What the UK Cyber Security & Resilience Bill and Software Security Code of Practice Mean for Organisations Operating Critical SystemsFor many years, cyber resilience has largely been viewed through the lens of security controls, monitoring, governance and...
Cyber Resilience Starts With Software Engineering
Cyber Resilience Starts With Software Engineering
What the UK Cyber Security & Resilience Bill and Software Security Code of Practice Mean for Organisations Operating Critical Systems
Introduction
For many years, cyber resilience has largely been viewed through the lens of security controls, monitoring, governance and compliance. While these remain important, they represent only part of the picture.
Increasingly, the resilience of critical systems is being determined much earlier in the lifecycle by software architecture, technology choices, systems integration decisions and the ability to maintain software over decades of operation.
The proposed UK Cyber Security & Resilience Bill and the UK Software Security Code of Practice both point in the same direction: cyber resilience must be engineered into systems from the outset rather than added later.
For organisations operating critical infrastructure, that shift has significant implications.
The Growing Gap Between Infrastructure and Technology
Rail signalling systems, industrial control systems, defence platforms, transport systems and utilities infrastructure are often expected to remain operational for decades. Yet the software, hardware and development environments on which they depend evolve at a dramatically faster rate.
This creates a growing disconnect between the operational life of infrastructure and the lifecycle of the technologies embedded within it.
Historically, this was viewed primarily as an obsolescence issue. Today it is increasingly becoming a cyber resilience issue.
Many organisations are discovering that software and hardware require replacement not because they have failed, but because they can no longer be adequately secured, supported or maintained.
The UK Government’s response to the Software Security Code of Practice consultation highlighted that 59% of organisations globally are believed to have been impacted by a software supply-chain attack or exploit, yet only 11% of businesses assess risks posed by immediate suppliers.
The implication is clear: software lifecycle management and supply-chain understanding are becoming fundamental components of cyber resilience.
Why Cyber Resilience Starts Long Before Deployment
The Software Security Code of Practice places significant emphasis on secure-by-design principles.
At first glance this may appear to be a software development concern. In reality, it is a systems engineering challenge.
Cyber resilience is influenced by decisions made long before a system enters service, including:
- Software architecture
- Interface design
- Technology selection
- Third-party dependencies
- Verification strategies
- Update mechanisms
- Systems integration approaches
Many organisations understand these principles. The challenge is applying them within complex operational environments where legacy systems, operational constraints and long asset lifecycles must also be considered.
This is particularly true within critical infrastructure, where replacing a system is rarely straightforward and where changes often carry operational, safety and regulatory implications.
Beyond Cyber Security: Engineering Resilience
A resilient system is not simply a system that is secure today.
It is a system that can still be understood, maintained, tested, modified and supported years into the future.
Many organisations possess source code but no longer possess the build environments, test frameworks, engineering knowledge, configuration baselines or specialist tooling required to safely evolve their systems.
Over time:
- Original engineering teams retire
- Suppliers cease trading
- Development tools become obsolete
- Documentation becomes incomplete
- Knowledge gradually disappears
As software lifecycles continue to shorten while infrastructure lifetimes continue to extend, engineering resilience is becoming an increasingly important part of cyber resilience.
This is an area that receives far less attention than vulnerabilities and threat detection, but it often determines whether organisations can respond effectively when change becomes necessary.
The Hidden Cyber Risk: Software Lifecycle Management
Cyber security discussions often focus on vulnerabilities, threats and incidents.
Less attention is paid to the engineering capability required to support software over time.
Questions organisations should be asking include:
- Can we still build the software?
- Can we still test it?
- Do we understand how it behaves?
- Are the original development tools still available?
- Can security updates be implemented safely?
- Do we understand all external dependencies?
In many cases, source code still exists, but the surrounding engineering ecosystem has disappeared.
Compilers, build environments, test harnesses, simulators and specialist diagnostic tools may no longer be available.
The result is that seemingly small software changes become increasingly difficult, expensive and risky.
