Everything you are saying makes perfect sense, but that just isn't how big businesses work. Nobody wants their head on that chopping block so the only way that happens is if all the external parties are demanding it because of some regulatory changes that require the application be replaced and even then there will be meetings upon meetings upon meetings and even then they will stall to see if someone can find a clever work around that meets the new requirements. If all the external parties agree to the risks (they won't) and agree to the potential downtime(s) then the new code may move forward. These are incredibly rare events. I've seen a few of these in my lifetime and I am currently retired. Just to get SSLv2 deprecated in most of the customers took a very long time and very delicate hand holding every step of the way. Some customers just couldn't upgrade so they were assigned a special load balancer IP and strict firewall rules just for their companies. Most old crusty applications die with the company assuming it is not taken over in bankruptcy in which case some new people get to deal with it.