Our engineer left, we do not want to renew with the original vendor, but the system is still running and orders come in daily — can you take it over? That is the real scenario: a NT$30k/month admin staffer shows up with a set of servers nobody knows the passwords to and a three-year-old Word doc. A legacy takeover is the highest-risk outsourcing job — and the one that best builds long-term trust. Do it right, and you become the company long-term technical partner; do it wrong, and you eat the last team mess.
Myth-Busting
- Myth 1: It runs, so takeover should be quick. Reality: running is not changeable. On a system with no docs, no tests and expired dependencies, one line can trigger a cascade failure.
- Myth 2: Just rewrite it all — cleaner. Reality: a hasty rewrite is the most expensive takeover mistake. Tear it down before you understand the business rules and you will miss the implicit requirements hidden in the code.
- Myth 3: Getting the source code means takeover is done. Reality: source is one piece. Domain, hosting, database, payment accounts, DNS, certificates, third-party API keys — miss any one and you do not truly control it.
Core Framework: The 30-Day Risk Quadrant
Make the first job an inventory, not development. Map risk into four quadrants:
- Visible and high-risk: known breakage (expired certs, soon-to-lapse APIs) — handle in week one.
- Invisible and high-risk: unknown landmines (no backups, hardcoded keys, single points of failure) — surface via audit.
- Visible and low-risk: known small issues — into the backlog.
- Invisible and low-risk: tech debt — log it, do not rush.
Principle: establish observability and backups before you touch a single line of code.
Three Typical Scenarios
- Small (a five/six-figure e-commerce site, one WordPress plus plugins): risk in plugin dependencies and no backups. 30-day goal is full backup plus monitoring plus account handover, no architecture changes yet.
- Mid (member system plus custom admin, old Laravel): risk in lagging framework version and no tests (check the Laravel official support policy to see whether your version is still in security maintenance). 30-day goal is tests on critical paths plus upgrade roadmap, staged upgrades.
- Mature (multi-system integration incl. ERP/payments): risk in integration points and knowledge gaps. 30-day goal is system map plus interview remaining staff plus start ADRs (Architecture Decision Records).
Full Hidden-Cost List
- Inventory and audit labor: the first 30 days need ~40 to 80 engineering hours for inventory, environment restoration and doc-writing — usually underestimated.
- Cost of no tests: every change needs manual verification, halving dev efficiency — an implicit ~50% surcharge.
- Firefighting cost: early takeover is the most incident-prone period — reserve a contingency (~20% to 30% of the first month fee).
- Account-recovery cost: recovering forgotten domain/hosting/payment accounts may require vendor migration fees or support labor.
KPI Scorecard: Should We Even Take This On?
- ☐ Is there accessible source code and version history? (0 to 2)
- ☐ Is there any form of backup? (0 to 2)
- ☐ Can domain/hosting/DB/payment accounts be handed over? (0 to 3)
- ☐ Is the framework/language version still maintained? (0 to 2)
- ☐ Is there any remaining staff to interview? (0 to 2)
- ☐ Are the third-party APIs still valid? (0 to 2)
- ☐ Is there any automated testing? (0 to 2)
- ☐ Can anyone articulate the business rules? (0 to 3)
Below 8 total: sign a one-month paid health check before deciding on a long-term takeover.
ScriptWalker Fit + When It Does Not Fit
We offer a Legacy Health-Check Pack: within 30 days we complete backups, monitoring, account inventory, system map and upgrade roadmap, from NT$60,000, then decide maintenance retainer or revamp project by the roadmap. We will decline when:
- The client insists skip the inventory, just change what I say — we do not operate without observability.
- Accounts are unrecoverable and the original vendor will not cooperate — a black box, uncontrollable risk.
- The client just wants someone to blame and will not invest in basic backups and tests.
Transition Playbook (30/60/90)
- Days 1 to 30: Establish backups and monitoring, inventory all accounts, map the system, run the KPI scorecard, deliver a health-check report.
- Days 31 to 60: Add critical-path tests, fix visible high-risk items, build deploy and rollback flows.
- Days 61 to 90: Kick off phase-one upgrade or revamp per the roadmap, sign a maintenance SLA.
Decision Checklist
- ☐ Can I get the source and all accounts?
- ☐ Does the system have backups now?
- ☐ Do I know what it actually does daily?
- ☐ Can anyone articulate the business rules?
- ☐ Am I willing to health-check first, not rush features?
- ☐ Have I reserved a firefighting budget?
- ☐ Do I want long-term maintenance, or just to survive this?
FAQ
What is the first step when taking over an old system?
Not changing features — inventory plus backup. First ensure full backups and basic monitoring, recover all accounts, map the system and understand its daily behavior, then touch any code. Reversing that order is the number-one cause of takeover crashes.
How do you understand a system with no documentation?
Three ways: reconstruct business rules from code and database structure, interview remaining staff and users, and observe real traffic with monitoring. Along the way we write docs and ADRs so whoever inherits it in six months has a map.
Why do you not recommend a full rewrite up front?
Because legacy systems hide many undocumented implicit business rules; rewriting before you understand them guarantees omissions. The right path is stabilize, add tests, map a roadmap, then replace high-risk modules in stages.
How much and how long is a takeover health check?
ScriptWalker Legacy Health-Check Pack completes in 30 days from NT$60,000, delivering backups, monitoring, account inventory, system map and upgrade roadmap. After that you decide a maintenance retainer or revamp project.
Call to Action
Got a system nobody dares touch but cannot stop? Do not rush to rewrite. Book a free 30-minute consult and we will help you judge whether it needs a health check, maintenance, or a staged revamp:
- Email: [email protected]
- Phone: 0916-224-047
- LINE: @ufv9089p