Eight Days Before October 7: What DoD 5000 Could Have Forced Israel to Do
Eight days from now, Israel will again mark October 7.
We will remember the murdered, the wounded, the kidnapped, the devastated communities, and the soldiers and civilians who fought under extraordinary circumstances.
But remembrance must also produce institutional learning.
In my previous Times of Israel blog, I argued that October 7 was not only an intelligence failure. It was also a failure of strategic risk governance.
That raises the question I want to address here:
What kind of management discipline could have forced Israel to act on a catastrophic risk before catastrophe occurred?
My answer is found in a system that has governed much of my professional work: the U.S. Department of Defense 5000 series, commonly referred to as DoD 5000.
DoD 5000 was developed for defense acquisition, not for running a nation’s intelligence or military command structure. I am not suggesting that Israel simply import an American acquisition regulation.
I am arguing something more fundamental.
The risk-governance discipline underlying DoD 5000 provides a model for what Israel was missing: a structured process that forces a catastrophic risk from identification to ownership, from ownership to mitigation, from mitigation to scheduled execution, and from execution to measurable risk reduction.
That is the central argument of my new book, Ignored Warnings: How Israel’s Failure to Apply DoD 5000 Risk Governance Enabled the October 7 Massacre.
What DoD 5000 changes
DoD 5000 does something that is critically important in complex systems.
It makes risk a management problem, not merely an analytical observation.
An intelligence organization can say:
We assess that Hamas is deterred and a major invasion is unlikely.
A risk-governance system must ask another question:
What happens if that assessment is wrong?
That distinction is enormous.
Risk is not probability alone.
It is the interaction between probability and consequence.
If the potential consequence is catastrophic—mass civilian casualties, hostage-taking, attacks on military installations, disruption of command and control, and possible regional escalation—then uncertainty about probability cannot be the end of the analysis.
The consequence must drive action as well.
My first blog addressed that issue. This article addresses what should happen next.
Once a catastrophic risk has been identified, a disciplined DoD 5000-style system demands a chain of accountability:
IDENTIFY → CLASSIFY → ASSIGN → MITIGATE → SCHEDULE → VERIFY → REASSESS → ESCALATE
The purpose is not bureaucracy.
The purpose is to prevent catastrophic risk from disappearing inside bureaucracy.
RED must mean something
Calling something a RED risk is meaningless if nothing happens afterward.
In the framework I develop in Ignored Warnings, RED means that the institution must confront the risk.
Someone must own it.
Specific mitigation actions must be identified.
Those actions must be assigned.
They must be scheduled.
Their effectiveness must be tested.
The residual risk must then be reassessed.
And if it remains unacceptable, it must be escalated.
The book describes the risk register as a mechanism for making danger visible: description, likelihood, consequence, risk level, owner, mitigation, status and residual risk are tracked rather than left as disconnected concerns.
That structure changes institutional behavior.
A warning can be forgotten.
A briefing can end.
An email can remain unanswered.
But a RED risk with a named owner, mitigation plan, schedule and recurring senior review is much harder to make disappear.
Risk does not decline because nothing happened yesterday
This brings us to one of the most important DoD 5000 concepts in my book: risk burn-down.
One of the most dangerous mistakes an organization can make is to confuse the absence of catastrophe with the reduction of risk.
Imagine that a catastrophic vulnerability is identified in January.
Nothing happens in February.
Nothing happens in March.
Nothing happens in April.
By May, confidence has increased.
But has the risk declined?
Not necessarily.
If no mitigation has reduced either the probability of the event or its consequences, the underlying risk may be exactly where it was in January.
What changed was confidence.
Figure 5.2 — Risk Burn-Down Example for Hamas Mass-Infiltration Scenario
Figure 5.2 illustrates the principle.
The curve moves downward only when actual mitigation measures are completed and validated.
Each downward step represents accomplishment—not optimism.
For the Hamas mass-infiltration scenario, illustrative mitigation actions could have included full-scale breach simulations, reserve-mobilization stress tests, surveillance redundancy, civilian emergency-preparedness exercises and multi-axis infiltration war games.
Every successful action would answer an operational question.
