paraphrase of 3000 words
Learning from Failure and Building Resilience in High-Risk Systems: A Critical Analysis of Maritime and Security Domain Incidents
1 Introduction
High-risk organizations persistently struggle to learn from catastrophic failures (Szostek & Prabucki, 2025). Post-disaster investigations often blame technical faults or human error, yet safety science research demonstrates that major failures emerge from systemic organisational weaknesses, eroded safety barriers, and ineffective learning feedback loops (Gruchała et al., 2025). This report critically examines how organisations learn from failure and how resilience can be systematically embedded in high-risk systems.
Two contrasting case studies are selected. The MV Golden Ray capsizing (September 2019) represents a maritime industry failure involving total loss of a large vehicle carrier. This case is selected because the NTSB investigation provides comprehensive causal data, and the incident reveals fundamental gaps in safety management system verification procedures. The Disney Slack data breach (July 2024) represents a security-domain failure where the hacking group NullBulge compromised over 10,000 internal channels, exfiltrating one terabyte of sensitive data. This case is selected as a multi-level security failure illustrating architectural vulnerabilities in collaboration platform access controls. Together, these cases enable derivation of interdisciplinary lessons about learning from failure and resilience building.
2 Literature Review
2.1 Learning from Failures: Mechanisms, Barriers, and Institutionalisation
Organisational learning from failure is not an automatic or linear process. Purwar et al. (2024) propose three essential components of effective learning: (i) feedback to design, where operational insights reshape technical and organisational systems; (ii) deployment of advanced analytical tools such as Fault Tree Analysis (FTA) or Bowtie modelling to structure causal understanding; and (iii) generation of interdisciplinary lessons that transfer across sectors rather than remaining confined to isolated domains. However, Cunha et al. (2022) demonstrate a persistent "learning–doing gap": organisations capture lessons in post-incident reports but fail to translate findings into policy changes, procedural adjustments, or resource reallocations. Leong & Howlett (2021) extend this critique, arguing that much organisational learning remains symbolic—oriented toward stakeholder reassurance rather than substantive risk reduction.
A critical distinction emerges between learning from failure and learning despite failure. Mehrizi et al. (2022), drawing on a longitudinal study of information system incidents, identify that effective learning requires three conditions: psychological safety to report errors without fear of retribution, systematic processes for root cause analysis beyond immediate technical triggers, and governance mechanisms ensuring that lessons are translated into enforceable safety requirements. Where these conditions are absent, organisations may repeatedly experience similar failures despite apparent lesson identification.
2.2 Unlearning and the Normalisation of Deviance
Perhaps more concerning than failure to learn is the phenomenon of unlearning—where previously institutionalised safety knowledge degrades over time. Labib (2015), in an empirical analysis of major disasters from Bhopal to Fukushima, classifies organisational learning outcomes as not learnt, superficially learnt, or unlearned. Critically, the third category—unlearning—was most prevalent in complex, high-risk organisations where early safety improvements gradually eroded under operational pressures.
Choi et al. (2025) provide a mechanism for how this erosion occurs, drawing on the concept of normalisation of deviance. When modest safety deviations occur without immediate negative consequences, organisations may gradually recalibrate their perception of acceptable risk. Repeated success despite procedural violations creates false confidence, reducing the perceived necessity for corrective action. Production pressures, cost constraints, and scheduling demands exacerbate this process, as documented extensively in analyses of both offshore oil and space exploration sectors (Morrison & Wears, 2022). Organisational incentives and performance metrics that prioritise throughput over safety actively impede the retention and institutionalisation of safety knowledge.
2.3 Resilience Theory and Engineering: From Static Security to Dynamic Adaptation
Traditional safety paradigms have emphasised prevention and control—designing systems to resist failure through robustness and redundancy. Resilience theory offers a complementary perspective, emphasising anticipation, absorption, adaptation, and recovery (Lv et al., 2024). The resilience triangle provides a valuable heuristic: system resilience is not merely about avoiding failure but about minimising performance loss following disruption and accelerating recovery trajectories (Bevilacqua et al., 2018).
