DocbyteFacebookPixel
Deutsch

The New Pressure to Decommission Legacy Systems

Cyber resilience, data integrity and regulatory accountability in the age of DORA, NIS2, AI and digital evidence

the new pressure to decommission legacy systems

Legacy systems used to be seen mainly as an IT cost problem.

They were expensive to maintain, difficult to integrate and dependent on ageing infrastructure. Many organisations accepted that cost because the systems still contained historical data that someone might need for audit, legal, regulatory or customer service reasons.

That position is becoming harder to defend.

Today, legacy systems are also a resilience problem. They increase the attack surface. They complicate recovery. They create hidden ICT risk. They are difficult to monitor, patch, test and govern. They may contain data that is still legally or operationally relevant, but whose integrity, provenance and context become harder to prove over time.

At the same time, regulations and supervisory expectations increasingly require organisations to demonstrate control over ICT risk, data integrity, recordkeeping, auditability and evidence.

The question is no longer only:

Can we afford to keep this legacy system running?

The better question is:

Can we still justify keeping this legacy risk online when the data could be preserved in a trusted archive?

Image for legacy system cyber resilience archiving

Legacy is no longer only an IT cost problem

For years, legacy application retirement was mainly presented as an IT efficiency topic.

The usual arguments were familiar:

Those arguments still matter.

But they are no longer the full story.

Legacy systems increasingly create risk because they remain part of the operational and security landscape even when their business function has largely disappeared.

Many are kept alive only because historical data has not been properly archived. These systems may no longer support active processes, but they still need accounts, infrastructure, backups, monitoring, security patches, access control, support contracts and recovery procedures.

If the only reason a system remains online is historical lookup, the organisation should ask whether the system is still an asset, or whether it has become an avoidable risk.

A legacy system kept alive only for historical access is not a business application. It is a risk surface.

Image for legacy application retirement risk

Three pressure waves are changing the legacy system discussion

The pressure to retire and decommission legacy systems is coming from three directions.

Icon for cyber operational resilience

Pressure Wave 1: Cyber and Operational Resilience

Regulations such as DORA and NIS2 push organisations to better understand, manage, protect, monitor, recover and test their ICT environment. Obsolete systems make that harder.

Icon for data integrity evidentiary trust

Pressure Wave 2: Data Integrity and Evidentiary Trust

In regulated sectors such as Life Sciences, historical records must remain complete, accurate, attributable, legible, accessible and trustworthy. A system may be retired, but the evidence must remain inspection-ready.

Icon for regulatory data governance

Pressure Wave 3: Regulatory Accountability and Data Governance

The AI Act, AML regulation, financial crime obligations and broader compliance frameworks increasingly require organisations to explain the origin, quality, context, use and integrity of data.

These three waves point to the same conclusion:

Legacy systems should not remain online simply because no one has created a trusted archival alternative.

Legacy systems can weaken resilience in several ways:

Why legacy systems weaken cyber resilience

Cyber resilience is not only about protecting active systems. It is also about reducing unnecessary exposure.

Every obsolete system that remains online adds complexity.

More systems means more assets to inventory, more vulnerabilities to manage, more access rights to control, more backups to validate, more recovery procedures to test and more incidents to investigate.

Resilience improves not only by strengthening critical systems, but also by removing unnecessary systems from the risk landscape.

DORA: legacy systems as an ICT risk management issue

The Digital Operational Resilience Act changes how financial entities need to think about ICT risk.

DORA is not only about cybersecurity incidents. It establishes a broad digital operational resilience framework covering ICT risk management, governance, identification of ICT assets and risks, protection, prevention, detection, response, recovery, backup, restoration, testing and ICT third-party risk.

This matters for legacy systems.

A legacy application that is still online for historical access remains part of the ICT environment. It must be identified, protected, monitored, governed and recoverable. If it relies on old infrastructure or a third-party vendor, it may also increase ICT third-party risk. If it is not properly included in resilience testing, backup procedures or access control reviews, it becomes a weakness in the ICT risk framework.

For financial institutions, the question becomes:

Can we demonstrate that every legacy system still online is necessary, controlled, recoverable and proportionate to its risk?

If the answer is no, archive-only access may be a better strategy.

Image for DORA legacy ICT risk management

NIS2: cybersecurity risk management across essential and important entities

NIS2 expands the cybersecurity risk management discussion beyond the financial sector.

It applies to a broad set of essential and important entities across sectors such as energy, transport, health, drinking water, wastewater, digital infrastructure, ICT service management, public administration, space, postal services, waste management, chemicals, food, manufacturing and digital providers.

The Directive increases the focus on technical, operational and organisational cybersecurity risk management measures.

Legacy systems are relevant because they often sit at the edge of governance. They may not be business-critical anymore, but they still contain sensitive data. They may not receive the same attention as active core systems, but they still create cyber exposure.

For organisations in NIS2-relevant sectors, the legacy question becomes:

Why keep obsolete systems online if their only remaining purpose is historical access?

