Wednesday Reality: A System Can Protect You to Death
The Discipline of Interruption
An electrical protection system spends most of its life waiting. Current passes through cables, motors turn, transformers hum, and the protective apparatus observes without intervening. Its apparent inactivity does not indicate passivity. Relays continuously compare the state of the circuit with the boundaries engineers have defined for it: excessive current, abnormal voltage, an unexpected flow towards earth, a temperature rising beyond tolerance. When the apparent system detects a condition likely to damage equipment or endanger people, it interrupts the circuit.
The speed of that interruption can determine whether an incident remains a replaceable fuse or becomes a destroyed installation. Protection therefore occupies a peculiar position within electrical engineering. It produces nothing, transports nothing and consumes resources while healthy operation continues. Yet the productive system cannot safely exist without it. The factory depends upon machinery, but it also depends upon the ability to stop that machinery before a fault propagates through cables, switchboards and transformers.
That dependence makes protection deceptively difficult to design. A breaker that never trips offers little protection. A breaker that trips too readily offers little electricity. Between those failures lies the actual engineering problem: the device must distinguish a dangerous abnormality from the violent but legitimate behaviour of a working system.
An electric motor, for example, may draw several times its normal current while starting. A protection mechanism designed around steady operation could interpret every start as a fault and disconnect the motor at precisely the moment it attempts to perform useful work. Engineers therefore coordinate thresholds, delays and protection curves. They consider not merely how much current flows, but for how long, through which part of the installation, and under what operating conditions. Protection requires judgement encoded into machinery.
The objective does not consist in interrupting every anomaly. It consists in interrupting the right anomaly, at the right place, quickly enough to contain it and selectively enough to preserve everything that can continue operating safely.
When Safety Becomes the Disturbance
Electrical engineers have a wonderfully understated expression for unnecessary interruptions: nuisance tripping. The phrase sounds harmless, as though the machinery had developed an irritating habit. Its consequences can prove anything but trivial.
A protective device may trip because it has been badly calibrated, because several harmless leakage currents accumulate, because an ageing component produces intermittent readings, or because the installation has evolved while its protection scheme has not. Each interruption may satisfy the local logic of the device. A threshold was crossed. The breaker opened. The dangerous condition disappeared.
Examined in isolation, the protection worked. Examined as a system, it failed.
Production stops. Refrigeration warms. Pumps cease circulating. Control systems restart in uncertain sequences. Operators abandon planned work to diagnose a fault that may no longer exist by the time they arrive. If the same protection trips repeatedly without revealing a credible danger, people begin to distrust it. They reset the breaker automatically. They postpone investigation. Eventually, somebody discovers a way to bypass the troublesome protection, replace it with a less sensitive device or prevent the alarm from interrupting the process.
The protection system has now created the behaviour it existed to prevent.
This inversion matters because reliability depends upon more than technical correctness. It depends upon the relationship between the system and the people operating it. A protection mechanism that generates too many false positives consumes the attention required to recognise a true positive. It turns alarms into background noise and intervention into ritual. The device still protects the circuit according to its specification, while the wider installation becomes progressively less safe.
Nothing dramatic needs to fail for this deterioration to begin. The thresholds may remain technically defensible. Every interruption may correspond to a documented rule. The maintenance report may show that all protective devices operated as designed. Yet the factory learns, slowly and rationally, to work around them.
Selectivity
A well-designed electrical network does not respond to every fault by disconnecting everything. Protection must isolate the smallest possible section of the installation while allowing the rest to continue. If a machine develops a fault, its local breaker should open before the upstream breaker disconnects an entire workshop. If the workshop protection fails, the next level provides a fallback. Each layer acts within a deliberately coordinated hierarchy.
This property, known as selectivity, reveals that stopping a system safely requires an understanding of its structure. Protection cannot operate intelligently if it sees only isolated components. It must know where boundaries lie, which dependencies cross them and which upstream consequences follow from a local intervention.
Selectivity also contains an economic judgement. Absolute isolation would simplify protection: disconnect the whole site whenever anything suspicious occurs. The resulting installation might achieve an impressive record of preventing electrical damage, mainly because it would spend so little time doing useful work. Engineering rejects that simplistic definition of safety. The protected system must remain capable of fulfilling its purpose.
The same tension appears wherever organisations introduce controls intended to protect information, infrastructure or access. Security policies revoke permissions, expire credentials, enforce device configurations and remove accounts that no longer satisfy a rule. Each mechanism resembles an electrical relay: it observes a condition, compares it with a boundary and interrupts something considered dangerous.
The resemblance extends to failure.
When an employee unexpectedly loses access to a system, someone can usually explain the local event. A group membership changed. A device fell outside compliance. A token expired. A policy propagated. A licence disappeared during reconciliation. An automated process corrected a configuration that another automated process had previously applied. Every component possesses an explanation, yet nobody can explain why the person who needed access on Tuesday no longer has it on Wednesday.
The individual event looks legitimate. The system behaviour looks random.
A Control Plane Without Configuration Control
Managed computers create an especially revealing version of this problem. A company hands responsibility for accounts, devices and policies to a specialist provider because central administration should improve consistency. The provider standardises configurations, applies updates, enforces security rules and controls the lifecycle of user access. In principle, the organisation replaces fragile local improvisation with professional discipline.
