Windowed, Not Fixed: The Long Bill of How We Survived Y2K
Fear had funded the work, and once the fear was gone, so was the argument for doing anything more.
The Silence at Midnight
For three years it was the only date that mattered. Boards that had never once asked how the payroll actually ran suddenly wanted personal assurance about it. Programmes that could not be funded on their merits were funded overnight because they touched it. And then the first of January arrived, the clocks rolled over, the lifts kept working and the cash machines kept paying, and within a fortnight the whole affair had acquired the faintly embarrassing air of a party everyone had over-catered.
Nearly a year on, it is tempting to file the millennium under “expensive false alarm” and move along. That would be a mistake. The interesting question was never whether the systems would survive the rollover — almost all of them did — but how each organisation chose to make them survive. That choice, taken quietly through 1998 and 1999 under enormous time pressure, sorted organisations into two camps whose fortunes are only now beginning to diverge. One camp treated the deadline as a nuisance to be survived at least cost. The other treated it as the single chance in a generation to renew an estate everyone knew was ageing and no one could otherwise get funded. The first camp looked far cleverer in January. I am no longer sure they will look clever in 2005.
Two Roads to the Same Midnight
Strip away the acronyms and the war rooms, and the remediation was, at bottom, a choice between two philosophies.
- Fix the symptom. Find every place a two-digit year could be misread and make the minimum change that carries the system safely past the date. In practice this usually meant windowing: teaching the code a pivot year, so that “27” is read as 2027 and “54” as 1954, without ever storing the century at all. Cheap, fast, low-risk — and, this is the part that matters, invisible in its consequences until much later.
- Renew the asset. Use the mandate, and the money it unlocked, to actually replace or re-platform the systems that were most exposed — to expand the dates properly, retire the most decrepit code, migrate onto a packaged system, and leave behind something documented and maintainable.
In the winter of 1999 the first road looked obviously superior, and for entirely respectable reasons. It was faster, so it fit the deadline. It was cheaper, so the board loved it. And it was far less likely to fail on the night — which, when the downside was cheques not clearing and a name in the newspaper, was the consideration that trumped all others. The organisations that windowed their way to compliance came in on time and under budget, passed the rollover without a tremor, and were quietly proud of having called the hysteria correctly.
I have sat in the review meetings where those teams were congratulated, and the congratulations were deserved: they had done exactly what they were asked to do. The trouble is that what they were asked to do and what they needed to do had quietly come apart, and no one in the room was paid to notice the gap.
Windowing Was a Loan, Not a Repair
Here is the mechanism the celebrations obscured. Windowing does not remove the date problem. It relocates it to the edge of the window and sets a timer.
Picture a composite that will be familiar to anyone who spent those years in financial services: a long-established insurer running its policy administration on a two-decade-old mainframe system, hundreds of thousands of lines of COBOL, much of it written by people who had long since retired. Two divisions of the same firm took the two roads. The life division, cautious and cost-conscious, windowed everything on a pivot of 1930 to 2029 and sailed through the rollover having spent perhaps three million pounds. The pensions division, with a bolder head of IT, used its share of the Y2K budget to begin migrating onto a packaged administration platform, spent closer to twelve million, ran late, and was still stabilising the new system in the spring of 2000 while its sister division was already taking a victory lap.
Twelve months later the picture has begun to invert. The life division’s windowed system has started, very occasionally and very expensively, to misfile policies with maturity dates past 2029 — the thirty-year endowments and the whole-of-life contracts whose dates fall on the wrong side of the pivot and are read as 1930 rather than 2030. Each error is small; each investigation is not, because the people who understood the code well enough to trace it were contractors, hired at the very top of the market for exactly this work, who left the day the project closed. The documentation they produced described what had been changed for compliance, not how the system actually worked. The knowledge walked out of the door, and the day rate to bring it back — for the few who still read the language — has not fallen.
Windowing did not fix the date problem; it rented a solution and post-dated the invoice. The rollover everyone feared was not cancelled. It was quietly rescheduled for a year when there would be no programme, no budget, and far fewer people left who could read the code.
