Many firms think about system upgrades as housekeeping – something the IT team schedules for a quiet weekend. Kirsteen Forisky, head of development at LEAP Enterprise, argues that this framing is exactly what leaves firms exposed. Every upgrade a firm defers is a risk it has chosen to carry: on security, on compliance, on the ability to keep operating when something goes wrong.
I’ve spent more than 30 years building software for law firms, and over that time, I’ve seen the same exchange repeat itself in room after room. Someone puts an upgrade on the table. Someone else asks whether it can wait. Usually, it can – at least in the narrow sense that nothing goes wrong the following morning.
So it waits. And it goes on waiting, until the version a firm is running sits two or three releases behind, the vendor has stopped supporting it, and the question has quietly changed from “should we upgrade?” to “how did we end up here?”
I understand the instinct. Upgrades have the feel of maintenance; they feel easy to defer precisely because the cost of deferring stays hidden right up to the moment it doesn’t. But that instinct is the trap. A system upgrade isn’t housekeeping; it’s a judgement about how much risk your firm is prepared to carry, and each time you postpone one, you’ve made that judgement.
What you’re actually deciding
Begin with security, because that’s where the cracks appear first. Vendors and researchers turn up new vulnerabilities all the time, and the moment one becomes public knowledge, the clock is running. An attacker needn’t be sophisticated to take advantage. Once the details are out there, an unpatched system is a soft target. Leave it unpatched, and you’ve left an open door: to ransomware, to data theft, to someone quietly making off with confidential client information.
Apply updates promptly, and you shut those gaps before anyone can step through. That really is all there is to it. It’s not clever – which is exactly why leaving it undone is so difficult to defend once the damage is done.
Compliance is not optional
Compliance comes next, and for a law firm, this is anything but optional. Frameworks such as ISO 27001, the UK’s Cyber Essentials scheme, and the UK GDPR all place genuine emphasis on managing vulnerabilities and keeping systems in a secure, supported state. Come an audit, out-of-date software is no footnote: it can show up as a finding, draw closer scrutiny, and bring financial and legal consequences — all the more so where personal or client data is at stake.
Firms are entrusted with some of the most sensitive information their clients will ever hand over. The regulatory expectations follow from that, and “we hadn’t got round to it” is not a line anyone wants to be giving the SRA.
Set the security and compliance case aside, and there’s a simpler operational one underneath. Vendors don’t ship updates only to close holes; they ship them to fix defects, sharpen performance, and keep pace with everything shifting around them. A firm stuck on an old version tends to gather the reverse: more downtime, sluggish systems, integrations that quietly stop speaking to one another, and people working around the software rather than with it. None of that lands as a line item, yet every bit of it costs you.
The end-of-support cliff
The risk that troubles me most is the silent one: end of life. When a product reaches end-of-support, the vendor stops issuing security fixes, stops fixing bugs, and stops picking up the phone. Nothing signals the change. The software keeps on running, and that is precisely what makes it dangerous: you’re now exposed on every side at once, and the day something does break, there’s no one left to call.
Staying on supported versions keeps you tied to the people who build the thing: their expertise when you need it, security work carried on your behalf, and a clear view of what’s coming next. That last point counts for more than it might seem. A firm that stays current isn’t merely dodging problems; it’s keeping its options open.
Do the arithmetic
Whenever a firm baulks at the cost of an upgrade programme, I’d suggest running the opposite sum. Recovering from a cyberattack. Handling a breach. Getting operations back after an outage. Answering a regulator. Any single one of those routinely comes to more than staying current ever would. And that’s before you factor in the part with no invoice records: the loss of client trust when a firm has to account for how their data ended up somewhere it shouldn’t. Confidence is slow to earn and quick to squander, and in this profession, it’s most of what you’re selling.
The honest way to read an upgrade budget is as insurance that you’re deciding whether or not to buy. Proactive currency isn’t the costly choice. It’s the cheap one. It just happens to be the one you settle up for before the incident rather than after.
Make it someone’s decision
If there’s one change I’d press firm leaders to make, it’s to stop treating upgrades as something IT takes care of, and start treating currency as a business decision that leadership owns. Throughout my career, the factor that’s separated the projects that succeed from those that stall has been buy-in — people at the top who grasp the stakes and stand behind the work. Upgrades are no exception. Once staying current becomes a standing commitment rather than a task shunted down the list every quarter, the firm’s posture shifts. You stop reacting to problems and start heading them off.
This is part of why the move to genuine cloud platforms matters so much for firms with an eye on the long term. Handled well, the cloud lifts a great deal of this weight off the firm altogether. Updates come as part of the service, security is kept up continuously rather than in anxious batches, and the version you’re on is simply the current one. It’s also what kept so many firms working through the upheaval of recent years — operating from anywhere, on any device, with no server room to fret over. The firms that had already made the move weren’t scrambling. They were simply getting on with it.
Treat upgrades as a technical obligation, and they’ll forever feel like a cost to be trimmed. Treat them as what they truly are — a strategic choice about resilience — and the logic turns over. Staying current shores up your security, keeps you compliant, reduces your operational and financial risk, and provides a steady foundation to build on. It’s no drag on growth. It’s a condition of it.
The upgrade you keep putting off is trying to tell you something. Better to listen now than to have circumstances make you.
About the author
Kirsteen Forisky is chief development officer at LEAP Enterprise, with over three decades of experience in legal technology. Having held multiple senior leadership roles at LEAP Legal Software – including head of development across the UK, Ireland, and Canada, as well as head of innovation – she has been instrumental in shaping market-leading legal software that aligns closely with the real-world needs of practitioners. With a strong foundation in product development, legal aid systems, and client-driven innovation, Kirsteen is known for building high-performing development teams and delivering solutions that improve efficiency and outcomes for law firms. Her work is grounded in a deep commitment to continuous improvement, user feedback, and practical impact within the legal sector.
















