Architectural technical debt as a source of systemic cyber risk in critical digital infrastructure
Abstract
Critical digital infrastructure faces a category of cyber risk that is structurally embedded rather than operationally introduced. Existing cybersecurity discourse has concentrated on known vulnerabilities, patch compliance, and incident response; however, it has largely neglected the role of accumulated architectural deficiencies as a foundational enabler of systemic risk. This paper conceptualises Architectural Technical Debt (ATD) as the aggregate of deferred structural decisions, inherited legacy constraints, and design-era compromises that cumulatively increase system complexity, erode trust boundaries, and amplify cyber risk in operational technology and critical digital infrastructure environments. Drawing on technical debt theory, systems theory, resilience engineering, and socio-technical systems perspectives, this paper develops a formal definition of ATD, identifies its primary sources, proposes a six-category taxonomy, and constructs a seven-stage causal model tracing the pathway from architectural debt accumulation to operational disruption. The paper further proposes a formal set of testable propositions supporting future empirical validation, an Architectural Technical Debt Maturity Model, an ATD Assessment Matrix, and an Architectural Technical Debt Index (ATDI) formulation for future quantification research. Implications are derived for operators, regulators, and policymakers, with particular attention to the compounding ATD burden characteristic of resource-constrained emerging economy contexts, including illustrative reference to sub-Saharan African critical digital infrastructure.
Received 29 June 2026
Accepted 17 August 2026
Published 23 September 2026
Keywords
Full Text:
PDFReferences
K. Stouffer et al., “Guide to Operational Technology (OT) Security,” Nat. Inst. Stand. Technol., Gaithersburg, MD, USA, NIST SP 800-82 Rev.3, Jan. 2023, doi: 10.6028/nist.sp.800-82r3.
W. Cunningham, “The WyCash Portfolio Management System,” Addendum to the proceedings on Object-oriented programming systems, languages, and applications (Addendum) - OOPSLA ’92, vol. 4, no. 2, pp. 29–30, 1992, doi: 10.1145/157709.157715.
P. Kruchten, R. L. Nord, and I. Ozkaya, “Technical Debt: From Metaphor to Theory and Practice,” IEEE Software, vol. 29, no. 6, pp. 18–21, Nov. 2012, doi: 10.1109/ms.2012.167.
N. S. R. Alves, T. S. Mendes, M. G. de Mendonça, R. O. Spínola, F. Shull, and C. Seaman, “Identification and Management of Technical Debt: A Systematic Mapping Study,” Information and Software Technology, vol. 70, pp. 100–121, Feb. 2016, doi: 10.1016/j.infsof.2015.10.008.
P. Avgeriou, K. Philippe, I. Ozkaya, and C. Seaman, “Managing Technical Debt in Software Engineering (Dagstuhl Seminar 16162),” Dagstuhl Reports, vol. 6, no. 4, pp. 110–138, 2016, doi: 10.4230/DagRep.6.4.110.
C. Seaman and Y. Guo, “Measuring and Monitoring Technical Debt,” Advances in Computers, vol. 82, pp. 25–46, 2011, doi: 10.1016/b978-0-12-385512-1.00002-5.
J. D. Morgenthaler, M. Gridnev, R. Sauciuc, and S. Bhansali, “Searching for Build Debt: Experiences Managing Technical Debt at Google,” in 2012 Third International Workshop on Managing Technical Debt (MTD), Jun. 2012, pp. 1–6.
Z. Li, P. Avgeriou, and P. Liang, “A Systematic Mapping Study on Technical Debt and Its Management,” Journal of Systems and Software, vol. 101, pp. 193–220, Mar. 2015, doi: 10.1016/j.jss.2014.12.027.
N. A. Ernst, S. Bellomo, I. Ozkaya, R. L. Nord, and I. Gorton, “Measure It? Manage It? Ignore It? Software Practitioners and Technical Debt,” in Proceedings of the 2015 10th Joint Meeting on Foundations of Software Engineering, Aug. 2015, pp. 50–60.
International Electrotechnical Commission, “Security for Industrial Automation and Control Systems (IACS),” IEC 62443 Series (Parts 2-1:2009, 2-3:2015, 3-2:2013, 3-3:2013). Geneva, Switzerland: IEC.
