Article
The Signal That Never Got a Seat at the Table
Real operational signals, a known vulnerability, a repeated complaint, a pattern flagged by frontline staff, often exist clearly inside an organization's own systems long before they reach the forum where a resourcing or prioritization decision actually gets made. The signal is not missing. The foru
- Published
- July 16, 2026
- Updated
- August 19, 2026
- Reading time
- 9 min

The Global Signal
In March 2017, a critical vulnerability in the Apache Struts web framework (CVE-2017-5638) was publicly disclosed along with a patch. Equifax's own internal scanning processes reportedly should have identified affected systems, but the vulnerability was not patched before attackers exploited it starting in mid-May 2017, and the resulting breach, discovered by Equifax on July 29, 2017, exposed the personal data of approximately 147 million consumers. This sequence, and the specific finding that the vulnerability and available patch information existed inside Equifax's own security processes well before exploitation began, is documented in the US Government Accountability Office's 2018 report on the breach and in the House Oversight and Government Reform Committee's December 2018 report, "The Equifax Data Breach" (GAO-18-559; House Committee on Oversight and Government Reform, December 2018). Equifax reached a global settlement with the Federal Trade Commission, the Consumer Financial Protection Bureau, and all fifty states in July 2019, worth up to $700 million.
The patch notice existed. It reached the technical teams responsible for applying it. It did not reach, with sufficient urgency, the forum where a decision to prioritize that patch above other work would have been made.
Consumers whose personal data was exposed in the Equifax breach
A documented figure specific to this case, from Equifax's own disclosure and subsequent regulatory findings, not a general statistic about data breaches.
The signal is not missing. The forum was never built to receive it.
What changes when signals have a defined path to a decision forum
A signal being captured somewhere in an organization's systems is not the same as that signal reaching the people who can prioritize acting on it.
Defining an explicit, calibrated escalation threshold tied to a named decision body closes the gap between capture and decision.
Why the Visible Metric Misleads
An organization can correctly claim it has a process for capturing a given signal, a scanning tool, a feedback system, a ticketing queue, while that claim says nothing about whether the signal reliably reaches the forum where it would compete for prioritization against other work. The more revealing question is not whether a capture mechanism exists, but whether a defined threshold or escalation rule connects that mechanism to the specific meeting or decision body that allocates resources. Equifax's case shows the gap plainly: the vulnerability was captured somewhere in the organization's own security processes well before exploitation, and the House Oversight Committee's investigation found that gap was not a lack of information but a gap in how that information reached a decision.
The Leadership Move
The right move is not adding another dashboard or another feedback channel. It is defining, for each existing signal-capture mechanism, an explicit threshold that automatically escalates a signal to the specific decision forum where it can compete for prioritization, rather than assuming visibility inside a system is equivalent to visibility at the table where resourcing decisions happen.
- Ownership
The team closest to a signal, security, frontline service, support, typically owns capturing it accurately. Leadership and resourcing forums own deciding what gets prioritized. Between those two groups sits an escalation rule that, in most organizations, either does not exist or is informal enough to fail under pressure, which is exactly the gap Equifax's case exposed.
- Tradeoff
A hard escalation threshold will sometimes surface signals at a decision forum that turn out, in hindsight, not to have warranted the interruption, and that false-positive cost is real. The alternative, a signal capable of causing Equifax-scale consequences sitting uncaptured by any escalation rule, is a far larger and less visible cost that only becomes apparent after the fact.
- Human consequence
Roughly 147 million people had personal data exposed in a breach traceable to a patch that existed and was not applied in time, according to the GAO's and House Oversight Committee's own findings. The gap between a signal being captured and a signal reaching a decision forum is invisible to the people it affects until the consequence arrives.
Implication for Operators
Any organization with a scanning tool, feedback system, or reporting process should assume that a signal being technically captured is not the same claim as that signal reaching the forum where a prioritization decision gets made. The practical shift is defining an explicit escalation threshold for each capture mechanism, tied to a specific decision body, rather than relying on the informal assumption that important signals will naturally find their way to leadership's attention.
Equifax's own processes captured the signal that mattered most well before it became a 147-million-person breach. The organization was not blind to the vulnerability's existence. It was blind to the fact that capturing a signal and escalating it to a decision forum are two different steps, and no reliable rule connected the first to the second.
The decision blindness here is not a missing signal. It is a signal that reached every system except the one where a resourcing decision could actually have been made in time.
When frontline teams repeatedly see the same customer or operational problem, is there a formal path for that evidence to reach the forum that can fund or change the decision?
FAQ
Did Equifax lack the technical capability to detect the vulnerability?
The GAO's and House Oversight Committee's reports indicate the vulnerability and patch information existed inside Equifax's own processes; the failure documented was in escalation and remediation timing, not in the initial technical capability to detect the issue.
How is this different from simply having poor security practices?
Security practice quality is one factor, but this pattern is specifically about the gap between a signal being captured somewhere in an organization's systems and that signal reaching the forum with the authority to prioritize acting on it, a gap that exists in customer service and product functions just as often as in security.
How can an organization tell if a signal-capture mechanism actually reaches a decision forum?
Ask whether a defined, automatic threshold connects the capture mechanism to a named meeting or decision body, or whether reaching that forum depends on someone informally deciding to escalate it. If it depends on informal escalation, the connection is not reliable.
Would automatic escalation overwhelm leadership with noise?
Only if the threshold is poorly calibrated. The fix is a defined, deliberately set threshold, not escalating every captured signal, so that only signals crossing a genuine severity or frequency bar reach the decision forum automatically.
Who should own setting the escalation threshold?
A function with visibility into both the capturing system and the decision forum's actual capacity and priorities, typically risk, operations, or a cross-functional governance role, rather than the team that owns the capture mechanism alone.
Related intelligence
Article
Steering From Lagging Indicators
Strategic choices are routinely built on the most recent quarter's or year's results, indicators that are, by construction, a record of conditions that have already changed by the time they are reported. Leadership can steer confidently, using genuinely accurate numbers, toward a destination defined
Article
Automating a Decision Nobody Had Actually Made
Organizations frequently automate a workflow, a trading rule, a routing decision, a pricing exception, before anyone has explicitly decided what that workflow should optimize for, what should happen at its edges, or who owns the exceptions it will inevitably produce. Automation does not remove a dec
Article
Governance as a Way Not to Decide
A review committee, a steering group, or a multi-stage sign-off chain can look like careful oversight while actually functioning as a way to defer an uncomfortable decision indefinitely, because each additional review step looks rigorous and simultaneously postpones the moment someone has to actuall