
Modernisation is a critical process for overcoming risk in outdated systems. CFOs, more than anyone, know just how expensive a cyberattack or outage from old IT infrastructure can be. But sometimes the modernisation process itself can be equally expensive, especially when companies are forced into change by a system outage or their operating systems (OSs) reaching end-of-life deadlines.
This kind of forced change often leads to rushed modernisation programmes, which can themselves increase the risk of further disruption and outages. Crucially, it is also the most expensive way to modernise. Unplanned downtime, for example, is one of the most costly potential impacts of server and platform changes, with the majority (90%) of mid-size to large enterprises reporting downtime costs exceeding $300,000 per hour. What’s more, organisations and CFOs can end up paying significantly more than necessary for system upgrades when change is driven by urgency rather than strategy.
As a result, CFOs are often forced to choose between the risk of failure that comes with running outdated systems and the risk of failure associated with complex, high-stakes upgrade projects. Rewriting or recoding existing applications is rarely a realistic alternative either, with full application rewrites typically costing anywhere from $200k-$1m. In this context, doing nothing can feel safer than changing. But major incidents eventually force action. Outages, audits, fines and end-of-life deadlines all trigger unplanned spending, and the cycle continues.
Clearly, change is necessary for security, growth and ensuring the good hygiene of IT estates. But how can CFOs modernise cost-effectively without increasing risk? Here are four questions CFOs should ask about a project before it takes place.
1. Is this modernisation a short-term fix until the next OS end-of-life, or can you find a longer-term solution even if it costs slightly more now?
One of the main drivers of an upgrade can be applications and OSs reaching their end-of-life. Last year this was Windows 10, compelling many organisations to carry out major upgrades of their apps and devices so that they were running on Windows 11 and could continue to receive vital security updates and support.
The issue is many industries like healthcare, government and manufacturing depend on business-critical apps that aren’t designed for modern OS environments. They can have hardcoded OS-specific dependencies which make them very complex and expensive to migrate on to newer servers – and having to complete this process every time a new deadline approaches is resource-intensive, disruptive and risky. Moreover, different applications and OSs might be on different timelines, adding to the costs and complexity of modernisation.
So, is there a way of paying for software that enables ongoing modernisation and updates to applications? What’s imperative to understand is that application compatibility – not hardware – is the top blocker for OS upgrades in large enterprises. Therefore, CFOs should look for software that enables them to seamlessly migrate apps onto new OSs without having to change the coding of the apps themselves.
2. What is the revenue and cost impact on any disruption from the modernisation?
When assessing new software or upgrade projects there is, firstly, the cost of packaging and deploying apps to account for. Packaging can take on average 4-8 hours per app, and with large organisations easily running over 500 apps, the labour cost can be eye-watering. Then there are considerations around employee training costs required for new systems and operating models, coupled with any drop in productivity during the transition to new apps and processes.
It’s crucial CFOs ask suppliers how long it will take to restore service and what impact the project could have on business activity. There’s also the potential cost of a ‘failed’ project to work out: most outages are change‑related, and we’ve seen how much unplanned downtime can cost.
What this calls for is gradual, incremental updates on a continuous basis that can provide a more cost-effective and secure way of modernising, instead of paying large sums in one go for a project (which could also fail). This all begs the next question…
3. And is there a tool that could minimise the downside and provide swifter resolution of any downtime?
One of the main drivers of risk is a lack of visibility over the IT estate. CFOs should look for configuration monitoring tools that can establish a live, consolidated view of their entire IT infrastructure, across cloud and hybrid environments. With the software continually monitoring for unauthorised changes and drift, IT teams can detect and rectify configuration issues wherever they happen. If there is downtime, for example, they can quickly spot where this has taken place and how to remediate it efficiently.
4. What cost savings can modernisation unlock across infrastructure, delivery or per‑user costs?
We’ve looked at the costs of upgrading systems, but there are also the costs of maintaining existing, outdated systems – IT, ops and HR teams can spend a decent chunk of their time performing repetitive manual tasks that could be automated. Through modernising, however, automated configuration and drift management can alleviate remediation and deployment effort. Research has proven that the error rate in manual deployments can be reduced by more than 85% with automation.
Central visibility allows change to be easily managed across the organisation, pre-empting unplanned upgrades and forced change leading to downtime, outages and business disruption. It also makes onboarding new users a more efficient process and therefore reduces costs per user. Finally, a modern infrastructure can also be flexible, agile and vendor agnostic, eliminating costly licensing fees and dependency on providers.
Changing systems, managing risk
Modernisation is crucial for stability and growth – but it also brings risk, especially when it’s rushed or forced. This dilemma places CFOs in the unenviable position of deciding how best to modernise systems while also reducing the chance of costly threats like outages, downtime and security breaches.
What emerges is the need to implement systems that enable continuous monitoring and modernisation capabilities, allowing organisations to maintain control without suffering from major disruption or failures. Expensive, short-term fixes will only cost more in the long run.