Trusted archiving can help reduce the active system landscape while preserving access to the information that still needs to be retained.

Image for NIS2 cybersecurity risk management

The hidden risk of keeping systems alive for historical access

Many legacy systems are not kept alive because they are still operationally valuable.

They are kept alive because someone may one day need to look something up.

This creates a dangerous compromise.

The organisation carries the cost and risk of an operational system, but only receives the value of a historical archive.

That is inefficient and risky.

Yet it may not receive the same governance attention as a modern core system.

This creates a gap between perceived risk and actual exposure.

If a system is only needed for historical lookup, the safer pattern is archive-only access, not permanent read-only legacy access.

A legacy system kept alive for historical access may still require:

Data integrity: when old data still needs to be proven

Cyber resilience is only one part of the pressure.
In many regulated sectors, the bigger issue is evidentiary trust.

Historical data must not only exist. It must remain understandable, complete, traceable and trustworthy.

Organisations may need to prove:

A database export without context may not be enough. A backup may not be enough. A file share may not be enough.

The more regulated the environment, the more important provenance, auditability and integrity become.

Data that cannot be verified cannot be trusted. In regulated environments, data that cannot be trusted may become unusable.

Image for historical data integrity evidence
Image for life sciences data integrity archive

Life Sciences: data integrity can become a regulatory blocker

Life Sciences provides a clear example of why historical data cannot be treated as ordinary legacy data.

Clinical trials, laboratory data, quality records, validation evidence, regulatory submissions, pharmacovigilance records and batch records may remain relevant long after the systems that created them have changed or disappeared.

In this sector, data integrity principles such as ALCOA++ are central. Records must remain attributable, legible, contemporaneous, original, accurate, complete, consistent, enduring and available.

A useful recent example is the Applied Therapeutics case. The FDA issued a Warning Letter after a pre-approval inspection linked to a clinical trial, and the company also received a Complete Response Letter for its new drug application. Public reporting and the FDA letter point to clinical application deficiencies and inspection findings. The case should not be oversimplified, but it illustrates how clinical data integrity, electronic records, auditability and inspection findings can directly affect regulatory approval risk.

The lesson is broader than one company.

If a sponsor or regulated organisation cannot reconstruct, explain, verify and trust the records behind a regulated activity, it may face inspection risk, approval risk, litigation risk or remediation cost.

In Life Sciences, legacy system retirement must preserve inspection readiness, not merely historical access.

AI Act: historical data becomes regulated AI input

The AI Act creates another reason to take legacy data seriously.
Historical data is increasingly used for analytics, automation, model development, validation, testing and decision support. In regulated contexts, this means old data may become an input into new AI systems.

For high-risk AI systems, data governance becomes a formal requirement. Organisations need to understand the origin of data, data collection processes, preparation operations, suitability, limitations, bias risks, completeness and relevance. Logging and traceability also become important for accountability across the AI lifecycle.

This creates a direct link with legacy data preservation.

This is not a traditional archive problem. It is a data governance and evidence problem.

Legacy data is not just old data. In the AI era, it may become regulated input data.

If historical data is used to train, validate, test or justify AI-assisted decisions, the organisation must be able to explain:

This is relevant for legacy system retirement because AML and customer due diligence records are often spread across multiple systems:

AMLR: regulatory accountability requires controlled recordkeeping

Anti-money laundering regulation also reinforces the need for trustworthy recordkeeping.

Under the EU AML Regulation, obliged entities must retain customer due diligence information, records of certain assessments, supporting evidence and transaction records. These records must be available for competent authorities and must support financial crime prevention, detection, investigation and prosecution.

When these systems are replaced, consolidated or decommissioned, organisations must ensure that the retained records remain accessible, complete, controlled and trustworthy.

The combination of customer due diligence obligations and record retention requirements creates a clear need for governed preservation.

Financial crime records must not disappear into obsolete systems. They must remain accessible, reliable and controlled for regulatory purposes.

Why backup is not evidence preservation

Backups are essential for recovery. They are not the same as long-term evidence preservation.

A backup answers a recovery question:

Can we restore the system or data after an incident?

An archive answers an evidence question:

Can we find, understand, trust and prove the information after the original system is gone?

Backups are usually system-centric. They are designed for restoration, not for governed historical access. They may be difficult to search. They may not preserve business context in a usable way. They may not support retention rules, legal hold, audit trails or controlled access for business and regulatory users.

A regulated archive must do more.

It should preserve:

Backup helps you recover a system. Trusted archiving helps you preserve evidence when the system should no longer exist.

Image for backup versus evidence preservation
Image for legacy data migration risk

Why full migration is not always the answer

Some organisations respond to legacy risk by migrating everything into a new operational system.

That may be right for active data. It is not always right for historical evidence.

Full migration can create new problems:

For inactive, closed, historical or evidentiary data, archive-only access is often more resilient than full migration.

