Project Case Study - A Strategic Approach to Obsolescence Remediation
Project Description
The engagement
Unsung was engaged to conduct a comprehensive strategic assessment of obsolete hardware and software supporting a business-critical Issuing Certificate Authority (CA). The engagement originated from urgent operational concerns regarding end-of-life technology infrastructure that underpinned essential digital trust services across the enterprise.
The client required immediate tactical remediation to address short-term operational risks whilst simultaneously developing a robust, cost-effective transformation roadmap capable of delivering sustainable strategic outcomes across a multi-year modernisation programme. This dual mandate required balancing urgent operational continuity requirements against longer-term architectural modernisation objectives.
How obsolescence accumulates in PKI estates
Certificate authorities are unusually prone to obsolescence, for reasons that have little to do with neglect. They are long-lived by design, since a trust hierarchy is intended to remain stable for years. They are stable in operation, which means they rarely generate the incidents that prompt investment. And the risk they carry is concentrated: a certificate authority typically supports a very large number of dependent systems, so the case for touching it is weak until the case for touching it becomes urgent. The result is infrastructure that quietly passes end of support while continuing to work perfectly well, right up to the point at which it becomes both unsupportable and unavoidable.
By the time the position becomes urgent, the organisation usually faces the same difficulty this client faced: the immediate risk demands action now, but acting now without a strategic view risks spending significant money on a like-for-like replacement that reproduces the same problem on a longer timescale.
The tension the engagement had to resolve
Tactical remediation and strategic transformation are frequently treated as competing options, with organisations choosing one at the expense of the other. Both choices carry cost. Purely tactical action addresses the immediate exposure but consumes budget without advancing the target architecture. Purely strategic action produces a well-reasoned destination while leaving unsupported infrastructure in service throughout a multi-year programme.
Unsung's remit was to hold both together: to establish what needed to be done immediately to reduce operational risk, and to ensure that the immediate action formed a deliberate first step towards a defined target state rather than a detour from it. That required an evidence base robust enough to support decisions at both timescales, and a roadmap that made the relationship between the two explicit.
Outcomes & Deliverables
Unsung delivered a comprehensive suite of strategic and technical deliverables that equipped the client with the evidence base required for confident, risk-managed decision-making:
- A detailed assessment paper evaluating the full spectrum of vendor options, technology platforms, and architectural patterns. This included analysis of consolidation opportunities that could reduce operational complexity and ongoing support costs, alongside comprehensive evaluation of business change implications affecting people, processes, and governance frameworks.
- A strategic transformation roadmap incorporating structured build logic that clearly delineated mandatory change activities from tradeable elements and transitional requirements. This roadmap provided executive stakeholders with a clear view of investment phasing across the multi-year programme lifecycle.
- A comprehensive service decomposition exercise that quantified enterprise-wide service consumption patterns across people, process, and system integration dimensions. This analysis provided granular visibility into how the PKI service was consumed across diverse business units and technical platforms.
How Unsung approached the assessment
Every Unsung consultancy engagement opens with a structured assessment of the current environment, the business requirements it must satisfy and the compliance obligations it operates under. That discovery phase establishes a shared baseline and identifies the immediate priorities, which in an obsolescence engagement means separating the components carrying genuine near-term risk from those that are simply approaching end of support on a manageable horizon.
From that baseline we develop recommendations tailored to the organisation rather than to a reference architecture, presenting multiple options with the trade-offs made explicit, a risk assessment for each, an implementation roadmap with clear milestones, and the cost-benefit position underpinning them. The intent is to leave the client able to make and defend the decision themselves, which matters particularly in public sector environments where investment cases face external scrutiny.
Assessment and options analysis
The assessment began with the current environment: the obsolete components, the risk each presented, and the constraints within which any remediation would have to operate. Options were then evaluated across the full spectrum of vendor platforms and architectural patterns, rather than narrowed prematurely to the incumbent or to an assumed successor. Each option was presented with its trade-offs made explicit, covering cost, risk, operational implication and strategic fit.
