Infrastructure & Migration

Firewalls, Switches, and Routers: How Old Is Too Old?

Firewalls, Switches, and Routers: How Old Is Too Old?

Network hardware is easy to forget about precisely because, when it's working, it is completely, wonderfully invisible. Nobody stands around admiring the firewall. Nobody thinks about the switch under the desk until something gets through it or stops working entirely. That invisibility is exactly why so many small businesses are quietly running gear that stopped being genuinely safe years before anyone had any reason to notice, because why would you go looking for a problem in the one part of the office nobody looks at?

Nobody sends you a retirement notice

This is the core of the problem, and it's worth saying plainly: hardware doesn't announce when it becomes a liability. Manufacturers eventually stop supporting older firewall, switch, and router models, no more firmware updates, no more security patches, sometimes no more technical support of any kind, and the device simply keeps humming along exactly as it did the day before. It looks identical on the day support ends and the day after. There is no flashing light. There is no email, usually, unless you happen to be subscribed to a very specific manufacturer newsletter that almost nobody reads.

A rough, honest guide to lifespan

  • Firewalls: typically 5 to 7 years before hardware capability and threat coverage fall meaningfully behind
  • Switches: often 7 to 10 years, but check specifically for firmware support cutoffs rather than assuming age alone tells the story
  • Routers: similar to switches, though consumer-grade equipment (the kind that looks suspiciously like something from a home electronics aisle) ages faster than proper business-grade gear
  • Wireless access points: 5 years is a reasonable planning horizon, given how quickly wireless security standards move

The signs your hardware has quietly aged out

Look for a manufacturer that no longer lists your specific model as actively supported, firmware that hasn't been updated in more than a year, or a device that simply cannot run modern security features your business now actually needs, like current VPN standards or updated threat detection. None of these signs are dramatic. They're the network equivalent of a car that still starts every morning but hasn't had its brakes checked since a previous government was in office.

Why this matters more today than it used to, and it's not your imagination

The threat landscape has moved considerably faster than most small businesses' hardware refresh cycles. A firewall that was appropriately capable five years ago is now being asked to defend against attack techniques that simply didn't exist when it was installed, the way a five-year-old smartphone can technically still make calls but is a strange choice for running today's software. It's not that the device is broken. It's that the device was never equipped for the job it's currently, quietly, being asked to do.

"But it still works fine" is not the test

This is the trap that catches even careful, attentive business owners. Hardware failing to actively malfunction is not the same as hardware being safe. A switch can pass traffic perfectly well right up until the exact moment its outdated firmware becomes the specific door an attacker walks through. Working and secure are two different questions, and it's genuinely reasonable that nobody explained that distinction to you before now, because most vendors have very little incentive to bring it up.

Budgeting for a refresh without buying a small data centre

This doesn't mean acquiring enterprise-grade equipment sized for a company ten times your headcount, and it definitely doesn't mean panic-buying the most expensive option on a rushed timeline. It means matching hardware to your actual traffic, your actual risk profile, and your actual budget, and then planning the next refresh calmly before this one quietly becomes an emergency dressed up as a Tuesday afternoon.

A five-minute gut check

  • Do you know the make and model of your current firewall, off the top of your head? If not, that's completely normal and also worth finding out.
  • Has anyone checked its firmware update history in the last year?
  • If you called the manufacturer today, would they still recognize the model as something they support?

A quick audit of your current network hardware, model numbers and firmware versions included, is usually enough to tell you exactly where you stand, in about the time it takes to have a coffee. If a refresh is genuinely overdue, we'll size the replacement to your business, not to a sales quota, and definitely not to make you feel bad about how long it's been.

Keep Reading

More on this topic