By Donato Poveda
Published 2026-08-14
7 Min Read
Security Operations
0:00 / 0:00

A fire watch is a person walking the building. When the fire-protection system is down, somebody covers the gap on foot, once an hour, every hour, because nothing else is watching. The round gets logged. Initials, time, done.

At one nuclear plant those logs came back complete for ten months. Every line filled in, every hour accounted for.

The rounds were not being walked.

The finding there belongs to the regulator rather than to me, so I will use its words. The Nuclear Regulatory Commission concluded that contract workers "willfully failed to conduct compensatory hourly fire watches and willfully falsified the fire watch tour logs by initialing that fire watches were performed with knowledge that watches had not been performed."

What should bother a security executive about that is not the dishonesty. It is that for ten months there was nothing to find. Anybody reviewing that program would have seen a clean sheet, because a complete log looks exactly like a complete log. The only way to test it is to put the paperwork down & go looking for evidence the guard never touched. That is what the plant agreed to start doing afterward: pull the door records, & check them against the rounds.

The other half of the fix was a new logging system, electronic this time, running alongside the paper one. Better paperwork. Still paperwork.

A stapled paper fire watch log on a clipboard hung beside a heavy industrial door, initials filling every hourly line, a card reader mounted on the wall above it in cool corridor light

A Known-Known That Is False

In "Hunting the Unknown-Unknown" I wrote about the threat that beats a team because nobody ever thought to look for it. It was never on anybody's list, because it was never in anybody's head.

This is the opposite failure, & in a working program it is the more common one. The data is not missing. It is right there. Specific, dated, signed, & wrong.

That is worse than a gap, & the reason is not complicated. A blank line makes somebody pick up the phone. A complete one gets filed. Nobody has unlimited time to check things, & a confident record sends that time somewhere else. In my experience a green report does something a blank one cannot: it ends the question. That is my professional judgment after twenty years of running & reviewing this kind of reporting, not a research finding.

So the program is not blind. It is looking straight at something it believes, & what it believes is not true.

The Structure That Produces the Record

The easy read is that this is a story about dishonest people, & it is worth taking seriously, because the answer decides the fix. If the problem is individuals, you vet harder & you audit more. If the problem is the structure, honest people under the same pressure hand you the same paperwork, & auditing the paperwork harder just produces more paperwork.

It is the structure. Look at what we actually ask of the person holding the clipboard.

We give them more to do than the shift contains. Then we leave them no way to say so that does not land on them. Nobody sits anybody down & tells them to invent a round. We build a system where the only two choices are to fall behind in the record or to fall behind in the world, & then we grade the person on the record. The Army studied this inside its own ranks & found the same machinery: requirements that outrun the days available to meet them, & no workable way to report the shortfall. What that costs is worth quoting once. An officer's signature & word, the authors wrote, "have become tools to maneuver through the Army bureaucracy rather than being symbols of integrity and honesty."

The receiving end is worse, & the same study found it there too. The people getting those reports knew the numbers were soft. They took them anyway, because the report was the deliverable & the report arrived on time. Both ends knew. The number stayed on the record. That was interview work rather than a survey, so it tells you how the thing happens & not how often.

None of this is new & none of it is military. A social scientist named the rule in the 1970s & the shape has not moved since: the more weight you hang on a number, the more pressure builds to bend it, until the number stops describing the work & starts standing in for it. Measure the report, & you will get reports.

Where It Lives in a Security Program

Once you have the shape, you see it everywhere an organization trusts a self-report. Guard tours are the obvious one & the least interesting. Access reviews, where a manager certifies that everybody on the list still belongs on it. Vendor questionnaires, where a company grades its own security & sends you the grade. Incident logs, where the number of incidents depends on somebody choosing to write one. Drills & after-action reports, describing a rehearsal nobody outside the room watched.

Every one of them ends in the same place. You are holding a piece of paper that describes work you did not see.

The most honest read on how often that paper is wrong comes from auditing, of all places, because auditing is the rare field where a regulator inspects the inspectors & then publishes what it found. A federal oversight board went through a run of audit engagements in 2024, & its staff came back with roughly two in five of them in which the opinion had been signed before the evidence to support it was in the file. That is not fraud & it is not a scandal. It is the ordinary rate at which a professional sign-off outruns the work behind it, in a field that has a regulator, an inspection regime & a public record. Security has none of the three.

Military readiness data fails the same way, & it fails in a way you can picture. When auditors went behind the reported numbers, they found soldiers carried as available for duty who were sitting in jail. That is the entire problem in one line. Nobody reading the record could have found those men. You would have to go look.

Federal contracting has its own version. A university's research arm settled a case over a cybersecurity readiness score it had given the Defense Department, which the government alleged rested on a setup that was not the system actually handling its data. Those claims are allegations only, and there has been no determination of liability. The shape interests me more than the outcome: one number, submitted to win the work, standing in for the thing itself.

Now notice where every one of those comes from. Nuclear plants, federal contracts, the military. Not because those places are worse than the commercial world, but because those are the places where somebody outside is required to look, & then required to publish what they saw. In commercial security this ends with a canceled contract & a quiet non-renewal. Nothing is published, nothing is counted, & the next buyer never hears about it. So when somebody quotes you a percentage for how often a patrol log gets signed for a round nobody walked, they invented it. There is no such number, & the fact that there is none is the point.

Measure the Act, Not the Record

There is somebody else reading this paperwork, & he benefits from it in a way worth saying out loud. A program that reports itself healthy does not chase the thing that looks slightly wrong, because the slightly wrong thing is arguing with a record everybody already believes. That hesitation is time, & time is the only thing an intruder genuinely needs. The firms that get called in after a breach publish their numbers on this every year & the shape does not move: intruders sit inside for weeks before anyone notices, & a large share of victims hear about it first from somebody outside the company. A false green report does not open the door. It lengthens the quiet after somebody comes through it.

So what do you do about it? Three things, & none of them make anybody compliant or satisfy an audit requirement. This is security practice, & these are my recommendations rather than anybody's standard.

A security operations desk at night, one screen showing a completed patrol checklist and a second showing raw door-access timestamps that do not align, no people present

Go back to the fire watch for a moment, because the uncomfortable part is not that logs were signed for rounds nobody walked. It is that for ten months the paperwork was clean, & anybody reviewing that program would have seen it doing exactly what it was supposed to do. The evidence that could have settled the question was being recorded the whole time, in a system nobody had thought to point at it.

So the question I would put to the next executive review is not whether the reports are accurate. Everyone in the room will say yes, & most of them will be right most of the time. The question is what would have to be true for this report to be false, & what evidence we have that the person being measured did not create. At Scopos Strategies, an assessment starts there. We go & check the program itself, the one leadership only ever sees written up in a report, instead of reading the report again.

Take the control you are most confident in, & ask one question about it: what evidence do we have that this work was done, that was not created by the person who did it?

Sources

Back to Insights

This article was produced with AI assistance. The perspective and security expertise are the author's own.