Moshe Kamionski

“Even Then, We Didn’t Understand”: The Risk-Governance Lesson Israel Must Learn

On the morning of September 11, 2001, I left home for shul after hearing that an airplane had struck one of the World Trade Center towers.

When I arrived, I asked someone, “Did you hear what happened? A plane hit the tower.” He answered: “Did you hear what happened? A second plane hit the other tower.”

In the few minutes it had taken me to get to shul, the meaning of the event had completely changed. One airplane could conceivably have been an accident. A second airplane striking the other tower meant something entirely different.

The information changed. The risk changed. And the required response had to change.

I have remembered that exchange for 25 years. I thought about it again this week as Israel began investigating the attempted terrorist attack aboard FlyDubai Flight FZ1073—and as increasingly disturbing facts emerged about what Israel may have known, or failed to know, about the people flying foreign aircraft into Ben Gurion Airport.

“Even then, we didn’t understand”

On October 4, N12 reported testimony from a former Ben Gurion Airport employee who said that she personally processed pilots and flight attendants holding Lebanese, Syrian and other passports.

She described crew members from hostile countries passing through the airport and said that some who attempted to enter Israel were refused entry when the system detected an additional passport.

Then she made the statement that should command our attention: “Even then, we didn’t understand how pilots from hostile countries could fly to Israel.”

But why should an airport employee have been expected to understand the full strategic significance?

She wasn’t the risk manager. The system was supposed to understand.

The employee observed an anomaly. The system should have transformed that observation into a question: Does this reveal a vulnerability that could produce catastrophic consequences?

That distinction—between seeing a warning and governing the risk revealed by that warning—is central to the argument I have been making about October 7.

The alleged attacker had already flown the Israel route

The emerging facts make the question considerably more troubling.

According to Channel 12 reporting cited by The Times of Israel, the alleged attacker, Hamam al-Hammami, had flown FlyDubai aircraft on the Dubai-Tel Aviv route several times before the September 30 attack. Israeli authorities were reportedly checking whether he had flown the route again only days before the attack.

FlyDubai had provided Israeli authorities with the crew names, including al-Hammami’s, before the September 30 flight. His name reportedly raised no security concern. Israel was also reportedly unaware that his former employer, Oman Air, had barred him from flying because of concerns about radicalization.

Then, on September 30, UAE prosecutors said al-Hammami attacked the captain with a cockpit crash axe and attempted to take control of the aircraft in what the UAE characterized as an attempted terrorist attack. More than 170 passengers and crew were aboard.

These facts change the risk-governance question. The alleged attacker was not someone encountering the Israel aviation system for the first time. He had reportedly passed through that system repeatedly.

The question is therefore not simply how one dangerous individual got onto one aircraft. It is: What system was responsible for recognizing and managing the underlying vulnerability before catastrophe nearly occurred?

This argument preceded FlyDubai

This is not a framework I developed in response to this incident.

On September 23, before the FlyDubai attack, I wrote in The Times of Israel that October 7 was not only an intelligence failure, but also a failure of strategic risk governance.

Six days later, in “Eight Days Before October 7: What DoD 5000 Could Have Forced Israel to Do,” I described the management discipline underlying the U.S. Department of Defense 5000 risk-management approach:

IDENTIFY → CLASSIFY → ASSIGN → MITIGATE → SCHEDULE → VERIFY → REASSESS → ESCALATE.

FlyDubai now provides a disturbing real-world test of that argument. What should have happened when Israeli personnel first encountered aircrew from hostile countries flying into Ben Gurion?

What would DoD 5000-style risk governance have done?

For more than four decades, I worked in national-security research, systems engineering and defense risk management, including at RAND and on major U.S. defense programs.

The discipline I discuss in my book, Ignored Warnings: How Israel’s Failure to Apply DoD 5000 Risk Governance Enabled the October 7 Massacre, does not require anyone to predict precisely when catastrophe will occur. It asks a different question: If this vulnerability is exploited, what could happen?

Applied to Ben Gurion, the question is not whether a Lebanese, Syrian, Iranian, Omani or other foreign pilot should automatically be regarded as dangerous. Nationality is not proof of hostile intent.