The pensions division, meanwhile, spent more, suffered more, and looked reckless for eighteen months. But it now runs a documented, supported, current system, staffed by people who understand it, with the century stored properly and no timer ticking underneath it. It bought a decade. Its sister division bought a delay and told itself the delay was a triumph.
The Certificate That Did the Real Damage
If the story ended with a deferred technical bill it would be an ordinary tale of short-termism. What makes the millennium different — and worse — is the certificate.
Every serious remediation programme ended by declaring its systems compliant. That declaration was necessary; auditors and boards required the comfort. But it had a second effect almost no one intended. A system that has just been formally certified as sound is a system that cannot easily be replaced. The very document that closed the Y2K programme became the strongest available argument against any future investment in renewal.
- For a decade these systems had been quietly understood as legacy — old, fragile, overdue for replacement, tolerated only because no one could find the money.
- The millennium provided the money, on a scale never seen before, and unlikely to be seen again for work this unglamorous.
- And the money, in the windowing camp, was spent in a way that produced a piece of paper certifying that the legacy was fine.
So the one budget that could have renewed the estate was used to re-legitimise it. The next time someone proposes replacing the policy system, the answer will be that it passed the millennium without a hitch — as though surviving a date rollover were evidence of fitness for another twenty years. Fear had funded the work, and once the fear was gone, so was the argument for doing anything more. That is how an organisation arrives, at the end of 2000, with core systems that are a year older, no better understood, formally blessed, and further from replacement than they were in 1997.
The Case for Having Patched
It would be too easy, and a little dishonest, to leave the windowing camp condemned. There is a serious argument on their side, and it deserves its strongest form.
The deadline was real and the downside was catastrophic. When failure means a payment run that does not complete, the responsible engineer chooses the smallest, most predictable change — not an ambitious re-platforming that might itself fail on the worst possible night. Nor were the big renewal programmes launched under Y2K cover all triumphs; plenty overran spectacularly, and some of the packaged-system migrations of those years delivered less than the code they replaced, at several times the price. Windowing, on this account, was not cowardice but discipline: do one thing, do it safely, and do not gamble the business on a promise of modernisation that so often goes unkept. And consider, the advocate might add, the world of this very winter — the froth coming off the technology market, the once-limitless capital for anything with an “e-” in front of it evaporating by the week. Is this really the moment to wish more firms had bet twelve million on renewal?
It is a strong case, and on the night it was the right one. But it proves less than it claims. The choice was never only between a safe patch and a risky rebuild. The third option — the one most organisations skipped straight past — was to make the safe patch and use the mandate to fund the plan, the documentation, the retention of scarce skills, and the first orderly stage of a renewal that could then proceed at a sane pace. Windowing to survive the night was prudent. Windowing and then declaring the problem solved was the error. The market reversal actually sharpens the point rather than softening it: capital for this kind of work will be scarce for years now, which makes the squandering of the one guaranteed budget more costly, not less. The patchers did not merely choose safety. They spent the renewal fund on survival and then threw away the receipt that said renewal was still needed.
“The organisations that merely survived the millennium will pay for it twice — once in the deferred repair, and again in the years of neglect their own certificate bought.”
What the Next Mandate Is Really For
There will be another deadline. It will not be the millennium, but it will have the same shape: an external, immovable date, a catastrophic downside, and a sudden willingness to fund work that could never be justified on its own merits. When it comes, the lesson of the last one is worth having ready.
A forced remediation is a forced renewal in disguise, and the gap between the organisations that grasp this and those that do not will not show up on the night. It shows up eighteen months later, in whether the money left behind an asset or an alibi. The questions to press, while the budget is still open, are unglamorous and decisive. When this fix is done, will we understand our own systems better or worse than before? Will the people who did the work, and the knowledge they built, still be with us? And are we buying a repair — or a certificate that will be used to argue against the repair for the next ten years?
The systems most organisations carried across the millennium are the same systems they will still be running in 2010. That was decided not on the first of January, but in the quiet, sensible, much-congratulated choices of the year before. Surviving the deadline was the easy part; everyone managed that. The organisations that used it to renew rather than merely to survive are the ones who will look, a decade from now, as though they saw something the rest of us were too relieved to notice.