In my career I have focused on preventing, preparing for, and investigating workplace accidents – mainly in the oil & gas, chemicals, power generation, and mining sectors.
I’ve written about several major accidents on this website, unpacking the human factors aspects. Reflecting on the 25th anniversary of September 11, I revisited the events of 9/11 through a human factors lens. You can read my article on 9/11 here.
But 9/11 was not an accident.
- Was it foreseeable? Yes
- Were several warning signs present? Yes
- Were the relevant organisations fully prepared? No
9/11 was different to the major accident scenarios that most organisations prepare for (and those on my Incidents page) because it was intentional.
In my experience, most companies have relatively mature systems for managing the risk of foreseeable safety accidents. These frameworks are based around the assumption that “people are trying to do the right thing”. Many human performance issues are unintentional (see the Human reliability topic page for several articles that discuss ‘human error’ and human failure).
But if companies focus exclusively on foreseeable accidents, what could be missed when adversaries deliberately exploit weak points in the system? It is possible that many companies are not prepared for intentional events, such as sabotage, fraud or terrorism.
In my research for the 9/11 article, a theme running throughout several 9/11 investigations was a lack of coordination between different agencies in the intelligence community. When applied to major hazard companies (those that manufacture, store or transport dangerous materials) and other safety critical industries, a lesson from 9/11 may be to assess whether your different “risk” teams are fragmented across organisational silos.
Key questions to help you prepare for intentional safety events:
- How well do your safety assessment and investigation models (human reliability assessment, root cause analysis, HOP, Safety-II, bowties, barrier models, Swiss cheese etc.) handle malicious intent?
- Could there be scope to better integrate security risks into your health and safety frameworks?
- Would it be useful to combine security and safety into one risk system? (“Security-informed process safety” anyone?).