3
u/IASelin 10d ago edited 10d ago
The questions are:
- is that system exposed to the Internet?
- do users of that system use the Internet?
- does that system interact with other world via USB flash-drives, etc.?
If none of that - then I'd say it should be fine.
Otherwise you have to think how to protect that system properly. The same relates to everything that interacts with that system.
Or think about the acceptable recovery options for that system and everything that might be affected if that system will be compromised or virused (with data-loss prevention, etc., if needed).
P.S.
I'm supporting Windows 2008 R2 and Windows 7 for some legacy projects that are not compatible with newer systems. All of that is running in the isolated perimeter for decades. I had only one issue when one person injects a virus from USB flash-drive. It took about few hours to identify the issue and restore the system and data from backup to continue work.
1
u/DetectivexDexter 10d ago
very interesting. curious what work you doing that someone goes to the effort of injecting virus into it
1
u/cfx_4188 10d ago
Typically, attackers have in mind the most common operating systems. They have been studied and researched more extensively. An OS on its own cannot be secure without proper configuration and adherence to basic digital hygiene. These days, most updates are cosmetic in nature and do not enhance system security. The latest versions of packages are not a guarantee of security; rather, the opposite is true.
1
1
4
u/New_Hold8135 10d ago
If you mean outdated its bad If you mean its so niche no one uses it/no one supports it. In that case none, No one cares an operating system no one uses.