The question is systemic: Could weaknesses in the screening, verification or approval of foreign aircrew permit a hostile or compromised insider to obtain operational control of an aircraft carrying Israeli passengers or approaching Israeli territory?

If that possibility existed, the consequence could plainly be catastrophic. That should have triggered a formal risk process: Who owned the risk? What information about cockpit crews was required? Who independently verified it? Was reliance upon foreign airlines sufficient? How were dual nationalities handled? What happened when relevant information was held by a previous employer or foreign government? Who had responsibility for finding it? Who could approve an exception? And most importantly: How would Israel know that the risk had actually been reduced?

Information existed—but who owned the risk?

The emerging reporting illustrates exactly why this matters.

One organization reportedly possessed information that al-Hammami had previously been removed from flying duties because of concerns about radicalization. Israeli authorities reportedly did not have that information. FlyDubai knew his employment and flight history. Israel received crew names. Airport employees had encountered aircrew from hostile countries. Israeli agencies possessed their own databases and intelligence capabilities.

Different institutions therefore may have possessed different pieces of a potentially important picture. That does not mean anyone should necessarily have predicted al-Hammami’s attack. Prediction is not the standard.

The risk-management question is whether a system existed that could assemble relevant information, recognize a catastrophic vulnerability, assign somebody responsibility for it, and force mitigation.

One employee sees one anomaly. Another employee sees another. An airline has one piece of information. A foreign employer has another. A regulator has another. An intelligence service may have another. No individual necessarily sees the entire picture.

The system must be capable of seeing what individuals cannot.

Low probability does not eliminate catastrophic risk

Officials may reasonably have believed that a foreign airline pilot attempting to seize an aircraft was extraordinarily unlikely. Thousands of flights had arrived safely. Airlines vetted their personnel. Nothing happened.

But disciplined risk management separates probability from consequence. A low estimated probability does not erase a catastrophic consequence.

The appropriate question is not: “Do we believe this will happen?” It is: “If it can happen, can we afford to leave the vulnerability unmitigated?”

The danger of “nothing happened”

The fact that al-Hammami reportedly flew the Tel Aviv route several times before the attack makes another risk-management principle especially important.

Every previous flight apparently ended normally. That could easily have reinforced confidence in the existing system: he flew once, nothing happened; he flew again, nothing happened.

But repeated safe outcomes are not proof that a vulnerability has been eliminated.

A vulnerability does not become safe merely because it has not yet been exploited.

That lesson should sound painfully familiar after October 7. Years without a successful Hamas mass infiltration could reinforce the belief that deterrence was working even while Hamas’s ability to carry out such an attack was increasing.

Confidence is not risk reduction.

That is the connection to October 7

FlyDubai and October 7 are obviously different events. I am not comparing their scale or circumstances. I am comparing the institutional question that precedes catastrophe: What happens after warning signs reveal a potentially catastrophic risk?

Before October 7, Israel possessed information concerning Hamas’s capabilities, preparations and vulnerabilities along the Gaza border. No individual observer needed to predict precisely what Hamas would do on the morning of October 7.

The better question is: Once enough information existed to reveal the possibility of a catastrophic mass infiltration, what happened to that risk?

Who owned it? How was it classified? What mitigation was required? Who was responsible for completing it? Was implementation tested? Were assumptions challenged? Did anyone determine whether the residual risk was actually declining?

That is the distinction between intelligence and risk governance. Intelligence seeks to understand the threat. Risk governance forces an institution to decide what it will do about the risk created by that threat.

The commission must ask the next question

A national commission of inquiry into October 7 will understandably ask: Who knew what, and when did they know it? It must. But that is only the beginning.

The commission must continue: Once the risk was known, who owned it? What was the plan to reduce it? Who was responsible for executing that plan? Was the mitigation completed and tested? What residual risk remained? Who had authority to say that the remaining risk was unacceptable?

Those questions examine the institutional machinery between warning and action.

