The Architecture of Inheritance
Some cities are built. Others are inherited.
There are cities that impress because of their scale. Others because of their beauty, their skyline or beach side. Then there are cities, which tell stories. Think of Venice, New York or Mumbai, they tell the story of a particular time in history, of migration, of an entire nation.
Istanbul on the other hand overwhelms by refusing to belong to a single nation, to a culture or a moment in history. Istanbul tells the story of inheritance.
Approaching the city from the Asian side, the Bosporus first appears to divide two continents. Yet as the bridge rises above the water, the distinction begins to dissolve. Then the skyline reveals minarets, domes, modern towers, container ships, ancient walls, and suspension bridges sharing the same horizon. It is difficult to tell where one era ends and another begins.
That is because Istanbul is not the product of a single civilization. Roman, Byzantine, Ottoman, and modern Turkey - none inherited a museum; they inherited a living city. None began with an empty landscape. Each adapted what already existed, replacing some structures, preserving others, and assigning new purposes to old foundations. The result is not a city frozen in time, but one in which history remains functional.
We often think of cities as places. From an architectural perspective they are processes. Every street, wall, church and public square reflects decisions made by different generations responding to different needs. The city is less a blueprint than a conversation across centuries.
This essay argues that enterprise information systems should be understood in much the same way. Rather than engineered products assembled from scratch, they are inherited institutions: living systems shaped by generations of decisions, each adapting what came before while leaving something for those who follow. From that perspective, legacy becomes operational history, enterprise architecture becomes stewardship, and cybersecurity becomes the practice of preserving continuity while enabling change, while leadership is ultimately stewardship of all inherited capability.
Istanbul is a city built upon twenty-five centuries of inheritance. That inheritance is extraordinary. Yet inheritance is also fragile and never without consequence. Much of Istanbul's built environment predates modern seismic engineering, leaving the city acutely vulnerable to the major earthquake that geologists consider inevitable. Every generation inherits not only the achievements of its predecessors, but also the assumptions under which they were built. Continuity therefore demands more than preservation. It demands judgment: what to reinforce, what to adapt, and what can no longer be safely carried forward.
Inheritance by Design
As I write these words, my hands rest on a ThinkPad. At first glance, it is simply another modern laptop: fast, lightweight, connected to the Internet, and capable of running applications that would have seemed unimaginable a few decades ago.
Yet the ThinkPad itself tells a story remarkably similar to that of Istanbul.
Although today's models bear Lenovo's logo, the ThinkPad lineage began at IBM in the early 1990s. The very distinctive matte black chassis, the red TrackPoint, the understated industrial design, even the emphasis on durability and repairability; all reflect decisions carried forward across generations of engineers. Each model introduced new processors, displays, storage technologies, and wired or wireless capabilities. However, only few attempted to reinvent the laptop from first principles. Instead, every generation inherited a design language, refined it, and passed it on. This pattern extends far beyond industrial design.
IBM itself followed very much the same path. The company did not set out to build what we now call enterprise information systems. Its early computers addressed the needs of their own time: census data, accounting, payroll, scientific calculation. As organizations changed, so did the systems surrounding those computers. New requirements rarely replaced existing architectures; they accumulated alongside them.
Computing emerged because information processing had outgrown human capabilities. IBM inherited this problem through its punched-card tabulating systems, which transformed paper records into something that could be processed mechanically. The technology was new, but the challenge was centuries old. The arrival of electronic computers did not fundamentally change what organizations wanted to accomplish. What changed was the scale. Mainframes allowed organizations to process more information, more quickly and with much higher reliability, availability, and serviceability.
They did not replace the administrative problems of the past; they inherited them and made them: computational.
In 1964, IBM introduced the System/360, one of the most influential computer architectures ever built. Its technical achievements were remarkable, but perhaps its greatest innovation was philosophical. Customers investing in a System/360 were no longer buying a machine; they were buying continuity. Future models would preserve compatibility with existing software and data, protecting years of investment. IBM recognized something that still remains true today: organizations are reluctant to abandon what already works. Progress would not come from repeatedly starting over, but from carrying the past into the future.
Yet the same principle contains a paradox. The investments that create trust also create inertia. Compatibility protects the past, but it can also make the future harder to reach.
