The Ghost in Your Warehouse: How Legacy OT Systems Are Quietly Expanding Cyber Risk in Modern Operations

Plus, practical steps to enhance cybersecurity across legacy warehouse systems without disrupting operations.

BY CAROL MILLER, CHIEF MARKETING OFFICER, MHI

WALK INTO A modern distribution center today and the impression is one of precision engineering and digital orchestration. Automated storage and retrieval systems (AS/RS) move product with near‑mechanical choreography. Warehouse management systems (WMS) coordinate inventory in real time. Fleets of autonomous mobile robots (AMRs) and automatic guided vehicles MHI(AGVs) glide through aisles. Networks of conveyors and sorters transport totes, containers, cartons and parcels in precisely timed sequences at varying speeds.

Yet even in these highly advanced environments, there is often a “ghost in your warehouse,” a hidden layer of legacy operational technology quietly running in the background. Beneath the visible modernization sits existing infrastructure that is far less visible and far more difficult to change. These systems continue to control material flow, but they’re often running unsupported software, outdated operating systems and communication protocols that were never designed for today’s highly connected environment.

What makes this environment so complex is not simply that legacy systems exist, but that they remain fully operational inside systems that otherwise appear modern, noted Abdil Tunca, supply chain analyst at Gartner.

“The irony is that some of the newest warehouses still rely on some of the oldest technologies. Because these systems often work reliably, they create a false sense of security,” he said. “Yet just because they work doesn’t mean they’re secure.”

These legacy system ghosts are an all‑too‑common issue across today’s warehouses. Here, a closer look at where (and why) legacy risks persist and what organizations can do to mitigate them.

THE SYSTEMS NO ONE TALKS ABOUT

Counterintuitively for most, the biggest risk in warehouse environments is rarely the newest automation layer or the most visible robotics deployment. Instead, it is the accumulated infrastructure that sits beneath it. These systems are so embedded in daily operations that they rarely appear in architectural diagrams or governance discussions.

Sabine Fröemling, an independent advisor in operational technology (OT) Security and a NIS2 governance architect, believes “the most dangerous legacy systems are the ones nobody puts on a slide. They’re the industrial PCs and operator panels tucked into a control cabinet, the single Windows 7 machine running a high‑bay storage crane, the engineering laptop under a conveyor that hasn’t been rebooted in years.”

Further, continued Fröemling, these systems are often vendor‑locked and touching them risks voiding support. Additionally, they’re often omitted on the IT department’s official network diagram. “If you don’t know a system is there, you can’t protect it—and admitting it’s there means owning a problem with no budget and no tolerance for downtime. So the risk gets understood, documented, and deferred year after year.”

The difficulty in addressing these systems is not technological but operational and organizational, she emphasized. In her experience, warehouses consistently prioritize uptime over remediation, as even minor disruptions can halt material flow or fulfillment operations.

“In a warehouse, uptime is everything. A 12‑year‑old PC controlling a zone of an AS/RS has never been patched because the one time someone tried, it stalled mid‑shift and nearly stopped the line,” noted Fröemling. “Operations will choose a stable, unpatched system over an updated one that might fail.”

Brian Curran, vice president of software at MHI member Designed Conveyor Systems, agreed. He observed that many legacy devices remain in place because “they are technically not broken. That makes them difficult to prioritize, even when vendors no longer support them or security vulnerabilities are known. The systems remain in production, not because they are secure, but because they are stable enough to avoid immediate attention.”

THE “AIR GAP” NO LONGER EXISTS

One of the most persistent misconceptions in warehouse cybersecurity is that operational systems remain isolated from external networks, known as an “air gap.” This security approach, however, has largely been reduced to documentation rather than reality, said Tunca.

“The idea of an air gap doesn’t hold up anymore because everything is connected. Your cloud‑based WMS integrates with an enterprise resource planning (ERP) system, transportation management system (TMS), yard management, robotics and so on. Every one of those connections creates a pathway that didn’t exist before,” he explained.

“I’ve seen companies assume their automation systems were isolated, only to find multiple remote access points and external connections upon closer investigation,” Tunca continued. “The reality is modern warehouse operations depend on that connectivity. So instead of assuming isolation, organizations need to assume connectivity and secure their legacy systems accordingly.”

Each connection is individually justified, but collectively they eliminate meaningful isolation. “The ‘gap’ survives on the architecture diagram long after it has been bridged in practice,” said Fröemling, who cited two types of air gap failures.

“The first is invisible—remote access introduced for legitimate reasons like vendor support, where a virtual private network (VPN) or remote‑desktop connection ends up undocumented or lightly controlled,” Fröemling explained.

“The second is more dangerous: truly isolated systems that never get patched because reconnecting them is seen as too risky. I’ve seen environments where machines were still missing critical patches years after known vulnerabilities like WannaCry because they were left isolated,” she continued. “No one was negligent—each decision made sense at the time—but the result is that isolation didn’t remove risk, it often preserved it until the moment someone finally reconnects the system.”

Click here to read the full article.

80’S CHILD/SHUTTERSTOCK.COM