Why outdated software is a preventable gateway for attacks

Jonas Buchholz
by Jonas Buchholz · 27.09.2026

01 Technical background

Attackers do not need to find new vulnerabilities. It is enough to know the old ones and find a system that they have not yet closed. This makes outdated software a worthwhile target: The vulnerability is publicly known, and the appropriate tool is freely available.

Almost all types of publicly accessible applications are affected, including web servers, content management systems, online stores, interfaces, frameworks, or firewall applications.

Outdated software is referred to when the applications or software components used no longer meet the current security standards. This can have two main causes:

  • Uninstalled security updates: A security update is already available for the installed software; however, it was not installed. The security vulnerability is known and has been fixed by the manufacturer; however, the system remains vulnerable.
  • Software after the end of support (End of Life): The manufacturer has stopped supporting the model or the version used. Security updates are no longer provided, so newly discovered security vulnerabilities cannot be fixed. This applies to both commercial products and open-source components.

Uninstalled security updates are often the result of insufficient patch management. However, continued use of software after support ends regularly points to deficiencies in asset and lifecycle management.

02 Risks and impacts

Known security vulnerabilities are publicly documented. For many, ready-made attack tools exist. Attackers do not specifically target individual companies, but instead continuously scan the Internet for vulnerable systems. In many services, it is already possible to see from the outside which software and version is being used – information that makes exploiting known vulnerabilities easier for attackers.

If an attack succeeds, the data processed there can be accessed. In the worst case, the attacker takes complete control of the system.

If personal data are processed through such a system, the requirements of the GDPR must also be taken into account. Article 32 of the GDPR requires controllers to take appropriate technical and organizational measures, based on the state of the art, to reduce the risks to these data. Operating a software version with known security vulnerabilities or after its support end will not regularly meet these requirements.

If the exploitation of such a vulnerability leads to unauthorized disclosure, modification, or loss of personal data, a violation of personal data protection (so-called data protection incident) is usually involved.

Older systems that have already been technically replaced but are still publicly accessible carry an increased risk. They are out of the scope of patch management, but remain accessible, often still containing valuable information and, in the worst case, even providing access to the internal network.

03 How to identify the vulnerability

In practice, data minimization is often associated with deletion policies or retention periods. In fact, it already begins at the time of collection of personal data.

Many forms have grown over the years and contain mandatory fields whose original purpose is no longer questioned. Often, information is requested because it was „always“ part of the form – not because it is required for the specific processing. Therefore, a closer look at website forms is worthwhile.

Which mandatory fields should companies check?

Not only the greeting can be affected. Often, mandatory fields are found such as:

The same question should be asked for each of these fields:

If this question cannot be answered convincingly, the field should at least not be made mandatory.

It's not just about websites

The principle of data minimization does not only apply to contact forms. Similarly, companies should, for example, consider:

  • Registration and customer accounts
  • Application forms
  • Newsletter sign-ups
  • Support and service portals
  • CRM systems
  • internal recording forms

Especially systems that have been in place for many years often contain mandatory fields whose necessity has never been questioned.

What companies should do now

The ECJ ruling is a good reason to critically review existing data collection procedures. Based on our consulting experience, we recommend:,

  • checking all forms for mandatory information,
  • to document the processing purpose for each date submitted,
  • Reducing mandatory fields to the necessary minimum,
  • regularly review internal processes to ensure compliance with the principle of data minimization,
  • and to design new applications to be data-saving from the very beginning.

This does not mean, however, that addressing someone in a general way is no longer permissible. What is crucial is whether the specific information is actually needed for the specific purpose.

Conclusion

The judgment of the European Court of Justice concerns much more than the question of the correct address. It reminds companies of one of the central principles of the GDPR:

Only those personal data that are actually necessary for the respective purpose may be collected.

Data minimization is therefore not a purely legal requirement, but an important component of data protection-compliant processes. By regularly reviewing its forms, systems, and mandatory fields, companies not only reduce data protection risks but often also improve the user-friendliness of their applications.

Our support

Whether website, customer portal or internal processes – we support you in putting existing data collection procedures under scrutiny. Together, we review which personal data is actually required, identify optimization potential and help you implement the principle of data minimization in a practical and legally compliant manner. In this way, you create lean processes, strengthen customer trust and meet the requirements of the GDPR at the same time.

Check the mandatory fields –
Step-by-step in the webinar

FAQ

What is meant by outdated software?


Why is outdated software a security risk?


What consequences can the use of outdated software have?

What significance does outdated software have in connection with the GDPR?


How can outdated software be identified?


How should outdated software be fixed?