The personal computer is often remembered as a revolution, yet revolutions rarely erase everything that came before. Mainframes continued running banks, governments, and airlines long after personal computers arrived in workers' offices. The PC introduced a new relationship between people and information, but it became another layer in an already existing architecture. Organizations now had both centralized systems and personal computing, each solving different problems while becoming increasingly interconnected.
As organizations expanded beyond single buildings and single cities, information inherited geography. Networks allowed data to move between offices, factories, and eventually continents. Yet networking did more than to connecting computers. It connected assumptions. Systems originally designed for isolated environments suddenly became part of larger ecosystems. The architecture remained unchanged to a large extent; the world surrounding it, however, would continue transforming.
The Internet did not simply make enterprise systems more accessible. It fundamentally changed the environment in which they existed. Applications designed for trusted internal networks now found themselves exposed to an unpredictable global audience. The problem was rarely that earlier engineers had designed poorly. They had designed for a different world. The assumptions embedded in yesterday's architectures no longer matched today's reality.
Organizations did not have to use the Internet or to be present in that new domain, they deliberately choose to do so.
This again required new capabilities, which we today summarize under the umbrella of cybersecurity.
Cybersecurity itself inherited two very different legacies. From information technology, it inherited decades of architectures, protocols, operating systems, and business applications. From other disciplines, it inherited ideas. Firewalls echo military fortifications. Defense in depth reflects centuries of strategic thinking. Intelligence, deception, reconnaissance, attribution, and even the language of campaigns all originated long before computers existed. Cybersecurity did not invent these concepts; it adapted them to a new battlefield.
As organizations inherited information systems that gradually became critical to business operations, cybersecurity emerged to protect those systems, not always the organizations themselves. This also explains why some conversations often sound strange.
When the board asks "How resilient is our business?", Security replies: "We have firewalls, MFA, EDR, Zero Trust and 85% patch compliance." But those aren't the same question. Security answers in terms of inherited technical controls because that's what it inherited responsibility for!
In contrast, military organizations don't defend walls, they defend objectives. And of course, sometimes that may mean defending walls. But sometimes also to abandoning them, sometimes maneuvering around or retreating from them. But the wall is never the objective, the mission is.
Cybersecurity, however, primarily inherited the wall: firewalls, the perimeters, network boundaries, assets and infrastructure.
Perhaps we should understand this differently, as the Maginot Line wasn't a failure because walls are inherently bad, it was a failure because the objective quietly shifted while the defensive concept remained anchored to inherited assumptions.
Cloud computing on the other hand is often presented as a technological break from the past. In reality, it resembles the extension of a city with new districts more than the construction of a new one. Organizations did not abandon their identity systems, business applications, databases, or governance models. They migrated them into those new districts. The foundations remained recognizable even as the infrastructure beneath them changed.
Artificial intelligence does not arrive in empty organizations either, but in inherited ones. It encounters decades of accumulated folders, documents, business processes, security controls, organizational structures, and technical decisions. Before an AI assistant can answer a question, it must authenticate users, respect permissions, understand organizational context, and navigate systems designed long before it existed. Like every generation before it, AI begins not by designing a new world, but by inhabiting an old one.
Looking back across IBM's history, another pattern emerges. Every technological transition preserved more than it replaced. Punched cards gave way to mainframes, mainframes coexisted with personal computers, networks expanded into the Internet, infrastructure moved into the cloud, and artificial intelligence is now becoming another layer in that evolution. Each generation introduced profound change, yet none began with an empty landscape.
That continuity became one of IBM's greatest strengths. Customers invested because their previous investments continued to matter. Yet continuity also imposed constraints. The longer architectures, products, and business models endure, the harder they become to fundamentally rethink. Inheritance creates resilience, but it can also create fragility when yesterday's solutions remain embedded after the conditions that created them have disappeared. The challenge is not escaping inheritance. It is learning how to manage it.
The same characteristic that made IBM valuable to customers also created strategic challenges. Compatibility became an advantage because organizations depended on stability. Yet dependence also made radical reinvention more difficult. The architecture that protected previous investments could become an obstacle when markets, technologies, and customer expectations changed faster than the systems built upon them.
Operational History
Every organization begins as someone else's inheritance.
