Worked case · Failure and stress · 12 figures

System learning after an incident

Learn from the system that allowed the event

Figure 01 / 12

Determine the eligible population first

Determine the eligible population first — System learning after an incident. Count; records. Exact values are in the figure data below.
Count; records

Of 1,150 source records, 989 are within the stated synthetic scope and 161 are outside it. Eligibility here is an explicit teaching input, not a legal conclusion. Production classification must use the actual entity, product, activity, jurisdiction, and facts.

Figure data and text version
Scope stateRecords
Within stated scope989
Outside stated scope161

A useful review explains how the system permitted and failed to detect harm. Remediation needs an owner and a check that the changed behavior addresses the mechanism.

The review ends with a reminder to be careful and no test of the failed control.

All amounts, rates, capacity limits, and outcomes in this case are synthetic. The three conditions are separate assumptions for comparison. A better result in the response condition is not measured proof that the proposed control causes that improvement. The figures expose the calculation and its limits; a real deployment needs its own evidence.

Read the result

The case identifies 989 eligible records from a source population of 1,150. The required workflow completes for 771, but 100 completed records miss the illustrative internal target. Another 218 remain incomplete. Communication evidence covers 671 generated notices. Scope, completion, timeliness, and delivery are four separate properties of the customer outcome.

Model inputs and calculated values

Inputs below are the case-specific values. Each figure states the condition-specific assumptions and units used in its calculation. Calculated values are rounded for display.

InputValue
population1,150
eligibility0.86
Calculated valueResult
population1,150
eligible989
excluded161
complete771
incomplete218
late100
ontime671
notices671
undelivered100
pending98
reviewed120
Figure 02 / 12

A control can miss eligible records

A control can miss eligible records — System learning after an incident. Count at a fixed observation cutoff. Exact values are in the figure data below.
Count at a fixed observation cutoff

The required workflow completes for 771 of the 989 eligible records. The 218 remainder needs an owned exception path. Reporting completion as a percentage of all source records would answer a different question and could hide the actual coverage gap.

Figure data and text version
MeasureRecords
Eligible records989
Workflow completed771
Workflow incomplete218
Figure 03 / 12

Completion and timeliness are distinct outcomes

Completion and timeliness are distinct outcomes — System learning after an incident. Count; exclusive states within eligible population. Exact values are in the figure data below.
Count; exclusive states within eligible population

The illustration applies an internal target, not a statutory deadline. Of 771 completed records, 100 miss that target and 671 meet it. The 218 open records are a third state; do not automatically classify them as timely merely because their final outcome is unknown.

Figure data and text version
OutcomeEligible records
Complete within target671
Complete after target100
Still incomplete218
Figure 04 / 12

An obligation record connects authority to behavior

An obligation record connects authority to behavior — System learning after an incident. Control contract. Exact values are in the figure data below.
Control contract

This case implements learn from the system that allowed the event. The record separates scope, trigger, required action, ownership, and retained proof. Exact legal duties belong to the applicable source and interpretation; the timing and counts in this worked example are synthetic.

Figure data and text version
ElementIllustrative value
Control subjectSystem learning after an incident
ScopeThe eligible population defined above
TriggerThe review ends with a reminder to be careful and no test of the failed control.
Required behaviorlearn from the system that allowed the event
Ownerservice owner
EvidenceVersioned event, action, and communication records
Figure 05 / 12

Different clocks start from different facts

Different clocks start from different facts — System learning after an incident. Internal teaching timeline; not a legal deadline schedule. Exact values are in the figure data below.
Internal teaching timeline; not a legal deadline schedule

These relative times are illustrative service targets. They deliberately distinguish customer contact, receipt by the institution, classification, investigation, and communication. A routing delay must not silently replace the original receipt time when that fact matters.

Figure data and text version
EventIllustrative timeRecord
Customer reportT0Original channel and words
Institution receiptT0 + 5 minutesRetained receipt timestamp
ClassificationT0 + 20 minutesApplicable process and owner
Internal review targetT0 + 1 dayInternal target only
Outcome communicationAt decisionContent, destination, and delivery state
Figure 06 / 12

Evidence fields fail independently

Evidence fields fail independently — System learning after an incident. Count; overlapping field-level checks. Exact values are in the figure data below.
Count; overlapping field-level checks

Each row is one evidence requirement over the eligible population. The same record can fail several checks, so the absent counts across rows must not be added as though they were distinct customers. Completeness does not itself prove that a field is accurate.

