Site navigation

Legacy Windows Systems Pose Hidden Risk to Enterprise Resilience

Graham Turner

,

Legacy server backups
The warning comes ahead of Windows Server 2016 reaching end of support in January 2027, prompting calls for organisations to review backup contracts, legacy estates, and resilience plans.

New analysis by container-based security software firm Droplet, has found that organisations still relying on Microsoft Windows 2003, 2008 and 2012 may not have experienced any system backup for almost a decade.

Having analysed the contracts of eight of the world’s leading backup vendors, Droplet has found that many users could unknowingly believe that their systems are being regularly backed up. However, the firm is warning that in actual fact, these have not been supported for a significant amount of time, or are now only partially supported.

In advance of Microsoft Windows 2016 reaching end of support in January 2027, Droplet is urging all organisations to review their backup posture and contracts to ensure they do not fall foul of a lack of backed up data and applications in a little over six months.

Speaking about the new insight, Barry Daniels, CEO, Droplet said: “When Microsoft announces the end of support for a server operating system, it rarely lands as a routine upgrade notice. For IT leaders across essential services, such as utilities, transport, and healthcare these announcements often trigger a cascading domino effect of operational, security, and commercial risk.

“In recent conversations, we have been made aware of one organisation with more than 900 unsupported servers. They assumed that their data protection provider was continuing to support its legacy systems, but in a passing conversation found that no backups had been carried out over the last 5 to 10 years.

“This lack of contract consciousness could mean that many more organisations may find themselves operating with a backup black hole which could be devastating should they either suffer a major cyber incident or fail a regulatory audit. With market conditions and the risk of cyber threats being more unsettled than ever, organisations must take a proactive approach to reviewing their legacy estates; otherwise, the effects could be crippling.”


Recommended reading


In addition, Droplet is also calling on organisations to confirm with their backup partners what server upgrades are supported as part of their contracts as further analysis has found that patch updates are also not supported.

With many providers only offering extended security updates, these are limited to critical updates and do not include any standard security updates and fixes, or any new features included in the latest operating systems (which can include just one patch which is updated over a 3-year period).

Daniels added: “While modernising legacy systems can be not only complex but also costly, organisations must consider quicker routes to maintain resilience. Protecting critical applications and data inside secure containers is one route that many organisations are adopting to ensure that their backups are shielded quickly and narrows the gap between legacy dependency and modern security expectations.

“This will become all the more important in advance of the royal ascent of the Cyber Security and Resilience Bill.”

Graham Turner

Sub Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data