Yeah, and that’s generally fine if it isn’t critical infra that could be targeted by bad actors, and they don’t have wifi or uncontrolled interfaces. The risk and damage of someone pulling apart an ATM to get at a USB port is negligible.
The main problem with it is the longer things don’t get upgraded the less people know how to fix or service them, which adds extra friction and cost to change anything with each passing year. After 10-20 years of zero updates, major projects are required because the OS and software stack need a complete overhaul to make even the smallest software change, and the software becomes a major bottleneck to organizational change or operations.
I work manufacturing, any computer that isn’t connected to the internet doesn’t get upgraded. Windows XP on PLC touchscreens.
Yeah, and that’s generally fine if it isn’t critical infra that could be targeted by bad actors, and they don’t have wifi or uncontrolled interfaces. The risk and damage of someone pulling apart an ATM to get at a USB port is negligible.
The main problem with it is the longer things don’t get upgraded the less people know how to fix or service them, which adds extra friction and cost to change anything with each passing year. After 10-20 years of zero updates, major projects are required because the OS and software stack need a complete overhaul to make even the smallest software change, and the software becomes a major bottleneck to organizational change or operations.
Yeah, maybe your CISO should read a book about Stuxnet lol
I’m not sure he can read :( Or fix a landline phone connection, apparently.