My research addresses a single organising question:
Why do governance architectures built for an idealised world – calculable risk, cooperative users, unbounded attention – systematically manufacture false confidence in the world that organisations actually inhabit, and what should be designed in their place?
The idealisation fails on three fronts, and each anchors a strand of the programme:
The diagnostic half of the programme explains what these three assumptions do when they fail together. The prescriptive half designs decision architectures in which the trade-offs are chosen openly, by accountable people, instead of settling themselves by default.
The lens is enterprise architecture: the practice of designing how an organisation's structures, incentives, and systems fit together, and of working out why they fail to deliver what they were built for. An architect does not fix a system by asking the people inside it to be more careful or more honest – an architect changes the structure. Seen this way, governance failures are failures of architecture, and most have nothing to do with cyber.
The lens was ground by a particular combination of experience: four decades in technology – from software development in the 1980s to Principal Enterprise Architect in critical national infrastructure – across eight countries and six industries, with information security the focus of the most recent decade. Each element contributes a habit of seeing that the programme depends on. Architecture teaches that every design is a trade-off, and that a trade-off that nobody has surfaced is still being paid. Security teaches the habit of modelling the actor who will not cooperate – the one whom cooperative designs assume away. And living and working across cultures teaches how differently the same governance mechanism lands in different communication traditions: what one culture states as a warning, another hears as routine. Trade-offs, non-cooperative behaviour, cultural context: all three recur through every strand below.
Like any architecture, a governance architecture must withstand the actors who will use it in practice, not the ideal ones the design assumes. Two of them keep appearing – one for each of the assumptions that fail.
The first actor has interests that pull against the system's: the official who is safer deferring than deciding, the firm that is safer hiding an incident than recording it. An unresolved conflict of interest is a structural weakness, and the remedy is to take the conflict out of the decision – through separation of duties, or an adjudicator with no personal stake – not to appeal to good character.
The second actor is neither hostile nor conflicted, but boundedly rational – limited in attention and time, and deciding on signals whose meaning is never certain. Under pressure people satisfice (they settle for "good enough"), anchor on what is already visible, and judge how urgent a warning is by whether it is stated plainly. You cannot remove this by urging people to do better, because attention has limits that good intentions do not change. The remedy is to design the decision environment so that these ordinary shortcuts still produce safe outcomes.
Neither actor responds to the usual language of trust and compliance. So the diagnosis is always the same: blame the architecture, not the person – who is either an adversary that will not comply or a bounded actor that cannot. The prescription is always the same in form too: build the quality that the system needs into the structure, instead of asking the people inside it to provide it.
Much of the diagnosis follows a single causal sequence. Governance frameworks build predictable errors into every stage of the decision cycle: in what they choose to measure, in how signals travel up through reporting hierarchies, in what stops a clear warning becoming a decision, in the assumptions that designers make about who will use their transparency mechanisms, and in how organisations cope when scale outgrows capacity. Each stage makes the one before it worse. A framework that measures the wrong thing produces false assurance; that false assurance is softened further as it moves up through reporting layers; the structure then rewards waiting for a certainty that will not come; the resulting signal reaches designers who assume cooperative use in adversarial conditions; and organisations that grow without rethinking how they coordinate absorb all of these failures at once.
That chain runs over months and years inside a single organisation. The same mismatch between the assumed world and the actual one then reappears in three further regimes: over the decades of infrastructure investment, where forecasts have no reliable reference class; in the state's own information powers, where the harm is produced by the system's accuracy rather than by its failure; and at the moment organisations decide to adopt AI, before any governance is in place at all.
These mechanisms are diagnostic. The programme's prescriptive claim is that they share one remedy – not a better control at any single stage, but two architectural properties that have to be designed in rather than demanded from the people inside the system. The first is the capacity to learn faster than the environment gets worse: institutional memory, an honest incident record, and shared visibility. The second is a decision architecture in which the trade-offs are surfaced and chosen openly by accountable decision-makers, and in which the people carrying the constraints can see why the constraints exist.