Where Cyber Resilience and Obsolescence Converge
For many organisations, cyber resilience and obsolescence are still managed as separate challenges.
In practice, they are becoming increasingly interconnected.
The same factors that create software obsolescence often create cyber resilience risks:
- Unsupported operating systems
- Unsupported software libraries
- Obsolete development tools
- Disappearing technical knowledge
- Inability to test or modify software safely
- Loss of supplier support
A system does not need to fail in order to become a risk.
It may continue to operate exactly as intended while becoming progressively more difficult to maintain, secure and evolve.
As a result, organisations are increasingly discovering that software lifecycle management, obsolescence management and cyber resilience are no longer separate disciplines. They are different perspectives on the same underlying challenge: how to maintain confidence in software-intensive systems over long operational lifecycles.
This is particularly relevant for organisations operating long-life infrastructure, where software may remain operational for decades while the technologies, tools, suppliers and security expectations around it continue to evolve.
When Operational Systems Can No Longer Be Maintained Securely
One of the most significant trends emerging across critical infrastructure is that cyber security is becoming a direct driver of obsolescence.
Historically, systems were replaced because they failed functionally or became unreliable.
Increasingly, systems are being replaced because they can no longer meet modern security expectations.
Examples include:
- Unsupported operating systems
- Unsupported software libraries
- Insecure communication protocols
- Inability to implement security patches
- Lack of secure update mechanisms
- Regulatory and compliance requirements
This creates a new category of obsolescence where systems remain operationally functional but become increasingly difficult to justify from a cyber resilience perspective.
As explored in Zircon’s previous articles on Artificial Intelligence Obsolescence, Cybersecurity and Obsolescence, and The Challenge of Obsolescence in UK Infrastructure, software obsolescence and cyber resilience can no longer be treated as separate disciplines.
What Organisations Should Be Doing Now
1. Assess Software Lifecycle Risks
2. Review Obsolescence Exposure
3. Preserve Critical Engineering Knowledge
4. Apply Secure-by-Design Principles
5. Plan for Continuous Evolution
How Zircon Helps
Our expertise spans software engineering, systems engineering, assurance, software obsolescence management, systems integration, lifecycle management and technology modernisation.
Whether the challenge is modernising a legacy system, understanding software lifecycle risk, addressing technology obsolescence or applying secure-by-design engineering principles, our focus remains the same: helping organisations build and maintain resilient operational systems.
Further Reading
To explore these topics in more detail, we recommend:
- Artificial Intelligence Obsolescence
- Cybersecurity and Obsolescence
- The Challenge of Obsolescence in UK Infrastructure
Together, these papers explore how ageing software, technology evolution, cyber security requirements and operational resilience are becoming increasingly interconnected challenges for organisations operating critical systems.
Looking Ahead
Organisations that understand the relationship between software engineering, lifecycle management, obsolescence and cyber resilience will be better positioned to manage risk, maintain operational capability and adapt to evolving regulatory expectations.
For critical infrastructure operators and suppliers, cyber resilience no longer starts with security controls.
It starts with software engineering.
More From The Blog
Cyber Resilience Starts With Software Engineering
Zircon Software Grows Senior Leadership Team with Technology Director Appointment
Zircon Software Grows Senior Leadership Team with Technology Director AppointmentZircon Software Limited is pleased to announce the appointment of David R Owen as Technology Director, further strengthening the company’s leadership team as it continues to invest in...
Zircon Software Accepted onto Aurora Engineering Partnership
Zircon Software Accepted onto Aurora Engineering PartnershipZircon Software is excited to announce our selection as a specialist supplier on the Aurora Engineering Partnership, marking a significant milestone in our continued growth and commitment to growing our...
AI Obsolescence: Is your Algorithm as accurate today as it was yesterday?
So far in our series on software obsolescence, we’ve covered the lifespan disparity between digital and physical systems in critical infrastructure, and the inescapable link between cybersecurity and obsolescence. But there’s another area that we specialise in, with...





