Two legacy systems assessed, one decade-defining decision made

Our client is a leading service provider in the live sports and media production sector, and operates its business based on two critical Java applications. In order to plan its investments for the coming years, it requires clear answers: What are these systems made up of, and how much will it cost to continue running them? As part of a 'Legacy Fast Check', 7P analysed both systems in parallel to provide management with a sound basis for decision-making.
Managed Legacy Service

At a glance

Client
A leading service provider in the live sports and media production environment (DACH) with customised Java ERP applications
Scope
Two business-critical Java applications as a customised ERP equivalent (planning & scheduling + booking, asset & service orchestration)
Analysed Codebase
Over 250,000 lines of Java in around 1,600 source files
Method
7P Legacy Fast Check: Scan. Score. Strategise.
Tools
26 automated analysis tools, AI pipeline, two expert walkthroughs per system
Time-to-Verdict
Scans in hours; complete dual assessment delivered within a few weeks

The company

The company is a specialised service provider in the field of professional live sports and media production. It is responsible for numerous time-critical live productions each year, collaborating closely with sports organisers, rights holders and production partners. Although the organisation is lean internally, it manages a large network of permanent and freelance employees, as well as technical partners. The business-critical nature of the work arises from the fixed dates of events and the low tolerance for errors in live operations. Over the course of more than a decade, two Java applications developed in-house have grown to become the de facto ERP system for the business. The first handles operational planning and resource scheduling. It determines which capacities are to be used, when and where. The second coordinates bookings, asset management and ancillary business services, such as allocations, contracts, billing input and daily workflow. Both systems have been running stably for years. However, stable operation does not automatically mean that the technical basis is sustainable for the coming years.

Initial situation

Both applications have been so reliable for so long that the technical foundation has become a black box for most people involved. Since the beginning of 2023, the platform stack (WildFly 26, JSF, EJB and Hibernate 5) has been running without vendor support. This knowledge rested with only a few people. New regulatory requirements, security expectations and the client’s own modernisation ambitions met systems whose limits could no longer be assessed. Before the client could approve a budget for modernisation, three things needed to be clarified:

  • Transparency: A fact-based assessment of maintainability, security posture, and technology gaps, based on metrics and code findings.
  • Options: A robust selection of evolution paths with formulated trade-offs: continued operation, stabilisation, modernisation, replatforming, each with concrete effort and risk assessments.
  • A takeover path: The certainty that an external partner can take over operational responsibility if necessary, without months of discovery.

The 7P Legacy Fast Check closes this exact gap.

The solution

7P applied the same three-stage method to both systems simultaneously to ensure the results were directly comparable.

Risk register with five categories

Scan: Four perspectives, one common basis of facts

Each system was analysed from four independent perspectives to ensure that no single tool, model or human bias dominated the verdict.

  • Classic GitLab pipeline with 26 best-practice Java tools (Checkstyle, PMD, SpotBugs, FindSecBugs, OWASP Dependency-Check, Semgrep, Gitleaks, SBOM, License Audit, JaCoCo, ArchUnit, jQAssistant, CK Metrics, Maintainability Index, ShellCheck, WildFly Config Lint, and more) in six CI stages.
  • AI pipeline for structural, technical debt, technology audit, and performance analyses within the agreed AI deployment framework (no model training on customer data).
  • Expert walkthrough with experienced 7P engineers who read code and configuration, validate machine findings, and identify the macro-risks that the tooling cannot detect.
  • Coding agent walkthrough, in which an AI agent traverses the codebase like a developer, summarises business logic, and marks hidden dependencies.
Risk matrix with five marked points

Score: Uniform assessment across both systems

Every finding flows into a unified Risk Register and is scored as (Impact × Severity) + Likelihood; it also feeds into an ISO/IEC 25010 Maintainability Assessment and a SQALE/SIG Technical Debt Rating. Architecture, dependency freshness, security posture, test coverage, and DevOps maturity are shown with a uniform traffic light system across both systems.

