← Back to Dead Reckoning

Published August 27, 2026

Issue 0012: The Risk You Can Quantify

The risks organizations can quantify are not always the risks that matter most. Repetition can increase total incidents while making each individual attempt safer. Confusing those two can lead teams to cut the very reps that build competence.

Issue 0012: The Risk You Can Quantify

Seven of us were seated on the canvas seats of a C-130. As we hit the heading for the drop zone, the rear ramp opened, revealing the Sydney skyline in the distance. It was the fourth time I'd seen it in two days, and it still looked just as surreal. We went through the usual commands, hooked up our static lines, and jumped out into the cool winter air.

It was a routine jump, the last military activity before we'd get a day in the city and head home. But I felt a little uneasy. Over the three prior jumps, three of the ten people on our team had picked up some kind of injury: a twisted ankle, a herniated disc, and a static-line bicep injury that, miraculously, wasn't a tear.

Would jump number four claim any more?

Turns out no. All of us walked away with nothing more than the minor bumps and bruises that come from doing four static line jumps in two days.

Over beers that night, a debate ensued about how risky jumping actually is and how much of it a team should do. My observation was that everyone who made it to jump number four was fine on jump four. Maybe that was a skill issue, a survivorship bias issue, or a combination of both. Others made the case that static line jumping was risky, it sucks, and we should do less of it. Our team’s 30% injury rate was proof.

Both sides of that debate were right, but about different risks.

Two Risks, One Word

There's a tension between the skill that comes with experience and the risk that comes with training. Early in your jumping career, the risk on any individual jump is highest. With each subsequent jump, the risk on the next one drops.

It never goes to zero.

Skill eliminates some risks (a bad landing, botched navigation on the way down), reduces others (hitting an obstacle on the drop zone), and does nothing at all about the third class: an equipment failure, a pilot heading that puts you off the DZ into the trees, or a thousand other things we can't enumerate.

The baseline risk, no matter the skill level, never drops to zero because of Murphy. Think of the “Murphy factor” as the plateau below which risk never drops.

But cumulative risk runs the other way. Every jump adds a draw against that plateau. Imagine someone who planned to jump one million times. They'd develop incredible skill, but eventually Murphy would get them.

So per-jump risk falls with volume while total exposure rises with it, and we use the same word, "risk," for both. That can cause confusion.

If you have N jumps and each carries a failure probability p(N) that falls as N grows, your expected incidents are roughly:

E(I) = N × p(N).

If p(N) falls with volume, but not as fast as 1/N, the total keeps climbing even as every individual jump gets safer.

It's worth noting which of these two has a number on it.

Cumulative exposure showed up on our team that week as three names on an injury roster. It's countable, it's current, and somebody has to explain it in a sitrep.

The per-jump risk that skill buys down doesn't show up anywhere. It's an estimate of what happens on a night that hasn't happened yet, on a possible future mission nobody can put in a report yet. One risk is visible this afternoon. The other is visible only on the day it matters.

Organizations tend to manage the risk they can see.

What the Roster Argues

To be fair to the roster: those injuries aren't an abstraction. A herniated disc is a real soldier who is now non-deployable for the mission you were supposedly training for.

Past some volume, training injuries reduce readiness more than skill increases it, and a commander looking at three injuries in three jumps is not being timid when he asks whether the fourth is worth it. He's reading the only instrument that has a number on it.

The Army's answer is a policy. Jump once a quarter to remain airborne qualified and keep drawing jump pay ($150 a month when I was in). Or, for units that are constantly deployed like ours, jump four times a year and stay current, which is how our team found itself taking advantage of clear skies and an available aircraft in Australia.

The policy is the Army thinking in exactly these terms, whether they’d phrase it that way or not. The policy encodes the answer so nobody has to re-derive it on a C-130 ramp, or at a bar after two days of jumping.

The ultimate concern is mission success on a real airborne operation, and on that night the only risk that matters is per-jump. So the mission sets a minimum skill floor, and the injury roster is the accepted cost of the floor.

The failure mode is an organization with no floor, managing to the roster.

The Business Risk Translation

A class of business risks has the same shape: risk per unit declines as scale increases, while total exposure rises because the number of units exposed keeps growing.

Security processes mature as a company grows, and so does the attack surface. Manufacturing improves with experience, and more units sold means more total failures. Procurement gets more sophisticated, and a broader supply chain means more individual dependencies. Run the arithmetic on any of them: ten times the volume at half the rate is five times the incidents.

The potential trap for managers is how they interpret that data.

Software releases are the cleanest version of it. A team that ships to production every day logs more incidents than a team that ships once a quarter, because there are more releases to go wrong. The total count goes up, and in many cases the count is what gets reported, and the natural response is to do the thing less. Fewer releases, fewer suppliers, fewer new units, fewer reps.

Each release then becomes bigger and less practiced. The quarterly release carries three months of changes, is run by people who haven't run one since the last quarter, and lands on the one date the business has already promised to a customer. Per-unit risk, the one that matters on the day the release has to go or the supplier has to deliver, goes up.

The release data is unusually good on this point.

DORA's State of DevOps report put teams that deploy on demand at a 0 to 15% change failure rate. The lowest performers, by contrast, are deploying somewhere between monthly and every six months, with a 46 to 60% change failure rate. The lesson here is that the teams doing the risky thing most often were the ones for whom each instance of it was least risky.

The Army has a discrete moment the reps are for. Plenty of organizations don't; their mission is continuous, so exposure and the moment of use are the same thing, and the cumulative count really is the mission risk.

The distinction only holds where there's an event the company is buying down risk for. Also, a 1% risk of twisting an ankle is different from a 1% risk of burning in, and a 1% chance of a warranty refund is different from a 1% chance of a breach that ends the company. When the failure is unrecoverable, exposure is the whole story.

Four Questions

What point are you navigating to, and which risk gets in the way of reaching it? A few questions worth asking to determine whether per-unit risk or cumulative exposure are more important:

  1. Which of your risk numbers are counts of things that already happened, and which are estimates of what happens on the day it matters?
  2. What is the moment the reps are for, and does anyone name it when the incident count comes up?
  3. Where has a rising count of small failures been read as a reason to do the thing less?
  4. Who sets the floor, and is it set by the mission or by the roster?

Get the next issue

Subscribe to receive future issues direct to your inbox.