The earlier sections set out the diagnosis; the later ones develop the remedy. The evidence base combines original data – a cross-sectional analysis of 171 NHS trusts and Freedom of Information research across health, policing, fire and local government – with the public documentary record (parliamentary inquiries, audit-office investigations, regulatory consultations) and the case studies through which institutional failure has been studied in depth, from WannaCry and Grenfell Tower to Diane Vaughan's account of the Challenger launch decision.
Work from the programme that has completed journal peer review. Papers under review, and those accepted but not yet published, are noted in the strand to which each belongs.
The sequence begins with measurement. Compliance frameworks assess static attainment – whether an organisation has met a standard at one moment in time – rather than adaptive capacity, meaning whether it can respond to threats that did not exist when the standard was written. An organisation that keeps unchanged 2020-era controls and one that constantly experiments with new defences receive identical ratings. The metric cannot tell them apart: it was built for a stationary world, and the threat environment is not stationary.
Empirical analysis of 171 NHS trusts finds no association between resource scale and mandatory security compliance: mean staff costs did not differ between compliant and non-compliant trusts (p=0.88, Cohen's d=0.02), the null held in multivariate logistic regression (p=0.35), and workforce size behaved the same way (p=0.93). Compliance does not track scale, so size or budget cannot tell the centre which organisations will fall short. What a static status certifies is that a trust cleared a fixed bar in one cycle, not whether it keeps pace as the threat moves on – which is why compliance metrics are disconnected, by design, from the capability they claim to measure. The remedy is not a better static score but a velocity signal – the Cyber Progress Measure (CPM), which scores whether the organisation is improving faster than the threat evolves, rather than whether it has met a fixed target. And the discretion that newer, judgement-based frameworks introduce makes the gap between what is compliant and what is safe wider, not narrower. The false confidence this creates is the entry point for every later failure in the chain.
False confidence from compliance metrics would be less dangerous if boards also saw the raw operational picture alongside it. They do not. Operational urgency is translated, softened, and reframed as it moves up through the organisation. By the time a risk reaches the board, it has often been turned into assurance. The board is told that governance is working at exactly the moment it most needs to hear that it is not.
This mechanism – cue validity collapse, the breakdown of the link between how a message sounds and how serious it actually is – works through the very communication habits that make organisations look professional: hedged language, diplomatic indirection, deference to rank. The communication style that protects an organisation's external standing quietly destroys the signal clarity needed to escalate a problem internally. An overloaded executive applies a reasonable rule of thumb: if it were urgent, it would say so plainly. That rule is ecologically rational – well-matched to its environment – everywhere except in a culture that has trained urgency and plain speaking apart. This is the bounded actor failing not through carelessness, but through a cue that the architecture itself has made unreliable.
The same suppression is built into the assurance instruments themselves: reporting formats built from closed questions strip out the conditional judgements that experienced experts produce, so the board receives ratings from which the doubt has already been removed.
A revised and extended academic treatment of this mechanism is under peer review; a link will be added on publication.
Between a signal reaching the board and the board acting on it lies a failure that the chain does not capture. A clear-enough warning arrives, and still nothing happens – not because it was suppressed on the way up, but because the structure rewards delay. Asking for more evidence is easy to defend; acting on a partial signal is not. Where no one has stated the objective function – the goal that the decision is meant to serve – at the level where the decision is taken, waiting for certainty is the rational choice for the individual, even when waiting costs more than acting. Under genuine uncertainty that certainty never arrives. The result is decision latency: the warning becomes a history lesson, and the audit trail records due process instead of a decision actually made.
This is the same architecture that spreads a decision across many signatories so that no single person owns it, and that treats an unpublished threshold as safer than a committed one. None of this requires bad faith; it requires only a structure in which being defensible is rewarded and the absence of a decision goes unseen. It is the conflicted actor and the bounded actor at once – a personal incentive that pulls away from the institution's, acting under genuine uncertainty. The remedy is to state the objective function before delegating the decision, to put an explicit price on delay, and to make inaction as accountable as action.
