I’ve seen organizations reach a point in a modernization program where the technology itself is no longer the biggest risk. A decision was made for a full rip-and-replace. The new environment is ready. The migration plan has been tested. The business case has been approved. But the team responsible for delivering it is also responsible for keeping the existing estate running. A change freeze is approaching; business units are nervous about the cutover and what started as a technology upgrade has become an exercise in managing operational risk.
That is the uncomfortable reality behind many large-scale modernization programs.
We often make assumptions that legacy infrastructure is the problem and replacement is the solution, but in practice, rip-and-replace can create as much disruption as it removes.
So rather than asking — what do we need to modernize, CIOs should be asking a more practical question — what needs to change right now? Do we really need to change everything?
The reality is, there is only so much an organization can take on at once. AI is demanding investment and attention, workplace technology is changing, security expectations continue to rise and the existing estate still must keep running reliably in the background. All those priorities are competing for the same budgets, infrastructure and crucially, the same people.
Modernization shouldn’t mean replacing technology simply because it is getting older. It should mean focusing time and investment where change will make the biggest difference.
Modernization needs triage, not a starting gun
With legacy technology, age is usually the trigger for change. A platform reaches a certain point in its lifecycle, an OEM support deadline approaches or a newer alternative becomes available, and replacement can start to feel like the obvious next step. But the age of an asset doesn’t necessarily tell us whether it is still doing its job, or whether replacing it is the right decision.
A better approach is to assess infrastructure against four things: performance, risk, business value and future requirements.
Is it still delivering the performance the business needs? Can it be operated securely and reliably? Does it support a business-critical workload? And will it be capable of supporting what the organization expects to do next?
A piece of older infrastructure might be stable, well understood and supporting a workload whose requirements have barely changed. If it can continue to be monitored, maintained and supported effectively, replacing it may deliver little additional business value.
But another system of the same age might be approaching capacity, difficult to secure or be preventing the business from adopting a new application or operating model. That is a very different modernization case.
This is why CIOs should start to move away from thinking about estates in terms of “legacy” and “modern”. The more useful distinction is between infrastructure that is still fit for purpose and infrastructure that is becoming a constraint.
The real constraint may be your people
Modernization is often discussed as a capital allocation problem, but the harder constraint is often technical capacity within the organization. The same infrastructure teams tasked with migrating workloads, introducing new platforms and supporting transformation are usually responsible for the day-to-day estate. They cannot simply stop patching systems, responding to incidents or maintaining availability while a two-year modernization program takes place.
If a team spends six months replacing infrastructure that could safely have remained in service for another two years, what did that team not work on during those six months?
That question is becoming much more important since AI has arrived as another major infrastructure demand. Organizations are trying to understand where AI fits into their technology strategies while dealing with practical questions about compute capacity, GPU-intensive workloads, data availability, networking, power and cooling. The physical demands behind that AI expansion are significant, with the International Energy Agency (IEA) expecting AI to be the biggest driver behind its prediction that global data center electricity consumption will more than double to around 945 TWh by 2030.
And none of this replaces what came before it. AI infrastructure is being added on top of estates that still support ERP platforms, databases, storage, customer applications and everyday business operations. CIOs have to create room for what comes next, without destabilising what the organization already depends upon.
With so many competing demands, replacing infrastructure unnecessarily becomes harder to justify. Extending the lifecycle of infrastructure in one part of the estate can release budget, skills and operational capacity for AI or another strategic priority elsewhere.
But the same principle also works in reverse. CIOs should not preserve technology simply because replacing it is difficult. If an existing environment can’t accommodate the organization’s future requirements, the case for modernization becomes much stronger. The decision is about where change is worth the disruption.
Modernization doesn’t stop at the data center
Modernization also needs to recognize that the way people use technology has changed. Employees are no longer accessing systems from one place, on a device owned and managed by the business. They might be working from home, a customer site, an airport or a shared workspace, using a corporate laptop, a smartphone or even their own device. The infrastructure itself might still be working perfectly well, but the way people are accessing it can introduce new risks that weren’t there when it was first put in place.
BYOD is a good example. Giving employees greater flexibility can make sense from a productivity and user-experience perspective, but it can also leave organizations with less visibility and control over the devices accessing corporate systems. Verizon’s 2025 Data Breach Investigations Report found that, among compromised systems containing corporate logins, 46% were unmanaged devices that also contained both personal and business credentials.
That does not mean BYOD is the wrong decision. It means workplace modernization needs the same kind of triage as infrastructure modernization. What information does the employee need to access? From which device? How much confidence do we have in the identity of that user and device? What happens to corporate data once it reaches an endpoint the organization does not own?
Modernization cannot simply be a hardware refresh program. Sometimes the server doesn’t need replacing, but the access model does. Sometimes the application remains perfectly capable of supporting the business, but the security controls around how people connect to it need to evolve. And sometimes a modernization program should focus on identity, endpoint management, monitoring or access rather than migrating the workload itself.
CIOs can use a relatively simple decision test when thinking about these choices.
First, what problem are we trying to solve? If we can’t articulate that without referring to the age of the technology, the case for replacement probably needs more work.
Second, what happens if we do nothing for another 12, 24 or 36 months? That exposes the difference between genuine risk and an arbitrary lifecycle milestone.
Third, can we reduce the risk without replacing the asset? Better monitoring, maintenance, security controls, capacity upgrades or changes to access may sometimes achieve the desired outcome with far less disruption.
Fourth, does retaining this technology constrain something the business genuinely needs to do next? AI, new digital services, workplace transformation and changing security requirements can all alter the answer.
Finally, where would our people create the most value? Every modernization project consumes engineering time, operational attention and organizational energy. Those resources should be treated just as carefully as the capital budget.
None of this is an argument against modernization. It is an argument for being much more deliberate about it. The CIO’s job is not to build the newest possible estate. It is to create an environment capable of supporting the organization securely, reliably and efficiently while remaining adaptable enough for whatever comes next.
Sometimes that requires replacing technology. Sometimes it means evolving it. And sometimes good modernization starts with having the confidence to leave something alone.