Unsung's vendor-neutral position was material here. An organisation weighing a multi-year investment in its trust infrastructure needs advice whose independence it can rely upon, particularly where the recommendation may point away from an established supplier relationship. Our role was to present the evidence and the trade-offs clearly, and to leave the decision properly informed and properly the client's.
Service decomposition
The service decomposition exercise established how the PKI service was actually consumed across the enterprise, quantified across people, process and system integration dimensions. This is consistently the most valuable and most frequently omitted element of an obsolescence assessment. Without it, migration planning proceeds on an incomplete picture of dependencies, and the gaps surface during implementation as unplanned scope. With it, the organisation can see which business units and platforms depend on the service, in what way and to what degree, which in turn allows change to be sequenced according to genuine impact rather than assumption.
The transformation roadmap
The roadmap set out the path from the current position to the target state, structured so that mandatory change activities were clearly distinguished from tradeable elements and transitional requirements. That distinction is what makes a roadmap usable as a planning instrument rather than an aspiration. It allows executive stakeholders to see where the programme has flexibility and where it does not, to phase investment across the programme lifecycle with confidence, and to make informed decisions when budget or timescale pressure arrives, as it invariably does.
Business change analysis
The assessment addressed the implications of change for people, processes and governance frameworks alongside the technology. Modernising a certificate authority alters how certificates are requested, who is accountable for issuance, which teams operate the service and how compliance is evidenced. Programmes that treat these as consequences to be managed after implementation tend to deliver platforms that are technically sound but operationally unadopted. Addressing them as part of the assessment allowed the roadmap to account for the organisational change effort the programme would genuinely require.
Challenges
The engagement presented significant organisational and stakeholder management challenges that required skilled navigation to achieve successful outcomes.
A complex stakeholder landscape
The client organisation featured a complex stakeholder landscape with multiple competing priorities, differing risk appetites, and varied levels of PKI technical understanding across business and technology leadership groups.
PKI is a domain where technical understanding varies widely even among otherwise well-informed senior stakeholders, which creates a practical difficulty: the same set of findings will be interpreted very differently across the leadership group unless the way they are communicated accounts for that variance. Unsung addressed this through structured stakeholder engagement with communication tailored to each audience, presenting the same underlying evidence in the terms most relevant to each group, whether that was operational risk, financial exposure, compliance position or technical architecture. Consistency of substance with variation in framing is what allows a diverse leadership group to reach a common decision.
Organisational risk aversion
Organisational risk aversion manifested as reluctance to adopt modern vendor technologies and architectural approaches, despite clear evidence demonstrating superior alignment to long-term strategic objectives. Unsung successfully navigated these challenges through structured stakeholder engagement incorporating tailored communication approaches for different audience groups.
Caution around change to critical trust infrastructure is rational, and treating it as an obstacle to be overcome tends to entrench it. The more effective response is to address it directly: to be explicit about the risk of change and the risk of inaction, to show how each option would be de-risked in delivery, and to demonstrate that the recommendation rests on evidence rather than preference. Presenting the assessment in these terms allowed the organisation to weigh modernisation on its merits rather than defaulting to the familiar option by inertia.
Holding tactical and strategic work together
Sustaining the dual mandate required constant attention throughout the engagement, since urgent operational concerns naturally draw focus away from longer-term planning. The structured build logic within the roadmap was central to resolving this, because it allowed immediate remediation activity to be positioned explicitly as a transitional step within the wider programme rather than as separate expenditure. Framed that way, tactical spend became defensible to stakeholders scrutinising the multi-year investment case.
Leaving the organisation able to proceed independently
The engagement was scoped to produce an evidence base the client could own and act upon without further dependency on Unsung. The assessment paper, roadmap and service decomposition were written to be used directly in the organisation's own investment and assurance processes, rather than as inputs requiring interpretation by their author. For a multi-year programme subject to periodic scrutiny and to changes of personnel, deliverables that remain usable long after the consultancy engagement has closed are worth considerably more than deliverables that do not.
Technologies Used
Related Services
Learn more about our PKI consultancy, central government.