I develop a much more comprehensive framework for such an inquiry in Appendix B of my book, Ignored Warnings. I will not reproduce that framework here. Its central purpose is straightforward: a commission should investigate not merely what warnings existed, but whether Israel possessed a system capable of converting warnings into owned, measurable and sustained mitigation of catastrophic risk.

Israel should build that system now

The purpose is not to import American defense-acquisition bureaucracy into Israel. Israel should build a risk-governance system appropriate to its own government, military, intelligence and security institutions.

But the basic discipline is transferable: IDENTIFY → CLASSIFY → ASSIGN → MITIGATE → SCHEDULE → VERIFY → REASSESS → ESCALATE.

A catastrophic risk should not disappear because a briefing ended, responsibility was divided among agencies, personnel changed, or nothing bad happened last time.

Someone must own it. Someone must reduce it. Someone must verify that the mitigation worked. And someone at the appropriate level must explicitly confront whatever catastrophic risk remains.

I am prepared to contribute

I wrote Ignored Warnings because I believe the risk-management disciplines I encountered during more than four decades involving U.S. national-security and defense programs can be adapted to Israel’s security environment.

I would welcome the opportunity to contribute that experience.

If a national commission of inquiry, government ministry, security organization, research institution or other appropriate body believes this perspective would be useful, I would be prepared to assist in developing and applying a structured risk-governance framework.

My purpose would not be to prescribe operational or intelligence decisions. It would be to help establish the management discipline that ensures catastrophic risks are identified, owned, mitigated, tracked and repeatedly reviewed.

The system should have understood

That brings me back to the former Ben Gurion employee: “Even then, we didn’t understand.”

Perhaps she did not. She should not have been expected to.

The system should have.

And the fact that the man now accused of attempting a terrorist attack had reportedly already flown the Israel route several times makes that question considerably more urgent.

My memory of September 11 remains relevant for exactly that reason. The second airplane changed the information. The changed information changed the risk. And the changed risk demanded a different response.

Israel cannot prevent every surprise. Nor can any risk-management framework guarantee that catastrophe will never occur.

But Israel can demand that when information reveals a potentially catastrophic vulnerability, somebody owns the resulting risk, somebody is responsible for reducing it, and senior leadership continues asking whether it has actually been reduced.

After FlyDubai—and after October 7—the question should no longer be simply: Did we have warning?

It should be: What did we do with the risk once the warning was there?

That is the question Israel must answer before the next ignored warning becomes another catastrophe.

Related Times of Israel articles

October 7 was not only an intelligence failure, but also a failure of strategic risk governance

Eight Days Before October 7: What DoD 5000 Could Have Forced Israel to Do

My book, Ignored Warnings: How Israel’s Failure to Apply DoD 5000 Risk Governance Enabled the October 7 Massacre, is available on Amazon.

About the author and book

Moshe (Murray) Kamionski, Esq., is an Israeli-American attorney, former RAND Corporation researcher, and national-security risk-management professional with more than four decades of experience involving defense analysis, systems engineering and risk management. He is the author of Ignored Warnings: How Israel’s Failure to Apply DoD 5000 Risk Governance Enabled the October 7 Massacre. The book includes his proposed framework and questions for a national commission of inquiry into October 7. He welcomes inquiries from institutions interested in applying structured risk-governance principles to Israeli national security.

Book: Ignored Warnings on Amazon | ISBN 979-8-90549-324-9

Contact: mkamionskiauthor@gmail.com

About the Author
Moshe (Murray) Kamionski is an Israeli-American attorney, former RAND Corporation researcher, and national-security risk-management professional with more than 40 years of experience in defense analysis and systems engineering. Born in Israel and now living in Jerusalem, he is the author of Ignored Warnings: How Israel’s Failure to Apply DoD 5000 Risk Governance Enabled the October 7 Massacre, available at https://www.amazon.com/dp/B0HGB88TL4 He can be reached at mkamionskiauthor@gmail.com.
Sign in or Register
Please use the following structure: example@domain.com
Or Continue with
By registering you agree to the terms and conditions
Register to continue
Or Continue with
Log in to continue
Sign in or Register
Or Continue with
check your email
Check your email
We sent an email to you at .
It has a link that will sign you in.