Knowledge base

n

Legacy system modernisation: rewrite or replace gradually?

n

A legacy system is older but still business-critical software. Its age matters less than operational risk, changeability and sustainable ownership.

n

When does modernisation become urgent?

n

Warning signs include knowledge concentrated in one person, unsupported components, blocked security updates, recurring manual data repair and disproportionate risk for every change. The NIST Risk Management Framework applies to new and legacy systems and integrates security and privacy throughout the lifecycle.

n

Why is a full rewrite risky?

n

Old software often contains undocumented business rules. A big-bang replacement can lose them while combining migration, integration, permission and parallel-operation risks. A full rewrite needs clear boundaries and a strong commercial reason.

n

How does gradual replacement work?

n

Begin with system, data and integration maps. Introduce a stable interface between the old core and new modules. Replace the highest-risk or highest-value capability separately, using measurable acceptance criteria and a recovery plan.

n

What is the first step?

n

Run a technical audit and document dependencies, critical workflows, data owners and outage tolerance. Explore legacy modernisation, custom software development and API integrations.

n

Source and further data: https://csrc.nist.gov/projects/risk-management/about-rmf