Could Hamas penetrate the barrier simultaneously at multiple points?
Could drones disable critical surveillance or communications?
Could command and control continue functioning after those systems were attacked?
Could reserve forces mobilize quickly enough?
Could forces respond simultaneously to attacks against military installations and civilian communities?
Could exposed communities survive until reinforcements arrived?
A disciplined risk-governance system does not simply assume the answers.
It tests them.
Warnings do not burn down risk
This is the point I believe has been missing from much of the discussion surrounding October 7.
Intelligence does not, by itself, reduce risk.
Warnings do not reduce risk.
Surveillance does not necessarily reduce risk.
A sophisticated border barrier does not necessarily reduce the particular catastrophic risk being examined.
Those things provide information and capability.
But mitigation must be tied to the specific scenario.
My book makes precisely this distinction. Israel invested heavily in border barriers, surveillance and intelligence collection, but general defensive improvements are not the same as scenario-specific mitigation of a coordinated mass infiltration.
If the scenario is multiple simultaneous breaches accompanied by attacks on surveillance, communications, military positions and civilian communities, then the defensive architecture must be stress-tested against that scenario.
Otherwise, an institution can possess enormous technological capability while retaining an untested catastrophic vulnerability.
DoD 5000 forces the next question: Who owns it?
Identifying the mitigation is still not enough.
Someone can recommend an exercise.
Someone can recommend additional redundancy.
Someone can recommend greater readiness.
Someone can recommend strengthening civilian defenses.
Six months later, all four recommendations can still be recommendations.
DoD 5000-style governance asks:
Who owns the action?
That is where responsibility begins to become accountability.
But even ownership is insufficient without time.
An action without a completion date can remain open indefinitely.
That brings us to another tool from the defense programs on which I worked: the Integrated Master Schedule, or IMS.
From warning to an executable schedule
The IMS converts mitigation from intention into obligation.
Figure 5.3 — Integrated Master Schedule for Hamas Mass-Infiltration Risk Mitigation
This figure illustrates what a structured mitigation program for the Hamas infiltration risk might have looked like.
The questions are deceptively simple:
Who is responsible?
What precisely must be completed?
When does it start?
When must it be finished?
What other tasks depend upon it?
How will successful completion be demonstrated?
Who reviews the result?
What happens if it fails?
“Improve border readiness” is not an executable mitigation task.
“Conduct and validate a surprise reserve-mobilization exercise by a specified date, document deficiencies, implement corrective actions, and retest until the required response capability is demonstrated” is.
Figure 5.3 illustrates this distinction by linking surveillance redundancy, command-and-control integration, operational testing and civilian preparedness to responsible authorities, dates, dependencies and milestone reviews.
That is what an integrated schedule accomplishes.
It answers a question that every organization facing catastrophic risk should be required to answer:
Are we actually safer today than we were at the last review—and what completed action proves it?
The Risk Management Board
A schedule alone cannot govern risk.
Someone must review it.
During my work on major American defense programs, Risk Management Boards provided a management mechanism for reviewing significant risks and their mitigation.
The important point is not the name of the board.
It is the discipline the board imposes.
A functioning Risk Management Board should repeatedly ask:
Why is this risk still RED?
What mitigation was due since the previous review?
Was it completed?
If not, why not?
Did the completed action actually reduce risk?
Did testing uncover additional vulnerabilities?
Has the threat changed?
Are additional resources necessary?
Does the risk need to be escalated?
And ultimately:
Who has authority to accept the residual catastrophic risk?
That last question may be the most important.
If nobody is required to explicitly accept residual catastrophic risk, an institution can accept it by default.
Nobody signs a document saying:
“We accept the possibility of catastrophe.”
The organization simply continues operating.
The risk remains.
Risk governance avoidance
This is what I call risk governance avoidance.
Risk governance avoidance does not require bad people, indifference or a conscious decision to ignore danger.
It can occur inside highly professional organizations staffed by talented and dedicated people.
There can be intelligence reports.
There can be warnings.
There can be meetings.
There can be advanced technology.
There can be plans.
There can be defensive improvements.
There can even be intense discussion of the threat.