The 4R framework proposed by Kammouh et al. (2019)—comprising robustness, redundancy, resourcefulness, and rapidity—extends this conceptualisation by identifying measurable dimensions of resilience. However, Scharte (2024) offers a significant critique: the 4R framework risks treating resilience as a static set of engineering traits rather than dynamic organisational capabilities that must be continuously cultivated. Robustness, for instance, may paradoxically reduce resilience if over-reliance on physical defences leads to atrophied monitoring and adaptive capacities.
Azadeh et al. (2016) position resilience engineering as an organisational capacity to anticipate disturbances, monitor risk indicators, respond effectively under stress, and learn from both successful and failed adaptations. In the context of crisis management, Wallo & Coetzer (2026) argue that this approach is particularly valuable because crisis scenarios are characterised by uncertainty, time pressure, and incomplete information—conditions that overwhelm conventional decision-making frameworks and require adaptive, learning-oriented responses.
A significant limitation in the resilience engineering literature, noted by Hu et al. (2024), is the persistent gap between conceptual frameworks and practical implementation guidelines. While resilience principles are widely endorsed, organisations lack validated instruments for measuring resilience capacities or systematically integrating them into safety management systems.
2.4 Systemic Accident Models
Crisis management and accident analysis require formal modelling approaches because the complexity of socio-technical systems exceeds unaided human cognitive capacity (Juhola et al., 2024). Systemic accident models externalise this complexity, mapping relationships across technological, human, organisational, and regulatory levels to enable anticipation, learning, and structured decision-making.
Capobianco et al (2025) provided the foundational critique of linear "root cause" models, arguing that accidents emerge from the dynamic interaction of multiple system levels under conflicting performance pressures. van Erkelens et al (2024) further developed this concept through the notion of "drift into failure," where systems gradually migrate toward the boundary of safe performance under economic and operational pressures, beyond which control is lost.
A comprehensive review by Delikhoon et al. (2022) systematically compares three leading systemic accident models: AcciMap, which maps contributing factors across sociotechnical system levels; STAMP (System-Theoretic Accident Model and Processes), which conceptualises accidents as resulting from inadequate control or enforcement of safety constraints; and FRAM (Functional Resonance Analysis Method), which focuses on functional variability and performance variability resonance. A comparative survey by Yousefi et al (2019) found that STAMP was most reliable for establishing preventive measures, while AcciMap provided the most succinct graphical summaries, and FRAM, though resource-intensive, yielded the richest recommendations for system redesign.
Stephen & Labib (2018) advocate hybrid approaches, combining the causal clarity of Fault Tree Analysis with the systemic breadth of STAMP or AcciMap. This integrated strategy recognises that no single analytical tool adequately captures all dimensions of complex failures, and methodological pluralism is required for robust learning from failure.
2.5 Axiomatic Design and the Independence Axiom in Safety
A critical, yet often overlooked, framework in disaster analysis is Axiomatic Design, particularly the Independence Axiom (Purwar et al., 2024). This principle states that for a system to be controllable and resilient, its functional requirements (FRs) must be independent of one another. In high-risk systems, if the "Execution" function and the "Verification" function are coupled—meaning they share the same data source, personnel, or software—the system becomes "coupled" and inherently vulnerable to single-point failures. Applying this axiomatic lens allows for a critical critique of whether safety barriers are truly redundant or merely "symbolic" duplications of a single flawed process.
2.6 Feedback to Design and Safety Barrier Management
A critical yet underexplored dimension of learning from failure is the mechanism by which lessons are translated into design improvements. Purwar et al. (2024) emphasise that learning is incomplete unless it results in demonstrable changes to system architecture, operational procedures, or safety barriers. Safety barriers—whether physical, technical, or organisational—function as layers of protection between hazards and potential consequences. Barrier management requires three reinforcing capacities: detection (identifying when barriers degrade or fail), prevention (designing barriers effective against identified threat scenarios), and degradation monitoring (tracking barrier condition and performance over time).
