All resources Resources

The "don't touch that" audit: finding the oldest risks in your tech

The most dangerous thing in many businesses isn't a new threat. It's an old box in the corner and three words: "don't touch that."

It's usually said with a nervous half-laugh. It means the aging server or device that still works, still runs something important, and has survived so many fixes and workarounds that nobody feels confident changing it anymore. That's not just old tech. It's old tech that everything else now depends on. And that kind of thing quietly piles up risk until it becomes downtime, a security incident, or an emergency upgrade at the worst possible moment.

The good news is that bringing this risk back into the light is straightforward. We call it a quick audit of your oldest, riskiest tech, and you can start it this week.

What "old" risk really looks like

The problem isn't age on its own. It's age plus dependence: old gear that's become so normal nobody questions it. It's the server running a critical app, the network device no one remembers buying, the temporary fix that quietly turned permanent. Industry experts describe this kind of buildup as something that happens even to well-run businesses: it accrues silently, basically unnoticed, until it's too costly to ignore.

The clearest danger sign is when "old" becomes "can't be fixed." The UK's national cyber-security authority is blunt about it: ideally, once technology is out of date it shouldn't be used at all, and the only fully effective fix is to stop using the unsupported product. If something can no longer receive updates, its weaknesses don't age out. They just sit there waiting for the wrong day.

It also shows up as the basics quietly slipping: updates that fall behind, extra services left running that nobody needs, and backups nobody has actually tested. When those fundamentals drift, old tech turns into a reliability problem, not just a security one.

The three oldest risks to find first

These three categories are where age most often turns into outsized risk, because they combine being old with being important. They either sit at your front door, can't be fixed anymore, or have quietly drifted out of a safe setup.

Risk 1: Internet-facing gear that's past support

Start at the edge: the devices that sit between your business and the wider internet: firewalls, remote-access gateways, routers. They're your front door. When they reach the point where the maker stops releasing security fixes, they don't just become outdated; they become genuinely harder to defend. In your audit:

  • List every internet-facing device and check whether each one is still supported.
  • Confirm which ones are actually reachable from the internet, and what's exposed.
  • Flag any that can't run current updates or no longer receive them at all.

Risk 2: Products that can't be fixed anymore

This is the purest form of the problem: systems still running but no longer receiving security updates, which means every new weakness discovered becomes permanent. There's no clever workaround that makes an unsupported system safe, only ways to reduce the risk until you can replace it. In your audit:

  • Identify anything past its support date: server operating systems, appliances, older business apps.
  • Flag systems that only keep working thanks to special exceptions, like old protocols or custom firewall rules.
  • Single out the "business-critical but unsupported" systems for a real plan.

Risk 3: "It still works" servers with neglected basics

This is the sneakiest one, because it looks fine. The server is supported, the hardware runs, nobody's complaining, but the fundamentals have drifted. Patching is inconsistent, unnecessary services are still running, and the backups haven't been proven when it counts. National security guidance treats good server care as an ongoing discipline: keeping up with updates, watching the logs, removing services you don't need, and taking backups you can actually restore from. Those unglamorous basics are what stop a small problem from becoming a long outage. In your audit:

  • How current is patching, and how often does it slip?
  • What's running that doesn't need to be?
  • Where are the broad permissions and shared logins?
  • When was the last time a backup restore was actually tested, and did it work?
  • Who can make changes, and how are those changes tracked?

Stop carrying silent risk

This kind of debt never announces itself. It sits quietly in the background until the day it becomes downtime, a breach, or an upgrade you didn't plan or budget for. An audit gives you control back by turning "we should deal with that someday" into a short, specific list you can act on.

Start with the highest-leverage items: internet-facing gear that's past support, products that can't be patched, and servers where the basics have slipped. Then assign an owner, set a date, and move one item at a time from "too scary to touch" to "handled." If some of these warning signs sound familiar, our guide to spotting tech that's past its prime is a good companion read.

If you'd like a hand running that audit, and a plain-English plan for what to fix first, that's exactly the kind of work we do for businesses across the Denver area.

Got a "don't touch that" box of your own?

Book a free IT check-up and we'll find the oldest risks in your setup and give you a clear plan for what to handle first.

Get started