AI Is Finding More Software Flaws Than Ever, But What About Systems You Can't Patch?
AI-assisted code analysis is uncovering long-standing coding mistakes at a pace many organisations struggle to keep up with. While this is gradually improving software quality overall, it also means a growing backlog of vulnerabilities in systems that simply cannot be patched, either because they are certified to run only specific software versions or because they rely on unsupported, end-of-life platforms.
This is a particular concern for operational technology (OT), the systems behind medical equipment, building management, and industrial infrastructure such as chemical plants. History shows the risks of ignoring this problem: the 2017 WannaCry worm severely disrupted the UK's NHS, partly due to reliance on the outdated Windows XP operating system. More recently, attackers exploited end-of-life software to breach government systems in 2023. Even custom-built systems often rely on common libraries and protocols that can harbour vulnerabilities, and systems hidden from the public internet can still be reached by attackers who have already gained a foothold inside a network.
Applying official patches remains the strongest defence when possible. Where that is not an option, organisations can lean on the predictable, stable nature of OT systems to build protective measures instead. The first step is visibility: legacy systems often have recognisable network fingerprints that make them easier to identify, allowing businesses to build an accurate inventory of systems that need extra attention and monitoring.