MITRE Corporation, “ATT&CK for Industrial Control Systems (ICS),” attack.mitre.org. [Online]. Available: https://attack.mitre.org/matrices/ics/
X. Pàmies-Morell, J. Ros-Giralt, and J. Soué-Pla, “Technical debt in embedded systems: A systematic literature review,” IEEE Trans. Ind. Informat., vol. 17, no. 12, pp. 8447–8458, 2021.
S. Martínez-Fernández and et al., “Software architecture in the age of cyber-physical systems: A systematic mapping study,” Inf. Softw. Technol., vol. 146, p. 106826, 2022.
E. D. Knapp and J. T. Langill, Industrial Network Security: Securing Critical Infrastructure Networks for Smart Grid. SCADA, and Other Industrial Control Systems, 2nd ed. Waltham, MA, USA: Syngress, 2014.
C. Perrow, Normal Accidents: Living with High-Risk Technologies. New York, NY, USA: Basic Books, , 1984.
L. von Bertalanffy, General System Theory: Foundations, Development, Applications. New York, NY, USA: George Braziller, 1968.
M. Howard and J. Pincus, “Measuring relative attack surfaces,” in Workshop Adv. Develop. Softw. Syst. Security, 2003.
E. Hollnagel, D. D. Woods, and N. Leveson, Eds., Resilience Engineering: Concepts and Precepts. Aldershot, U.K.: Ashgate, 2006.
N. G. Leveson, Engineering a Safer World: Systems Thinking Applied to Safety. Cambridge, MA, USA: MIT Press, 2011.
E. L. Trist and K. W. Bamforth, “Some Social and Psychological Consequences of the Longwall Method of Coal-Getting,” Human Relations, vol. 4, no. 1, pp. 3–38, Feb. 1951, doi: https://doi.org/10.1177/001872675100400101.
S. Rose, O. Borchert, S. Mitchell, and S. Connelly, “Zero Trust Architecture,” NIST Special Publication 800-207, vol. 1, no. 800–207, Aug. 2020, doi: 10.6028/nist.sp.800-207.
National Institute of Standards and Technology, “The NIST Cybersecurity Framework (CSF) 2.0,” Nat. Inst. Stand. Technol., Gaithersburg, MD, USA, NIST CSWP 29, Feb. 2024, doi: 10.6028/nist.cswp.29.
U.S. Cybersecurity and Infrastructure Security Agency (CISA), “Shifting the Balance of Cybersecurity Risk: Principles and Approaches for Security-by-Design and Security-by-Default,” www.cisa.gov. [Online]. Available: https://www.cisa.gov/resources-tools/resources/secure-by-design
T. Besker, A. Martini, and J. Bosch, “Managing Architectural Technical Debt: A Unified Model and Systematic Literature Review,” Journal of Systems and Software, vol. 135, pp. 1–16, Jan. 2018, doi: 10.1016/j.jss.2017.09.025.
J. P. Biazotto, D. Feitosa, P. Avgeriou, and E. Y. Nakagawa, “Technical Debt Management Automation: State of the Art and Future Perspectives,” Information and Software Technology, vol. 167, p. 107375, Dec. 2023, doi: 10.1016/j.infsof.2023.107375.
F. Bi, B. Vogel-Heuser, Z. Huang, and F. Ocker, “Characteristics, Causes, and Consequences of Technical Debt in the Automation Domain,” Journal of systems and software/The Journal of systems and software, vol. 204, pp. 111725–111725, Oct. 2023, doi: 10.1016/j.jss.2023.111725.
Y. Yang, D. Verma, and P. S. Anton, “Technical Debt in the Engineering of Complex Systems,” Systems Engineering, vol. 26, no. 5, pp. 590–603, Apr. 2023, doi: 10.1002/sys.21677.
M. Masi, G. P. Sellitto, H. Aranha, and T. Pavleska, “Securing Critical Infrastructures With a Cybersecurity Digital Twin,” Software and Systems Modeling, vol. 22, no. 2, pp. 689–707, Jan. 2023, doi: 10.1007/s10270-022-01075-0.
O. Michalec, S. Milyaeva, and A. Rashid, “When the Future Meets the Past: Can Safety and Cyber Security Coexist in Modern Critical Infrastructures?,” Big Data & Society, vol. 9, no. 1, p. 205395172211083, Jan. 2022, doi: 10.1177/20539517221108369.
