IT architects and CISOs often face a dilemma: regulatory requirements demand a transition to Zero Trust architecture, yet legacy components remain at the core of their infrastructure. Rebuilding these systems from scratch means halting critical processes, while leaving them unchanged poses severe cyber risks. Traditional perimeter defense is no longer effective, as a breach of a single node grants attackers access to the entire network. Retrofitting infrastructure using Identity-Aware Proxy (IAP) and microsegmentation offers an effective solution.
The anatomy of legacy system vulnerabilities
Legacy systems were developed in an era of absolute trust in the internal network. The lack of multi-factor authentication (MFA) support and modern protocols makes them an easy target for lateral movement by attackers. The scale of this issue is highlighted by international research:
- According to the Cisco Cybersecurity Readiness Index 2025, only 27.7% of organizations have a mature level of readiness in network resilience.
- The ENISA Threat Landscape 2025 report indicates that the exploitation of legacy protocols remains a critical risk for the telecommunications sector and critical infrastructure facilities.
What changes for the sector
For enterprises and critical sectors like telecommunications, failing to secure legacy systems leads to severe non-compliance risks under NIS2 and ISO/IEC 27001 standards. Unprotected legacy nodes expose the entire corporate network to lateral threat movement, potentially resulting in devastating data breaches, operational downtime, and loss of customer trust. Successfully retrofitting these systems allows businesses to maintain operational continuity while meeting modern security mandates.
Technological security tools: IAP and microsegmentation
An Identity-Aware Proxy (IAP) acts as an intelligent gateway. Instead of granting direct access to the server, all traffic is routed to a proxy node that verifies the user and the request context. For the legacy system itself, this process is transparent: it receives the request as if it had passed its own authentication, even though the actual control took place at an external layer.
Microsegmentation operates at the transport and network layers. It creates individual micro-perimeters around each workload based on the principle of least privilege. This prevents attackers from exploiting vulnerabilities in neighboring servers.
Stages of Zero Trust implementation
Transitioning to the new security model is an iterative process consisting of several steps:
- Gap analysis: assessing system non-compliance with security requirements (e.g., using the NIST CSF 2.0 methodology).
- Flow mapping: analyzing and documenting all legitimate connections within the traffic.
- IAP deployment: configuring the proxy node with MFA applied for interface access.
- Microsegmentation implementation: gradually transitioning rules into blocking mode following a preliminary audit.
A platform foundation for modernization
Implementing the combination of IAP and microsegmentation helps address the core requirements of the NIS2 and ISO/IEC 27001 standards. Specialized tools are used to integrate legacy infrastructure with modern security requirements. In particular, the domestic low-code platform UnityBase can serve as the technological foundation for building secure gateways. It enables flexible access control, detailed auditing, and operation in isolated environments without modifying the code of legacy systems.
Steps for businesses
To secure legacy enterprise systems under a Zero Trust framework, organizations should take the following practical steps:
- Conduct a comprehensive gap analysis using the NIST CSF 2.0 methodology to identify non-compliance.
- Map and document all legitimate traffic flows within the network.
- Deploy an Identity-Aware Proxy (IAP) to enforce multi-factor authentication (MFA) at the access layer.
- Implement microsegmentation to isolate workloads and prevent lateral movement.
- Utilize low-code integration platforms like UnityBase to build secure gateways without altering legacy system code.
Prepared by a Software Ukraine member. Original publication.