A control system installed twenty years ago is still running the same PLC, the same wiring, and in some cases the same operator interface it shipped with. It also works. That combination, old but functional, is exactly what makes the modernization decision difficult. Nothing is forcing an operator’s hand the way an outright failure would, yet the case for upgrading rarely goes away either.
Two paths dominate the conversation. The first, commonly called rip-and-replace, removes the legacy system entirely and installs a new one in a single, concentrated project. The second, layered modernization, adds governed logic and modern data capability on top of the existing control system without removing what already works.
Neither is universally correct. Each answers a different set of constraints, and the honest version of this decision requires being specific about which constraints actually apply to a given facility.
What Rip-and-Replace Actually Solves
Full replacement has a real advantage that is easy to undervalue: it eliminates the legacy system entirely, along with every problem specific to that system. There is no longer a proprietary protocol nobody remembers how to service. There is no longer a dependency on a subject matter expert whose knowledge of the original installation is not written down anywhere. The facility starts over with current-generation hardware and current documentation.
That advantage comes from also being the source of its cost and risk. A full replacement typically requires a concentrated production outage, and the size of that outage tends to scale with the complexity of the system being replaced rather than with the operator’s budget flexibility. The project also concentrates risk into a single cutover window: if something goes wrong during that window, the facility is not partially degraded, it is down.
Where Full Replacement Genuinely Makes Sense
Rip-and-replace tends to be the right call in a narrower set of circumstances than the framing usually suggests:
- The legacy system is so obsolete that no vendor support, spare parts, or qualified technicians remain available at any reasonable cost
- The facility is already scheduling an extended outage for other reasons, making the incremental cost of a full controls replacement lower than it would be as a standalone project
- The existing system’s proprietary protocols create a security exposure that layered modernization cannot adequately address
- The organization has the capital budget and outage tolerance to absorb concentrated risk in exchange for a clean, fully current starting point
Outside these conditions, the case for full replacement weakens considerably, and the tradeoffs start to favor an approach that does not require betting an entire facility’s uptime on a single cutover.
What Layered Modernization Actually Solves
Layered modernization takes a different position on the same underlying problem. Instead of removing the legacy system, it adds a governed logic and data layer on top of it, standardizing alarm structure, reporting, and control governance across existing hardware without requiring the hardware itself to change. This is the core mechanism behind automation process controls designed for layered deployment: the legacy PLC keeps running. What changes is what sits above it.
This approach directly addresses a dependency that rip-and-replace mostly ignores: the people who understand the original system. According to Deloitte and the Manufacturing Institute’s 2024 talent study, manufacturers will need to fill roughly 3.8 million positions between 2024 and 2033, with as many as 1.9 million of those roles potentially going unfilled. The engineers who know a legacy system’s undocumented quirks are part of that same shrinking labor pool, and a modernization approach that captures and standardizes their knowledge into governed logic, rather than requiring them to be replaced along with the hardware, is directly responsive to a labor market that is not getting easier to hire into.
Layered modernization does not eliminate legacy risk. It manages it differently. The proprietary PLC still exists underneath the new logic layer. What changes is that the organization is no longer solely dependent on the one or two people who understand it, because the governed layer captures and standardizes what used to live only in someone’s head.
Where Layered Modernization Genuinely Makes Sense
The conditions favoring a layered approach mirror, almost exactly, the conditions that make full replacement risky:
- The facility cannot tolerate an extended production outage without severe financial consequence
- The existing hardware, while old, remains functionally reliable and not a genuine safety or security liability on its own
- The operator manages multiple facilities and needs a way to standardize governance and reporting across a mix of equipment ages and vendors without a synchronized capital replacement cycle
- The capital budget favors a lower upfront cost with continued investment over time, rather than one large concentrated expenditure
The Real Decision Criteria
This is why the CISA-led federal guidance on operational technology asset inventory explicitly frames the decision as a cost comparison rather than a default answer. The joint guidance from CISA and its federal and international partners instructs operators to compare the costs of potential downtime or degraded service against the cost of replacing vulnerable legacy systems, or deploying compensating controls that manage the risk without full replacement. That framing treats layered modernization, in the form of compensating controls and governed logic layered onto existing systems, as a legitimate risk management strategy on equal footing with replacement, not a lesser substitute for it.
The table below summarizes how the two paths compare against the factors that actually drive the decision:
| Factor | Rip-and-Replace | Layered Modernization |
| Upfront capital cost | High, concentrated | Lower, distributed over time |
| Production outage required | Yes, typically extended | Minimal to none |
| Dependency on legacy subject matter experts | Eliminated | Reduced through captured, standardized logic |
| Risk profile | Concentrated in a single cutover window | Distributed across a longer implementation |
| Best fit | Fully obsolete systems with no vendor support | Functional legacy systems needing governance and visibility |
Neither Path Is a Default Answer
The mistake most operators make is not choosing the wrong path. It is treating the choice as ideological rather than situational, defaulting to whichever approach their organization has always used regardless of whether the facility in front of them actually matches the conditions that make that approach the right one.
This mirrors a broader pattern McKinsey has documented in manufacturing more generally: organizations often assume a single, uniform standard should apply across every facility in a portfolio, then discover that rigid, one-size-fits-all standards prove unworkable once they reach sites with genuinely different equipment, ages, and operating conditions. The same logic applies at the level of an individual modernization decision. A single default answer, applied without regard to the specific facility’s constraints, produces the same mismatch between policy and reality that shows up when a corporate standard is imposed uniformly across a diverse portfolio.
A facility running a genuinely obsolete system with no available support and enough budget flexibility to absorb an extended outage is a legitimate rip-and-replace candidate. A facility running older but functionally sound equipment, where the real gap is governance, visibility, and standardized reporting rather than fundamental hardware failure, is a legitimate candidate for layered modernization instead.
The right answer depends on which of those two facilities is actually in front of the decision-maker, not on which approach sounds more thorough on paper. An organization managing a multi-site portfolio will likely find both paths represented across its own facilities simultaneously: some sites genuinely warrant full replacement, while others would only accumulate unnecessary cost and outage risk from an approach better suited to a different set of conditions. Treating modernization as a portfolio-level decision, rather than a single policy applied uniformly, is what allows each facility to get the approach its actual condition warrants.






