online only because someone may still need the data, it may be time to
rethink the strategy.
Docbyte Vault helps organisations preserve historical data, business context and evidentiary value in a
governed archive, so legacy systems can be decommissioned without losing the evidence that still matters.