A new system should not carry old risks

TechnologyBusiness & Finance
13 Sep 2026 • 12:05 AM MYT
The Manila Times
The Manila Times

One of the longest-running English broadsheets in the Philippines

 A new system should not carry old risks

MIGRATING an old website can sound like a straightforward technology project. Move the pages to a newer platform, improve the design, update the applications behind it, transfer the necessary data, test everything, and go live.

I recently found myself going through this process. As we discussed the scope and reviewed how the migration would work, the exercise started raising questions that went beyond how the new website would look or what technology would power it.

What are we really transferring? Who will be able to access it? And if our needs change in the future, how easily can we recover or move what belongs to us?

These are healthy questions to raise when planning a technology project. They help the organization and its service provider establish responsibilities before implementation begins.

I realized that these were no longer merely technical questions. They were governance questions.

Ownership not same as control

One of the easiest assumptions to make when outsourcing technology is that because a company paid for a system, it controls it. That is not necessarily the case.

A company may legally own its website, custom software, and data while a service provider manages the server, database, source-code repository, backups, or other parts of the infrastructure. Such arrangements are common and can be practical. Managing these responsibilities may be exactly why the provider was hired.

The governance issue is whether the organization understands the arrangement and can maintain business continuity when circumstances change.

Imagine the technology provider suddenly becoming unavailable. Could the organization access its systems? Would the necessary credentials, data, and code be available? Could another qualified provider take over?

Outsourcing operations does not mean outsourcing accountability.

Modernization chance to rethink data

The migration made me think differently about another issue: data.

When organizations accumulate information over many years, the instinct can be to move everything from the old system to the new one. Storage has become relatively inexpensive, and historical information may continue to have legitimate business, operational, or research value.

Modernization, however, creates an opportunity to reconsider how that information should be managed. Does everything we decide to retain also need to remain continuously available in the production environment?

Some information may need to remain readily available for current operations. Other information may continue to have value while being more appropriately archived with suitable safeguards. There may also be information that has reached the end of its legitimate retention period, subject to applicable legal, contractual, research, and operational requirements.

The goal is thoughtful retention: understanding why information is kept, how long it remains useful, and what environment is appropriate for storing it.

Instead of automatically transferring everything simply because it exists, modernization gives organizations an opportunity to decide what needs to be migrated, what should remain readily accessible, what can be archived and what has reached the end of its useful retention period.

Access follows purpose

There is another dimension to data governance that businesses can easily overlook. When we say that a service provider has access to a system, who exactly does that include?

A developer may require access to maintain an application, but that does not automatically require unrestricted access to all production information. Troubleshooting may sometimes be possible using test, anonymized, or appropriately limited data. The same principle can apply to backups and administrative systems.

Access should follow purpose. People and systems should receive the level of access necessary to perform their roles.

This becomes more important because outsourcing today can involve more than the organization and its immediate technology provider. A provider may itself rely on cloud infrastructure, backup services, analytics platforms, and other third-party technologies.

Artificial intelligence adds another layer. Transcription, document processing, analytics and customer-service functions can involve external AI services. Organizations should understand what information is sent to these services, whether it is retained, how it may be used, and what controls apply to sensitive or confidential information.

The point is not to avoid third-party technology or AI. These services can bring significant benefits. The governance responsibility is to understand where important information goes and the safeguards that follow it.

Migration, recovery need to be tested

Moving information successfully is just as important as protecting it afterward.

A service provider’s confirmation that a database has been transferred should not necessarily end the migration process. Organizations need some way of determining whether the transfer was successful.

Expected and actual results can be reconciled. Failed or incompatible records can be identified. Important relationships among datasets can be checked. Information retrieved from the new environment can be compared with what existed before.

Migration therefore needs acceptance criteria agreed upon before the old environment is retired. Successful migration should mean more than completing a transfer. The information should remain complete, accurate and usable for its intended purpose.

The same thinking applies to backups. Businesses are often reassured when they hear that their systems are backed up regularly. But recovery is the real test.

A backup provides limited business-continuity protection if it cannot be successfully restored when needed. Organizations therefore need to think about backup retention, accessibility, restoration procedures, and periodic recovery testing.

The more useful question is not simply, “Do we have backups?” It is, “Can we recover?”

Plan for continuity from beginning

Technology relationships change. Businesses outgrow systems. Providers change direction. Better technologies emerge. Costs and requirements evolve. That is why continuity should be considered at the beginning of the relationship rather than only when an organization wants to leave.

Source-code ownership is important, but source code alone may not allow another development team to take over a system easily. Applications accumulate configurations, dependencies, database structures, deployment procedures, and technical decisions. Some of that knowledge can remain with the people who originally built or maintained the system unless it is documented.

Another competent technology professional should be able to understand the important components of the system. Key configurations, dependencies, deployment procedures and recovery requirements should be documented well enough to support maintenance and transition.

Organizations should also understand how they can retrieve their information and digital assets in a usable form, which credentials and documentation will be transferred, and what assistance may be available if systems eventually need to move elsewhere.

The objective is not to make a good provider easily replaceable. Strong technology partnerships can last for many years. The objective is to prevent critical institutional knowledge and access from existing in only one place. Exit planning is business continuity.

Modernization should improve governance

Perhaps the biggest realization from this experience is that the apparent simplicity of a technology project can be misleading.

What looks like a website migration may touch systems and information accumulated over many years. The value of what is being entrusted to a provider can therefore be considerably greater than the technology project itself.

This applies well beyond websites. A retailer outsourcing its e-commerce platform, an association moving its membership database, a cooperative implementing a member portal, a small business adopting a customer relationship management system, or an organization moving operations to the cloud faces variations of the same issues.

Capability, reliability, cost, and delivery will continue to matter when evaluating technology providers. But moving to a new system also provides an opportunity to examine practices that may have simply accumulated over time.

Digital transformation is sometimes described as replacing old technology with something newer. Transferring outdated assumptions, unnecessary data practices, undocumented dependencies, and excessive access into a new environment simply carries many of the old risks forward.

Digital modernization gives us a rare opportunity to rethink what we keep, who can reach it, how we recover it, and how dependent we become on the systems and providers around us.

The real transformation happens when better technology is matched by better governance.

Newswav Malaysia Best News App

Newswav is an online content aggregator and obtains its content from different online sources. The content in the app do not belong to Newswav nor do they reflect the opinions of Newswav and its staff. Your use of this app indicates your understanding and acceptance of this information.

Newswav Sdn. Bhd. (201701008480 (1222645-M)) 2026 All Rights Reserved