Long before the newest employee joins, decisions have already been made. Processes have taken shape. Systems have been deployed. Relationships have formed. Information has accumulated. Every newcomer inherits an organization shaped by choices they had no part in making.
New engineers inherit source code they did not write. Administrators inherit directories they did not design. Architects inherit integration patterns established years, sometimes decades, earlier. Their first task is rarely to invent something new. It is to understand what already exists.
We often describe inherited systems as legacy, a term that has become almost synonymous with obsolete technology or technical debt. Yet legacy is not simply a measure of age. It is the visible record of thousands of decisions, each made to solve a problem that was real at the time.
A payroll application reflects employment models, regulatory obligations, and accounting practices that once shaped the organization. A directory service preserves assumptions about identity and trust. An ERP system embodies decades of decisions about how a business buys, manufactures, ships, and accounts for its products.
Every inherited system contains assumptions that eventually stop matching reality.
What we call legacy is often history that remains operational.
Organizations preserve history only insofar as it continues to serve the present. Archaeologists preserve ruins because they help us understand the past. Organizations preserve systems because they still create value. The distinction matters. Enterprise architecture is not about conserving technology for its own sake. It is about deciding which parts of yesterday remain useful tomorrow.
Archaeologists don't approach Istanbul as a collection of isolated buildings. They read it as layers of successive civilizations, each adapting what earlier generations left behind. A collapsed part of the Byzantine wall is not simply stone; it is evidence. The repurposed Hagia Sophia or the Çırağan palace tell stories about the priorities of the respective generations. Every surviving structure reflects decisions that proved durable enough to endure.
Mature enterprise systems invite much the same kind of reading.
A mainframe application speaks of centralized computing. An Active Directory forest recalls the rise of corporate networks. A VMware cluster belongs to the era of server consolidation. Kubernetes reflects a world of distributed applications. Cloud platforms reveal another chapter altogether.
Each layer records the assumptions of its own time. None completely replaced the previous one. Each adapted, extended, or surrounded what already existed. It is tempting to interpret this accumulation as unnecessary complexity. Yet that perspective overlooks an important fact.
Every layer solved a genuine problem. Identity systems emerged because organizations needed to distinguish between users. Virtualization improved hardware utilization. Cloud computing reduced the operational burden of infrastructure. Containers simplified software deployment. Artificial intelligence now promises to assist with increasingly cognitive forms of work.
None of these innovations were mistakes. They addressed the constraints of their generation. The complexity of modern enterprise IT is therefore not the consequence of poor decisions. It is the consequence of many good decisions made over a long period of time. That observation also explains why complexity rarely disappears but moves into new layers.
Virtual machines reduced dependence on physical hardware while introducing new management layers. Cloud computing simplified infrastructure provisioning while creating new challenges around governance, identity, cost, and resilience. Artificial intelligence promises to reduce the effort required to find, interpret, and generate information while introducing entirely new questions around trust, accountability, and oversight.
Inheritance alone, however, does not explain evolution. Every generation also decides what deserves to survive. Some systems are retired. Others are modernized. Some assumptions remain valid for decades; others quietly become liabilities. Organizations do not evolve because they inherit everything, but because they continually select what to carry forward.
Some organizations are genuinely created greenfield. Yet even they begin accumulating operational history almost immediately...
We often celebrate innovation because it is visible. New technologies attract headlines, investment, and excitement. Maintenance rarely receives the same attention. Yet civilizations do not survive because they continually rebuild themselves. They survive because roads are repaired, bridges are reinforced, buildings are adapted, and infrastructure remains useful even as the world around it changes.
Organizational theorists have long observed that institutions evolve through accumulated routines rather than continuous reinvention. Enterprise systems reveal the same pattern in technological form. Every application, policy, and architectural decision becomes part of an organizational memory that shapes future choices. Technology, in this sense, does not merely support institutions. It becomes one of the ways institutions remember.
Cybersecurity - The Custodian
Unlike many engineering disciplines, cybersecurity was never given the opportunity to begin with a blank sheet of paper.
By the time information security emerged as a distinct profession, organizations already depended on decades of accumulated technology. Mainframes processed payroll. Networks connected offices. Databases stored customer records. Business applications had become indispensable. The Internet was transforming them all.
Security did not design this landscape, it inherited it.
