Cover of Preventing Surprise Attacks

Preventing Surprise Attacks

Richard A. Posner

6 ideas

  1. Surprise Attacks Are Inevitable, Not Preventable

    Intelligence failures are structural rather than the product of incompetence, because the volume of ambiguous data always exceeds the capacity to distinguish signal from noise. Investigators reconstructing a disaster always find the warning signs that were invisible amid contemporaneous clutter, creating an illusion that the attack should have been foreseen.

  2. Signal Versus Noise in Threat Detection

    Warning indicators ('signals') are buried in a vast stream of irrelevant or misleading information ('noise'), and the ratio is overwhelmingly tilted toward noise before an event. The relevant signals only become legible after the fact, when the outcome tells analysts which fragments mattered.

  3. Centralization Versus Competition Tradeoff

    Consolidating intelligence agencies under a single authority promises better coordination but risks suppressing dissenting interpretations and concentrating analytic error. A competitive structure of overlapping agencies generates redundancy and rival hypotheses, which improves the odds that some unit catches a threat others miss.

  4. Reform Driven by Political Theater

    Major restructuring after a catastrophe is shaped less by analytic merit than by the public demand to see decisive action, so reforms optimize for the appearance of having fixed the problem. This produces reorganizations that satisfy political pressure while sometimes degrading the very capabilities that failed.

  5. Cost-Benefit Limits on Security Spending

    Defending against every conceivable attack is economically impossible because the universe of vulnerabilities is effectively infinite while resources are finite. Rational security policy must accept a calculated level of residual risk rather than chase the unattainable goal of total prevention.

  6. Bureaucratic Incentives Distort Intelligence

    Analysts and agencies act on career and institutional incentives that reward avoiding blame more than taking interpretive risks, so they hedge, conform, and defer to consensus. This systematically biases the system against the bold, dissenting warnings that surprise attacks would require to be caught.

Save and mark ideas in the app