Legacy System Modernization: A Pressing Challenge for Government CIOs and CISOs
An often-overlooked but crucial technology issue facing government Chief Information Officers (CIOs) and Chief Information Security Officers (CISOs) is the modernization of legacy systems. Ranked fifth on the National Association of State Chief Information Officers (NASCIO) priority list for 2025, this topic, while overshadowed by pressing issues like cybersecurity and artificial intelligence (AI), is vital for maintaining the integrity and efficiency of government operations.
The Cybersecurity Paradox
It’s no secret that cybersecurity remains at the forefront of the technology agenda for CIOs. Conventional wisdom argues that legacy systems pose a significant cybersecurity threat, necessitating immediate attention. Many initiatives aimed at modernizing IT infrastructures often cite cybersecurity vulnerabilities as a primary motivation for moving away from aging platforms. Systems that can’t be effectively supported or patched expose organizations to increased risks and potential breaches.
While it’s evident that legacy systems require urgent attention due to these vulnerabilities, the challenges are far-reaching and not purely limited to cybersecurity threats.
Multiple Dimensions of Legacy Systems
Understanding the issues surrounding legacy systems requires a broader perspective. Many factors contribute to the decision to upgrade, modernize, or outright replace outdated technology. These range from inefficient data management and limited software integration capabilities to strategic governance and scalability challenges.
The concept of "legacy" technology varies, but one thing is clear: many of the issues we face today have existed long before the infamous Y2K scare. The challenges associated with outdated technology are not going away; in fact, they are likely to compound over time.
For example, a recent headline from the United Kingdom caught my attention: "Government Urged to Wake Up to ‘Serious Cyber Threat’ as Report Reveals Some Systems Still Run on Windows 3.1." According to this report, legacy systems constitute a staggering 28% of the public sector’s IT infrastructure. By January 2025, 319 legacy systems had been identified, with approximately 25% rated as having a high risk for failure or breach.
What’s Clear and What’s Not
Among tech professionals, consensus exists regarding the necessity of replacing or upgrading unsupported technologies. If organizations are still running Windows 3.1, it’s undeniable that they need to move forward. Similarly, there’s a well-documented migration effort off of Windows 10, which is set to reach its end of life in October 2025.
Various resources, including end-of-support lists from reliable organizations like the Center for Internet Security and Microsoft, should be integral to any IT operations strategy focusing on security.
However, the conversation becomes muddied when addressing the role of mainframes, many of which still receive support. An interesting discourse highlights how mainframes can be perceived as less attractive targets for cybercriminals. This perception might stem from their relatively small presence in public attention compared to cloud environments.
Nonetheless, it’s crucial to recognize that mainframes handle an enormous amount of sensitive data. The complex technological landscape surrounding mainframes—different hardware, software, programming languages, and data formats—means that security assessments should still be a priority.
Strategic Considerations for Mainframe Modernization
As organizations deliberate the future of their mainframe systems, they must adopt a strategic approach to ensure that their technology stack supports long-term business objectives. IT leaders are urged to contemplate which applications to rewrite, re-platform, or maintain in their original state. This nuanced approach to mainframe modernization acknowledges the importance of operational stability alongside advancements in technology.
Security becomes even more critical in this frame of discussion, particularly as cyber threats grow more sophisticated. Companies must grapple with the need for robust protective measures alongside any modernization initiatives.
Exploring Solutions for Legacy Upgrades
While solutions for upgrading legacy systems are often fraught with complexities, resources like EPAM Systems’ "Mainframe Modernization ROI: A Cost-Focused Guide for Businesses" provide valuable insights. This guide outlines a few primary costs associated with different modernization strategies:
-
Rehosting (‘Lift and Shift’): This approach entails moving mainframe applications to a more cost-effective environment without altering the underlying architecture.
-
Replatforming: This middle-ground strategy maintains the core architecture of applications while transitioning them onto modern runtime platforms, requiring some code modifications.
- Refactoring/Rearchitecting: This comprehensive approach optimizes the existing codebase and modifies data models for targeted environments without changing external behaviors.
Another pertinent discussion revolves around the transformative role of generative AI in the modernization process. Mainframes, despite being essential for many industries, are increasingly seen as outdated when juxtaposed against innovative cloud solutions.
According to Kyndryl’s 2024 research, 86% of respondents are either deploying or planning to use generative AI tools within their mainframe ecosystems. Generative AI holds the potential to overcome long-standing modernization challenges, offering new pathways for efficiency and innovation.
Driving Change with Artificial Intelligence
An urgent appetite for modernization is rapidly taking shape, spurred on by advancements in AI technology. AI is recalibrating the cost-effectiveness and benefits associated with modernizing legacy technology. For instance, a transaction processing system that once commanded costs exceeding $100 million can now be modernized for significantly less.
The emergence of generative AI enables organizations to measure and itemize the impact of technology debt, allowing them to track returns on investments and gauge their influence across operational budgets. This capability positions modernization as a more attainable goal for organizations previously constrained by financial or logistical barriers.
Legacy Systems and Government Initiatives
For many public sector entities, legacy systems represent a hurdle in the quest for AI adoption and broader technological innovation. With governments operating on outdated platforms that often inhibit cybersecurity measures, addressing system modernization takes on heightened importance.
Perhaps it’s time for governments to consider merging priority categories, integrating legacy modernization efforts with broader cybersecurity strategies and AI initiatives, maximizing both budgetary considerations and safety protocols.
The road to effective legacy system modernization is not straightforward, but with the right mindset and tools, government CIOs and CISOs can turn these challenges into opportunities for growth and enhanced security.

