When Superstorm Sandy hit the New York space in 2012, elements of New York Metropolis suffered a week-long blackout.
I used to be dwelling in Brooklyn on the time, and I used to be fortunate sufficient to have energy.
That meant that my condominium became a workspace for a half-dozen associates who had misplaced their energy.
Now, having a half-dozen associates crash at your house is enjoyable for just a few days. However in my expertise, the marginal utility begins to say no by round day 4…
Particularly while you notice there’s an opportunity they could by no means depart.
Final week, tens of thousands and thousands of individuals throughout Spain and Portugal have been confronted with an analogous downside when each nations instantly misplaced energy.
It was one of many worst blackouts in European historical past.
And as we mentioned in our final concern, one thing related might occur right here within the U.S. as a result of our energy grid is simply as weak.
It’s outdated and desires updating. It’s uncovered to excessive climate occasions like hurricanes and wildfires. And the mixing of renewable power sources makes it liable to giant energy fluctuations just like the one Spain simply skilled.
In the meantime, our grid is being strained by an growing demand for energy.
Sadly, that’s not the one huge infrastructure downside the U.S. is going through at present.
You see, the legacy software program nonetheless powering America’s air visitors management, transport logistics, protection programs and even our hospitals is hanging on by a thread.
This downside may appear far much less apparent, however it’s equally as harmful. And except we deal with it quickly, it’s solely a matter of time earlier than there are severe penalties.
A Drawback That’s Tougher to See
The largest threat to our important infrastructure is buried deep in traces of code, written many years in the past and patched collectively ever since.
In keeping with Synopsis/Black Duck’s 2025 Open Supply Safety and Danger Evaluation Report, the overwhelming majority of those fragile legacy programs include at the least some open supply software program (OSS).
Supply: www.resilientcyber.io
However whereas using OSS could be cheaper and clear, the examine discovered that 91% of the codebases reviewed had outdated OSS elements.
And 90% of them include elements which can be greater than 10 variations behind essentially the most present model.
Which means they weren’t designed for the threats we face at present.
And that’s comprehensible when you think about the size of time it usually takes for presidency initiatives to get off the bottom.
By the point software program is applied, it’s commonplace for it to already be old-fashioned.
And lots of of those legacy programs now not obtain updates or safety patches in any respect.
That’s why hospitals, air visitors networks, protection contractors and different areas of important infrastructure are such ripe targets for hackers.
For instance…
- The Wolf Creek nuclear energy plant in Kansas was the goal of Russian hackers again in 2017.
- The Colonial Pipeline hack in 2021 was the most important cyberattack on an oil infrastructure goal in U.S. historical past.
- And simply final yr, a China-linked state-sponsored group infiltrated main U.S. telecoms as a part of a cyberespionage marketing campaign.
But regardless of these main safety breaches, we nonetheless depend on software program written when Invoice Clinton was president.
In keeping with a latest RSAC panel, some visitors programs run on firmware from a number of many years in the past, with little standardization and no centralized oversight.
Our water infrastructure is fractured into greater than 55,000 unbiased districts, every with its personal growing older software program stack.
And the well being care sector isn’t faring a lot better.
A 2023 examine confirmed that roughly 40% of open-source code utilized in medical software program accommodates identified vulnerabilities…
Regardless that a single ransomware assault might completely shut down a hospital.
In spite of everything, that’s what occurred to St. Margaret’s Well being in Spring Valley, IL.

Supply: wqad.com
It was hit with a ransomware assault in 2021 that disrupted the hospital’s skill to submit claims to insurers, Medicare or Medicaid for months.
These billing delays despatched St. Margaret’s right into a monetary spiral, and the 120-year-old hospital was pressured to close its doorways in 2023.
It was the primary time a hospital was shut down within the U.S. as a result of a cyberattack. But it surely possible gained’t be the final…
If we fail to behave on our legacy software program points.
The Price of Doing Nothing
The issue with sustaining outdated code is that it’s costly and inefficient.
Legacy programs usually depend on outdated programming languages, customized {hardware} and a lack of awareness.
As the unique engineers retire, there’s nobody left who really understands how every thing matches collectively.
It’s like making an attempt to repair a crumbling bridge with out the unique blueprints… and whereas visitors remains to be working throughout it.
However right here’s the factor…
The longer we delay modernization, the extra we threat falling behind.
We’re already seeing it occur within the airline business, the place legacy flight ops programs at the moment are a significant purpose for delays.
In keeping with the Division of Transportation, final yr over 22% of U.S. business flights arrived late.
And tarmac delays of over three hours have been up greater than 51% from the yr earlier than.
The airline business loses an estimated $60 billion a yr from these disruptions. But, many carriers proceed counting on decades-old scheduling platforms as a result of changing them is considered as too dangerous or costly.
I imagine there’s a far higher threat in doing nothing.
The excellent news is that momentum appears to be constructing to do one thing about our legacy software program downside.
In January 2025, the Cybersecurity and Infrastructure Safety Company (CISA), in partnership with the Protection Superior Analysis Initiatives Company (DARPA) and different authorities companies, printed a report titled Closing the Software program Understanding Hole.
It acknowledges that the majority legacy programs are so advanced, we now not totally grasp how they work.
The report highlights the dangers of this software program understanding hole to each nationwide safety and important infrastructure, and it recommends a broad, government-coordinated method to assist repair the issue.
One answer is to put money into rigorous software program evaluation strategies generally known as formal strategies that permit deep auditing throughout huge codebases.
Formally verified software program used to look unimaginable to do at scale, however advances over the previous decade have made it a lot simpler to make use of in on a regular basis growth.
Naturally, AI is enjoying an element. It’s already serving to builders untangle and refactor legacy code.
In truth, in accordance with GitLab analysis, 34% of builders at the moment are utilizing AI to modernize legacy code.
That proportion will solely go up as AI continues to enhance.
By analyzing, testing and rewriting outdated software program, AI instruments ought to lower the time and price of modernization considerably.
Right here’s My Take
The blackout in Spain and Portugal final week needs to be a wake-up name for all of us.
Not simply concerning the vulnerabilities of our power grid however concerning the software program that powers our important infrastructure.
As a result of the longer we rely on outdated code, the higher the prospect that one thing will break.
That’s why sensible cash is backing the businesses powering America’s digital rebuild.
As federal companies and Fortune 500s start to improve their software program, firms engaged on secure-by-design software program, AI-powered growth instruments and formal verification ought to profit from America’s digital rebuild.
Members of my Strategic Fortunes service know this already.
In the beginning of final yr, I recognized an organization that’s serving to giant establishments map and modernize advanced legacy programs, together with authorities infrastructure.
As of this morning, its inventory worth is up over 640% since my advice.
And as concern round this concern retains rising, we’ll possible see extra probabilities for related good points.
Regards,
Ian King
Chief Strategist, Banyan Hill Publishing
Editor’s Observe: We’d love to listen to from you!
If you wish to share your ideas or strategies concerning the Each day Disruptor, or if there are any particular subjects you’d like us to cowl, simply ship an electronic mail to [email protected].
Don’t fear, we gained’t reveal your full identify within the occasion we publish a response. So be happy to remark away!