Running Unsupported ERP is a Financial Decision, Not an IT Decision

September 21, 2026
Bill Evert
Author

Bill Evert

I spend my days doing cybersecurity work for companies that are about to be audited or acquired, or for companies that have already been breached. I also sit on the board of Doozy Solutions. When the Doozy team asked me to walk their group through what end-of-life ERP actually means, I gave them the short version. Here is the longer one.

When a vendor stops supporting a release, patching stops. That is the whole thing. Patching is not a nice-to-have layer of defense. For most mid-market companies, it is the primary layer. 

Vendors constantly find vulnerabilities. They roll them into the next patch, and customers stay a step ahead. The day support ends, that engine turns off, and the gap only widens from there.

Most executives hear that and file it under IT risk. It is not. It’s audit risk, insurance risk, customer risk, and valuation risk. Here is how each one bites.

Your auditor is going to charge you for it

Nearly every company I work with in this industry carries debt. If you have a real loan with a real bank, you are getting audited. Private company audits are less regulated than public ones, but the auditor still has to assess your internal controls against recognized auditing standards, including your IT general controls.

This matters more than people realize because of how sampling works. If an auditor can rely on your controls, they test a smaller sample. If they cannot rely on your controls, they move to substantive testing, which is transaction-level detail work. A sample that might have been fifteen items becomes thirty, sixty, eighty. That’s a lot more hours.

No one will send you an invoice line item that says “surcharge for running dead software.” They don’t have to. The fee comes back higher because the work was higher. This is exactly how an ERP implementation gets priced. You count the hours, then you quote the number.

There’s also the part that auditors won’t say out loud. I’m signing my name on an opinion that goes to your lender. If the foundation underneath your financials is a system nobody supports anymore, where a break has no one to call and a vulnerability has no fix coming, I’m less comfortable signing. And on top of the fee increase, you pay again in your own team’s time pulling all that extra documentation.

A graphic about Unsupported ERP that says Unsupported software = Unprotected business

Your cyber insurance probably will not pay

Almost every company has a cyber policy now. Very few have read page seventy-two of it.

Basic patching hygiene is a condition of coverage in essentially every policy written. An unsupported core system is a clean, documented violation of that condition. I’ve watched companies get breached, file the claim, and get told no. The carrier points at the requirement, points at the system, and closes the file. 

An insurance company is a business. Denying a claim is a legitimate business outcome for them.

So the sequence is: you get hit, you eat the ransomware or the fraud loss, you eat the remediation, you eat the reputational damage, and the policy you have been paying for does none of the work.

The damage does not stop at your walls

Attackers rarely stop at the company they get into. They spider outward.

They get into your system, look at your customer list, and use your access and credibility to move into your customers. Now you are on the phone with a customer who can see exactly how the attacker reached them. That is a relationship problem, and sometimes a litigation problem. Then they do the same thing in the other direction through your vendors.

I have seen attackers access bank accounts and wire money to themselves. It happens more often than people think.

Hosting does not solve this. If you are running a hosted single-tenant deployment, your host can protect the network, servers, firewalls, and configurations. They cannot patch the vendor’s application. That patch does not exist anymore. 

Worse, a compromise at the hosting provider is a compromise of every customer running out of that environment. 

The attackers know the calendar

I was asked whether attackers know when a product goes end-of-life and whether they are sitting on exploits waiting for the support window to close.

Yes. Obviously yes. This is a business, and federal cybersecurity guidance backs up what I see in the field: unsupported systems get disproportionately targeted precisely because attackers know a fix isn’t coming.

There are buildings full of people doing this work, finding low-hanging fruit, selling what they take to organizations that anonymize it and pay them. They read the same press releases you do. Knowing a system will be permanently unpatchable after a certain date is valuable information, and vulnerabilities held until then become permanently exploitable rather than temporarily exploitable.

AI has made this worse in both directions. An amateur can now operate at a level that once took years to reach, and a competent operator can hit far more targets, far faster. The attackers have the same tools as the defenders.

