Think Log / 3 September 2026
2026-09-03
Security questionnaires can’t patch obsolete software.
A customer using a very old version of one of our products recently sent us a detailed security assessment.
Lots of good questions.
Development practices.
Vulnerabilities.
Security controls.
Processes.
All perfectly reasonable.
Except they’re still running software that reached end of life years ago.
There’s something slightly backwards about applying increasingly sophisticated governance around software you’ve chosen not to modernise.
Security isn’t just the process surrounding the software.
The lifecycle of the software itself is part of your security posture.