Skip to content
Artifisys
Menu
Start a conversation Talk to us

Public sector · UK & Europe

Seven of ten critical legacy systems flagged for modernisation were not modernised.

Of $10.9 billion allocated across 24 programmes, more than half encountered failure.

7 of 10

critical defence legacy IT systems flagged for modernisation had not been modernised.

Source: GAO-25-107795: Agencies Need to Plan for Modernizing Critical Legacy Systems

In the UK and Europe

This is what it actually runs on here.

Platforms in this market

  • air-gapped networks
  • on-premise deployment
  • on-device inference
  • MOD legacy interfaces

Rules that apply here

  • DEFCON 658 cyber risk
  • JSP 440 security
  • NATO STANAG interfaces
  • Cyber Essentials Plus

We read the rule before the call. It is the cheapest way to prove we did the work.

What is happening

The system works. It just cannot be reached from anywhere it is needed.

$10.9B Allocated, and more than half of programmes hit failure

Inaccurate cost and schedule estimates, uncontrolled scope expansion, inadequate cloud migration planning and missing cybersecurity strategies.

Requirements outlive the systems built to meet them

A multi-year programme is specified against a threat picture that has moved by the time it delivers.

Data is classified, distributed and disconnected

Which is correct from a security standpoint, and means the operational picture has to be assembled by people.

Modernisation is treated as replacement

The highest-risk possible approach, applied to the systems where risk is least acceptable.

However hard, whatever it is

Air-gapped modernisation is one example. Bring the harder one.

This page is about reading a legacy system with no internet. If yours is test data, supply assurance or something you cannot name here, say so on the call.

  1. 01

    We sit with you

    Days where the work happens, not a workshop in a meeting room. We watch the job get done and write down the shortcuts nobody wrote down.

  2. 02

    We read everything

    Your data, your rules, your vendors and their documentation, and the published research on your sector. We report what is actually in there.

  3. 03

    We break it to first principles

    Not which tool fixes this. What is actually causing it, taken apart until we reach the piece that cannot be divided further.

  4. 04

    Then we build

    Weeks, not quarters. By this point we are not guessing what to build, and guessing is the thing that makes projects long.

Where we sit

It stays inside your wire. We build for a network with no internet at all.

4

What you get

  • Incremental Capability delivered in months, not programme cycles
  • Air-gap ready Architectures that work in disconnected environments
  • Auditable Provenance and access logged as a design property
3

Built new for you — none of this exists in your stack today

  • A rugged box that runs the model with no network
  • A one-way feed out of the legacy mainframe
  • A dashboard that works with the link down
2
The on-premise layer Runs air-gapped. No data leaves the network. No cloud call, ever. Connectors, one agreed meaning per field, and a model reading what no field holds. Accuracy measured on your own records.
1
  • air-gapped networks
  • on-premise deployment
  • on-device inference
  • MOD legacy interfaces

What you already run — unchanged, and still yours

No internet is not a limit. It is a requirement we design for. A mainframe behind a one-way feed, a radio link that drops, a box with no network at all. We have built for each.

  • No API
  • No documentation
  • A terminal from 1994
  • It arrives as paper
  • The vendor said no
  • It reports nothing

Not a list of limits. Name yours on the call.

And once we can reach it, a model can read it. Most of the value here is in the sources nobody ever structured — the note, the letter, the screen.

Intelligence, plumbed in

The model runs inside your wire. No data leaves the network.

On-device inference on hardware we specify and build, with no cloud call to make and nothing to call out to.

How we make AI survive real data
  • Connectors
  • A semantic layer
  • Evals you can check

What changes

Judge us on this, not on what we built.

Incremental

Capability delivered in months, not programme cycles

Small, verifiable increments around existing systems, each useful alone.

Air-gap ready

Architectures that work in disconnected environments

Local-first, on-device inference where required, and designed for intermittent or absent connectivity.

Auditable

Provenance and access logged as a design property

Not added at accreditation time, when it is most expensive.

Who this is for

The people who feel this first

  • Programme Manager
  • Chief Technology Officer
  • Head of Digital
  • Systems Integration Lead
  • Security Accreditation Lead

Straight answers

The questions you would ask on the call

  • Can you work in air-gapped or classified environments?

    We build for it architecturally — local-first data, on-device inference, no dependency on external services at runtime. We have shipped fully offline inference with encrypted local storage. Clearance and accreditation requirements are jurisdiction-specific and we would work within whatever your programme requires.

  • Why do defence modernisation programmes fail so consistently?

    The GAO findings point at cost and schedule estimation, scope expansion and migration planning. Underneath all three is scale: multi-year replacement programmes cannot absorb changing requirements. Incremental delivery around the existing system can.

  • How do you handle security requirements?

    As design constraints from the first day rather than a review at the end. Encryption, access logging, data minimisation and provenance are cheap to build in and expensive to retrofit.

  • Can AI run on an air-gapped network?

    Yes. Inference runs on hardware we specify and build, inside your wire. There is no cloud call and nothing to call out to.

Do you know the rules that apply in the United Kingdom, Ireland and the European Union?

For defence that means DEFCON 658 cyber risk, JSP 440 security, NATO STANAG interfaces and Cyber Essentials Plus. We read the rule before the call, so the first meeting is about your operation rather than about us catching up.

Whatever defence needs here, we can make it.

What you already run stays where it is. Around it we build software, hardware and the process itself. Here that means a rugged box that runs the model with no network.

See everything we build
  • Software
  • Hardware
  • Ways of working
  • Whole ventures

Honest about the numbers

The figure above is from GAO-25-107795: Agencies Need to Plan for Modernizing Critical Legacy Systems, for defence.

We have not localised it, because a number nobody can check is worth less than a real one plus this sentence. The pattern travels. The size of it in your market is a question for the call.

Same industry, other markets