When Superstorm Sandy hit the New York space in 2012, elements of New York Metropolis suffered a week-long blackout.
I used to be residing in Brooklyn on the time, and I used to be fortunate sufficient to have energy.
That meant that my residence become a workspace for a half-dozen pals who had misplaced their energy.
Now, having a half-dozen pals crash at your house is enjoyable for a number of days. However in my expertise, the marginal utility begins to say no by round day 4…
Particularly if you notice there’s an opportunity they may by no means depart.
Final week, tens of hundreds of thousands of individuals throughout Spain and Portugal have been confronted with the same drawback when each nations instantly misplaced energy.
It was one of many worst blackouts in European historical past.
And as we mentioned in our final difficulty, one thing related may occur right here within the U.S. as a result of our energy grid is simply as susceptible.
It’s previous and wishes updating. It’s uncovered to excessive climate occasions like hurricanes and wildfires. And the mixing of renewable vitality sources makes it liable to giant energy fluctuations just like the one Spain simply skilled.
In the meantime, our grid is being strained by an growing demand for energy.
Sadly, that’s not the one large infrastructure drawback the U.S. is going through right now.
You see, the legacy software program nonetheless powering America’s air visitors management, delivery logistics, protection programs and even our hospitals is hanging on by a thread.
This drawback might sound far much less apparent, nevertheless it’s equally as harmful. And except we deal with it quickly, it’s solely a matter of time earlier than there are severe penalties.
A Downside That’s More durable to See
The largest threat to our crucial infrastructure is buried deep in strains of code, written many years in the past and patched collectively ever since.
In accordance with Synopsis/Black Duck’s 2025 Open Supply Safety and Threat Evaluation Report, the overwhelming majority of those fragile legacy programs comprise no less than some open supply software program (OSS).
Supply: www.resilientcyber.io
However whereas the usage of OSS will be more cost effective and clear, the research discovered that 91% of the codebases reviewed had outdated OSS elements.
And 90% of them comprise elements which can be greater than 10 variations behind probably the most present model.
Meaning they weren’t designed for the threats we face right now.
And that’s comprehensible when you think about the size of time it typically takes for presidency initiatives to get off the bottom.
By the point software program is carried out, it’s common for it to already be outdated.
And lots of of those legacy programs not obtain updates or safety patches in any respect.
That’s why hospitals, air visitors networks, protection contractors and different areas of crucial infrastructure are such ripe targets for hackers.
For instance…
The Wolf Creek nuclear energy plant in Kansas was the goal of Russian hackers again in 2017.
The Colonial Pipeline hack in 2021 was the largest cyberattack on an oil infrastructure goal in U.S. historical past.
And simply final yr, a China-linked state-sponsored group infiltrated main U.S. telecoms as a part of a cyberespionage marketing campaign.
But regardless of these main safety breaches, we nonetheless depend on software program written when Invoice Clinton was president.
In accordance with a latest RSAC panel, some visitors programs run on firmware from a number of many years in the past, with little standardization and no centralized oversight.
Our water infrastructure is fractured into greater than 55,000 impartial districts, every with its personal ageing software program stack.
And the well being care sector isn’t faring a lot better.
A 2023 research confirmed that roughly 40% of open-source code utilized in medical software program comprises identified vulnerabilities…
Regardless that a single ransomware assault may completely shut down a hospital.
In any case, that’s what occurred to St. Margaret’s Well being in Spring Valley, IL.

Supply: wqad.com
It was hit with a ransomware assault in 2021 that disrupted the hospital’s skill to submit claims to insurers, Medicare or Medicaid for months.
These billing delays despatched St. Margaret’s right into a monetary spiral, and the 120-year-old hospital was pressured to close its doorways in 2023.
It was the primary time a hospital was shut down within the U.S. as a consequence of a cyberattack. But it surely possible received’t be the final…
If we fail to behave on our legacy software program points.
The Value of Doing Nothing
The issue with sustaining previous code is that it’s costly and inefficient.
Legacy programs typically depend on outdated programming languages, customized {hardware} and a lack of know-how.
As the unique engineers retire, there’s nobody left who actually understands how all the pieces matches collectively.
It’s like attempting to repair a crumbling bridge with out the unique blueprints… and whereas visitors remains to be working throughout it.
However right here’s the factor…
The longer we delay modernization, the extra we threat falling behind.
We’re already seeing it occur within the airline business, the place legacy flight ops programs are actually a significant cause for delays.
In accordance with the Division of Transportation, final yr over 22% of U.S. business flights arrived late.
And tarmac delays of over three hours have been up greater than 51% from the yr earlier than.
The airline business loses an estimated $60 billion a yr from these disruptions. But, many carriers proceed counting on decades-old scheduling platforms as a result of changing them is seen as too dangerous or costly.
I imagine there’s a far higher threat in doing nothing.
The excellent news is that momentum appears to be constructing to do one thing about our legacy software program drawback.
In January 2025, the Cybersecurity and Infrastructure Safety Company (CISA), in partnership with the Protection Superior Analysis Initiatives Company (DARPA) and different authorities companies, revealed a report titled Closing the Software program Understanding Hole.
It acknowledges that almost all legacy programs are so advanced, we not absolutely grasp how they work.
The report highlights the dangers of this software program understanding hole to each nationwide safety and significant infrastructure, and it recommends a broad, government-coordinated method to assist repair the issue.
One answer is to put money into rigorous software program evaluation strategies generally known as formal strategies that enable deep auditing throughout large codebases.
Formally verified software program used to look unattainable to do at scale, however advances over the previous decade have made it a lot simpler to make use of in on a regular basis improvement.
Naturally, AI is taking part in an element. It’s already serving to builders untangle and refactor legacy code.
Actually, in response to GitLab analysis, 34% of builders are actually utilizing AI to modernize legacy code.
That share will solely go up as AI continues to enhance.
By analyzing, testing and rewriting outdated software program, AI instruments ought to minimize the time and price of modernization considerably.
Right here’s My Take
The blackout in Spain and Portugal final week ought to be a wake-up name for all of us.
Not simply in regards to the vulnerabilities of our vitality grid however in regards to the software program that powers our crucial infrastructure.
As a result of the longer we rely on outdated code, the higher the prospect that one thing will break.
That’s why sensible cash is backing the businesses powering America’s digital rebuild.
As federal companies and Fortune 500s start to improve their software program, firms engaged on secure-by-design software program, AI-powered improvement instruments and formal verification ought to profit from America’s digital rebuild.
Members of my Strategic Fortunes service know this already.
In the beginning of final yr, I recognized an organization that’s serving to giant establishments map and modernize advanced legacy programs, together with authorities infrastructure.
As of this morning, its inventory value is up over 640% since my suggestion.
And as concern round this difficulty retains rising, we’ll possible see extra possibilities for related positive aspects.
Regards,
Ian KingChief Strategist, Banyan Hill Publishing
Editor’s Word: We’d love to listen to from you!
If you wish to share your ideas or recommendations in regards to the Day by day Disruptor, or if there are any particular matters you’d like us to cowl, simply ship an e-mail to dailydisruptor@banyanhill.com.
Don’t fear, we received’t reveal your full identify within the occasion we publish a response. So be at liberty to remark away!