Technical Debt

The future cost and effort created by postponing necessary work earlier in the product life cycle.

Key Points

  • Represents future rework and expense that accrues when teams delay needed work or accept shortcuts.
  • Can be deliberate to meet a deadline or unintentional due to poor design, lack of standards, or insufficient testing.
  • Should be made visible, estimated, and prioritized in the backlog alongside features and defects.
  • Manage it by refactoring regularly, automating tests, improving architecture, and tightening the Definition of Done to prevent new debt.

Example

To hit a release date, a team skips test automation and hard-codes configurations. In later sprints, they spend extra time adding automated tests, cleaning the code, and fixing bugs. That extra effort is the cost created by earlier postponement of work.

PMP Example Question

During a sprint, the team defers writing performance tests to meet a milestone, planning to add them in a future iteration. What does this decision most directly create?

  1. Technical debt
  2. Schedule buffer
  3. Scope creep
  4. Change request

Correct Answer: A — Technical debt

Explanation: Deferring necessary work introduces a future cost to complete it and address resulting issues.

ICS/OT Cybersecurity Fundamentals — Security Built for Industrial Systems

Industrial control systems cannot be secured like ordinary IT. A forced reboot, aggressive scan, or incompatible patch can interrupt production and create real safety consequences. Effective OT security begins with understanding the systems, constraints, and risks unique to industrial environments.

This course gives IT professionals, engineers, operators, and security practitioners a practical foundation in ICS threats, zone and conduit design, risk assessment, passive asset visibility, and vendor evaluation. You will learn how IEC 62443, NIST CSF, and MITRE ATT&CK for ICS apply where availability and safety come first.

Eight reconstructed incidents—including Stuxnet, Triton, Ukraine 2015, Colonial Pipeline, and PIPEDREAM—show how attackers move through OT environments, what they target, and which defenses could have changed the outcome.

Watch the course preview, then build the vocabulary, frameworks, and judgment needed to take credible first steps in ICS/OT cybersecurity.

Explore the Course


ICS/OT Cybersecurity Fundamentals course preview

Build an ICS/OT cybersecurity foundation that fits the real environment

Standard IT controls can disrupt the industrial systems they are meant to protect. Learn how to assess OT risk, design zones and conduits, apply IEC 62443 security levels, use MITRE ATT&CK for ICS, and establish passive asset visibility without risking production. Eight reconstructed incidents connect attacker techniques to the controls that failed, giving you the vocabulary and judgment to make credible security decisions from day one.

Explore the Course