Cyber

Technical security debt

Accumulated gap between the security state of a system and the state it ought to present, created by trade-offs rational when taken and long lacking a maturity, a creditor and a unit of measurement.

Definition

The word debt is not a metaphor. Like a financial debt, security debt arises from a trade-off between present and future, it bears interest since the cost of remediation rises with the age of the component and the number of systems depending on it, and it falls due on a date the debtor does not choose. Its peculiarity lay until now in its accounting invisibility: it appears on no balance sheet, is measured in no shared unit, has no maturity, and omitting it is no irregularity. A business could therefore present entirely faithful statements while carrying a considerable liability whose size nobody, itself included, knew. The European cyber resilience regulation changed that status without changing the nature of the danger, by supplying the four missing attributes, a due date, a creditor in the form of the market surveillance authority, a unit of measurement through the software bill of materials, and a penalty scale.

Example

An obsolete library left un-upgraded because migration would cost three months of development is a rational choice at the moment it is made, and a liability that then grows silently.

Related terms
Also known as

dette technique, security debt, dette de sécurité