The academic treatment of this strand – tracing how a displaced management theory has migrated into the structural design of governance itself, producing exactly these architectural signatures – is under peer review; a link will be added on publication.
The measurement and reporting failures are not accidental – they are designed in. Governance designers optimise for the cooperative user: the board member who wants assurance, the citizen who wants to understand a decision, the regulator who wants compliance. They are blind, by design, to the adversarial behaviour that their own systems invite. This is the cooperative-use assumption at work: the behaviour of the system's users is treated as known and benign, when part of the population is actively optimising against the design.
Transparency mechanisms – explainability requirements, disclosure obligations, open publication of decision formulas – create accountability interfaces that are, at the same time, reverse-engineering interfaces. The same overconfidence that inflates compliance metrics leads designers to assume transparency will produce accountability rather than gaming. The pattern appears in welfare algorithm design, cybersecurity disclosure rules, and AI governance. The failure is not about attitude – it is the predictable result of designing for cooperative use in an adversarial environment. And the discipline that routinely models the actor whose interests diverge – threat modelling – is rarely brought to the governance table.
Explainability is the clearest case. Regulators require explainable AI and open decision logic so that affected citizens and oversight bodies can understand and challenge automated decisions – a cooperative-use rationale. But the same interface that explains a decision to a legitimate challenger also specifies to an adversary exactly which inputs to manipulate to obtain a desired output. In welfare and fraud-detection systems, the published criteria become a gaming manual: the transparency meant to produce accountability produces a reverse-engineering interface instead. The design error is to treat explainability as something that serves only the cooperative user, when in an adversarial environment it serves both. The remedy, bounded explainability – giving an individual the account that they need without handing a whole population a recipe for gaming the system – is rarely the form specified.
Peer-reviewed developments of this strand – on architectural accountability in algorithmic systems and on the calibration of transparency against gaming – are under review; links will be added on publication.
Organisations that absorb the earlier failures – false metrics, suppressed signals, deferred decisions, blind-spot-laden design – face a problem that builds on itself. As an organisation grows, coordination costs grow faster than its defensive capability. When skilled people simply cannot be hired, however large the budget, the problem changes shape: the question is no longer how to reach a compliance target, but how to improve at the fastest rate that it can sustain with the capacity that it has.
This is where the programme's empirical finding – that resource scale does not predict compliance – meets a prescriptive framework. Flow-Constrained Risk Management applies the logic of the Theory of Constraints – focus effort on the one bottleneck that limits the whole system – to the order in which security work is done, replacing static targets with velocity-based metrics. An organisation at 50% maturity improving by 5% each quarter is on a better security path than one stuck at 80% with no ability to adapt.
The same coordination-cost logic reaches well beyond cybersecurity: too many initiatives at once in government, capability gaps in public services, and funding designs that mistake the size of the input for the quality of the output all show the same structural pattern. Slack, in this reading, is not waste – it is the reserve capacity that lets an organisation respond to what it could not have predicted.
The failure chain operates in cybersecurity and health governance over months to years. A parallel strand of this programme looks at where the same mechanisms operate over decades: government technology and infrastructure investment. Here the mismatch between assumed risk and actual uncertainty is at its starkest: over decades the future is one of deep, Knightian uncertainty – there is no reliable probability distribution to forecast at all. The failure is no longer a true signal distorted on its way up, but the illusory precision of a point forecast treated as if it were knowledge.
Funding decisions that depend on long-range forecasts show every stage of the chain. Cost–benefit appraisals anchor on single point estimates that end up serving as compliance artefacts rather than real inputs to the decision (the measurement failure). Optimism bias is made worse by reporting structures that turn uncertainty into confidence as a business case moves up through approval layers (signal suppression). The Treasury and sponsoring departments design appraisal rules for cooperative use – honest forecasters – while the politics of megaprojects rewards strategic misrepresentation, the deliberate understating of cost and overstating of benefit (the cooperative-use blind spot). And the coordination costs of programmes that run for decades overwhelm the capacity of the institutions managing them to adapt (the resilience ceiling).