Every mature organization contains security decisions made for circumstances that no longer exist. Password policies reflect earlier threat models. Network segmentation reflects older assumptions about geography. Disaster recovery plans preserve memories of previous outages. Even modern controls often protect architectures designed decades earlier. Security inherits not only technology, but yesterday's risk decisions.
Over time, however, decisions accumulate faster than their explanations. Security professionals therefore spend an extraordinary amount of time asking questions that appear technical, but rarely are:
Why does this authentication mechanism still exist?
Why are these systems connected?
Who approved this exception?
Why does this application bypass our standard controls?
The answers seldom begin with technology, but with archaeology.
Behind every configuration lies a migration, an acquisition, a regulatory obligation, a business priority, or a compromise whose original authors may have left the organization years ago. Security professionals inherit not only systems, but also the institutional memory embedded within them. Like archaeological evidence, these artifacts rarely explain themselves. They reveal traces of earlier decisions: a technology selected, a risk accepted, a compromise reached. Understanding them requires interpretation before intervention.
In that respect, they resemble conservators more than architects.
Architects create new structures, conservators preserve existing ones while enabling them to remain useful under changing conditions. Cybersecurity operates within much the same reality as other custodians of inherited systems. Its responsibility is rarely to replace inherited architectures. More often, it must understand them well enough to protect them while they continue evolving.
This perspective also explains why the profession borrows so much of its language from older disciplines: firewalls, defense in depth, reconnaissance, intelligence, campaigns, perimeters, etc.
These concepts were not invented for computers. They originated in military strategy, diplomacy, policing, and the protection of physical infrastructure. Identity management inherited ideas from public administration. Auditing owes much to accounting. Risk management reflects traditions from finance and insurance. Digital forensics extends methods developed for criminal investigation.
Cybersecurity became a meeting place where many older disciplines found new relevance. Public discussion often portrays cybersecurity as a field defined by constant innovation. New attack techniques, new vulnerabilities, new defensive technologies, new regulatory frameworks. Yet, daily practice tells a quieter story.
Most security professionals do not spend their days securing ideal architectures designed according to contemporary principles. They secure organizations as they exist: organizations where modern cloud platforms coexist with decades-old business applications.
Where identity systems span multiple generations of technology, where yesterday's assumptions continue to shape today's risks. Assuming every improvement must respect the continuity upon which the business depends.
Security therefore resembles stewardship more than construction. Every new technology becomes another layer added to an already inhabited landscape, where acquisitions introduce another history and exceptions become part of the inheritance. Or, where migrations preserve something while changing something else.
The Weight of Inheritance
There is something deeply attractive about the idea of starting over: architects sketch clean blueprints, engineers imagine elegant systems, consultants propose greenfield transformations.
Every generation is tempted by the belief that complexity can be eliminated simply by beginning again. Reality on the other hand rarely offers that luxury; successful systems do not exist in isolation.
The longer they remain useful, the more deeply they become woven into the organizations around them. Business processes adapt to them. Regulations acknowledge them. Contracts depend upon them. People learn them. Other systems integrate with them. And over time, what began as a technical decision gradually becomes an organizational one. This is why mature enterprises rarely resemble carefully executed master plans.
They resemble living cities.
Roads determine where buildings appear. Buildings influence commerce. Commerce attracts institutions. Institutions shape neighborhoods. Each generation inherits not only the decisions of its predecessors, but also the consequences of those decisions.
An authentication system influences business processes. Business processes influence compliance. Compliance affects procurement. Procurement shapes vendor relationships. Every successful decision becomes part of the environment within which future decisions must operate. Each decision expands some future possibilities while quietly eliminating others.
Every successful decision also embeds assumptions about the world in which it was made. Corporate networks assumed employees worked inside offices. Identity systems assumed people interacted directly with applications. Enterprise software assumed information was structured, curated, and searched by humans. None of these assumptions were unreasonable. They reflected the realities of their time.
The challenge is that assumptions often survive longer than the conditions that justified them. Organizations therefore inherit not only technology. They inherit yesterday's view of the world. The longer a system survives, the less likely it is that any one person understands it in its entirety. Instead, organizations develop specialists: database administrators understand databases, identity specialists understand identity, network engineers understand networks, and security professionals understand threats. Increasingly, organizations coordinate knowledge rather than possess it.
