[{"data":1,"prerenderedAt":305},["ShallowReactive",2],{"\u002Fen\u002Fdossiers\u002Fit-obsolescence":3,"dossiers-catalogue":272},{"id":4,"title":5,"body":6,"description":233,"extension":234,"image":235,"kind":236,"manufacturer":235,"meta":237,"metaTitle":238,"model":235,"navigation":239,"order":240,"path":241,"publishedAt":242,"relatedDossiers":235,"relatedDrones":235,"relatedServices":235,"seo":243,"sources":250,"specs":235,"stem":269,"translationKey":270,"updatedAt":242,"__hash__":271},"content\u002Fen\u002Fdossiers\u002Fit-obsolescence.md","IT obsolescence: what it really costs you",{"type":7,"value":8,"toc":223},"minimark",[9,18,21,26,33,36,58,65,69,72,88,103,109,120,124,138,141,145,148,158,172,176,179,206,209,213,216],[10,11,12,13,17],"p",{},"IT obsolescence is the one major risk in an information system that has ",[14,15,16],"strong",{},"no symptom",". An\napplication past end of support runs exactly as it did the day before. It keeps delivering\nthe expected service, without slowdown, without an error message, sometimes for years.",[10,19,20],{},"That is precisely what makes it hard to fund. There is no incident to show, so no urgency\nto invoke — until the day there is one, and it is too late to choose your own timetable.",[22,23,25],"h2",{"id":24},"what-exactly-is-it-obsolescence","What exactly is IT obsolescence?",[10,27,28,29,32],{},"It is neither a failure nor a slowdown: it is ",[14,30,31],{},"the end of the vendor's commitment to fix\nflaws",". The software does not degrade; the world around it keeps moving.",[10,34,35],{},"Three states are worth separating, and they are routinely confused:",[37,38,39,46,52],"ul",{},[40,41,42,45],"li",{},[14,43,44],{},"Supported"," — the vendor publishes security fixes. The only healthy situation.",[40,47,48,51],{},[14,49,50],{},"Extended support"," — the vendor publishes critical fixes only, usually for a fee and\nfor a bounded period. That is bought time, not a solution.",[40,53,54,57],{},[14,55,56],{},"Out of support"," — no more fixes. Every vulnerability published from then on stays\nopen permanently.",[10,59,60,61,64],{},"Moving from the first state to the third is a ",[14,62,63],{},"date known well in advance",", often years.\nThat is what makes obsolescence unlike every other risk: it is the only one you can plan\nwith certainty, and it is the one least planned for.",[22,66,68],{"id":67},"why-has-obsolescence-become-the-leading-cyber-risk","Why has obsolescence become the leading cyber risk?",[10,70,71],{},"Because attackers changed their entry point.",[10,73,74,75,78,79,83,84,87],{},"For the ",[14,76,77],{},"first time in the report's nineteen-year history",", the 2026 edition of\nVerizon's ",[80,81,82],"em",{},"Data Breach Investigations Report"," ranks ",[14,85,86],{},"vulnerability exploitation as the\nleading initial access vector, at 31 % of breaches"," — ahead of stolen credentials, which\nhad dominated until then. The same report notes that AI on the attacker's side is\nshrinking the defence window \"from months to mere hours\".",[10,89,90,91,94,95,98,99,102],{},"France's cyber agency describes the same mechanics: the rate at which vulnerabilities are\npublished has grown ",[14,92,93],{},"18 % per year since 2020",", and ",[14,96,97],{},"about 29 %"," of those exploited in\n2025 were exploited ",[14,100,101],{},"on the very day they were published, or before",".",[10,104,105,106],{},"Put the two ends together. On one side, remediation measured in weeks. On the other,\nexploitation measured in hours. An up-to-date estate absorbs that gap because all it has\nto do is apply a patch. An obsolete estate cannot: ",[14,107,108],{},"there is no patch to apply.",[10,110,111,112,115,116,119],{},"Add that automation now sits