The Persistent Challenge of Legacy IT: A Roadblock to Modernizing UK Government
The UK government’s ambition to embrace cloud technologies adn artificial intelligence (AI) is being significantly hampered by a pervasive and poorly understood problem: legacy IT systems. Recent parliamentary scrutiny, spearheaded by the Public Accounts Committee (PAC) and detailed in reports from october 2025 and ongoing questioning of officials like DWP‘s (Department for Work and Pensions) representative, reveals a complex landscape where defining, measuring, and ultimately addressing legacy IT remains a critical – and concerning – challenge.
A Cloud Transformation with Lingering Shadows
The drive to modernize government IT is underway.The Department for Work and Pensions (DWP) provides a compelling case study. Their transition to Crown hosting, a public cloud solution, took seven years but yielded considerable benefits, including annual savings of £150 million on legacy IT costs and a return on investment achieved within just nine months. This success demonstrates the potential of cloud adoption, with 70% of DWP’s services now hosted publicly.
though, the DWP’s positive experience highlights a broader issue: the sheer volume of outdated systems still operating across government. This isn’t simply a matter of aging hardware; it’s a systemic problem impacting efficiency, security, and the ability to leverage cutting-edge technologies like AI.
Defining “legacy”: A Surprisingly Broad Brush
The core of the problem lies,surprisingly,in how the government defines “legacy IT.” During questioning by Labor MP Chi Onwurah, it emerged that the government currently considers any IT asset not hosted in the public cloud to be “legacy,” nonetheless of its age or functionality. This definition, as acknowledged by officials, is “engaging” and raises questions about the accuracy of current assessments.
While seemingly counterintuitive, this approach provides a method – albeit a perhaps flawed one - for tracking the extent of legacy systems. Currently, the government relies on HM Treasury’s annual electricity consumption reporting for IT systems, analyzed by Defra (Department for environment, Food and Rural Affairs) to calculate carbon savings. Because cloud providers don’t report their energy usage likewise, all non-cloud IT infrastructure is automatically categorized as legacy for carbon impact calculations.
This reliance on power consumption as a proxy for legacy status is a workaround, not a solution. It doesn’t account for the nuances of system age, security vulnerabilities, or cost-effectiveness.
The Scale of the Problem: 28% and Counting
Despite the unconventional definition, the numbers are stark. According to DSIT (Department for Science, Innovation & Technology), an estimated 28% of central government systems met a more conventional definition of legacy IT in 2024 – systems that are end-of-life, unsupported by vendors, impossible to update, no longer cost-effective, or pose an unacceptable security risk. The PAC report rightly describes this as “extremely problematic,” notably in the context of the government’s AI ambitions.
The PAC report emphasizes a critical gap in knowledge: DSIT dose not know the total number of legacy assets across government. this lack of visibility is “wholly unacceptable,” especially given the escalating threat landscape and the increasing sophistication of cyberattacks. Outdated systems are inherently more vulnerable, creating significant risks to sensitive data and critical infrastructure.
A Blueprint for change, But Urgent Action Needed
DSIT has unveiled a “blueprint for a modern digital government” (January 2025), outlining plans to address the legacy IT challenge. However, the PAC remains “extremely concerned” about the scale of the problem and stresses the urgent need to prioritize funding for remediating the highest-risk technologies.
The PAC’s recommendations are clear: the government must establish a robust approach for measuring both the costs of addressing legacy IT and the costs of inaction. Increased transparency and improved decision-making are essential to effectively tackle this complex issue.
Looking Ahead: A Call for Strategic Investment and Clear Metrics
The situation demands a strategic, multi-faceted approach.Simply migrating to the cloud isn’t enough. A complete assessment of all IT assets is crucial, moving beyond the current reliance on power consumption data. This assessment should consider:
* Security vulnerabilities: Identifying and prioritizing systems with known weaknesses.
* Cost of maintenance: Evaluating the ongoing expenses associated with supporting outdated systems.
* Interoperability: Assessing the ability of legacy systems to integrate with modern technologies.
* Business criticality: Determining the impact of system failures on essential government services.
Moreover, the government
Related reading