Most risk plans are made of reminders.
Write the policy. Run the training. Add the warning banner. Every one of those needs a human being to remember something, correctly, on their worst day — and they are what most organisations reach for, because they are cheap and they look like action. There is a ranking of what actually works, it comes from occupational safety, and almost nobody applies it to anything else.
Guess first — commit before you look
Your staff are pasting customer records into public AI chatbots. You get one move this quarter. Which one cuts the risk most?
Pick on instinct. There is a right answer here and it is not the popular one.
The model
The hierarchy of controls
Industrial safety has ranked these for decades, and the ranking holds anywhere a human being can make a costly mistake. Read it top down: you only move to the next rung when the one above is genuinely impossible.
The ordering is not about how much the control reduces risk on a good day — on a good day a policy everyone follows works fine. It is about how much of the control's strength depends on a person choosing correctly, every time, forever. That is the property that collapses under pressure, and pressure is exactly when you need it.
Drive it
Spend the budget, then turn up the pressure
Pick a situation, fund what you would actually fund, then move the pressure slider to a bad quarter — a deadline, some turnover, a cost freeze. Watch which of your controls are still there afterwards.
The rung ordering is the real hierarchy of controls, used in occupational safety and engineering. The individual numbers here are judgements chosen to make the shape visible — treat the ranking as the lesson and the decimals as illustration. Nothing leaves this browser.
The question nobody asks
How would you know the control actually works?
Every control above is a claim: this stops the bad thing. Most organisations never test the claim, and the ones that do usually run a test the control could not have failed. A fire drill announced a week in advance tests the calendar, not the building.
A test that could not have failed tells you nothing. That is the whole of it. Karl Popper's point about theories is a practical instruction about controls: before you run the check, write down what result would prove the control is broken. If you cannot name one, you are not testing — you are rehearsing.
The announced restore
You tell the team on Monday that Thursday is backup-restore day. Thursday goes fine. You have learned that a prepared team can restore a system they warmed up on Wednesday.
The unannounced restore
Someone picks a random system on a random day and asks for it back by lunchtime. It could fail. That is what makes the pass worth something.
The policy attestation
Ninety-eight per cent of staff signed to confirm they read the AI policy. That measures signature collection. Nobody has checked whether anyone's behaviour changed.
The thing you tried to break
Ask someone to get customer data into a public chatbot on a managed laptop, and pay attention to how long it takes them. Then ask whether they could have done it faster.
This is the same instinct as a pre-mortem, run forwards: instead of asking "will this work?", ask "what would I see if it didn't?" — and then go and look for that.
Where this bites
How to spot a bottom-rung plan
You rarely hear "we chose a weak control." You hear these instead. Each one is a plan living on the bottom two rungs, described in language that makes it sound like action.
"We'll add it to the onboarding deck"
A control whose entire mechanism is that a new starter remembers slide 34 in month seven. Ask instead: what would have to be true for the mistake to be impossible?
"We've updated the policy"
The document changed. Nothing in the system did. Worth asking what a person trying to do the wrong thing would now bump into that they didn't before.
"There'll be a sign-off step"
Approval gates feel like engineering but they are administrative: their strength is one tired person reading carefully at 5pm on a Friday.
"We're taking it seriously"
Attention is not a control. It has no mechanism, degrades within about two weeks, and cannot be handed to whoever does the job next.
The three things this tool deliberately does not re-teach, because they have their own homes: shrinking what a failure can reach in Small Batches, making a release reversible in Feature Flags, and why stacking more layers still leaks in The Swiss Cheese Model. If the risk you are weighing could end the organisation rather than bruise it, The Expected-Value Tree is the one to read first — no ladder saves a bet you cannot survive losing.
Go deeper
Every rule you write is a cost you pay forever.
The top of the ladder is unpopular for an honest reason: eliminating a hazard usually means giving something up — a feature, a data set, a way of working someone likes. The bottom of the ladder asks nobody to give up anything, which is exactly why it is always available and rarely enough. Most of the value in a de-risking conversation is getting a room to say out loud what they would have to stop doing.
Talk to us about running this session