The failure of these capacities was evident in both the Piper Alpha disaster, where permit-to-work system failures allowed the removal and miscommunication of a critical pressure safety valve (Reid, 2020), and the Space Shuttle Challenger disaster, where O-ring seal degradation was known but normalised rather than remediated (Petrov et al, 2024). In both cases, degraded barriers were not effectively detected, prevention mechanisms were overridden by production pressures, and systematic monitoring of barrier condition was absent.
3 Case Study 1: MV Golden Ray Capsizing (Maritime Industry)
3.1 Background and Causes
On 8 September 2019, the vehicle carrier MV Golden Ray capsized departing Brunswick, Georgia, USA. The NTSB (2022) investigation identified the probable cause as the chief officer’s error entering ballast quantities into stability software. Critically, the vessel’s Safety Management System (SMS) contained no procedure to verify stability calculations before departure, and neither operator nor master was aware of the stability deficit. Three systemic failure categories emerged: (1) absence of input validation in software design; (2) SMS lacking verification procedures despite ISM Code requirements; (3) regulatory audits checking procedure presence rather than effectiveness.
FTA decomposes the capsizing into logical causal pathways (Stephen & Labib, 2018).
Figure 1: Fault Tree Analysis of MV Golden Ray Capsizing
The FTA reveals two critical insights. First, capsizing required conjunction of stability loss AND absence of corrective action—neither alone sufficed. Second, inaccurate calculation could arise through three independent pathways (data entry error, insufficient training, no input validation), representing OR logic meaning any single failure suffices. Most significantly, absence of corrective action resulted from two organisational failures: SMS had no verification procedure, and master did not independently verify. This demonstrates systemic rather than individual failure.
3.3 Reliability Block Diagram (RBD)
RBD models the stability assurance system as series and parallel configurations. In designed state, four barriers function in series: SMS procedure → chief officer calculation → automated validation → master verification. System reliability equals product of individual reliabilities—with 0.99 each, series reliability is 0.96. In actual state, barriers (SMS procedure, automated validation, master verification) were effectively non-functional (reliability near zero), reducing system to single-barrier reliance on chief officer, yielding unacceptable failure probability.
Figure 2: Reliability Block Diagram (RBD) of the MV Golden Ray Stability System
3.4 STAMP Control-Loop Analysis: The Golden Ray
While FTA and RBD identify what failed, STAMP (System-Theoretic Accident Model and Processes) explains why the safety constraints were not enforced. In the Golden Ray capsizing, the primary "Control Loop" failure occurred between the Chief Officer (Controller) and the Ballast System (Process).
· Inadequate Control Action: The Chief Officer provided an "Inaccurate Data Input" based on an unverified mental model of the vessel’s stability.
· Missing Feedback Loop: The Master and the Safety Management System (SMS) failed to provide the necessary "Control Feedback" to identify the discrepancy before departure.
· Systemic Constraint Violation: The safety constraint—"The vessel must not depart with a GM (Metacentric Height) below the regulatory minimum"—was violated because the "Controller" (the officer) lacked an independent sensor (automated validation) to challenge his input.
This STAMP analysis reveals that the disaster was not a "human error" but a Control Loop Failure where the system allowed a single agent to operate without a challenging feedback mechanism.
3.5 Learning Outcomes
NTSB (2022) recommended independent verification procedures for stability calculations. However, critical evaluation reveals limitations: recommendations focus on procedural additions rather than redesigning interfaces to prevent data entry errors. A resilience-oriented redesign would incorporate input validation, interlocking confirmations, and continuous monitoring during transit.
4 Case Study 2: Disney Slack Data Breach (Security Domain)
4.1 Background and Multi-Level Failure
In July 2024, NullBulge compromised a Disney software development manager’s computer, gaining access to Slack and exfiltrating 44 million messages, 18,800 spreadsheets, and sensitive data. The breach exploited not merely compromised credentials but architectural design: once authenticated, the account could access over 10,000 channels without additional authorisation. Four failure levels are identifiable: (1) architectural—Slack’s access model lacks least privilege; (2) procedural—no mechanism for detecting anomalous access patterns; (3) organisational—no regular access reviews; (4) governance—default configuration prioritised collaboration over restrictive security (Wire, 2024).