End of life is the obvious version of a broader problem

Not being end of life does not mean you are safe. Plenty of ERP vendors are fully supported yet still cannot meet the demands of modern defense.

Security has to be built in layers because bots will get through layers one and two and need to be stopped at layer three. That takes real infrastructure and real headcount. 

Oracle has hundreds of people doing nothing but watching for this, and they carry the SOC reporting to prove the controls exist. That’s part of why the platforms I point clients toward are ones built in Oracle NetSuite. Even if a smaller vendor patches as fast as it can, it still won’t reach that level, no matter how diligent it is. The platform underneath you either has that capacity, or it does not.

A graphic about unsupported ERP that says "The patches stopped. The risk didn't."

Acquirers look at this before they look at you

If you are private equity-owned or expect to sell or raise capital, this is where the abstract risk turns into a number.

Every serious acquirer does cybersecurity and IT general controls diligence. They layer in their own requirements depending on the deal. They are asking one question: what am I inheriting? My firm has done this work for both sides, conducting cyber diligence on targets and preparing companies for sale.

When diligence reveals a liability like this, it usually does not kill the deal. It reprices it. It becomes a haircut. It becomes an indemnity. It becomes a holdback. Nobody wants a written deficiency in their file, and these are now showing up in private company diligence reports, not just public ones.

Having a name like Oracle underneath you helps on both sides of that table.

What to actually do

If you’re staring down an end-of-mainstream-maintenance date right now, SAP Business One’s migration timeline is a useful place to start, since that’s the system I see most often in this conversation. Beyond that specific case, we’ve also written more broadly about the risk factors of unsupported software if you want the fuller picture.

Running unsupported software as the core system of record for a real company is borderline crazy to me. Even doing it for a short stretch would make me nervous. Doing it because a migration feels expensive is a trade no one would take if the other side of the ledger were written honestly.

If you want a second opinion on where your system actually stands, reach out to the Crafted ERP team to talk through what a realistic transition looks like.


About Bill Evert

Bill Evert is the retired co-founder and current member of the Doozy Solutions board of directors. He is also the managing partner and program manager at CP Cyber Security, where he leads cybersecurity and IT assessments for organizations nationwide.


FAQ: Running Unsupported ERP Software

What does “end of life” mean for ERP software?

Once a vendor stops supporting a release, patching stops entirely. No new updates, no fixes for newly discovered vulnerabilities. That removes one of a company’s core defenses, leaving it exposed to breaches it may eventually have to disclose.

Why do auditors care about unsupported ERP systems?

Weak IT general controls (ITGCs) push auditors away from sampling toward more detailed, transaction-by-transaction testing, increasing audit costs. This applies to public companies under SOX and to private companies facing lender-required audits alike.

Does running unsupported software void cyber insurance?

In many cases, yes. Most cyber insurance policies require basic patching hygiene, and an unsupported system is a clear, documented violation that insurers can cite when denying a claim, leaving the company to cover breach costs on its own.

Do hackers specifically target end-of-life software?

Yes. Hackers track public end-of-life announcements and often hold known vulnerabilities until patching stops, then exploit them at scale. AI has lowered the skill barrier for these attacks, making them accessible to less sophisticated actors.

How does an unsupported ERP affect M&A due diligence?

Acquirers and private equity firms treat it as inherited risk. An EOL core system flagged in diligence can lead to a lower valuation, a longer negotiation, or a stalled deal while the buyer assesses what they’re taking on.

Is this risk different for private companies than public companies?

Public companies face it under federal SOX requirements. Private companies face it through lender-required audits tied to any meaningful debt. Company size also plays a role — smaller companies see less scrutiny today, though that changes with growth.

Does the ERP platform itself affect the level of risk?

Yes. Platforms backed by large, dedicated security teams and layered, built-in defenses, like those built in Oracle NetSuite, carry a different risk profile than smaller or aging platforms that can’t match that investment.