on both sides: campaign ",[14,113,114],{},"C0062"," in MITRE ATT&CK, documented\nin late 2025, targeted around thirty organisations with ",[14,117,118],{},"80 to 90 % of operations carried\nout autonomously"," by an agent. An automated sweep makes no distinction between a large\ngroup and a small business: it is looking for a version string.",[22,121,123],{"id":122},"how-long-do-you-have-after-end-of-support","How long do you have after end of support?",[10,125,126,127,130,131,134,135,102],{},"Less than you think, and the best-documented case shows it. Support for ",[14,128,129],{},"Windows 10 ended\non 14 October 2025",": Microsoft states that from that date, technical assistance, feature\nupdates and ",[14,132,133],{},"security updates"," stop. The consumer extended security updates programme\nruns ",[14,136,137],{},"until 12 October 2027",[10,139,140],{},"That second date is the real trap. It creates a feeling of comfortable margin, when it\nonly covers fixes deemed critical, with no assistance and no functional correction. It\nbuys time to migrate, not time to wait. And on the day it expires, there is no net at all.",[22,142,144],{"id":143},"what-does-regulation-change","What does regulation change?",[10,146,147],{},"It shifts the burden, in both directions.",[10,149,150,153,154,157],{},[14,151,152],{},"NIS2"," widens the French regulatory perimeter from roughly 500 entities to some fifteen\nthousand, with penalty ceilings set by the directive at ",[14,155,156],{},"€10 M or 2 % of worldwide\nturnover"," for essential entities, and accountability explicitly carried by the management\nbody. As I write, the French transposition law has not yet been promulgated: the deadline\nis coming, it has not passed.",[10,159,160,163,164,167,168,171],{},[14,161,162],{},"The Cyber Resilience Act"," acts on your suppliers. ANSSI notes that from ",[14,165,166],{},"11 December\n2027",", manufacturers of products with digital elements will have to identify and document\ntheir products' components, fix vulnerabilities without delay, and ",[14,169,170],{},"distribute patches\nwithout delay",". Good news in the medium term: the market will get healthier. Immediate\nconsequence, however: a product whose supplier cannot meet those obligations becomes a\ncompliance problem, not merely a technical one.",[22,173,175],{"id":174},"how-do-you-build-an-obsolescence-management-plan","How do you build an obsolescence management plan?",[10,177,178],{},"In four moves, none of them technical to begin with.",[180,181,182,188,194,200],"ol",{},[40,183,184,187],{},[14,185,186],{},"Inventory."," What runs, which version, and its end-of-support date. That third column\nis the one missing everywhere, and the only one that turns worry into a calendar.",[40,189,190,193],{},[14,191,192],{},"Map the dependencies."," A component past end of support is not an isolated problem:\nit carries applications. The number of applications carried sets the priority, not the\nage of the component.",[40,195,196,199],{},[14,197,198],{},"Schedule."," Every item gets an exit date, aligned on its real end of support rather\nthan on team availability. A plan without dates is not a plan.",[40,201,202,205],{},[14,203,204],{},"Decommission."," A migration that leaves the old system running \"just in case\" has\nsolved nothing: it has doubled the attack surface. Switching off is part of the batch.",[10,207,208],{},"The first two steps are high-volume, repetitive and verifiable — exactly the work profile\nwhere AI assistance collapses the unit cost, and the reason an obsolescence plan has\nbecome fundable when it was not three years ago.",[22,210,212],{"id":211},"where-should-you-start","Where should you start?",[10,214,215],{},"With the \"end of