Computer Science and Engineering
p-ISSN: 2163-1484 e-ISSN: 2163-1492
2026; 16(2): 29-48
doi:10.5923/j.computer.20261602.01
Received: Jul. 6, 2026; Accepted: Jul. 25, 2026; Published: Jul. 31, 2026

Cornelius Chipasha, Simon Tembo, Mulundumina Shimaponda
Department of Electrical and Electronics, University of Zambia, Lusaka, Zambia, University of Zambia
Correspondence to: Cornelius Chipasha, Department of Electrical and Electronics, University of Zambia, Lusaka, Zambia, University of Zambia.
| Email: | ![]() |
Copyright © 2026 The Author(s). Published by Scientific & Academic Publishing.
This work is licensed under the Creative Commons Attribution International License (CC BY).
http://creativecommons.org/licenses/by/4.0/

Critical Digital Infrastructure (CDI), the power grids, water utilities, pipelines, and industrial control environments on which modern society depends, is undergoing rapid Information Technology / Operational Technology (IT/OT) convergence. This convergence has expanded the attack surface of systems that were never designed for external connectivity, and repeated incidents, including the 2000 Maroochy Water Services breach, the 2015-2016 Ukrainian grid attacks, the 2017 TRISIS/TRITON safety-system compromise, the 2020 SolarWinds supply-chain intrusion, and the 2021 Colonial Pipeline ransomware event, demonstrate that architecture, not merely control gaps, is a persistent source of systemic cyber risk, meaning risk capable of cascading beyond a single asset or organisation to affect an entire sector. Existing standards such as IEC 62443, NIST SP 800-82, and NIST CSF 2.0, adversary-behaviour catalogues such as MITRE ATT&CK for ICS, and enterprise architecture frameworks such as TOGAF, SABSA, Zero Trust, and the Purdue model, describe controls, risk-assessment procedures, adversary techniques, and design principles, but none catalogues the recurring architectural mistakes, or anti-patterns, that make those techniques and control gaps possible in the first place. This distinction matters: a technique catalogue explains how an intrusion unfolds once inside a system, and a control catalogue lists what safeguards exist, while neither explains why the same structural conditions keep recreating the same opportunity across unrelated organisations and sectors. This paper addresses that gap. Drawing on software anti-pattern theory, security pattern literature, architectural technical debt research, and forensic analysis of major CDI incidents, we identify, define, and classify twelve recurring architectural anti-patterns spanning governance, identity, trust, segmentation, visibility, operations, and resilience domains. Each anti-pattern is documented using a structured template covering context, problem, symptoms, root cause, security consequences, detection indicators, and a recommended pattern; each is corroborated by at least two independent sources spanning at least two CDI sectors, and mapped to one or more corresponding architectural security patterns. Contributions include a cross-sector catalogue of architecture-level anti-patterns for CDI, explicitly distinguished from existing adversary-technique catalogues and single-incident lessons-learned advisories; a reusable identification methodology; an anti-pattern dependency analysis; and a direct anti-pattern-to-pattern mapping with partial-remediation pathways. Practical implications, including implementation barriers and prioritisation guidance, are discussed for architects, operators, auditors, regulators, and researchers. The catalogue provides a practical, architecture-first foundation for proactively eliminating structural weaknesses in Critical Digital Infrastructure before they evolve into systemic cyber risk.
Keywords: Critical digital infrastructure, Architectural anti-patterns, Security patterns, IT/OT convergence, Zero trust, Industrial control systems, Cyber-physical security
Cite this paper: Cornelius Chipasha, Simon Tembo, Mulundumina Shimaponda, Architectural Anti-Patterns in Critical Digital Infrastructure: A Catalogue of Recurring Structural Weaknesses and Their Mitigation Through Security Patterns, Computer Science and Engineering, Vol. 16 No. 2, 2026, pp. 29-48. doi: 10.5923/j.computer.20261602.01.
|
![]() | Figure 1. Anti-pattern identification methodology |
|
![]() | Figure 2. Anti-pattern classification stack |
|
|
|
![]() | Figure 3. Relationship between anti-patterns and security patterns |