Legacy risk assessment

How exposed are you, really, if the ColdFusion box dies tonight?

Unsupported runtime, unpatched CVEs, one contractor who understands it, and no rebuild path. We quantify that risk in writing and hand you a sequenced way out.

Fixed-scope · 10 working days · Written report you can take to the board

to a board-ready risk register
10 days
access is all we need to start
Read-only
typical time to close the quick wins
2 weeks

The situation

If any of this sounds familiar, you are in the right place

The version you run stopped getting patches

Adobe support windows close on a schedule. Once yours passes, published vulnerabilities against your runtime simply stay open — and CF has attracted some serious ones.

One person is the disaster recovery plan

There is a name everyone says when the server misbehaves. That name is a single point of failure, and it is usually a contractor with no successor.

You cannot answer the auditor honestly

The questionnaire asks about supported software versions, patch cadence and recovery testing. You know what the truthful answer is, and it is not the one you want to write.

What we do

How we approach it

Risk written down in business terms

Not a vulnerability dump. A register that says what breaks, how likely it is, what it costs you when it happens, and what the cheapest mitigation is — in language a board reads.

Containment before migration

Some risks can be closed in a fortnight: network isolation, WAF rules, credential rotation, a tested restore. We separate "stop the bleeding" from "leave the building" so you are safer before the big project starts.

A sequenced exit, costed

A plan that moves the highest-risk, highest-value parts of the estate off ColdFusion first, with real numbers per stage — so you can fund it in increments the finance team will actually approve.

Key-person risk removed

The audit documents what only one person knows. Even if you never migrate a line, you end up with the system written down.

The engagement

How it runs

  1. 1 · Discovery

    Read-only access to the code, the server config and the deployment process. We inventory runtime versions, exposed surfaces, integrations, scheduled jobs and credentials.

  2. 2 · Risk register

    Each finding scored on likelihood and business impact, with a named owner and a mitigation cost. Delivered as a document you can put in front of your board or your insurer.

  3. 3 · Quick wins

    We implement the containment items that can be done in days rather than months — isolation, patching what can still be patched, tested backups, removing dead public endpoints.

  4. 4 · Exit plan

    A staged migration off ColdFusion, sequenced by risk rather than by convenience, with costs per stage so it can be funded incrementally.

Questions

Frequently asked

Is my version of Adobe ColdFusion still supported?

Adobe publishes a support lifecycle per release, with core support followed by a limited extended-support window, after which no security updates are issued at all. Versions from the 2016 and 2018 era are well past that point, and 2021 is in the late part of its life. The practical test is simple: if you cannot download a current security hotfix for your exact version, published vulnerabilities against it will never be fixed. Our assessment confirms exactly which build you run and what is outstanding against it.

What is the actual risk of running unsupported ColdFusion?

ColdFusion has a history of severe, actively exploited vulnerabilities — several have carried critical severity ratings and appeared on national cyber agency exploited-vulnerability lists, including unauthenticated remote code execution. Once your version is out of support these are permanent. Beyond the security exposure there is availability risk (no vendor to escalate to during an outage), compliance risk (many frameworks and cyber insurance policies require supported software), and key-person risk.

Can we just keep patching instead of migrating?

If you are still inside the support window, yes, and you should — patch promptly and get the containment basics right. That buys you time to migrate deliberately rather than in a panic. What does not work is treating patching as the permanent strategy, because the support window closes on Adobe schedule regardless of your roadmap. Patch to buy time; use the time to leave.

We are not allowed to give an external supplier code access. Can you still help?

Yes. The assessment can run entirely on your premises or in your VDI with read-only credentials, under your NDA and your logging. We do not need write access, production credentials or customer data at any point during discovery — and a lot of what matters is in server configuration and network exposure rather than the application code.

How is this different from a penetration test?

A pen test tells you which doors are currently unlocked. This tells you why the building keeps producing unlocked doors and what it costs to move out. There is overlap on the security findings, but we also cover support status, key-person concentration, recovery capability and the cost of the exit — and we deliver a funded plan, not just findings. The two complement each other; several clients run both.

What if the assessment says we are fine?

Then we tell you that and you have a documented, defensible position for your auditor, which is worth having. We would rather write a short report saying the containment is sound than manufacture urgency. It does happen — well-isolated CF applications with no public surface and a tested restore path are a genuinely different risk profile.

Do we have to migrate everything?

Almost never. Most estates have a small number of applications carrying most of the risk and most of the business value, and a long tail that is low-traffic, internal and nearly dormant. The exit plan sequences by risk, and it is entirely reasonable for the tail to sit behind network isolation for years while the important systems move first.

How quickly can you start?

Discovery needs read-only access and a couple of hours from whoever knows the estate best. From signature to a draft risk register is typically two to three weeks. If you are dealing with an active incident rather than planning ahead, say so in the form and it goes to the top of the queue.

Get a risk assessment

Two fields to start. We reply within one working day. If you are mid-incident, say so — that jumps the queue.

No newsletter signup, no sales sequence. One reply from a person.