4.2 Fault Tree Analysis (FTA)
The FTA shows that data exfiltration requires unauthorised access AND exfiltration capability. Unauthorised access has three OR pathways: compromised credentials, insider collaboration, or overly broad access rights. Critically, architectural vulnerability (A3.1) lowers the threshold for other pathways. Exfiltration capability depends on platform permitting bulk download (B1—Slack does not restrict download volumes) AND absence of anomaly detection (B2—Disney lacked effective monitoring). The FTA reveals that addressing any single pathway would be insufficient because alternative pathways exist.
Figure 3: Fault Tree Analysis of Disney Slack Data Breach
4.3 Reliability Block Diagram (RBD)
Figure 4: Reliability Block Diagram (RBD) mapping the theoretical security constraints against the actual administrative bypass exploited in the Disney Slack breach.
RBD analysis of security barriers identifies a series configuration for primary access control (identity management → authentication → authorised access → logging). Failure of any component compromises security. A parallel defence-in-depth configuration (endpoint security, network monitoring, anomaly detection, data loss prevention) theoretically provides redundancy. However, the RBD exposes a single-channel vulnerability: Slack platform directly provides administrative account holders access to all communication data without per-channel authorisation—violating least privilege and defence in depth principles.
4.4 Axiomatic Critique of the Disney Breach: The Coupling Problem
The Disney Slack breach represents a classic violation of the Independence Axiom. In a resilient security architecture, Authentication (who you are) and Authorization (what you can access) must remain independent functional requirements. In the Slack environment exploited by NullBulge, these two functions were dangerously coupled: once the "Authentication" requirement was satisfied via the manager's compromised credentials, the "Authorization" for 10,000+ channels was automatically granted.
This coupling created a "Highly Coupled Design," where a single failure in the credential barrier led to a total collapse of the data confidentiality barrier. A critical evaluation suggests that Disney’s reliance on a Single-Sign-On (SSO) model without per-channel Axiomatic Independence (such as Just-In-Time access) fundamentally ignored the "Safety Barrier" principles discussed by Purwar et al. (2024).
4.5 Learning Outcomes and Critique
Disney responded by migrating from Slack to Microsoft Teams. Critical evaluation reveals shallow learning: platform migration addresses symptoms rather than root causes (architectural access vulnerability). Microsoft Teams shares similar centralised characteristics. The decision may represent symbolic learning—visible action without substantive reform (Leong & Howlett, 2021). Substantive learning would require zero-trust access controls, continuous authentication, and anomaly detection—less visible but fundamental changes. The breach also highlights industry failure to learn from analogous incidents like the 2014 Sony hack.
5 Comparative Analysis
Table 1: Comparative Analysis of Maritime and Security Failures
|
Dimension |
MV Golden Ray |
Disney Slack Breach |
|
Failure type |
Physical stability |
Data confidentiality |
|
Immediate trigger |
Data entry error |
Compromised credentials |
|
Systemic vulnerability |
Single-point in verification |
Broad admin access rights |
|
SMS failure |
No verification procedure |
No least-privilege control |
|
Learning outcome |
Procedural recommendations |
Platform migration |
|
Learning depth |
Moderate—procedural |
Shallow—symbolic |
|
Resilience capacity |
Low—detection absent |
Low—detection absent |
Three critical findings emerge. First, both incidents share single-point failure vulnerability: Golden Ray’s stability assessment relied on one person’s data entry; Disney’s security relied on one account’s integrity. Second, learning outcomes differ: maritime generated specific procedural recommendations (moderate depth); security produced platform migration (shallow, symbolic). Third, both reinforce that failures result from multiple degraded barriers, requiring architectural redesign not merely procedural additions.