Roadmap graphic with rating chart

Strategise: From numbers to decisions

The result is not a blanket recommendation for ‘modernisation’. The Strategic Evolution Roadmap contrasts five explicit options:

  1. Continue Operation
  2. Stabilise & Maintain
  3. Strangler Fig
  4. Lift & Shift
  5. Full Rewrite

Each option is evaluated according to effort, risk, time-to-value, and long-term costs. The roadmap is supplemented by a prioritised list of the ten most important immediate measures for each system, as well as a service takeover checklist in case 7P takes over operations.

Sebastian Grundhöfer
Senior Solution Engineer
Voice from the project
'The systems were running stably, but under the surface, the risk picture was sobering. What we uncovered automatically in a few weeks would have taken months manually. The fact that we independently demonstrated the same patterns in both applications made the result credible to the board.'

The result

Two systems went into the Fast Check as black boxes. Ultimately, both were given a reliable assessment, supplemented by prioritised measures. This enabled the need for action to be defined in concrete terms for the first time. The Fast Check revealed the risk categories that every IT manager of a long-lived Java enterprise system should anticipate. Specific exploit details have been generalised here; the severity levels correspond to those reported to the client.

Application A:
Operational planning & resource scheduling

  • Automated test coverage in the single-digit range, where every change effectively goes into production untested.
  • Unpatched third-party dependencies with publicly known critical CVEs. Several of these in widely used Java components that are actively being attacked.
  • Embedded secrets and credentials in the source code, which could be exposed by repository access alone, could open up production systems.
  • Credential storage far below current security standards. A single database access would expose the entire user base in one step.
  • Double-digit number of libraries with two or more outdated major versions, for which there is no supported upgrade path within the current platform.
  • The application server has not received vendor support since the beginning of 2023. A platform change is unavoidable for any future security posture.
  • Large-scale architectural erosion due to oversized classes, structural rule violations, and tightly coupled packages that slow down every change.
  • Code quality density significantly above accepted industry standards.

There is no structured database migration tool, so schema changes are not traceable and there is no defined rollback path.

Application B:
Booking, Asset & Service Orchestration

  • The same pattern of credential storage weakness as in Application A was independently proven. This does not confirm individual findings, but the method.
  • Several bundled libraries with publicly known CVEs in widely used Java components are the long shadow of a discontinued runtime environment.
  • Credentials embedded in plain text in configuration files.
  • Gaps in basic web hardening, such as the lack of enforcement of secure transport protocols, missing standard security headers, and insufficient cross-site protection measures.
  • Too permissive transaction isolation settings lead to “dirty reads” in business-critical flows.
  • No structured database migration tool, identical to Application A.

What the client received

Assessed as-is status report
Maintainability, security posture, tech stack verdict, and DevOps maturity per system. Every finding is traceable and source-based.
Top 10 immediate measures
The ten findings per system to be addressed first, prioritized by impact and effort.
Strategic Evolution Roadmap
Five explicit options (Continue Operation → Stabilise → Strangler Fig / Lift & Shift / Full Rewrite) evaluated according to effort, risk, time-to-value, and long-term costs.
Service takeover checklist
Structured handover document for operations, CI/CD, runbooks, and team transfer, which is immediately implementable.
Interactive dashboard
17 page types form a central basis that the client can navigate, search, and present internally.
Graphic about managed legacy service

The decision the client can now stand by

Before the Fast Check, the general consensus was that the systems were outdated. Afterwards, a reliable assessment based on the code itself was available for the first time. This showed where the problems lay and what effort and costs could be expected.

Would you like this result for your system?

The Legacy Fast Check offers reliable external insights, including structured scores, a comprehensive risk register and prioritised recommendations for action. Act now!

Request a Legacy Fast Check
A picture of our contact person for Artificial Intelligence, Michael Hess.