The Annual Portfolio Model proposes an alternative built for that regime: instead of predict-and-act, it works by robust satisficing – spending limits revised every year, commitments made in stages with clear exit options, and fast-and-frugal priority rules that still hold up when the forecasts are wrong. Current work extends the same staged-commitment architecture to defence investment planning.
The mismatch takes its sharpest form where the decisions concern the state's own information architecture. Here the failure is not a signal distorted or a forecast mistaken – it is harm produced by the system working exactly as designed. Reforms to information powers are drafted and cleared one instrument at a time, each proportionate on its own terms; but privacy loss does not stay inside each instrument, it composes.
The point is old in the re-identification literature: attributes that identify no one on their own can, joined together, single a person out, so a series of individually safe steps reveals what no single step would. The same holds for information powers. When several reforms each sharpen how accurately the state can resolve identity across systems, the aggregate reach falls between the per-instrument assessments, where no safeguard is looking – and the burden lands on exactly the records engineered to be lawfully inconsistent: a protected witness, a suppressed address, a sealed adoption, which fail the sharper match by doing precisely what they were designed to do. This is consistency-driven exposure: exposure produced by the system's accuracy, not by its breach.
The stakes are highest where the data cannot be reissued. A password can be rotated and a card cancelled; a biometric identifier cannot, so a biometric leak is irreversible. That changes what a safeguard has to be. When mandated data flows move raw or reversible identifiers into stores that the sending state does not control, a legal adequacy finding does not certify the operational security of the receiving store – the duty to protect irreversible data cannot be discharged by delegating it, and because no post-breach remedy repairs the harm, the protection must be built in before the transfer, not litigated after it. The same gap appears inside the EU's own architecture, where one body of law mandates centralised financial registries while another leaves their security obligations unresolved.
The remedy mirrors the programme's general one: assess the powers in combination rather than singly, state the trade-off between matching accuracy and protection explicitly, and make its setting an accountable, recorded choice by the legislator rather than one settled implicitly, clause by clause. There is no costless setting of that dial – the claim is only that someone answerable should be the one to set it.
A peer-reviewed development of this strand is under review, and two further papers are in preparation; links will be added on publication.
Each of the earlier stages concerns governance architectures that are already in place. But a failure comes before all of them. At the moment they decide to adopt AI, organisations – public and private – consistently underestimate the long-term human and social consequences of that choice. The cause is not negligence but a predictable effect of overconfidence bias working at the level of the decision itself: adopting AI is framed as a narrow efficiency problem, the costs of transition are treated as manageable and temporary, and the longer-term consequences are made invisible by the cost-benefit lens being used. And this decision is taken in the regime where overconfidence is least entitled to its precision: adoption at this scale has no precedent, no repeatable experiment, and no base rate to anchor on – the norms form faster than the evidence that could justify them.
Three versions of this pattern are visible in the current wave of AI adoption. The first is social: companies keep the efficiency gains from AI-driven redundancies while passing the psychological and community costs – the loss of purpose and of a recognised role in society – to individuals and the state. Replacing lost income does not restore what the history of deindustrialisation shows can persist for decades. The second is organisational: the norms for delegating to AI form before anyone consciously designs them, and accountability spreads thin as the person who formally owns a decision no longer owns the reasoning behind it. The third is generational: automating the basic analytical work removes the path through which organisations grow leaders who can later challenge the systems that they inherit.
Compliance frameworks assume that once a control is in place, people will follow it. Mostly they do not – not out of indifference, but because a control that feels arbitrary or disconnected from the actual work is rationally bypassed under pressure. What keeps a constraint alive is not enforcement but visible purpose: people accept the friction when they can see the failure that it is there to prevent. Where that meaning is missing, compliance becomes performative – it holds while the auditor is in the room and breaks down the moment operational pressure rises.
