The conventional wisdom is backwards. Here’s what the data actually shows.
Photo by Joshua Sortino on Unsplash
In our last video, we covered 5 signs your data stack is holding you back. This article goes deep on one sign: the belief that legacy systems are “stable” and migration is “too risky.”
It’s a belief we hear constantly. And it’s almost always wrong.
On February 12, 2024, hackers breached Change Healthcare through a single missing security control, a Citrix portal without multi-factor authentication.
They spent nine days inside the network before anyone noticed.
By the time the dust settled: 190 million Americans had their health data compromised. Total cost: $3.09 billion.
The root cause? Not sophisticated nation-state malware. A legacy authentication gap that basic security hygiene would have caught.
As Senator Ron Wyden put it: “This hack could have been stopped with cybersecurity 101.”
This wasn’t an outlier. It was a preview.
“Stable” Is Not the Same as “Safe”
Here’s the thing about legacy systems: they feel stable because they’re familiar, not because they’re actually low-risk.
Consider Southwest Airlines, December 2022:
A winter storm hit. Other airlines recovered within hours. Southwest canceled 59% of its flights vs. just 3% for other carriers.

he difference wasn’t the weather. It was a legacy crew scheduling system that couldn’t reassign pilots fast enough when things went sideways.
The system worked fine on normal days. It catastrophically failed the moment conditions changed.
That’s the pattern. Legacy systems don’t fail gradually — they fail suddenly, at the worst possible time, in ways nobody anticipated.
The Costs Nobody Wants to Calculate
This is usually the next objection: “We can’t afford to migrate right now.” What’s easier to ignore is that keeping legacy systems in place isn’t “free” — it’s a cost that hides in plain sight until something breaks.
The downtime math is brutal
For large organizations, a meaningful outage can cost thousands of dollars per minute, and healthcare is often cited in the $5,300 to $9,000 per minute range.
Do the math for a real incident and you’re quickly talking about six or seven figures in an afternoon — and that’s before you account for downstream messiness like backlog, manual workarounds, SLA penalties, and customer churn.
The point isn’t whether the number is $9,000 or $14,000 per minute. The point is that a single bad hour can wipe out the budget people claim they don’t have.
Then there’s the budget trap nobody puts on the slide
A lot of organizations are already paying a “legacy tax” every year: research and industry surveys commonly put 60–80% of IT spend toward simply maintaining existing systems.
That’s how you end up in the loop where teams say they can’t invest in modernization because budgets are tight… while the reason budgets are tight is because legacy maintenance is consuming them.
In other words: you’re spending money. You’re just not buying progress.
Finally, the talent problem becomes an operational risk
Legacy stacks don’t just age out technically, they age out demographically. The average COBOL developer is frequently cited as being in their late 50s, with a meaningful portion retiring each year.
And it’s not like you can solve that overnight with hiring. Many universities moved away from teaching mainframe-era skills decades ago, which means the bench is thinner than people assume.
That’s not an abstract “future risk.” That’s a supportability risk you feel the moment something breaks at 2 a.m. and your one person who knows the system is on a flight.
Even insurance doesn’t save you the way people think
A lot of teams treat cyber insurance as a backstop: “If something happens, we’re covered.” But in 2024, roughly 40% of cyber insurance claims were denied. And even when claims are approved,, insurers often don’t cover the full cost — outcomes can hinge on whether basic controls were actually in place (MFA, segmentation, documented practices).
The punchline is uncomfortable but important: you may not discover your coverage gaps until you’re already filing the claim.
The Deadlines Already Passed (And Coming Fast)
Consider this timeline:

Source: Microsoft Lifecycle, Lansweeper
Yet 17% of SQL Server installations are still running SQL Server 2014 — software that’s been unsupported for 18 months.
The clock isn’t ticking. For some systems, it’s already past midnight.
The Real Lesson from Failed Migrations
A fair counterargument: “But migrations fail all the time. We tried once and it was a disaster.”
We won’t pretend they don’t fail. Only about 16% finish on time and under budget.
But here’s what those statistics don’t tell you: why they fail.
According to Cloudficient’s 2025 analysis:
- 84% of migrations are negatively affected by poor data quality going in
- 61% exceed timelines by 40–100% due to underestimated scope
- 52% find that existing applications can’t access migrated data — discovered after the move
These aren’t execution failures. They’re planning failures.
This is why we advocate for Phase 0 — comprehensive discovery before you touch anything. Map your data sources. Understand your dependencies. Identify quality issues upfront.
Here’s the uncomfortable truth: that failed migration wasn’t evidence that migration is too risky. It was evidence that the planning was insufficient.
Staying on legacy doesn’t fix that, it defers the problem while making it worse.
Reframing the Risk
When organizations tell us migration is “too risky,” we ask them to compare the two types of risk side by side.

That’s what happens when you treat migration as a risk reduction strategy instead of a risk to avoid.
Ready to see where you actually stand?
In last week’s newsletter, we put together a 10-question data audit checklist to help you audit your data stack before the year picks up speed. If you score below a 7, shoot us a note at info@southshore.llc and we can send you our extended diagnostic template. Plus, if you include the two questions you answered “no” on, we’ll send back a quick note on where we’d start if we were in your seat.
Thanks for reading! Want more? Check out our blog, YouTube channel, or Linkedin for deeper dives. We’ll be back next week — subscribe to stay in the loop.