Skip to main content
Guidance

Device security guidance

Guidance for organisations on how to choose, configure and use devices securely.

Page 28 of 37

Obsolete products

Reducing the risks from using out of date smartphones, tablets, laptops, desktop PCs, appliances or software applications

All software, including device operating systems, will eventually become out of date. Ideally, once out of date, technology should not be used.

This guidance provides advice to organisations who are unable to fully migrate away from obsolete products, before the end of their support dates.

Note

This guidance does not provide a risk-free way of continuing to use obsolete products, but will help to reduce the risks of doing so.

The only fully effective way to mitigate this risk is to stop using the obsolete product.


In combination, these issues make high-impact security incidents more likely. This will include malware exploiting remotely-accessible vulnerabilities, which can have a catastrophic impact, across an entire organisation.

When a product is no longer supported by its developer, there are limits on the measures that will be effective in protecting against new threats. Over time, new vulnerabilities will be discovered that can be exploited by relatively low-skilled attackers.


Product support

When choosing new hardware or licensing new software, always consider the support lifetime of the product. This will help you ensure that your systems remain supported for as long as possible.





Published

Reviewed

Version

2.1