Ninety days to retire an estate of legacy systems
Replacing a fragile collection of ageing systems before a failure made the decision for us.

What was happening
An organisation in the trust and advisory sector was running on systems that had quietly stopped being safe. Documents held with no version history and no record of who changed what. Correspondence sitting on a server the manufacturer no longer supported. Years of scanned paper that could only be found by someone who already knew where it was. And a piece of software that nobody left in the business knew how to rebuild.
Why it mattered
None of it had failed yet. That is the normal position and it is the dangerous one. A system can look healthy right up until the moment the one machine, or the one person, keeping it alive disappears. In a regulated business the day it finally goes tends to be an audit or an incident rather than a quiet Tuesday, and by then the choice has been made for you.
The decision
Move the whole estate inside ninety days rather than repair it piece by piece. Doing it gradually would have meant paying for the old arrangement and the new one at the same time, and carrying the same risk for longer while doing so.
What changed
Everything moved, on schedule. The unsupported server went. The software nobody could rebuild was rebuilt, so it no longer depends on a single machine or a single memory. The paper archive became searchable text. Reporting moved onto a platform the organisation itself controls.
Result
Finding a document fell from hours to seconds. A substantial share came off the annual licensing bill, because retiring the old systems retired what they cost to license. Most of the intended users were working in the new systems inside the first month, which is what actually decides whether a migration worked or merely finished. And recovery was not assumed. It was demonstrated, in a ransomware exercise.
How it worked technically
One component survived only as a compiled artefact, with no source and nobody left who had written it. It was reverse-engineered and containerised, which removed the dependency on one host and made it reproducible from a build file instead of from institutional memory.
The scanned archive went through optical character recognition and was indexed for full-text retrieval. Scan quality varied enormously across it, so the indexing had to tolerate poor source material rather than assume clean text.
Reporting was rebuilt on a cloud analytics platform under the organisation's own tenancy. The licensing reduction came mostly from retiring overlapping products, not from renegotiating any single one of them.
Recovery was tested against a simulated ransomware event, measuring how long a restore actually took and how much recent work it lost, rather than accepting a documented target as evidence that either number was true.
Client anonymised. Only the problem, the decisions and non-identifying outcomes are described here.







