
Every October, the Cybersecurity and Infrastructure Security Agency (CISA) leads Cybersecurity Awareness Month, an annual effort to strengthen cybersecurity and protect the systems we rely on. This year’s theme, “Securing the Next 250,” looks toward the next 250 years of American innovation and the critical infrastructure needed to support it.
Critical infrastructure depends on applications that have been operating for decades, which is why we’ve released an updated edition of our popular ebook, Application Security Guide for COBOL: Protecting Legacy Systems in a Modern Threat Environment. More than 65 years after its introduction, COBOL remains embedded in critical infrastructure across banking, insurance, government, retail, and other sectors. Protecting that infrastructure means securing the legacy applications and organizations that rely on it as they connect with newer technologies.
According to IBM, COBOL still supports 95% of ATM transactions and more than 40% of online banking systems, reflecting its continued role in critical financial infrastructure. That makes long-standing systems an important part of the challenge of “Securing the Next 250.” COBOL applications have run reliably for decades, even as the technologies, development practices, and security threats surrounding them have changed.
As experienced COBOL developers retire, organizations are losing specialists who understand the language and decades of institutional knowledge. At the same time, security teams still have to manage compliance requirements and vulnerabilities such as SQL injection and insufficient input validation in applications shaped by years of piecemeal maintenance.
COBOL code is only part of the security picture. These applications also connect with APIs, build pipelines, third-party components, and other services. Vulnerabilities in those connections and dependencies can put the broader system at risk, so teams need to understand what their legacy applications rely on.
Modernizing a COBOL application can extend its useful life, but integrating it with newer technologies also creates additional potential avenues for vulnerabilities. APIs, cloud services, and DevOps pipelines can expand what legacy applications can do, but they also become part of the attack surface.
AI coding tools can accelerate development and migration, but their output still needs security testing and human review. With COBOL, AI may misinterpret copybooks or complex logic, producing code that looks correct but behaves differently from the original.
AI can also create visibility and control issues. A developer using an unapproved tool might expose proprietary code or sensitive data, while autonomous agents can interact directly with repositories, dependencies, APIs, and pipelines. Agentic prompts can also uncover dormant APIs that teams may not realize are still accessible, creating additional blind spots.
Security needs to extend beyond the application itself. SAST can identify vulnerabilities in proprietary code, while SCA and SBOMs provide visibility into third-party and open-source components. Integrating these checks into development workflows helps teams identify issues earlier, including in AI-assisted code.
Governance helps ensure changes are tested before they reach critical systems and defines how developers and AI tools can interact with applications and dependencies. Combined with application security posture management, these practices help teams manage risk throughout development.
“Securing the Next 250” starts with protecting the infrastructure we already depend on. As new technologies and development practices become part of critical systems, legacy applications need to remain part of the security conversation.
At Kiuwan, that means helping organizations identify and address application security risks across both legacy and modern development. Download the updated Application Security Guide for COBOL: Protecting Legacy Systems in a Modern Threat Environment to explore common security risks facing COBOL applications, and get checklists to assess your current security posture and tips to fix issues.