In the first of a series of Festive Stories, Chief Consultant Lawrie Abercrombie takes us through a journey of cyber security discovery through the lens of Charles Dickens.
It was the best of times, it was the worst of times; it was the age of digital transformation, the epoch of operational neglect. It was the season of innovation, it was the winter of vulnerability. In the shadowy corridors of the United Kingdom’s Critical National Infrastructure, where the hum of machinery is as constant as the fog upon the Thames, there lurked a silent adversary. One not of flesh and blood, but of code and consequence.
Chapter the First: The Ghosts of Systems Past
In the grand halls of industry, where iron giants toiled and the pulse of the nation’s lifeblood was measured in kilowatts and cubic metres, there persisted relics of a bygone era. These legacy systems, venerable in their longevity, were built to endure decades, twenty, thirty, forty years or more. Their creators, long since retired to the countryside or the churchyard, could scarce have imagined the perils that would one day beset their handiwork.
Yet, as the world outside hastened toward the electric dawn of the digital age, these ancient engines remained, not out of affection, but necessity. For to replace them would be to risk the very beating heart of production, to invite chaos and cost upon the enterprise. And so they lingered, deeply entwined in the sinews of business. Their obsolescence masked by the steady rhythm of routine.
Chapter the Second: The Gathering Storm
But all was not well in the land of operational technology. For these legacy systems, though steadfast, were ill-prepared for the marauders of the modern age. Their walls, unpatched and crumbling, offered scant resistance to the cunning of cyber thieves. Vendor support had faded like the gaslights of old London and the tools of modern security could find no purchase in their antiquated halls.
The architecture of their networks was as flat as the marshes of Kent, allowing villains to slip from chamber to chamber with nary a locked door to hinder them. And so it was that sixty percent of all cyber incidents in OT could be traced to these outmoded sentinels, their vulnerabilities as plain as the nose on Mr. Pickwick’s face.
Chapter the Third: A Catalogue of Catastrophes
Recent years brought calamity upon calamity. In the year of our Lord 2024, the Synnovis NHS Pathology fell prey to ransomware, its legacy lab systems exploited, services halted and patients imperilled. The following year, the mighty Jaguar Land Rover was brought low by AI-assisted brigands, its production silenced for five weeks, the cost to the realm a staggering £1.9 billion. Even the venerable British Library, under-invested and overexposed, suffered a prolonged outage, its recovery exacting a toll of £600,000.
Nor were these woes confined to Albion’s shores. The tale of Stuxnet, which haunted Siemens PLCs in 2010 and the Colonial Pipeline, disrupted by ransomware in 2021, serve as grim reminders that the spectre of legacy risk knows no borders.
Chapter the Fourth: The Sectors in Peril
The energy and utilities, with their SCADA systems and outdated protocols, stood exposed. Healthcare, with its patchwork of legacy EPR systems, was a patchwork of risk. Transport, manufacturing, none were spared. Embedded systems with hardcoded credentials, rail signalling platforms with limited patching, all were grist for the mill of cyber misfortune.
Chapter the Fifth: The Voices of Caution
“Legacy systems are the Achilles’ heel of critical infrastructure cybersecurity,” declared Christopher Burgess of CSO Online. “Unpatched legacy systems are responsible for 60% of OT cyber incidents” echoed IDS-INDATA. The UK Government Digital Service, in tones as grave as Marley’s ghost, warned: “Legacy IT is not just inefficient, it is incompatible with modern security standards.” And from the learned Paul Shaver of Mandiant: “The time to mitigate legacy risk is now. These systems are prime targets for disruption.”
Chapter the Sixth: The Reckoning
The statistics were as chilling as a London fog:
- 28% of UK central government IT systems were classified as legacy.
- £44 billion lost over five years to OT cybersecurity failures.
- An 87% increase in OT-targeted cyberattacks in 2024.
- Only 12% of organisations possessed adequate OT network monitoring.
Chapter the Seventh: The Path to Redemption
Yet, all was not lost. The government, awakened to the peril, issued the Legacy IT Risk Assessment Framework and the Cyber Security and Resilience Bill, mandating both reporting and modernisation. The NCSC and CISA, like benevolent spirits, offered guidance: asset inventories, segmentation, software bills of materials.
The wise counsel was clear:
- Conduct full OT asset inventories and risk assessments.
- Prioritise patching and segmentation of legacy systems.
- Invest in secure gateways and monitoring tools.
- Develop incident response plans tailored to the peculiarities of legacy OT.
Chapter the Last: A Warning and a Hope
Let it be known: legacy systems in OT are no longer mere operational liabilities, they are cybersecurity time bombs, ticking away beneath the foundations of national infrastructure, public safety and economic stability. The hour is late, but not yet struck. Let those who hold the keys to the kingdom act with urgency, lest the ghosts of systems past become the ruin of the future.
For further reading, consult the NCSC OT Security Guidance and the Legacy IT Risk Assessment Framework.