---

---


Both [[entity-todd-la-porte|Todd La Porte]]'s [[entity-high-reliability-theory|High Reliability Theory (HRT)]] and the [[claim-perrow-1984-normal-accident-theory-tight-coupling-complexity|Normal Accident Theory (NAT)]] literature it engages frame the source of catastrophic failure as latent operational error, uncertainty, or organizational pathology internal to a system's own operation — not intentional manipulation by an actor who already holds legitimate access. The June 1996 special issue of the *Journal of Contingencies and Crisis Management* in which La Porte's paper appears reproduces [[entity-scott-sagan|Scott Sagan]]'s 1993 summary of NAT's tenets in a footnote — note 2 to Gene I. Rochlin's guest-editor introduction, "Reliable Organizations: Present Research and Future Directions," pp. 55–59, immediately preceding La Porte's article at pp. 60–71: "accidents are inevitable in complex, tightly coupled systems; ... redundancy often reduces safety by increasing complexity and opaqueness and encouraging risk-taking." Both theories' shared object of study is an organization managing uncertainty in its own operation.

[[claim-bit2watt-gpu-scheduling-destabilizes-power-grid|Bit2Watt]] describes something structurally different: an attacker who "operates entirely within the cyber layer as a legal tenant" and deliberately schedules GPU workloads to induce grid instability on purpose. This is not the founding scenario of either theory. HRT's "necessary but not sufficient" rebuttal to NAT's fatalism is an argument about organizations managing their own operational uncertainty and sustaining a culture of reliability against it — redundancy, technical competence, aggressive external watchers. Neither theory, in the texts read by this vault, addresses whether those defenses generalize to an adversarial threat model, where the source of the disturbance is a participant with no interest in keeping the system running.

The scope of that gap is narrower than the founding texts alone suggest, and the qualifier "as formulated" is load-bearing. Perrow himself later wrote a book about deliberate attack: *The Next Catastrophe: Reducing Our Vulnerabilities to Natural, Industrial, and Terrorist Disasters* (Princeton University Press, 2007; paperback 2011), whose publisher's description sorts disaster causes into natural, organizational and deliberate, and argues for deconcentrating "critical infrastructures such as electric energy, computer systems, and the chemical and food industries" to reduce their attractiveness as targets. That is an adversary-aware argument from NAT's own author about the same class of infrastructure Bit2Watt attacks, and the vault has not read it. What remains unexamined here is the narrower question — whether a *legitimate insider* exploiting tight coupling from inside the system's normal operating envelope is covered by either theory, as opposed to an external attacker — and it should not be stated as though the whole adversarial question were untouched. See [[question-verify-perrow-1984-normal-accidents-primary-read]]; a direct read of Perrow's 2007 book is the obvious companion to it.

> [!note] Seek's commentary:
> Both theories argue about who is to blame when a tightly coupled system breaks on its own — bad luck and impossible knowledge for Perrow, insufficiently expensive vigilance for La Porte. Bit2Watt isn't a data point for either side of that argument. It's a system breaking on purpose, by someone the system was built to trust. That's not a harder version of the old question; it's a different question nobody in this debate was asking, and I don't think either camp's toolkit was built to answer it. — Seek
