Services Experience Recommendations Blog In the Media Contact Get in touch
← Back to Blog 17 Aug 2026

We all live in a legacy world....

We all live in a legacy world....

AI Has Turned Every Organisation Into a Legacy Environment

For years, we’ve talked about legacy technology as somebody else’s problem. It’s the old server sitting in a government department. The ageing operating system nobody dares switch off. The piece of critical infrastructure running software that should have been retired a decade ago.

This definition no longer works.

In the age of AI, I would argue that almost every organisation is now operating a legacy environment. Not because every piece of technology they own is old, but because the architecture behind modern cyber defence was built for a fundamentally different adversary. And that is a much bigger problem.

Look at how the Security Operations Centre (SOC) has evolved. We started by collecting security information centrally. Then we added better event management, automation, SOAR platforms and playbooks. Now we’re adding AI assistants capable of helping analysts triage alerts and make decisions faster.

Every generation has improved something, but we have largely been improving the same basic model. Something happens somewhere in the organisation. The telemetry is collected, normalised and aggregated, and then it reaches a central system. The security platform analyses it. Eventually, somebody or something decides what to do.

We keep shortening the reaction time at the end of that chain. What we haven’t really addressed is the chain itself. This distinction matters enormously when the attacker is using AI. I’ve spent enough time on the offensive side of security to know how quickly a compromise can unfold. An attacker does not care that your SOC can now analyse an alert in seconds if they have already achieved what they came to do before that alert reaches the dashboard.

We are putting increasingly powerful engines into a car and ignoring the fact that the road to the incident is getting longer.

There has always been an asymmetry between attackers and defenders. An attacker can try something 999 times, fail every time, and nobody cares. If attempt number 1,000 works, they win. The defender has the opposite problem. They can stop 999 attacks and still find themselves explaining the one that got through.

AI makes that imbalance worse.

Capabilities that previously required considerable technical expertise are becoming available to people who simply didn’t have them before. That doesn’t suddenly make every criminal an elite hacker. There is still skill involved in infiltration, malware development and understanding how systems work. But the barrier to entry has fallen dramatically.

This means more capable attackers, more experimentation and, above all, more volume. Meanwhile, defenders are still constrained by architecture, procurement cycles, budgets, governance and the need to avoid breaking the systems they are supposed to protect.

The attacker gets to experiment. The defender gets a change-control meeting.

This is where I think the security industry’s definition of legacy needs to change. A cloud-native business can be legacy. A company running the latest endpoint protection can be legacy. A SOC with AI-assisted triage can be legacy.

If your security model depends on moving huge amounts of information away from where an event is happening, processing it somewhere else and then sending a decision back, you are still working within an architecture designed for a slower threat environment.

The alternative is to move intelligence closer to the event. If something is happening on an endpoint, process it there. If it is happening inside cloud infrastructure, make the decision there. If it is happening at a network control point, analyse it there. Security decisions increasingly need to happen in milliseconds, not after data has completed a journey through the organisation.

This is a significant architectural shift. It also means questioning assumptions that have guided security investment for years. And organisations are not particularly good at doing that. There is a very human problem underneath all of this.

Imagine somebody tells you that this summer will be exceptionally hot and dry. Wildfires are likely. Your house is in an exposed area and you really ought to install a sprinkler system. You look at the cost and think: they’re probably right, but we’ll deal with it if the fire gets closer.

Then the fire appears on the horizon. Now you start calling sprinkler companies.

And this is essentially how we approach major shifts in cybersecurity.

The warning signs around AI are not particularly subtle. We know offensive capability is increasing. We know attacks are becoming faster. We know automation will continue to compress the time between initial access and impact. Yet many organisations will wait until that change becomes an incident before they seriously reconsider how their defences work.

Part of the problem is budget. Transforming security architecture is expensive. If an organisation is already spending millions every year on its SOC, asking for another major investment to redesign how detection and response happens is not an easy conversation.

It enters the annual planning cycle. It competes with other priorities. Somebody asks for a business case. Somebody else wants to know what the return on investment will be.

Meanwhile, the attacker doesn’t have an annual operating plan.

If I were sitting on the board of a large organisation today, one of the questions I would ask my security team is surprisingly simple: where do we lose time?

Instead of: are we compliant? Not: how many alerts did we process last quarter? Not even: how much AI have we deployed?

Where, from the moment an attacker touches our environment, do we lose time?

Ask the people actually defending the network. They know. They know where telemetry gets delayed. They know which systems generate noise. They know where analysts are waiting for information. They know which processes take two minutes when an attacker may only need 30 seconds. Those conversations are far more valuable than another presentation about how many security tools the organisation owns.

Because the next generation of cyber defence isn’t going to be won by whoever has the most AI in their SOC. It will be won by whoever can make the right decision closest to the attack, before the attacker has time to make theirs.

Legacy is no longer defined by the age of your technology. It is defined by whether your security architecture can keep pace with the threat in front of it.

And by that measure, far more of us are running legacy systems than we’d like to admit.