6 Discussion
The prevailing resilience engineering literature posits that high-risk systems require four dynamic capacities: anticipation, monitoring, response, and learning (Azadeh et al., 2016). However, the comparative analysis of the Golden Ray and Disney Slack incidents reveals a troubling gap between this theoretical ideal and organisational reality. Neither case demonstrated more than rudimentary resilience capacities. Golden Ray failed entirely at anticipation: despite routine ISM Code audits and classification society surveys, no mechanism identified the absence of stability verification procedures before the disaster. Disney failed equally at monitoring: anomalous access patterns—a single account suddenly downloading terabytes of data—went undetected for an extended period. These are not isolated oversights but symptomatic of systemic weaknesses in how resilience is conceptualised and operationalised.
A critical interrogation of resilience theory itself is warranted. Scharte (2024) has persuasively argued that frameworks such as the 4R model (robustness, redundancy, resourcefulness, rapidity) treat resilience as a set of static engineering traits rather than dynamic organisational capabilities. This criticism applies directly to the cases examined. In Golden Ray, the safety management system was *robust* on paper—documentation existed, procedures were written—but this robustness was entirely illusory when tested against an actual stability error. The vessel possessed *redundancy* in the sense of multiple crew members, but no redundancy in the critical function of independent verification. The case exposes that resilience indicators measured by compliance audits often capture form rather than function.
Feedback to design—the process of translating post-incident insights into proactive architectural changes—represents the primary mechanism by which organisations are supposed to learn from failure (Purwar et al., 2024). Yet, in both cases, feedback to design was systematically incomplete. Golden Ray generated procedural recommendations from the NTSB, but these address *adding* verification steps rather than *redesigning* the human–system interface to prevent data entry errors or provide real-time stability monitoring during transit. This is a crucial distinction: adding procedures to a flawed architecture does not eliminate single points of failure; it merely layers additional human tasks onto an already vulnerable process. Similarly, Disney’s decision to migrate from Slack to Microsoft Teams represents technological displacement, not architectural learning. Unless Disney simultaneously implements zero-trust access controls, continuous authentication, and per-channel authorisation—none of which were mentioned in public disclosures—the same class of vulnerability will recur on the new platform. This pattern exemplifies what Leong & Howlett (2021) term symbolic learning: visible organisational action that reassures stakeholders without addressing root causes.
The concept of unlearning provides a further critical lens. Labib (2015) demonstrated that even when lessons are initially learned, high-risk organisations systematically forget them under production pressures. In Golden Ray, the ISM Code’s verification requirements had been learned and then effectively unlearned as audits prioritised documentation over effectiveness. In Disney, the security industry had learned from the 2014 Sony hack that administrative accounts require strict controls—yet this lesson was unlearned as collaboration platforms prioritised usability over security. The recurrence of essentially identical failure patterns across sectors and decades suggests that current approaches to learning from failure are fundamentally inadequate.
More fundamentally, the linear accident models that still dominate organisational practice—including the FTA and RBD applied in this report—may themselves constrain learning by representing failures as static trees rather than dynamic control problems. Capobianco et al (2025) argued decades ago that accidents emerge from the gradual migration of systems toward unsafe boundaries under conflicting performance pressures. Neither FTA nor RBD captures this migratory dynamic. The implication is critical: organisations may conduct rigorous post-incident analyses using sophisticated tools, yet still fail to build resilience because their analytical frameworks cannot represent the slow, creeping degradation of safety margins that precedes most major failures.
The primary lesson for high-risk systems in 2026 is the adoption of a Zero Trust philosophy, spanning not only IT but also operational technology (OT) and maritime safety. Within the security domain, Zero Trust necessitates continuous detection and degradation monitoring rather than a solitary login event, while in the maritime sector, it manifests as autonomous validation where a ship’s own sensors—such as inclinometers and tank gauges—actively challenge the manual calculations of human officers. This cross-sectoral "feedback to design" demonstrates that systemic resilience is achieved by designing frameworks that expect failure at the human-system interface, allowing for the construction of "resourceful" barriers that can absorb errors before they escalate into catastrophes.