Figure data and text version
Evidence fieldPresentAbsent
scope91079
trigger870119
action841148
notice89099
evidence791198
Figure 07 / 12

A generated notice is not a delivered notice

A generated notice is not a delivered notice — System learning after an incident. Count; generated equals delivered plus unresolved. Exact values are in the figure data below.
Count; generated equals delivered plus unresolved

771 completed records generate a modeled notice event. 671 have a delivered state and 100 do not. The system must distinguish generation, dispatch, delivery evidence, and any required follow-up under the actual process.

Figure data and text version
Communication stateNotices
Generated771
Delivered state recorded671
Delivery unresolved100
Figure 08 / 12

Authority differs by operation

Authority differs by operation — System learning after an incident. Illustrative permission matrix. Exact values are in the figure data below.
Illustrative permission matrix

The access matrix is a proposed teaching separation of duties. Read, propose, approve, and administer are distinct capabilities. The final policy must match the organization’s actual roles and obligations, with controlled emergency access and an audit trail.

Figure data and text version
RoleRead evidencePropose actionApprove release
service ownerScopedYesNo
Independent approverScopedNoYes
SupportLimitedRequest onlyNo
System administratorOperational logsNoNo
Figure 09 / 12

Exceptions need capacity and a closing state

Exceptions need capacity and a closing state — System learning after an incident. Records per observation window. Exact values are in the figure data below.
Records per observation window

The control has 218 incomplete records. The available exception capacity covers 120, leaving 98 pending. A pending state requires an owner and a next action; changing a status label without resolving the required behavior does not close the gap.

Figure data and text version
Queue itemRecordsMeaning
Exceptions opened218Eligible workflow incomplete
Capacity applied120Records handled in this window
Pending exceptions98Still require an owned response
Figure 10 / 12

A rate includes its denominator

A rate includes its denominator — System learning after an incident. Percent; named populations. Exact values are in the figure data below.
Percent; named populations

These rates deliberately use different populations. Overall throughput, eligible coverage, completed-record timeliness, and delivery evidence are not interchangeable. Each needs the same cohort, cutoff, and definition every time it is compared.

Figure data and text version
MetricNumeratorDenominatorPercent
Eligible coverage77198977.96
On-time among completed67177187.03
On-time among eligible67198967.85
Delivered among generated67177187.03
Figure 11 / 12

A change needs an evidence trail

A change needs an evidence trail — System learning after an incident. Control-change lifecycle. Exact values are in the figure data below.
Control-change lifecycle

The trigger is The review ends with a reminder to be careful and no test of the failed control.. A controlled change connects the revised requirement or interpretation to implementation, replay, customer impact, and approval. The old version remains relevant to decisions already made under it.

Figure data and text version
StageRetained proof
InterpretScope, source, effective date, and owner
ImplementVersioned logic, data contract, and message template
VerifyBoundary cases and affected-population comparison
ReleaseApproval, start time, and rollback condition
CorrectAffected records and customer outcome where required
Figure 12 / 12

Correction follows the affected population

Correction follows the affected population — System learning after an incident. Illustrative correction responsibilities. Exact values are in the figure data below.
Illustrative correction responsibilities

A remediation map links the defect to affected records, financial consequences, communication, and closure evidence. It should retain exclusions and unresolved cases. A change that prevents future failures does not by itself correct earlier customer outcomes.

Figure data and text version
FromToRelationship
System learning after an incidentAffected populationReproducible query
Affected populationFinancial reviewAmount and balance impact
Affected populationCustomer messageRequired communication
Financial reviewClosure evidenceVerified adjustment
Customer messageClosure evidenceDelivery and follow-up

Connect the result to the system

Change the relevant contract or control and verify the same failure no longer escapes detection.

Check the population, evidence, permitted action, and actual effect together. A balanced calculation can still use the wrong population; a successful response can still leave an unknown financial outcome. The case’s numerical result applies only to its stated assumptions.

Sources and further reading

The chapter sources support the concepts and scope. They do not prescribe the synthetic model rates.

  1. NIST: Cybersecurity Framework
  2. Google SRE: handling overload
  3. Federal Reserve SR 23-4: third-party relationships