I'm not sure why we laugh at
old systems that are still
doing their job
Because other countries are hacking our infrastructure, as we hack theirs, and those laughing are doing so nervously, because with an operating system that is decades out of date, it's painfully obvious that anything defended by a password protected user account on that operating system isn't really protected against a determined enemy at all, and any of the permissions and privileges conferred by user accounts on that system are likely a facade protected by an honor system, and mostly physical security.In truth, even if the operating system were newer, we would not want it hooked up to the internet, but if the operating system were up to date, and not well isolated and became exposed to any public gateways, it would stand a fighting chance of not spilling its guts to the world.
With such a system disconnected from the internet, one can still bet that a determined attack is going to implant remote connectivity under their own control, and their job is much easier once the implant is connected. They don't need to sweat OS level password rotation, probably won't worry about strong encryption key changes or having to prove identity to policy enforcement tools with signing keys or tokens. Very little in the way of locking the integrity of the system is built into the concept of the OS. The application layer may offer better protection with proprietary controls, but the contents of disk and RAM are very probably possible to dump, inspect, bit twiddle and write back in place to just do anything you want, if your expertise runs deep enough.