Finally, several limitations of this study must be acknowledged. The Disney breach investigation remains ongoing, and public data is incomplete, limiting causal depth. The analysis applied only two analytical tools; future research should apply STAMP or AcciMap to capture control feedback loops and governance failures more systematically (Delikhoon et al., 2022). Comparative studies across additional sectors—aviation, nuclear, healthcare—would test the generalisability of the interdisciplinary lessons identified.
7 Conclusion
This report examined how organisations learn from failure and build resilience through comparative analysis of MV Golden Ray and Disney Slack breach using Fault Tree Analysis and Reliability Block Diagram. Three conclusions emerge: (1) major failures result from systemic organisational weaknesses, not isolated errors; (2) genuine learning requires architectural redesign, not procedural additions or platform substitutions—maritime demonstrated moderate learning, security shallow symbolic learning; (3) resilience requires proactive design of anticipation, monitoring, response, and learning capacities. Without systematic barrier management, independent verification, and continuous learning feedback loops, the same failure patterns will recur across sectors regardless of technological sophistication.
References
Azadeh, A., Salehi, V., & Mirzayi, M. (2016). The Impact of Redundancy and Teamwork on Resilience Engineering Factors by Fuzzy Mathematical Programming and Analysis of Variance in a Large Petrochemical Plant. Safety and Health at Work, 7(4), 307–316. https://doi.org/10.1016/j.shaw.2016.04.009
Choi, E., Scott, K. A., Ng, S., & Fathallah, R. (2025). The Me You (Don’t) See: How Leaders Filter Intrapersonal Information at Work. Journal of Leadership & Organizational Studies. https://doi.org/10.1177/15480518251337261
Cunha, M. P., Clegg, S., Rego, A., Giustiniano, L., Abrantes, A. C. M., Miner, A. S., & Simpson, A. V. (2022). Myopia during emergency improvisation: Lessons from a catastrophic wildfire. Management Decision, 60(7), 2019–2041. https://doi.org/10.1108/MD-03-2021-0378
van Erkelens, A. M., Thompson, N. A., & Chalmers, D. (2024). The dynamic construction of an incubation context: a practice theory perspective. Small Business Economics, 62(2), 583-605. https://doi.org/10.1007/s11187-023-00771-5
Delikhoon, M., Zarei, E., Banda, O. V., Faridan, M., & Habibi, E. (2022). Systems Thinking Accident Analysis Models: A Systematic Review for Sustainable Safety Management. Sustainability, 14(10), 5869. https://doi.org/10.3390/su14105869
Hu, Z., Zhong, H., Li, S., Li, S., Shen, Y., He, C., & Xu, Z. (2024). Impact of Resilience Engineering on Physical Symptoms of Construction Workers. Buildings, 14(12), 4056. https://doi.org/10.3390/buildings14124056
Kammouh, O., Gardoni, P., & Cimellaro, G. P. (2019). Resilience assessment of dynamic engineering systems. MATEC Web of Conferences, 281, 01008. https://doi.org/10.1051/matecconf/201928101008
Labib, A. (2015). Learning (and unlearning) from failures: 30 years on from Bhopal to Fukushima an analysis through reliability engineering techniques. Process Safety and Environmental Protection, 97, 80–90. https://doi.org/10.1016/j.psep.2015.03.008
Leong, C., & Howlett, M. (2021). Policy Learning, Policy Failure, and the Mitigation of Policy Risks: Re-Thinking the Lessons of Policy Success and Failure. Administration & Society, 54(7). https://doi.org/10.1177/00953997211065344
Lv, Y., Sarker, M. N. I., & Firdaus, R. B. R. (2024). Disaster resilience in climate-vulnerable community context: Conceptual analysis. Ecological Indicators, 158, 111527. https://doi.org/10.1016/j.ecolind.2023.111527