Mature organizations also contain practices whose original purpose has long been forgotten. The people who introduced them have retired. The projects that justified them have ended. The technologies that required them may no longer exist. Yet the practices remain.
Not because they are necessarily essential, but because removing them introduces uncertainty that preserving them does not. Inheritance therefore produces a curious paradox. And the longer a system survives, the more difficult it becomes to distinguish between what is historically necessary and what is merely historical. That is why organizations rarely begin again, because continuity has value of its own. Innovation does not replace inheritance, it grows from it.
Conclusion and Outlook
We often describe enterprise information systems as engineered products, and in many respects, they are. Viewed across decades, however, they begin to resemble something else entirely. They resemble inherited cities.
Not cities imagined by urban planners, but cities shaped by generations. Places where roads outlive their original purpose, where buildings survive their architects, and where every new construction must accommodate foundations that already exist.
Their complexity is not the consequence of poor design. It is the visible record of countless rational decisions made under changing circumstances. The same is true of enterprise technology. Every operating system, protocol, business application, security control, and governance process reflects a moment in history when someone solved a problem that could not be ignored. Most of those solutions proved valuable enough to survive. Together, they became the landscape inherited by the next generation.
Perhaps that is why the language of legacy has always felt incomplete, as it suggests something outdated, waiting to be replaced. Inheritance suggests something different: it reminds us that we are rarely the first to shape the systems we encounter, and almost never the last.
We receive institutions, technologies, and ways of working that have already survived countless decisions. We adapt them to the realities of our own time, knowing that others will one day inherit the consequences of ours. That perspective also changes how we understand cybersecurity.
Rather than standing apart from enterprise architecture, security has become one of its custodians. Its challenge is not to defend a pristine design, but to preserve continuity while enabling change. Like every profession responsible for long-lived institutions, it works within a landscape whose history cannot simply be erased.
Artificial intelligence may become the greatest test this pattern has yet encountered. Unlike previous technological shifts, which largely extended existing architectures, AI increasingly questions the assumptions beneath them: how knowledge is organized, how people interact with systems, and where decisions are made. The infrastructure may endure. The assumptions may not.
Previous technology generations inherited the organization's operating model. AI may challenge the operating model itself. Mainframes automated calculations. Personal computers distributed access. The Internet connected organizations. Cloud changed the economics of infrastructure. AI reaches deeper: it interacts with knowledge, judgment, and decision-making - areas traditionally belonging to people and processes rather than systems.
If history offers any lesson, it is that transformative technologies rarely replace the worlds they enter. More often, they inherit them.
AI will encounter the same accumulated architectures, organizational structures, regulatory obligations, and institutional memory that every major technological shift has encountered before. But unlike previous technologies, AI does not merely extend existing capabilities. It exposes the assumptions underneath them. It forces organizations to reconsider how knowledge is created, accessed, governed, and transformed into decisions.
The challenge, therefore, is not whether organizations inherit. They always will. The challenge is recognizing when yesterday's successful assumptions have quietly become today's constraints. Continuity depends not on preserving every layer, but on continually reinterpreting the inheritance beneath it.
Earthquakes expose assumptions embedded in buildings, while AI may expose assumptions embedded in organizations.
Standing on the Bosporus Bridge, looking across Istanbul, it is impossible to identify the precise moment when one civilization ended and another began. Roman foundations supported Byzantine ambitions. Byzantine structures became part of the Ottoman Empire. Modern Turkey inherited them all.
The city never stopped changing, yet it never truly began again. Enterprise information systems have followed a remarkably similar path.
We often ask who designed our enterprise systems. That question assumes they were designed once. Perhaps the better question is who inherited them. Because the most enduring systems - whether cities, institutions, or technologies, are rarely those that begin with perfect designs. They are those whose foundations are continually re-examined, thoughtfully adapted, and deliberately transformed so they remain useful to those who inherit them next.
The greatest danger of inheritance is not obsolete technology. It is invisible assumptions. Technologies can be upgraded. Infrastructure can be replaced. Assumptions often survive unnoticed, quietly shaping decisions long after the world that justified them has disappeared. Every generation therefore inherits two responsibilities: preserving what still creates value, and questioning what no longer does.