Knowledge base
nLegacy system modernisation: rewrite or replace gradually?
nA legacy system is older but still business-critical software. Its age matters less than operational risk, changeability and sustainable ownership.
When does modernisation become urgent?
nWarning signs include knowledge concentrated in one person, unsupported components, blocked security updates, recurring manual data repair and disproportionate risk for every change. The NIST Risk Management Framework applies to new and legacy systems and integrates security and privacy throughout the lifecycle.
nWhy is a full rewrite risky?
nOld software often contains undocumented business rules. A big-bang replacement can lose them while combining migration, integration, permission and parallel-operation risks. A full rewrite needs clear boundaries and a strong commercial reason.
nHow does gradual replacement work?
nBegin with system, data and integration maps. Introduce a stable interface between the old core and new modules. Replace the highest-risk or highest-value capability separately, using measurable acceptance criteria and a recovery plan.
nWhat is the first step?
nRun a technical audit and document dependencies, critical workflows, data owners and outage tolerance. Explore legacy modernisation, custom software development and API integrations.
nSource and further data: https://csrc.nist.gov/projects/risk-management/about-rmf