Home / News & Updates / Managing OT Obsolescence: Strategic Approach to Industrial Cyber Resilience

A PLC that’s been running for fifteen years without incident feels like a success. However, it may be the biggest unmanaged risk on the plant floor yet to surface. OT obsolescence sits quietly inside aging PLCs, HMIs, and servers until a failure, an unpatched vulnerability, or a vendor’s discontinued support turns it into an emergency that is exploited by adversaries. 

Managing that risk isn’t about replacing hardware the moment it ages. Rather, it’s about knowing in-depth about your asset inventory, including which assets matter, why, when to act, where they are located, and what their status is. This is the strategic approach behind industrial cyber resilience, and it starts with a discipline that most OT programs still get wrong: Product Life Cycle Management.

To learn how structured product life cycle management transforms hidden aging asset risks into measurable industrial cyber resilience, you can watch our full webinar: Managing OT Obsolescence: Strategic Approach to Industrial Cyber Resilience – Ep 4- Webinar Series 2.

What Is OT Obsolescence, and Why It’s a Hidden Risk

Obsolescence risk isn’t visible from an asset name or an IP address. Aging OT assets can keep running for years while their portability and security posture quietly degrade. Unsupported technology means no vendor patches, no firmware updates, and a shrinking escalation path if something breaks.

The consequences compound. Operational fragility raises the odds of failure and slows recovery. Cyber exposure grows because legacy systems often can’t support modern authentication, encryption, or hardening. The risk stays hidden until failure happens, or until the asset becomes the entry point for an incident.

What Is Product Life Cycle Management (PLCM)?

PLCM is the structured process of evaluating and managing control system assets, PLCs, DCS systems, HMIs, and related infrastructure, based on visibility into their real condition and risk, not just their age. A twelve-year-old asset with strong spare parts availability and low criticality may still be perfectly acceptable. A five-year-old asset with no vendor support and a role in a safety system may already be high risk.

The goal isn’t blanket replacement. It’s the right decision for each asset: spares management, life cycle extension, a targeted upgrade, or full replacement, chosen deliberately rather than by default.

The Four Phases of the OT Asset Lifecycle

Every OT asset moves through the same four life cycle stages.

Introduction. The product is new to the market, vendor-supported, but still building adoption.

Growth. The product is actively promoted and enhanced, vendor support is strong, and replacement or expansion is straightforward.

Maturity. The product is stable and widely used. It’s still supported, but the vendor has largely stopped adding enhancements. Many OT assets sit in this phase for years, since industrial environments run legacy technology far longer than IT ever does.

Decline. Sales slow, production may stop, spares become scarce, and vendor support restricts. This is where obsolescence risk climbs sharply. Waiting until critical assets reach this phase before acting often means expensive emergency replacements, long lead times, and unmanaged cyber exposure.

Proactive vs. Reactive Obsolescence Management

Proactive management applies during the introduction, growth, and maturity phases, aiming to prevent obsolescence from becoming a crisis. It means continuously monitoring vendor life cycle status, tracking end-of-sale and end-of-support announcements, maintaining spare parts, ideally around 20% availability for shared components, and planning firmware, hardware, or virtualization upgrades before an asset becomes critical.

Three questions anchor this approach: Why do we have this asset? How long will it remain supported? What should we do before support becomes a problem? Answered early, these questions prevent most emergency decisions later. Proactive PLCM belongs in governance, with quarterly or semiannual reviews of critical assets, not a conversation that only happens after an incident.

Reactive management applies once an asset is already approaching or past end of life. It doesn’t mean the organization has failed. Plenty of OT assets run for years without vendor support while remaining stable and connected to critical processes. The response here starts with identifying mitigation options.

Hardware Obsolescence Strategies

For assets already in decline, four strategies typically apply:

Same-item replacement. Using existing stock or reclaimed spares. Useful short-term, rarely a long-term fix.

Life-of-need buys. Purchasing the estimated total quantity required for a defined future period, practical when immediate upgrades aren’t feasible but demanding accurate forecasting.

Functional substitution. Swapping in a technically interchangeable item, like replacing one firewall vendor’s model with another’s using the same configuration. This must be validated carefully in OT, since compatibility issues can directly affect process availability.

