Running unsupported Dynamics NAV exposes your organisation to serious security risks. Without active vendor support, Microsoft no longer releases security patches for the software, meaning every newly discovered vulnerability remains permanently unaddressed. This leaves your ERP environment open to exploitation, and the risk grows with every month you remain on an unsupported version. The sections below walk through the specific threats, compliance implications, and what to do about them.
What happens to security patches when Dynamics NAV loses support?
When Dynamics NAV reaches end of support, Microsoft stops releasing security updates for that version entirely. Any vulnerability discovered after that date will not be patched, regardless of how serious it is. Your system continues to function, but the security foundation underneath it quietly deteriorates over time.
Microsoft’s support lifecycle for Dynamics NAV follows a defined timeline. Mainstream support ends first, which is when new features and non-security fixes stop. Extended support follows, covering security updates only. Once extended support ends, both stop completely. Several older NAV versions, including NAV 2015, NAV 2016, and NAV 2017, have already passed both stages and are now fully unsupported.
The practical consequence is straightforward: attackers actively monitor Microsoft’s patch release notes. When a patch is issued for a supported product, security researchers and threat actors reverse-engineer it to understand the underlying vulnerability. Systems still running unsupported versions that share similar code are then targeted directly, because there is no patch coming, and the exposure is permanent.
What types of cyber threats target unsupported ERP systems?
Unsupported ERP systems face a range of cyber threats, with ransomware, data exfiltration, and privilege escalation being the most common. Because these systems hold sensitive financial, operational, and customer data, they are high-value targets. The absence of security patches makes exploitation significantly easier for attackers with moderate technical capability.
The most relevant threat types for organisations running legacy Dynamics NAV include:
- Ransomware attacks: Attackers exploit known, unpatched vulnerabilities to gain access to the system, encrypt business-critical data, and demand payment. ERP systems are attractive targets because operational disruption creates immediate financial pressure.
- Credential theft and privilege escalation: Unpatched authentication flaws can allow attackers to steal user credentials or elevate their access rights within the system, potentially reaching financial records, supplier data, or payroll information.
- Supply chain attacks: If your NAV environment connects to partner systems, customer portals, or third-party integrations, a compromised NAV instance can become an entry point into a broader ecosystem.
- Data exfiltration: Sensitive business data, including pricing models, contracts, and customer records, can be quietly extracted over extended periods without triggering obvious alerts.
The longer a system runs without patches, the larger the catalogue of publicly known vulnerabilities becomes. This is not a theoretical risk; it is an operational one that compounds over time.
Does running unsupported NAV create compliance and regulatory risk?
Yes, running unsupported Dynamics NAV creates real compliance and regulatory risk. Many frameworks, including GDPR, ISO 27001, NIS2, and industry-specific standards, require organisations to maintain software in a supported and patched state. Operating on unsupported software can constitute a failure to implement appropriate technical measures, which is a documented compliance gap.
Under GDPR, organisations are required to implement appropriate technical and organisational measures to protect personal data. Regulators have taken the position that running software with known, unaddressed vulnerabilities does not meet this standard. In the event of a data breach involving an unsupported system, the absence of patches becomes a significant factor in determining liability and the scale of any fine.
For organisations subject to NIS2, which came into force across EU member states and directly affects many multinationals operating in the Netherlands and Belgium, the requirements are even more explicit. Cybersecurity risk management obligations include keeping software current and ensuring that known vulnerabilities are addressed. Running unsupported NAV is in direct conflict with these requirements.
Beyond regulatory exposure, cyber insurance policies increasingly exclude claims arising from known vulnerabilities on unsupported software. Before assuming your policy covers a breach on a legacy NAV system, it is worth reviewing the terms carefully.
How does unsupported software affect data integrity and business continuity?
Unsupported Dynamics NAV software affects data integrity and business continuity in two distinct ways: through security incidents that corrupt or expose data, and through technical degradation as the surrounding technology stack evolves while NAV stays static. Both risks increase over time and can cause serious operational disruption.
On the data integrity side, a successful attack on an unpatched system can result in data corruption, unauthorised modification of financial records, or the silent exfiltration of transactional data. Recovering from this kind of incident is expensive, time-consuming, and sometimes incomplete, particularly when the compromise has been running undetected for weeks or months.
On the continuity side, unsupported NAV creates growing compatibility problems. Operating systems, browsers, and third-party integrations continue to update, and at some point they stop working reliably with a static, unsupported NAV version. This can cause unexpected failures in day-to-day operations, from broken integrations with logistics partners to reporting tools that no longer function correctly.
When a migration eventually becomes necessary, organisations that have delayed the decision often face a more complex transition. Data quality deteriorates over time, customisations accumulate without documentation, and the gap between the legacy environment and a modern platform widens. data migration and ERP transformation services exist precisely to manage this complexity, but the earlier the move begins, the lower the risk.
When should an organisation migrate away from legacy Dynamics NAV?
An organisation should begin planning a migration away from legacy Dynamics NAV as soon as it is running a version that has reached or is approaching the end of extended support. Waiting until the system fails or a security incident forces the decision significantly increases both cost and risk. The right time to act is before the pressure becomes urgent.
Several signals indicate that migration planning should start immediately:
- Your NAV version has passed its extended support end date
- Your IT or security team cannot confidently answer whether known vulnerabilities have been addressed
- Your cyber insurer has raised questions about your ERP environment
- Integrations with other business systems are becoming unstable or require workarounds
- A regulatory audit or internal review has flagged the unsupported system as a risk
- The business is growing in ways that the current NAV environment cannot support
The destination for most organisations moving off NAV is Microsoft Dynamics 365 Business Central, which is the modern successor and shares architectural DNA with NAV. The migration path is well established, though it requires careful planning around data migration, process redesign, and user adoption.
A structured starting point is a maturity assessment that maps your current environment, identifies risks, and defines a realistic roadmap before any budget is committed. This kind of baseline review helps organisations understand exactly where they stand, which avoids the common mistake of underestimating scope or overcommitting to a timeline that the organisation is not ready to support. Exploring your ERP transformation options early gives you the most flexibility to plan the transition on your terms rather than under pressure.
How Optinus helps with Dynamics NAV security and migration risk
We work with organisations across the Netherlands, Belgium, and internationally to manage the full journey from legacy ERP environments to modern, supported platforms. When it comes to unsupported Dynamics NAV, we address both the immediate risk picture and the longer-term migration path.
- Maturity assessment: We start by mapping your current ERP environment, identifying security gaps, compliance exposures, and technical debt before any migration decision is made.
- Data migration management: We use rigorous As-Is/To-Be analysis and testing procedures to ensure data integrity throughout the transition, preventing data loss or errors during the move to Business Central or another target platform.
- Cutover management: We plan and monitor the go-live transition end to end, including hypercare and aftercare, so operational continuity is protected at the most critical moment.
- Change management: We support your teams through the behavioural and process changes that come with a new system, driving genuine adoption rather than just delivering training sessions.
- On-site and remote delivery: Our consultants are available to embed on-site or work remotely, depending on what your programme requires.
If your organisation is running unsupported NAV and you want a clear view of the risks and a practical path forward, we can help you get started. Take a look at our ERP migration and transformation services to see how we approach these projects, or get in touch with us directly to discuss your specific situation.