RATE THIS ANSWER
+3
Click to Vote:
3
0
Best way is to jot down the vulnerabilities, risks and threats involved, classifying them in major/minor, and what would be their implications on your setup, security, and business. If Security manager is not convinced still, prove it by actual figures happening in the organization due to these outdated software/ devices.
If still this exercise does not open the eyes of Security Manager, he does not deserve to be a Security Manager as he does not understand the implications and intricacies involved with threats, risks and vulnerabilities.