Baarool

Method

How a signal fails

Organisations do not fail to know things in one way. They fail in at least five, and the distinctions matter because each has a different remedy — and only some are failures at all.

Non-representation

The signal arrives and has no category to land in. Every organisation must reduce the variety of its environment to something it can process, and that reduction discards according to categories fixed before the signal existed. This is not failure; it is the cost of being a finite regulator in an unbounded environment. But it means every organisation's shape of blindness is a direct function of its shape of attention, and almost nobody maps it.

Discounting

The signal has a category, it is received, a person assesses it and declines it. Most signals should be discounted — an organisation that acted on every warning would be paralysed inside a week. The pathology is not discounting. It is undocumented discounting, which is indistinguishable afterwards from never having read it.

Structural non-inquiry

Knowledge creates duty, so not commissioning the survey is frequently the rational move. Law recognises this as wilful blindness and struggles to prove it, precisely because the absence of an inquiry leaves no artefact.

Level-arrest

Someone knows. The knowledge never crosses a boundary. This is the finding of nearly every inquiry — not that nobody knew, but that knowing stopped below anyone who could act. A channel problem wearing the costume of an epistemic one.

Learned silence

People stop reporting because prior reports went nowhere. The sensors switch themselves off, and the resulting quiet is read as good news. This is the worst of the five, because absence of signal and suppression of signal are identical from inside the boundary. There is no test from within — which is the whole argument for external observation.

The record is the remedy

There is no final checker. The auditor is checked by the audit committee, composed of directors using information prepared by management, audited by a firm the company pays. Every layer is real and none is last.

So the tractable move is not to guarantee a competent checker at the moment of the decision. It is to guarantee that a checker arriving at any later time can evaluate what was done. Record the decline, with its reasoning and a dated expectation of what will be true if the judgment was right. At present, ignoring a warning is free and invisible. Everything else follows from changing that price.

Jurisdictional scope

The mechanism is not national. Attenuation, discounting and level-arrest operate identically wherever people report to other people. What differs between countries is how much of the aftermath is written down, who is obliged to write it, and what happens to them afterwards — and those differences are the reason the work is comparative rather than local.

Four bodies of material, each contributing something the others cannot.

The United Kingdom — the inquiry record

The most detailed public accounts of information failing to travel. The Post Office Horizon Inquiry is the clearest case in existence for this argument: Sir Wyn Williams found that a number of senior and not-so-senior employees knew, or should have known, that the Legacy Horizon system was capable of error, while the organisation maintained that its data was reliable. Knowledge inside the organisation, for sixteen years, routed nowhere. More than two million pages of evidence are public; the volumes dealing with what the board and senior management knew have not yet been published.

Alongside it: the Prevention of Future Deaths regime, in which responses to coronial recommendations are published centrally, and the Information Commissioner’s monetary penalty notices, which set out what an organisation knew and when.

The United States — the law

American law has come closer than any other to writing this argument into doctrine. The Delaware oversight line begins with Caremark (1996), which held directors liable either for failing entirely to implement a reporting and information system, or for consciously disregarding warnings produced by a system they did implement. Stone v. Ritter (2006) grounded that duty in loyalty rather than care, which matters because loyalty claims cannot be exculpated by charter provision.

Marchand v. Barnhill (2019) held that where a risk is mission critical, board oversight must be more rigorously exercised — and found no board-level reporting for the single most central safety issue the company faced. In re Clovis Oncology (2019) turned on red flags consciously ignored. In re Boeing (2021) sustained a claim that the board had failed to establish any airplane-safety reporting system and had turned a blind eye to a warning. In re McDonald’s (2023) went the other way, and is the more useful case for understanding where the line sits.

Two prongs, in the law’s own words: no system at all, or a system whose warnings were disregarded. Those are the first and second mechanisms above, stated by a court.

Separately, since December 2023, US registrants have been required to describe their cybersecurity governance annually and to disclose material incidents on a clock. That requirement created the first dated, comparable public record of what organisations claim about how they govern this risk.

The European Union — the live experiment

NIS2 and DORA are, read one way, external attempts to install these properties by statute. NIS2 Article 20 requires management bodies to approve cybersecurity risk-management measures, oversee their implementation, and undergo training sufficient to assess the risks — and provides that they may be held liable, including through temporary bans from managerial functions. DORA gives the management body ultimate responsibility for ICT risk, including approval of the framework and allocation of budget.

These are cadence and inescapability interventions in everything but name: they attach a named person to information that arrives, and a consequence to its arriving and being set aside. Whether that changes anything is an empirical question, and it is being answered right now across twenty-seven member states.

Australia — the operating context

Where the practice is based, and the source of most of the operational intuition behind this work. APRA’s prudential standards on information security and operational risk are, in places, ahead of international practice in imposing these conditions on regulated entities. Against that, the Hayne Royal Commission’s central finding about the conduct regulator was not that misconduct went undetected but that enforcement was too readily traded for negotiation — which is an inescapability failure one level above the firm.

The audit offices and coronial jurisdictions provide the public record; the corporate filing record does not, because no Australian requirement corresponds to the American cybersecurity governance disclosure.

The same duty, three phrasings

UK directors owe a duty to exercise reasonable care, skill and diligence. Australian directors owe the equivalent under section 180 of the Corporations Act. Delaware frames it as a duty of oversight grounded in loyalty. Three legal traditions, arriving at the same question from different directions: did the board have an information system that would actually have surfaced this, and what did it do when the system spoke?

What this work does not yet know

The sampling problem this method attributes to the inquiry record applies to its author. The intuitions behind the four properties were formed largely inside Australian organisations, in a market that is small, concentrated, and served by a director pool small enough that boards interlock — conditions which would independently predict weaker independence and softer competitive signals. Twenty-eight years of pattern recognition and twenty-eight years of accumulated local sample are indistinguishable from the inside.

Against that: the pattern is plainly not local. Horizon is British, Carillion is British, Boeing is American, Wirecard is German, and none of those involved a small market or an interlocked board. And Australia is not uniformly behind — the prudential standards are evidence to the contrary.

So the honest position is that whether jurisdiction moderates these properties, and which of them, is unresolved and worth answering rather than asserting. It is stated here as a limitation because a claim presented as universal, and then met with a single foreign counterexample, deserves to be discounted entirely.

Antecedents

None of the five mechanisms is new. They have been described, separately, in cybernetics, safety science, organisational learning and security economics — literatures that rarely cite one another. What is set out on the lineage page is which idea came from where, and the three things that are not inherited.

The paper

The formalism is published in full, with an ISBN, under a Creative Commons licence. Anyone may build on it, dispute it, or implement it independently. Contact hello@baarool.com for a copy.