LOOK ACROSS THE INCIDENTS
Different failures.
Shared lessons.
Put cases side by side. Find the common assumptions—and the safeguards that could break the chain.
Loading comparison…
LOOK ACROSS THE INCIDENTS
Put cases side by side. Find the common assumptions—and the safeguards that could break the chain.
Loading comparison…
SHARED FAILURE PATTERNS
These editorial tags are common to every selected case. Compare the details below before drawing parallels.
On smaller screens, swipe the comparison horizontally.
| Case file | Year 2000 readiness ↗January 1, 2000 | Knight Capital ↗August 1, 2012 |
|---|---|---|
| Failure pattern | Hidden assumptions · Untested recovery | Unsafe changes · Hidden assumptions |
| What happened | The Year 2000 date transition put computer systems and the services depending on them under scrutiny. This exhibit focuses on the US federal response documented by GAO: inventories, repairs, testing, partnerships, and contingency plans before an immovable deadline. | Knight Capital’s order router sent more than four million orders while attempting to fill just 212 customer orders. In the first 45 minutes of trading, the firm accumulated unwanted positions and lost more than $460 million. |
| Why it spread | The risk crossed organizational boundaries. An agency could not establish readiness solely by examining its own applications; data exchanges, service partners, and continuity arrangements mattered too. GAO identified leadership, coordinated reporting, and sustained oversight as major contributors to the response. | An incomplete deployment and the reuse of a flag activated obsolete trading logic. Controls failed to stop the resulting orders. |
| Impact in context | 99.9% — reported federal critical-system readiness · Dec 1999 | $460M+ — trading loss |
| Recovery | GAO reports that OMB’s stated readiness for mission-critical systems at 24 major federal departments and agencies rose from 21% in May 1997 to 99.9% in December 1999. Most federal Y2K errors reported during the century and leap-day rollovers were minor and did not affect services. This was not proof of zero errors, worldwide readiness, or a risk that never existed. | Knight stopped the problematic trading and unwound positions. The incident exposed gaps in deployment verification and market-access safeguards. |
| Safeguards to discuss | Maintain an inventory that includes system owners and external dependencies. Test critical services end to end with partners. Preserve readiness evidence and contingency plans after the deadline passes. | Verify deployment consistency across every node. Remove dead code before reusing its controls. Enforce independent limits on automated actions. |
| Primary source | GAO · Year 2000 lessons learned, September 2000 ↗ | U.S. SEC · Enforcement release ↗ |
Take one shared pattern into a rehearsal or review the evidence behind your own safeguards.
Review your safeguards →