2. The compounding cost of delay
The case for delay always sounds reasonable at budget time. Legacy systems are still working. Teams are busy. The investment required looks large relative to the uncertain benefit. So another cycle passes, technical debt quietly compounds, and the eventual migration becomes both more expensive and more complex than it would have been.
The parliamentary committee was direct about why this logic fails over time. It identified three mechanisms by which delay makes things progressively worse - all of which are compounding, not linear.
2.1 The cost spiral
McKinsey's research on technical debt estimates that CIOs put technical debt at 20–40% of the total value of their entire technology estate. More immediately, 10–20% of the technology budget nominally allocated to new products is diverted to servicing existing debt. High-debt organisations are 40% more likely to have incomplete or cancelled modernisation projects.
The parliamentary committee's evidence base reinforced this at a public sector scale: legacy maintenance costs three to four times more than maintaining modern equivalents, and there is a structural bias towards capital spend on new projects at the expense of maintaining existing systems. The result is that underfunding of legacy maintenance drives faster accumulation of legacy risk - a compounding dynamic rather than a stable steady state.
The numbers at stake
The government has committed £20 billion over the current Spending Review period to digital, data and technology modernisation. The DSIT State of Digital Government Review estimates that full digitisation of public sector services could unlock £45 billion in annual productivity savings. Both figures are contingent on successfully remediating the legacy estate that currently prevents them from being realised.
2.2 The security risk
The National Cyber Security Centre has stated that having a strategy to address technical legacy is 'a foundational precursor to engineering resilience'. That assessment has been tested repeatedly in recent years.
The NCSC managed 430 cyber incidents between September 2023 and August 2024, with 89 classified as nationally significant. The Government Cyber Resilience Report identified legacy systems as a prominent feature of security vulnerability. Of the 228 identified legacy systems across departments, many carry known vulnerabilities that cannot be patched because the vendor no longer supports the platform.
The data breach risk is not hypothetical. A 2023 Information Security Review - whose existence was kept secret until the SIT Committee's intervention - examined ten public sector data breaches and found common themes: insufficient controls over data exports, wrong-recipient email releases, and hidden personal data in published spreadsheets. The Rewiring the State report concluded that 'major cultural transformation is required to prevent mass data breaches from happening in the future' - and that modernised infrastructure is a prerequisite.
2.3 The knowledge concentration risk
This risk does not appear in most migration business cases. It should be the first item on the register.
Anyone who has read The Phoenix Project, the IT operations novel by Gene Kim, Kevin Behr and George Spafford, will remember Brent Geller, the lead engineer through whom almost every fix, change and outage has to pass, because so much of how the systems really work exists only in his head. Most legacy environments have a Brent, and often more than one. In public sector organisations it is common to find that the operational knowledge of a critical platform, such as its undocumented logic, its workarounds and its integration quirks, resides with two or three individuals who have worked with it for a decade or more. When those individuals retire or move on, organisations frequently discover that the documentation does not describe how the system actually works in practice.
The window in which experienced staff can support a structured migration and knowledge transfer is finite. Every year of delay narrows it. This is particularly acute in the public sector, where salary constraints mean that specialist technical staff are disproportionately likely to leave for better-paid private sector roles.
2.4 The blocked opportunity cost
Perhaps the least visible cost of legacy is what it prevents. The UK Government's ambition to deploy AI across public services, improve data sharing, and deliver joined-up digital services all assume data that is accessible, well-governed, and in modern formats. None of that is compatible with data trapped in legacy proprietary formats, undocumented schemas, and siloed systems that were never designed for integration.
The SIT Committee was explicit: "Failure to address [legacy] siloization will hamper delivery of the government's vision and put citizens' data increasingly at risk." The consequence in practice is that AI and analytics projects built on legacy foundations are almost always more expensive, slower, and ultimately deliver less than they should.