Rapid digitalisation without architectural hygiene¶

In recent years, ministries, NGOs, SMEs and grandma-run charities alike have been busily bolting on cloud migrations, SaaS platforms, shadow IT and remote access for everyone and their cat, while budgets for lifecycle management, threat modelling, or consolidating the resulting mess rarely followed. Europe has, in effect, built a digital IKEA wardrobe and skipped the screws that make it stand upright.
The panic stratum¶
The pattern set in hard in March 2020, when the order came down: everyone works from home starting Monday. In many organisations, VPNs designed for fifty users served five thousand, file shares opened to the internet with temporary access rules, two-factor authentication was disabled temporarily, and security policies were suspended until things calmed down, which they never quite did. A few weeks of panic laid down debt that still shapes behaviour: temporary measures became permanent, workarounds became infrastructure, and we will fix it properly later morphed into this is how we do things now. Later emergencies have tended to add their own layers on top, each one thinner on screws than the last.
Death by a thousand subscriptions¶
What begins as a well-meaning departmental choice can mutate quickly. Marketing needs an email tool, finance wants expense tracking, HR requires applicant tracking, and before long forty-seven SaaS platforms exist, some with admin access still held by departed staff, customer data in mysterious jurisdictions, auto-renewals nobody tracks, and alerts going to forgotten inboxes. Shadow IT thrives alongside, because official procurement takes nine months and three committees while a free tool takes an afternoon; a year later the free tool is business-critical, integrated through webhooks found on GitHub, and operated by someone who left in the spring. The killer question is seldom asked: can this be turned off if it needs to be? The answer, rather often, is no.
The illusion of inventory¶
Ask what systems exist and the official list may say fifty while the real number creeps toward four hundred. CMDBs age, acquisitions bring mystery infrastructure, and old systems never formally die. An organisation cannot secure what it does not know exists, patch what it has forgotten, or budget for contracts it never realised it had, which is why an auditor asking for a full view of personal data systems can provoke panic, frantic messages, and in the end guesswork with crossed fingers. Architecture diagrams often describe a building that was remodelled years ago by people who did not update the drawings.
The missing screws¶
Hygiene has a known parts list: centralised identity, a current asset inventory, architecture review before deployment rather than after the incident, a standing budget for technical debt, and monitoring that outlives the project that installed it. Each part costs money, time, and cultural change, which are scarce commodities, and broken incentives keep it that way: feature delivery is rewarded, maintenance is invisible, and knowledge walks out the door faster than documentation accumulates. The likely trajectory is slow-motion degradation, constant minor failures, firefighting, burnout, until something breaks badly enough for leadership to notice and a transformation programme is announced, planned, and quietly reduced. We appear to have built a digital infrastructure at pandemic speed without pandemic-scale resources. The wardrobe wobbles. We keep stacking things on top, praying physics does not notice.
The clerk’s brief¶
From the clerks, for the Patrician’s eyes
Compiled July 2026. Newest first; settled patterns sink into the core sample at the end. The clerks would note that this file concerns the things organisations do not know they have, which makes it, by definition, incomplete.
March 2026: The secrets are everywhere except the vault¶
GitGuardian’s secrets sprawl report, published March 2026, counts 28.65 million new hardcoded secrets reaching public GitHub in 2025, a 34 per cent rise and the largest single-year jump on record, with 96 per cent of organisations storing secrets outside dedicated managers, in code, configuration and CI/CD tooling. Roughly 64 per cent of credentials confirmed valid in 2022 were still valid when retested in January 2026. Four years, the clerks observe, is a long time to leave a key under a mat that everyone knows about.
December 2025: The people budget becomes a tooling budget¶
ENISA’s NIS Investments report, published December 2025, finds organisations responding to deepening talent shortages by directing budgets toward outsourcing and technology instead of hiring. More platforms, fewer people who understand how the platforms connect: the clerks recognise the wardrobe being reinforced with additional shelves rather than screws, and note that this sprawl is now, in part, official policy.
April 2025: The machines that escape the inventory¶
CyberArk’s identity security landscape, published April 2025 from a survey spanning France, Germany, Italy, the Netherlands, Spain and the UK among others, finds machine identities outnumbering humans by more than 80 to 1, most of them unknown and uncontrolled, and nearly half holding sensitive or privileged access. The inventory illusion, in other words, extends past the systems to the credentials the systems use to talk to each other. The clerks looked for the register of these identities and report, respectfully, that there is not one.
The core sample¶
The founding stratum is dated March 2020: the remote-work scramble whose temporary rules, opened shares and disabled controls hardened into infrastructure, and which subsequent reports keep excavating. Since then the sprawl has been measured rather than mended: secrets accumulating in public repositories year on year, machine identities multiplying past any lifecycle process, and, as of December 2025, security budgets officially flowing toward more tooling operated by fewer people. The clerks’ standing assessment: the wardrobe has not fallen over, which is being read upstairs as evidence that it will not. The clerks read it as evidence that nobody has yet leaned on it.