Legacy App: Use Case Scoping and Rebuild
Legacy App: Use Case Scoping and Rebuild
The Challenge: Use Case, Security, and Cost
The client relied on a custom legacy application hosted on an on-premises server, which was scheduled to be decommissioned to reduce operational costs.
However, re-hosting the application using a “lift and shift” cloud migration strategy was unviable due to major security vulnerabilities. Critical exposures in the legacy system included cleartext SQL database connection strings embedded in the configuration files, as well as cleartext user credentials stored in a public facing database.
Aside from the immediate security vulnerabilities within the application, the original vendor had ceased operations and was no longer able to support the system. With the client relying on the application to view historical policy data, the internal team had identified it as a critical risk; in the case of any form of system failure, the business would have no support to recover the application and no option for recovery.
Falx’s Approach: Discovery and Secure First Engineering
Prior to architecting a secure replacement, Falx conducted an initial discovery phase to evaluate core functional requirements and pinpoint existing pain points.
- Discovery: Stakeholder discussions revealed that the legacy system’s feature set was largely obsolete; the company no longer relied on it for new business, reducing its operational purpose to a read-only repository for historical policies and documentation.
- Cloud-native: Engineered to eliminate reliance on local infrastructure, the modernised platform embeds security into its core design while migrating to Cloud-native systems.
- Security-First Architecture: Security was prioritised at every stage of the rebuild to align with Falx engineering standards. Plaintext database credentials were replaced with a secure Entra identity workflow utilising App Registrations and Security Groups for access control. Additionally, Private Endpoints were implemented across the environment to completely remove public IP exposure.
The Results
By combining Falx’s secure development expertise and the outcomes of the discovery phase, the delivered product served the exact purpose required by the client whilst being cost effective.
- Functionality: The delivered solution precisely fulfilled core operational requirements of the client, establishing a streamlined read-only repository for historical policies and documentation while successfully decommissioning legacy components.
- Eliminated Vendor Risk: The transition directly resolved the internal risk team’s concerns, moving critical historical data off an unsupported platform and into the client’s internal environment.
- Cost-Efficiency: With the decommissioning of the legacy environment and moving to the Cloud hosted infrastructure, the client had a significant cost reduction of the app by 85%.
- Platform Management: Leveraging Entra ID for identity access and governance greatly streamlined administrative overhead for the client.
Trapped by unsupported legacy infrastructure?
See how our Technology Transformation and Secure Cloud Environment solutions can safely modernise your critical applications and eliminate vendor risk.
Contact Falx
Discuss Technical Due Diligence and Technology Transformations