The best technology is often the technology that people maintain and patch appropriately. But in some cases, older systems can provide a surprising security benefit: attackers may have fewer reasons to attack them.

Mikko Hyppönen, a Finnish cybersecurity expert, was a user of Eudora, an email program that he continued to use years after it stopped receiving technical support.

Eudora wasn't necessarily more secure than modern email software. It had vulnerabilities, and it didn't have the security updates that were in newer products. As users migrated to more mainstream services like Gmail and other modern platforms, however, Eudora fell into obscurity.

Hyppönen has called this idea ‘security by antiquity’ or ‘security by obsolescence'. The principle is simple: many cybercriminals are motivated by profit and therefore tend to focus their efforts on widely used systems, where a successful attack can impact a large number of people.

If you have a system that is run by 50 people, there may not be enough financial incentive for criminals to develop an attack specifically for it," Hypponen has argued.

But that doesn’t make the old system secure. That means it might be less of a target for attackers.

This is a significant distinction. Known vulnerabilities can never be addressed in a non-supported system. If attackers choose to target it, its age can become a weakness rather than a defence. Studies of legacy information systems have also found that organisations with larger stocks of older systems suffer more security incidents, bucking the notion that ageing technology is generally safer.

The same principle can, however, be applied outside of conventional cybersecurity.

When older systems offer resilience

A more concrete example is Ireland.

The Irish Aviation Authority has postponed the planned removal of some ground-based radio navigation systems in the face of increased concerns about interference with satellite navigation. Ground-based beacons are less reliant on GPS and consequently less vulnerable to jamming that might interfere with satellite-based positioning.

Records seen by the Irish Times show that the Irish authorities have considered retaining traditional navigation aids as a resilience strategy. The Irish Aviation Authority said the systems remained regulated and under regular oversight.

The issue is not that older technology is better than newer technology in every respect. Instead, the two systems face different threats.

GPS offers functions that are difficult to emulate with traditional navigation systems, but the signals can be blocked. So a terrestrial system could be a backup when satellite navigation is not available.

Military operations have similar examples. Paper maps and compasses are still being used, even in places where satellite communications or GPS may be compromised, according to Thomas Withington of the Royal United Services Institute. “You can’t electronically jam a paper map, like you can an electronic navigation system.

Other legacy technologies can provide resilience in similar ways. Take magnetic tape. This medium is still widely used to store data for long periods of time. Its security advantage is also physical: tapes can be removed from computer networks and stored separately, which makes them less vulnerable to some types of ransomware attacks.

The bigger point is that organisations should embrace modern technology.

Instead, security sometimes relies on diversity. If a system depends entirely on one modern technology, it can be vulnerable if that technology is disrupted, compromised or unavailable. But having a well-managed alternative adds another layer of resilience.

For everyday computing, cybersecurity specialists still recommend modern, supported and fully patched software.

So “security by antiquity” is best considered a narrow exception rather than the rule. Occasionally, the fact that technology is not mainstream makes it less attractive for criminals to use. In some instances, older analogue systems still have value because they are resilient against the threats that impact their digital counterparts.

The actual security benefit might not be age itself. It can come from being less exposed, less connected, or vulnerable in other ways.