Migration is for active data. Trusted archiving is for historical evidence.

Archive-only access as a resilience pattern

Archive-only access is a strategic pattern for reducing legacy risk
without losing historical value.

It allows organisations to decommission obsolete systems while
preserving the information that still matters.

Archive-only access reduces:

At the same time, it preserves:

This makes archive-only access relevant not only for cost reduction,
but also for cyber resilience, operational resilience and regulatory
accountability.

Image for archive-only access resilience pattern

How to decommission legacy systems without losing evidence

A resilient application retirement programme should
follow a controlled sequence.

Identify legacy systems

Create an inventory of systems that are no longer
strategically or operationally required.

01

Classify risk and value

Determine which systems create cyber, operational,
regulatory, legal or data integrity risk.

02

Assess data and records

Identify which data is active, historical, regulated,
sensitive, redundant or legally relevant.

03

Define retention and legal hold

Decide what must be kept, what may be deleted and
what must be preserved because of legal or regulatory
constraints.

04

Separate active data from historical evidence

Migrate only what remains operational. Archive what
must remain accessible and trustworthy.

05

Extract data, documents and metadata

Preserve the content, structure, relationships and
context needed to understand the records.

06

Validate completeness and integrity

Prove that the archive contains what it should contain
and that the evidence remains reliable.

07

Enable governed archive-only access

Provide controlled access for authorised users, auditors,
regulators, legal teams or business stakeholders.

08

Decommission the source system

Remove infrastructure, accounts, interfaces, licences
and obsolete dependencies after the evidence is
preserved.

09

Govern the archive over time

Apply retention, legal hold, access control, integrity
checks, auditability and controlled export.

10

Image for Docbyte Vault legacy risk preservation

Docbyte Vault: reducing legacy risk while preserving evidence

Docbyte Vault helps organisations move from legacy system
dependency to trusted archive-only access.

It enables organisations to decommission obsolete applications
while preserving the data, documents, metadata, relationships
and business context that still matter.

Docbyte Vault helps preserve:

It helps organisations reduce:

Docbyte Vault should not be positioned as a cybersecurity tool, an
AI compliance tool or a complete DORA, NIS2, AI Act or AMLR
compliance solution.

It should be positioned as:

The trusted archival layer that allows organisations to reduce
legacy system risk while preserving the evidence regulators,
auditors and business users still expect.

Decommission the system. Preserve the evidence. Reduce the risk.

Image for legacy system decommissioning series

Continue the application retirement series

This page explains why the pressure to decommission
legacy systems is increasing. For a broader understanding
of the terminology and sector-specific use cases, read the
other guides in this series.

Part 1: Application Retirement, Decommissioning, Sunsetting or Archiving?

Part 2: When the Business Moves On, the Evidence Must Remain

Frequently Asked Questions

Legacy systems may run on unsupported software, use outdated authentication, contain unmanaged accounts, depend on old infrastructure and be difficult to monitor, patch or recover. Even if they are no longer operationally important, they still increase the active risk surface.

DORA requires financial entities to manage ICT risk in a structured way. Legacy systems that remain online for historical access are still ICT assets and must be governed, protected, monitored, recoverable and proportionate to their risk. Decommissioning obsolete systems can help reduce unnecessary ICT complexity.

NIS2 increases cybersecurity risk management expectations across essential and important entities in many sectors. Legacy systems may create exposure if they are poorly governed, unsupported or kept online only for historical lookup.

Backup is designed for recovery. Regulatory evidence preservation requires searchable, governed, contextual and trustworthy access to records, metadata, relationships, audit trails, retention rules, legal holds and provenance.

Historical data may not fit the new operational model and may no longer need to be active. Migrating everything can increase cost, complexity, privacy exposure and data quality risk. Archive-only access is often more appropriate for historical evidence.

When legacy systems are retired, organisations must ensure that the records remain complete, trustworthy, traceable and accessible. This is especially important in regulated sectors such as Life Sciences, finance, healthcare, chemicals and manufacturing.

Historical data may be reused for AI training, validation, testing or decision support. In high-risk AI contexts, organisations need strong data governance, including understanding the origin, suitability, completeness and limitations of data.

AML obligations require certain customer due diligence information, transaction evidence and assessment records to be retained and made available to competent authorities. If those records are stored in legacy systems, decommissioning must preserve accessibility, integrity and control.

Archive-only access allows authorised users to consult historical records through a governed archive instead of keeping the original legacy system online.

Docbyte Vault preserves structured data, documents, metadata, relationships, audit trails, retention rules, legal holds, provenance and integrity evidence in a governed archive. This enables organisations to reduce dependency on obsolete systems while maintaining trustworthy access to historical records.

Still keeping legacy systems online for historical access?

If an obsolete system remains online only because someone may still need the data, it may be time to
rethink the strategy.

Docbyte Vault helps organisations preserve historical data, business context and evidentiary value in a
governed archive, so legacy systems can be decommissioned without losing the evidence that still matters.