support\" column of your inventory. If it does not exist, everything else\nis opinion.",[10,217,218,219,222],{},"It fills in quickly, it needs no tool, and it immediately produces the only list that\nmatters: what is ",[14,220,221],{},"exposed to the internet and already out of support",". That list is\nshort, it is urgent, and it can be dealt with independently of the rest of the programme.",{"title":224,"searchDepth":225,"depth":225,"links":226},"",2,[227,228,229,230,231,232],{"id":24,"depth":225,"text":25},{"id":67,"depth":225,"text":68},{"id":122,"depth":225,"text":123},{"id":143,"depth":225,"text":144},{"id":174,"depth":225,"text":175},{"id":211,"depth":225,"text":212},"End of support breaks nothing on the day. It turns your estate into attack surface, on a deadline you no longer set.","md",null,"dossier",{},"Managing IT obsolescence",true,3,"\u002Fen\u002Fdossiers\u002Fit-obsolescence","2026-08-21",{"keywords":244,"title":5,"description":233},[245,246,247,248,249],"IT obsolescence","end of support software","obsolescence management plan","unsupported systems security risk","NIS2 obsolescence",[251,255,258,262,266],{"label":252,"url":253,"date":254},"ANSSI \u002F CERT-FR — Panorama de la cybermenace 2025","https:\u002F\u002Fwww.cert.ssi.gouv.fr\u002Fuploads\u002FCERTFR-2026-CTI-002.pdf","2026",{"label":256,"url":257,"date":254},"Verizon — 2026 Data Breach Investigations Report","https:\u002F\u002Fwww.verizon.com\u002Fabout\u002Fnews\u002Fbreach-industry-wide-dbir-finds",{"label":259,"url":260,"date":261},"Microsoft — Windows 10 support has ended on October 14, 2025","https:\u002F\u002Fsupport.microsoft.com\u002Fen-us\u002Fwindows\u002Fdeployment\u002Fupdates-lifecycle\u002Fwindows-10-support-has-ended-on-october-14-2025","2025",{"label":263,"url":264,"date":265},"ANSSI — Cartographie du système d'information, guide d'élaboration en cinq étapes","https:\u002F\u002Fmesservices.cyber.gouv.fr\u002Fdocuments-guides\u002F20181213_anssi_guide_cartographie_v1b.pdf","2018",{"label":267,"url":268,"date":261},"MITRE ATT&CK — Campaign C0062","https:\u002F\u002Fattack.mitre.org\u002Fcampaigns\u002FC0062\u002F","en\u002Fdossiers\u002Fit-obsolescence","it-obsolescence","RkKIDA-dXBJ99bxdhMe1L03UAiCwcpqqjI-ojNGBTEw",[273,278,282,283,288,293,297,301],{"locale":274,"slug":275,"path":276,"title":277,"translationKey":275},"en","application-mapping","\u002Fen\u002Fdossiers\u002Fapplication-mapping","Application mapping: what it must contain",{"locale":274,"slug":279,"path":280,"title":281,"translationKey":279},"chatgpt-visibility","\u002Fen\u002Fdossiers\u002Fchatgpt-visibility","ChatGPT visibility: what actually works, measured",{"locale":274,"slug":270,"path":241,"title":5,"translationKey":270},{"locale":274,"slug":284,"path":285,"title":286,"translationKey":287},"technical-debt-ai","\u002Fen\u002Fdossiers\u002Ftechnical-debt-ai","Technical debt and AI: finally clearing the legacy","tech-debt-ai",{"locale":289,"slug":290,"path":291,"title":292,"translationKey":275},"fr","cartographie-applicative","\u002Ffr\u002Fdossiers\u002Fcartographie-applicative","Cartographie applicative : ce qu'elle doit contenir",{"locale":289,"slug":294,"path":295,"title":296,"translationKey":287},"dette-technique-ia","\u002Ffr\u002Fdossiers\u002Fdette-technique-ia","Dette technique et IA : solder enfin le legacy",{"locale":289,"slug":298,"path":299,"title":300,"translationKey":270},"obsolescence-informatique","\u002Ffr\u002Fdossiers\u002Fobsolescence-informatique","Obsolescence informatique : ce qu'elle vous coûte",{"locale":289,"slug":302,"path":303,"title":304,"translationKey":279},"referencement-chatgpt","\u002Ffr\u002Fdossiers\u002Freferencement-chatgpt","Référencement ChatGPT : ce qui marche, mesuré",1787432459017]