

To an extent, institutional inertia. If it ain’t broke, don’t fix it.
Adopting new systems brings in a layer of uncertainty, sure maybe there is some upside to the new system, but does it outweigh the risk and cost of overhauling all the dependencies of the old system? Can you be sure that all the relevant stakeholders and partners will be onboard with the new system, or will some reject it and insist on the old system, thus requiring everyone to maintain two standards.
It’s much easier to adopt a new system when the old system is clearly non-functional and untrustworthy, or when there just wasn’t an earlier system that did that function in a given economic environment. The more important the institution, the more issue it causes if it fails, the more this applies.




There are way more people who can attempt a hack than can attempt to break in.