Still Supported Isn't the Same as Still Safe: Legacy Assets and the Enforcement Gap

Organisations keep running insecure legacy systems not because they don't know about the risk, but because replacing them costs more than they can afford. And even when a system is supported and the patch is free, there are laws and guidelines saying you must update but actually enforcing that across every system in a large organisation is a different problem entirely. This talk uses real incidents to show both failure modes, and ends with three things you can actually do about it this week.


This talk is about why insecure systems stick around even when everyone already knows about them, and what actually happens when they do. It covers the gap between guidance and enforcement, looks at real incidents where legacy neglect had a measurable cost, and finishes with practical steps a security team can act on without a big budget.

The speaker's profile picture
Mateusz Madrzynski

I am an undergraduate student going into my final year at UWE Bristol who loves CTFs and giving students opportunities to learn outside the classroom. I lead The CTF Falcons, UWE's cybersecurity society, where we bring in industry speakers and run learning sessions on topics that interest us. I served as president in my second year and am moving into the vice-president role this coming year.