This is the other face of the bounded actor, and it matters precisely because the environment is uncertain. No rulebook written in advance can specify safe behaviour for situations that its authors did not foresee; in the gaps, the organisation depends on judgement, and judgement is exercised only by people who understand and share the purpose of the constraint. A cyber control whose purpose is unclear, or a clinical security rule cut off from any patient outcome, is honoured at the audit and abandoned at the bedside. Building meaning into the control, rather than urging people to comply with it, is what makes the behaviour last – and, as the next section argues, it is also what makes sustained learning psychologically possible, because questioning one's own working assumptions is cognitively costly and people bear that cost only for work whose point they can see.
The theoretical treatment of this strand – specifying the motivational precondition on which organisational learning depends – is under peer review; a link will be added on publication.
The earlier sections are diagnostic: they explain why governance architectures reproduce failure. This one is prescriptive. At every stage, the implied remedy is the same – not a better control, but the capacity to learn faster than the environment gets worse. Under uncertainty that cannot be reduced to risk, prediction fails by definition; what remains is adaptation, and the rate of adaptation is an architectural property. In a world where failure is inevitable, what sets resilient organisations apart is not that they never fall, but that they recover reliably, and with a better understanding than before. That capacity has to be designed in, and most governance systems actively suppress it in three distinct ways.
The first is memory. A system that keeps too little history cannot tell whether an incident is a one-off or the latest case of a pattern that it has already seen; each event is treated as new, and learning never builds up. The second is the honest record. Where the same channel that collects incident data also carries enforcement consequences, documenting a governance failure honestly becomes irrational for the individual – so the record turns technically accurate but silent on governance, defeating the very learning that the reporting was meant to produce. Separating the learning function from the deterrence function, as aviation safety reporting did fifty years ago, is what makes honest disclosure rational. The third is shared visibility. Learning that stays inside one organisation and is never pooled produces no collective immunity: attackers route through the weakest point, so without comparative, sector-wide visibility even well-governed organisations are left exposed through their neighbours – and the dependency data that would reveal the weakest point is often already being collected, unexamined.
Memory, honest record, shared visibility: each is a design choice, not a cultural aspiration, and each is the architectural answer to a failure that the earlier sections diagnose.
One theme runs across these strands and points beyond them. Where an actor's interests diverge from the system's, no amount of good faith resolves the conflict – the only lasting remedy is to separate the function from the stake. Aviation separates the learning channel from the enforcement channel so that honest reporting is the rational choice; the honest-record strand above is one example. The same move generalises: whoever adjudicates concentrated power should not be a party that profits from it, and a critical public system should not depend on a supplier whose legal duties, under another country's law, can diverge from its users' interests. This is separation of duties – the oldest security control – applied to institutions rather than to computer systems.
The mechanisms set out above are general: they describe why governance architectures of a certain shape reproduce failure, not what any one organisation should do on Monday. There is no silver bullet – no single remedy that can be dropped into any setup and trusted to work, because every organisation is a brownfield: existing controls, dependencies, and working practices that a well-meant change can disrupt as readily as improve.
So operationalising one of these frameworks is, first, an act of analysis – reading the specific architecture in front of you to understand what it already does and what a given change would cost it – and only then an act of careful customisation, fitting the mechanism and its remedy to that organisation's real asset register, real reporting lines, and real capacity. The governing principle is the clinician's: first, do no harm.
This is what an advisory engagement is for: a board or executive team facing one of these failures on its own architecture. The diagnosis here is the published half; the value is in the first application – made on a live system where the first mistake is expensive, without breaking what already works. A short note describing the failure that you are seeing is the best starting point: get in touch.
Separately, the same body of work is open to collaboration of a different kind – joint research, legislative and regulatory design, and teaching in governance, risk, and AI accountability – with practitioners, policy institutions, and academic colleagues working at the intersection of these fields. For joint work or guest teaching, please get in touch.
Three further working papers provide the empirical and theoretical foundations that underpin the programme as a whole.