Yet if the organization cannot demonstrate that the catastrophic risk itself is being reduced, all that activity can coexist with essentially unchanged residual risk.
As Ignored Warnings puts it, what can be missing is not awareness but a governance structure capable of forcing sustained mitigation: RED risks remain unassigned, mitigation actions remain unscheduled and residual risk remains unchanged.
That is the difference between discussing risk and governing risk.
DoD 5000 changes the questions we should ask about October 7
Much of the public discussion has understandably concentrated on the intelligence trail:
Who knew?
What warnings were received?
Who saw Hamas’s plans?
What did observers report?
How were those reports interpreted?
Why was the prevailing assessment not changed?
Those questions matter enormously.
But DoD 5000-style risk governance adds another set of questions:
When was the Hamas mass-infiltration scenario identified?
How were its consequences characterized?
Was it formally treated as a catastrophic risk?
Who owned that risk?
What mitigation actions were assigned?
Who owned each mitigation action?
What was its required completion date?
Was it completed?
Was it tested?
What did the test reveal?
Were deficiencies corrected?
Did the residual risk actually decline?
If it remained unacceptable, where was it escalated?
Who had authority to accept what remained?
That is the risk-governance trail.
It should be reconstructed alongside the intelligence trail.
Because the ultimate question is not merely:
What did Israel know?
It is:
What did Israel’s institutions force somebody to do about what was known?
What I am—and am not—proposing
I am not proposing that Israel adopt American acquisition bureaucracy.
Israel is not the Pentagon.
Strategic threats are not weapons-development programs.
Military commanders must retain the ability to exercise judgment, respond rapidly to changing conditions and make decisions under uncertainty.
But those differences do not invalidate the underlying risk-governance principles.
The United States Department of Defense itself describes formal risk management as a means of prioritizing and mitigating programmatic risk, with major risks and mitigation plans brought forward at relevant decision points and milestones. Earlier DoD risk-management guidance similarly emphasized a disciplined, forward-looking, continuous and documented process.
The principle I want Israel to consider is therefore not complicated:
Catastrophic risks should not depend solely upon institutional confidence or the prevailing assessment.
They should be governed.
Israel can develop its own structure appropriate to its government, intelligence services and military.
But the structure should accomplish the same essential functions:
identify, classify, own, mitigate, schedule, test, verify, reassess and escalate.
Eight days before October 7
Eight days from now, Israel will again confront the enormity of October 7.
Remembrance is essential.
But Israel owes the victims, their families, the soldiers who fought that day and future generations something more:
institutional learning capable of preventing repetition.
I wrote Ignored Warnings because I believe October 7 revealed a problem deeper than a collection of individual intelligence and operational failures.
It revealed the danger of allowing catastrophic risk to exist without a governance structure powerful enough to force that risk downward.
The title of Chapter Six of my book is:
“The Burn-Down That Never Occurred.”
That is the question I believe Israel must now confront.
If the possibility of a catastrophic Hamas mass infiltration was known, however uncertain its probability:
Where was the RED risk?
Who owned it?
Where was the mitigation plan?
Where was the schedule?
Who verified completion?
Where was the Risk Management Board or equivalent senior governance mechanism demanding to know why the risk remained?
And above all:
Where is the evidence that the catastrophic risk was actually burning down?
My book, Ignored Warnings: How Israel’s Failure to Apply DoD 5000 Risk Governance Enabled the October 7 Massacre, develops this argument in detail and proposes how the discipline behind DoD 5000 could be adapted to Israeli national-security risk.
For readers who want to examine the complete argument, the risk matrices, burn-down analysis, Integrated Master Schedule and proposed governance structure, Ignored Warnings is available on Amazon:
https://www.amazon.com/dp/B0HGB88TL4
October 7 demonstrated that warnings alone do not protect a country.
Warnings must identify risks.
Risks must have owners.
Owners must execute mitigation.
Mitigation must be scheduled and verified.
Residual risk must be measured and escalated.
And catastrophic risk must never be permitted to remain unresolved simply because the prevailing assessment says catastrophe is unlikely.
That is the discipline of DoD 5000.
That is the discipline Israel should adapt before the next ignored warning becomes another catastrophe.