A. Staves, T. Anderson, H. Balderstone, B. Green, A. Gouglidis, and D. Hutchison, “A Cyber Incident Response and Recovery Framework to Support Operators of ICS and Critical National Infrastructure,” International Journal of Critical Infrastructure Protection, vol. 37, p. 100505, Jan. 2022, doi: 10.1016/j.ijcip.2021.100505.
N. F. Syed, S. W. Shah, A. Shaghaghi, A. Anwar, Z. Baig, and R. Doss, “Zero Trust Architecture (ZTA): A Comprehensive Survey,” IEEE Access, vol. 10, no. 2169–3536, pp. 57143–57179, May 2022, doi: 10.1109/access.2022.3174679.
Y. Jiang, M. A. Jeusfeld, M. Mosaad, and N. Oo, “Enterprise architecture modeling for cybersecurity analysis in critical infrastructures: A systematic literature review,” International Journal of Critical Infrastructure Protection, vol. 46, p. 100700, Sep. 2024, doi: 10.1016/j.ijcip.2024.100700.
E. C. Balta, M. Pease, J. Moyne, K. Barton, and D. M. Tilbury, “Digital Twin-Based Cyber-Attack Detection Framework for Cyber-Physical Manufacturing Systems,” IEEE Transactions on Automation Science and Engineering, vol. 21, no. 2, pp. 1695–1712, Apr. 2024, doi: 10.1109/tase.2023.3243147.
A. Regenscheid, “Transition to Post-Quantum Cryptography Standards,” NIST Interagency Report (IR) 8547, Initial Public Draft, National Institute of Standards and Technology, Gaithersburg, MD, USA, Nov, 2024, doi: 10.6028/nist.ir.8547.ipd.
W. Newhouse et al., “Migration to Post-Quantum Cryptography Quantum Readiness: Cryptographic Discovery Volume B: Approach, Architecture, and Security Characteristics of Public Key Application Discovery Tools,” 2023. [Online]. Available: https://www.nccoe.nist.gov/sites/default/files/2023-12/pqc-migration-nist-sp-1800-38b-preliminary-draft.pdf
H. I. Kure, S. Islam, and H. Mouratidis, “An Integrated Cyber Security Risk Management Framework and Risk Predication for the Critical Infrastructure Protection,” Neural Computing and Applications, vol. 34, no. 18, pp. 15241–15271, Feb. 2022, doi: https://doi.org/10.1007/s00521-022-06959-2.
P. Avgeriou et al., “Technical Debt Management: The Road Ahead for Successful Software Delivery,” in IEEE/ACM Int. Conf. Softw. Eng.: Future Softw. Eng. (ICSE-FoSE), Melbourne, Australia, May 2023, pp. 15–30.
X. Feng and S. Hu, “Cyber-Physical Zero Trust Architecture for Industrial Cyber-Physical Systems,” IEEE Transactions on Industrial Cyber-Physical Systems, vol. 1, pp. 394–405, 2023, doi: 10.1109/ticps.2023.3333850.
B. Kitchenham and S. Charters, “Guidelines for performing systematic literature reviews in software engineering,,” EBSE Technical Report EBSE-2007-01, Keele University and Durham University, U.K, 2007.
T. L. Saaty, The Analytic Hierarchy Process: Planning, Priority Setting, Resource Allocation. New York, NY, USA: McGraw-Hill, 1980.
A. Shameli-Sendi, R. Aghababaei-Barzegar, and M. Cheriet, “Taxonomy of Information Security Risk Assessment (ISRA),” Computers & Security, vol. 57, pp. 14–30, Mar. 2016, doi: 10.1016/j.cose.2015.11.001.
DOI: https://dx.doi.org/10.21622/ACE.2026.06.2.2297
Refbacks
- There are currently no refbacks.
Copyright (c) 2026 Cornelius Chipasha, Simon Tembo, Mulundumina Shimaponda
Advances in Computing and Engineering
E-ISSN: 2735-5985
P-ISSN: 2735-5977
Published by:
Academy Publishing Center (APC)
Arab Academy for Science, Technology and Maritime Transport (AASTMT)
Alexandria, Egypt


