When Superstorm Sandy hit the New York space in 2012, components of New York Metropolis suffered a week-long blackout.
I used to be residing in Brooklyn on the time, and I used to be fortunate sufficient to have energy.
That meant that my residence was a workspace for a half-dozen mates who had misplaced their energy.
Now, having a half-dozen mates crash at your home is enjoyable for a number of days. However in my expertise, the marginal utility begins to say no by round day 4…
Particularly once you understand there’s an opportunity they could by no means go away.
Final week, tens of tens of millions of individuals throughout Spain and Portugal have been confronted with an identical drawback when each international locations all of the sudden misplaced energy.
It was one of many worst blackouts in European historical past.
And as we mentioned in our final difficulty, one thing related might occur right here within the U.S. as a result of our energy grid is simply as susceptible.
It’s previous and desires updating. It’s uncovered to excessive climate occasions like hurricanes and wildfires. And the combination of renewable vitality sources makes it vulnerable to giant energy fluctuations just like the one Spain simply skilled.
In the meantime, our grid is being strained by an rising demand for energy.
Sadly, that’s not the one huge infrastructure drawback the U.S. is going through at this time.
You see, the legacy software program nonetheless powering America’s air visitors management, transport logistics, protection programs and even our hospitals is hanging on by a thread.
This drawback might sound far much less apparent, however it’s equally as harmful. And except we handle it quickly, it’s solely a matter of time earlier than there are severe penalties.
A Downside That’s Tougher to See
The most important threat to our important infrastructure is buried deep in traces of code, written many years in the past and patched collectively ever since.
Based on Synopsis/Black Duck’s 2025 Open Supply Safety and Threat Evaluation Report, the overwhelming majority of those fragile legacy programs include at the least some open supply software program (OSS).
Supply: www.resilientcyber.io
However whereas using OSS might be less expensive and clear, the research discovered that 91% of the codebases reviewed had outdated OSS elements.
And 90% of them include elements which are greater than 10 variations behind probably the most present model.
Meaning they weren’t designed for the threats we face at this time.
And that’s comprehensible when you think about the size of time it typically takes for presidency initiatives to get off the bottom.
By the point software program is carried out, it’s common for it to already be old-fashioned.
And lots of of those legacy programs now not obtain updates or safety patches in any respect.
That’s why hospitals, air visitors networks, protection contractors and different areas of important infrastructure are such ripe targets for hackers.
For instance…
- The Wolf Creek nuclear energy plant in Kansas was the goal of Russian hackers again in 2017.
- The Colonial Pipeline hack in 2021 was the largest cyberattack on an oil infrastructure goal in U.S. historical past.
- And simply final 12 months, a China-linked state-sponsored group infiltrated main U.S. telecoms as a part of a cyberespionage marketing campaign.
But regardless of these main safety breaches, we nonetheless depend on software program written when Invoice Clinton was president.
Based on a latest RSAC panel, some visitors programs run on firmware from a number of many years in the past, with little standardization and no centralized oversight.
Our water infrastructure is fractured into greater than 55,000 unbiased districts, every with its personal ageing software program stack.
And the well being care sector isn’t faring a lot better.
A 2023 research confirmed that roughly 40% of open-source code utilized in medical software program accommodates identified vulnerabilities…
Although a single ransomware assault might completely shut down a hospital.
In any case, that’s what occurred to St. Margaret’s Well being in Spring Valley, IL.

Supply: wqad.com
It was hit with a ransomware assault in 2021 that disrupted the hospital’s capability to submit claims to insurers, Medicare or Medicaid for months.
These billing delays despatched St. Margaret’s right into a monetary spiral, and the 120-year-old hospital was pressured to close its doorways in 2023.
It was the primary time a hospital was shut down within the U.S. on account of a cyberattack. But it surely probably gained’t be the final…
If we fail to behave on our legacy software program points.
The Price of Doing Nothing
The issue with sustaining previous code is that it’s costly and inefficient.
Legacy programs typically depend on outdated programming languages, customized {hardware} and a lack of know-how.
As the unique engineers retire, there’s nobody left who really understands how all the pieces matches collectively.
It’s like making an attempt to repair a crumbling bridge with out the unique blueprints… and whereas visitors continues to be working throughout it.
However right here’s the factor…
The longer we delay modernization, the extra we threat falling behind.
We’re already seeing it occur within the airline business, the place legacy flight ops programs at the moment are a serious motive for delays.
Based on the Division of Transportation, final 12 months over 22% of U.S. industrial flights arrived late.
And tarmac delays of over three hours have been up greater than 51% from the 12 months earlier than.
The airline business loses an estimated $60 billion a 12 months from these disruptions. But, many carriers proceed counting on decades-old scheduling platforms as a result of changing them is considered as too dangerous or costly.
I consider there’s a far higher threat in doing nothing.
The excellent news is that momentum appears to be constructing to do one thing about our legacy software program drawback.
In January 2025, the Cybersecurity and Infrastructure Safety Company (CISA), in partnership with the Protection Superior Analysis Tasks Company (DARPA) and different authorities companies, printed a report titled Closing the Software program Understanding Hole.
It acknowledges that almost all legacy programs are so complicated, we now not totally grasp how they work.
The report highlights the dangers of this software program understanding hole to each nationwide safety and important infrastructure, and it recommends a broad, government-coordinated strategy to assist repair the issue.
One resolution is to put money into rigorous software program evaluation strategies referred to as formal strategies that enable deep auditing throughout huge codebases.
Formally verified software program used to appear not possible to do at scale, however advances over the previous decade have made it a lot simpler to make use of in on a regular basis growth.
Naturally, AI is enjoying an element. It’s already serving to builders untangle and refactor legacy code.
Actually, in response to GitLab analysis, 34% of builders at the moment are utilizing AI to modernize legacy code.
That proportion will solely go up as AI continues to enhance.
By analyzing, testing and rewriting outdated software program, AI instruments ought to reduce the time and price of modernization considerably.
Right here’s My Take
The blackout in Spain and Portugal final week ought to be a wake-up name for all of us.
Not simply in regards to the vulnerabilities of our vitality grid however in regards to the software program that powers our important infrastructure.
As a result of the longer we rely on outdated code, the higher the prospect that one thing will break.
That’s why sensible cash is backing the businesses powering America’s digital rebuild.
As federal companies and Fortune 500s start to improve their software program, firms engaged on secure-by-design software program, AI-powered growth instruments and formal verification ought to profit from America’s digital rebuild.
Members of my Strategic Fortunes service know this already.
At the start of final 12 months, I recognized an organization that’s serving to giant establishments map and modernize complicated legacy programs, together with authorities infrastructure.
As of this morning, its inventory value is up over 640% since my suggestion.
And as concern round this difficulty retains rising, we’ll probably see extra possibilities for related positive factors.
Regards,
Ian King
Chief Strategist, Banyan Hill Publishing
Editor’s Be aware: We’d love to listen to from you!
If you wish to share your ideas or solutions in regards to the Each day Disruptor, or if there are any particular matters you’d like us to cowl, simply ship an electronic mail to [email protected].
Don’t fear, we gained’t reveal your full identify within the occasion we publish a response. So be at liberty to remark away!