Mehrizi, R. M. H., Nicolini, D., & Rodon, J. (2022). How Do Organizations Learn from Information System Incidents? A Synthesis of the Past, Present, and Future. MIS Quarterly, 46(1), 531–590. https://doi.org/10.25300/MISQ/2022/14305
Morrison, J. B., & Wears, R. L. (2022). Modeling Rasmussen’s dynamic modeling problem: drift towards a boundary of safety. Cognition, Technology & Work, 24(1), 127–145. https://doi.org/10.1007/s10111-021-00668-x
National Transportation Safety Board. (2022). Safer Seas Digest 2021: Lessons learned from marine accident investigations (Report No. SPC-22/01). https://www.ntsb.gov/about/organization/MS/Documents/SPC2201.pdf
Purwar, D., Flacke, J., & Sliuzas, R. (2024). Improving community understanding of cascading effects of critical infrastructure service failure: An experimental interactive learning process. Progress in Disaster Science, 24, 100383. https://doi.org/10.1016/j.pdisas.2024.100383
Scharte, B. (2024). Translating resilience research to political practice – The case of the German Resilience Strategy. International Journal of Disaster Risk Reduction, 111, 104724. https://doi.org/10.1016/j.ijdrr.2024.104724
Stephen, C., & Labib, A. (2018). A hybrid model for learning from failures. Expert Systems with Applications, 93, 212–222. https://doi.org/10.1016/j.eswa.2017.10.031
Wire. (2024). The admin privilege model is broken. Wire Blog. https://wire.com/en/blog/admin-privilege-model-is-broken
Bevilacqua, M., Ciarapica, F. E., & Marcucci, G. (2018). A modular analysis for the supply chain resilience triangle. IFAC-PapersOnLine, 51(11), 1528-1535. https://doi.org/10.1016/j.ifacol.2018.08.280
Wallo, A., & Coetzer, A. (2026). Learning-oriented leadership in SMEs in volatile and disruptive environments. European Journal of Training and Development, 1-20. https://doi.org/10.1108/EJTD-08-2025-0159
Juhola, S., Bouwer, L. M., Huggel, C., Mechler, R., Muccione, V., & Wallimann-Helmer, I. (2024). A new dynamic framework is required to assess adaptation limits. Global Environmental Change, 87, 102884. https://doi.org/10.1016/j.gloenvcha.2024.102884
Yousefi, A., Rodriguez Hernandez, M., & Lopez Peña, V. (2019). Systemic accident analysis models: A comparison study between AcciMap, FRAM, and STAMP. Process Safety Progress, 38(2), e12002. https://doi.org/10.1002/prs.12002Digital Object Identifier (DOI)
Reid, M. (2020). The Piper Alpha disaster: a personal perspective with transferrable lessons on the long-term moral impact of safety failures. ACS Chemical Health & Safety, 27(2), 88-95. https://pubs.acs.org/doi/full/10.1021/acs.chas.9b00022
Petrov, I., Mykhailenko, V., Kharchenko, R., Gunchenko, Y., Kochetkov, A. V., & Zui, O. (2024). Intelligent analysis of the causes of the Challenger space shuttle disaster. In ICST (pp. 295-305). https://ceur-ws.org/Vol-3790/paper26.pdf
Gruchała, P. S., Nicosia, L., & Zięciak, M. (2025). Harmonising risk assessments for high-risk AI systems under the GDPR and the AI Act. Journal of Data Protection & Privacy, 7(4), 359-371. https://doi.org/10.69554/ULBO5448
Capobianco, V., Choi, C. E., Crosta, G., Hutchinson, D. J., Jaboyedoff, M., Lacasse, S. & Reeves, H. (2025). Effective landslide risk management in era of climate change, demographic change, and evolving societal priorities. Landslides, 22(9), 2915-2933. https://doi.org/10.1007/s10346-024-02418-2
Szostek, D., & Prabucki, R. T. (2025). High-risk AI systems. In The European Artificial Intelligence Act: Promises and Perils? (pp. 157-180). Cham: Springer Nature Switzerland.