Theory VS Reality

There is cybersecurity theory, and then there is the reality of your application portfolio.

On one side, the NIS 2 directive now imposes strict “digital hygiene” and strong authentication for critical access. On the other, your in-house ERP, SCADA interface, or inventory management tool were coded 15 years ago, back when “MFA” didn’t even exist in the specifications.

For many CIOs and CISOs, this is the impossible equation of 2026: how do you apply modern security standards to archaic foundations?

The Problem: Your “Legacy” Applications Are Invisible to Modern MFA

These applications are often the pillars of your business. They run perfectly, they are stable, but security-wise, they are frozen in the 2010s.

Their architecture poses three major problems against current threats (Ransomware, credential theft):

  • No Authentication Hooks: They often manage their own user bases locally and do not support modern protocols like SAML or OIDC.
  • The Perimeter Illusion: They were designed to be used within a “trusted network” (LAN). Today, with hybrid work and open IT systems, this concept no longer exists.
  • Native Incompatibility: Integrating a YubiKey or FaceID directly into an old Web or Linux application is technically complex, if not impossible without breaking everything.

The Rewrite Dead End

Faced with compliance requirements (specifically Article 21 of NIS 2 regarding supply chain security and access control), the first instinct is often “rewrite.”

Yet, this is a budgetary and operational trap. Recoding a critical app just to add a security layer means exposing yourself to:

  • Explosive Budget: Custom development is expensive.
  • Unacceptable Timeframe: Count on 12 to 24 months for a full rewrite. NIS 2 won’t wait.
  • Major Operational Risk: Touching “Legacy code” means risking regressions, bugs in production, and downtime.

As the IT adage goes: “If it works, don’t touch it.” So, how do you secure without touching?

The Paradigm Shift: The Security “Airlock”

The modern approach is no longer about modifying the application, but modifying how it is accessed. It is the principle of isolation.

Instead of forcing an old engine to accept modern fuel, we place a watertight security airlock in front of it. This is exactly the approach we have developed at Reemo.

How does it work?

The architecture is divided into two distinct zones, creating a protocol break:

  1. The Front Zone (The Modern Airlock): The user never connects directly to the Legacy app. They connect to the Reemo portal. Here, all 2026 technologies are native: strict HTTPS, MFA, and above all biometrics (FaceID, TouchID via WebAuthn).
  2. The Back Zone (The Secure Container): Once the user is strongly authenticated and validated, Reemo opens a secure tunnel to the Legacy app. The application remains in its original state, isolated in a container or protected network, invisible to the public internet.

Immediate Results for the IT Department

This “Security Overlay” (or protocol isolation) approach provides an immediate compliance building block.

  • Compliance Building Block: Your 2008 application suddenly benefits from banking-grade biometric authentication.
  • Zero Code Impact: No development, no complex testing (QA), no risk of regression.
  • Complete Traceability: Where logs from old apps are often obscure, passing through the Reemo airlock allows you to know exactly who connected, when, and with which authentication factor.

Don’t Pay Off the Debt, Secure It.

The race for NIS 2 compliance shouldn’t paralyze your IT roadmap. By dissociating and isolating access security from application logic, you win on both fronts: your users enjoy the fluidity of FaceID, and your IT system is protected against illegitimate access.

Do you have critical applications that don’t support MFA? Let’s discuss setting up an airlock.

Book a demo of Reemo – Réservez une démo de Reemo

Leave a Reply

Trending

Discover more from Reemo blog

Subscribe now to keep reading and get access to the full archive.

Continue reading