But centralisation changes the scale of error. A badly configured laptop inconveniences one person. A badly configured policy can alter hundreds of laptops before anyone understands what happened. Automation does not remove inconsistency. It gives inconsistency distribution.
A wild reset of account or or computer settings therefore represents more than an irritating support incident. It reveals a loss of configuration control. Someone or something has changed the recognised state of an asset without preserving an intelligible chain between intention, change and consequence. The machine may continue functioning, but neither the user nor the organisation can rely on its state.
That uncertainty spreads. Users begin keeping browser sessions open because they do not know whether they will regain access. They avoid restarting machines. They copy files locally before a policy removes a synchronisation path. Managers request exceptions for people whose work appears too important to expose to routine controls. Support teams create temporary accounts that gradually become permanent. Engineers build parallel channels outside the managed environment. The system intended to standardise work produces an ecology of defensive improvisations.
None of these behaviours requires carelessness. They emerge from rational adaptation to unreliable control. When the formal route repeatedly interrupts productive activity, people construct another route. The security organisation then discovers unauthorised tools, unmanaged identities and undocumented data flows, treating them as evidence that users resist discipline. More controls follow. The system responds to the consequences of unreliable protection by increasing the intensity of protection.
The alarm produces too many false positives, so the organisation installs another alarm to monitor the consequences.
Compliance and the Vanishing Purpose
Control systems often measure their own actions more easily than the outcomes they exist to preserve. A security team can count devices brought into compliance, accounts disabled, policies deployed, vulnerabilities remediated and exceptions closed. It finds it much harder to quantify the accumulated cost of interrupted concentration, delayed decisions, abandoned workflows and trust slowly withdrawn from the managed environment.
This asymmetry shapes behaviour. The organisation rewards visible enforcement while operational damage remains distributed across hundreds of small interruptions. No individual reset justifies an architectural investigation. Each incident becomes a ticket, each ticket receives a local resolution, and the recurring pattern disappears inside the machinery built to record it.
Ticket closure can then conceal system instability in much the same way that resetting a breaker conceals the reason it tripped. Service resumes and the incident appears resolved. Yet restoration and resolution describe different things. Restoring access returns someone to work. Resolving the failure requires understanding why the system withdrew valid access, whether the same mechanism can act again and which other users share the same exposure.
Without that investigation, the support operation becomes an efficient reset service for its own defects.
The economics remain equally well hidden. A ten-minute interruption rarely enters a financial ledger, but it does not consume only ten minutes. It breaks a meeting, invalidates preparation, transfers work to colleagues and creates uncertainty about the next attempt. Someone opens a ticket, someone triages it, someone escalates it, and a manager intervenes because the affected person cannot wait. The technical change may have taken milliseconds. The organisation spends hours absorbing its consequences.
Centralised controls concentrate authority while distributing their costs. The team applying a policy experiences one deployment. The organisation experiences every interruption separately.
The Reliability of Restraint
Protective engineering has never measured quality by the amount of intervention. A relay does not demonstrate vigilance by opening more circuits. Its value lies partly in what it prevents and partly in everything it allows to continue. Good protection possesses restraint.
That restraint requires observability. Engineers need to know what condition triggered an interruption, which device acted first, what other devices observed and whether the event matched the intended coordination. It requires reversibility, because an incorrect intervention must not leave the system stranded. It requires boundaries, because a local anomaly should not disable unrelated functions. Above all, it requires a model of normal operation rich enough to distinguish productive variation from genuine danger.
Organisations often purchase security administration as though it consisted mainly of applying controls. The difficult part, however, lies in understanding the productive system those controls surround. A provider can know identity platforms, device-management tools and compliance standards while knowing remarkably little about how the client actually works. From that distance, interruption looks cheap. The account can always be restored. The policy can always be reapplied. The user can always open a ticket.
The provider sees a reversible technical action. The organisation experiences an irreversible loss of time, context and confidence.
This explains why operational trust can collapse long before contractual metrics reveal a problem. Systems remain available. Tickets receive responses. Security policies execute. Service-level agreements remain technically intact. Yet employees start treating every authentication prompt, forced restart and configuration change as a possible threat to continuity. They no longer experience the managed environment as infrastructure. They experience it as weather.
Weather cannot receive responsibility. It simply happens, and people make contingency plans.
The Final Protection Layer
A factory exposed to nuisance trips does not immediately remove its protective equipment. It first tries to understand the pattern. Which loads were active? Which device operated? Did the event originate downstream or merely appear there? Has the installation changed? Does the original coordination study still describe the system that now exists?
These questions restore the connection between protection and purpose. They recognise that a control cannot prove its value merely by enforcing a rule. Its behaviour must remain intelligible within the system it interrupts.
Organisations rarely apply the same standard to digital controls. They tolerate a surprising degree of unexplained behaviour because software makes restoration look inexpensive. A lost permission can be regranted. A profile can be recreated. A password can be reset. The screen returns, the user reconnects and the visible incident ends.
But every unexplained intervention alters the system that follows it. People retain local copies, share credentials, delay updates, avoid approved tools and build private continuity mechanisms. Protection continues tightening around an organisation that has already begun escaping through the gaps.
Eventually, the dashboards may show an exemplary environment: policies enforced, exceptions reduced, accounts governed and devices compliant. Somewhere beneath those green indicators, people will have quietly arranged their work so that the protected system can no longer stop them from doing it.
Member discussion