Is it time for your legacy IT to byte the dust?

The risk of your legacy IT outstaying its welcome
Qudos Management Pty Ltd.
October 2025
Legacy IT is one of the headline topics in Cyber Awareness month. It refers to outdated computer hardware, software, or technology platforms that are still in use, despite them being superseded by newer solutions and / or no longer being supported by their vendors. Legacy IT can remain in use for many reasons but can pose serious security risks.
Legacy IT can occur in an organisation that does not have a formal management system in place that includes a process to catalogue, review, and update its systems. It can often occur with a device or software application that was not part of a general issue or roll-out but perhaps used for a special purpose. This can result in them es getting overlooked for updates or replacement. Unfortunately, just one rogue device or application may be all that’s needed for threat actors (IT-speak for bad guys) to cause you a great deal of harm.
If legacy IT is out of support by the vendor and not being updated by your IT team or contractor, they will not be receiving security patches and are quite simply vulnerable to any virus, malware or hack that has appeared since they were last updated.
They sit there like unexploded bombs. Who knows when they will go off – causing mayhem and destruction.
What can you do about your legacy IT?
What can you do to prevent such an unfortunate event from occurring? Well, if your IT support person / team doesn’t know about the legacy IT, they can’t deal with its risks. So, our suggestion is that the first step would be to do a stocktake. Check what devices you have, what software applications you have installed, and what are their version or build numbers. That information can then be listed in an inventory or Asset register. At that point, decisions can be made on what to do with the legacy IT e.g. updated, superseded, deleted, or disposed of.
Windows 10 End of Life
To illustrate the need to manage legacy IT, as of October 14, 2025, Windows 10 reaches EOL (End of Life ) status. That doesn't mean it can no lomger be used, but Micorsoft will no longer provide:
- Technical support
- Feature updates or new features
- Quality updates (including security and reliability fixes)
Over time, that will make it increasingly vulnerable to viruses and other malware. To stay secure, Microsoft recommends upgrading to Windows 11 for eligible devices, purchasing a new Windows 11 device, or enrolling in the paid Extended Security Updates (ESU) program for one additional year of support.
Relevance to ISO 27001
For those looking to comply with the ISO 27001 Information Security standard, there are a number of relevant controls in its Annex A. In particular:
- Annex A 5.9 Inventory of information and other associated assets requires you to identify and record the information and data assets that it holds.
- Annex A 5.11 Return of assets requires arrangements to be in place for the assured return of assets when no longer required for business purposes. Such arrangements may help to minimise incidence of legacy IT in the future.
Qudos3 IMS software clients can use its Assets module to list your hardware and software and also the linked tasks to prompt remiders about checking / updating etc. Just contact us for guidance.
PS. Apologies for the dreadful pun in the title! We just couldn’t resist.
PPS. A big shout-out to UDC and Unsplash for the old computer image. What are the chances that one of those post-it notes is her login password?
Contact Qudos today to learn how we can help you build a secure, compliant, and high-performing integrated management system.
Qudos Club is all about helping you with your management system, Its free to join and you will get access to newsletters, resources and more. Just click the button to join our growing community.
Click the LinkedIn Follow button below to follow Qudos and be the first to receive ISO management system news and further articles like this.