Design change or upgrade. The strongest long-term approach, requiring proper planning, testing, budgeting, and governance, is usually scheduled around existing turnaround or maintenance windows.

Why Basic Asset Inventories Fall Short

Asset management is the backbone of OT cybersecurity, and PLCM is really an application of it. But a static inventory, IP addresses, vendor names, firmware versions, doesn’t expose obsolescence risk. It shows what exists, not what’s about to fail or what happens if it does.

That gap is exactly what our earlier piece on why asset management is the foundation of OT cybersecurity explores in depth: a basic inventory is not the same as asset intelligence, and every meaningful security control depends on the difference.

Building Life Cycle Intelligence Through Deep Asset Inventory

Turning a basic inventory into obsolescence intelligence takes four steps.

1. Build a deep asset inventory.

Capture life cycle status, vendor support dates for both hardware and software, and whether the asset sits in a critical zone like safety or process control.

2. Assess operational and cyber factors.

Layer in hardware condition, application dependencies, known vulnerabilities, and performance history.

3. Apply weighted scoring.

Rather than treating every factor equally, weight them so scores are comparable across the fleet.

4. Map criticality.

The same model of switch or server can carry very different risk depending on whether it sits in a safety system or a low-criticality zone. Criticality is what turns a raw score into a genuine business risk.

A Practical Scoring Model

A useful obsolescence score combines four factors. Hardware covers physical condition, spare parts availability, and whether a direct replacement exists, typically the heaviest-weighted factor given its outsized impact on recovery. Application covers OS and firmware support status from the vendor. Cyber covers known vulnerabilities, patch ability, and hardening capability. Performance covers communication stability, resource usage, and any history of abnormal behavior or past incidents.

A common weighting looks roughly like 40% hardware, 25% application, 25% cyber, and 10% performance, though every organization should tune these to its own environment. The combined score is then multiplied by a criticality factor, so the same technical score produces a very different priority for an asset sitting in a safety system versus a less critical zone.

The output classifies every asset as high, medium, or low obsolescence risk, giving management a defensible basis for budget and replacement decisions instead of a gut call.

From Score to Action

High-risk, high-criticality assets typically justify replacement or emergency procurement, since no substitute or spare exists and the consequence of failure is severe. Medium-risk assets fit into a phased upgrade roadmap aligned with capex and opex cycles, especially where vendor support is likely to lapse soon. Low-risk assets need continuous monitoring, regular patching where possible, and periodic checks on vendor life cycle announcements.

This scoring approach also gives OT teams a concrete way to justify obsolescence investment to executive leadership, even when existing systems are still running without visible issues. Comparing the cost of a structured upgrade against the potential cost of an unplanned failure, in downtime, safety exposure, and emergency procurement, turns an abstract risk into a business case.

Building the Roadmap

A practical rollout follows four phases: inventory enrichment, adding life cycle, vendor support, and criticality data to the existing asset base; scoring strategy, defining and tuning the weighted model; risk baseline, generating scores and validating them with asset owners; and roadmap execution, prioritizing replacements, planning upgrades, and continuously monitoring lower-risk assets.

This structure aligns closely with the frameworks most OT programs already reference, including ISA/IEC 62443 and Saudi Arabia’s NCA OTCC, both of which expect asset criticality and life cycle awareness as part of a defensible compliance posture. CISA’s own guidance on OT asset inventory makes the same point from a different angle: you cannot build defensible architecture without knowing exactly what you’re defending.

Final Thoughts

Obsolescence isn’t a failure of engineering. It’s a natural part of every asset’s life cycle. What separates resilient organizations from exposed ones is whether that life cycle is actively managed or quietly ignored until something breaks.

A basic asset list can’t answer the questions that matter which assets are approaching end of life, which ones sit in critical zones, and which ones need budget this year rather than next. A deep, scored, criticality-weighted inventory can. That shift, from a static list to genuine life cycle intelligence, is what turns obsolescence management from a reactive scramble into a strategic, governed part of industrial cyber resilience.

Ready to see where your OT assets stand? Contact ACET Solutions to talk through building a deep asset inventory and obsolescence risk model for your environment.