Source · Select Committees · Public Accounts Committee

Recommendation 25

25

Government lacks comprehensive understanding of its total legacy IT estate and associated risks.

Recommendation
We challenged DSIT and the Cabinet Office on why they were not identifying and fixing legacy IT systems, where the risk is greatest and security lowest. DSIT told us that before 2023 the centre of government did not have much information about legacy IT but this was improving. DSIT data showed that around 28% of the public sector’s IT estate was legacy. Twenty–eight public sector organisations had identified 319 legacy systems and self–assessed almost 25% of these as ‘red’ for risk.53 DSIT said it wanted to expand this work and better align it with GovAssure.54 We asked how many legacy assets there were in total across government. DSIT told us it did not know, and that 15% of organisations it had spoken to, as part of the State of digital government review, also did not know the what the situation was for their own legacy IT.55
Government Response

A response document is linked to this report, dated 18 September 2025. Response attribution to this conclusion has not been verified. Read the response document ↗