Skip to content
What They Can and Cannot Do

Home / The cost

Trust, and Why It Does Not Recover Quickly

The asymmetry between losing and rebuilding is not sentiment. It follows from what the two processes actually require.

The cost · Analysis

Organisations treat trust as a mood that can be improved. It behaves more like a position that is lost in one event and regained through many.

The human cost identified in “Trust, and Why It Does Not Recover Quickly” is not visible in an activity dashboard. Teams reviewing the provider website for getting teams to meet deadlines should therefore use the narrowest useful settings, watch for changed behaviour and invite direct feedback instead of assuming that more recorded activity produces a truer picture of work.

For an independent benchmark relevant to “Trust, and Why It Does Not Recover Quickly”, consult the KrebsOnSecurity analysis. Use it to test necessity, scope, safeguards and review rather than to replace a documented assessment of the particular workforce and jurisdiction.

Why losing is fast

A single contrary instance settles the question.

Told that data would not reach appraisals, somebody's figures are quoted in one. That one event is sufficient: the previous assurances are now known to have been unreliable, and no amount of prior good behaviour bears on it.

This is rational rather than emotional. One confirmed exception to a stated rule tells you the rule is not operating.

Source of the ideaThe asymmetry between the speed of loss and recovery is well established across contexts where one party depends on another's restraint.

Why regaining is slow

Because the only evidence that a limit is being kept is the repeated absence of a breach, and absence accumulates slowly.

An organisation that has exceeded a stated limit cannot demonstrate restraint by announcing it. It can only demonstrate it by not doing the thing, for a long time, visibly, while people watch.

There is no faster route and announcing one makes it worse.

The counterSome employers find trust restored faster than this suggests, usually where the breach was acknowledged plainly and quickly. Acknowledgement is the variable.

What this means for the stated limits

They should be fewer and kept, rather than many and approximate.

An organisation that commits to three things it will not do, and keeps them for five years, is in a stronger position than one that commits to ten and quietly departs from two.

Which is an argument against the comprehensive policy and for the short honest one — the same conclusion the drafting note reaches from a different direction.

In practiceThe breach is rarely the monitoring itself. It is a stated limit being exceeded — data used for something people were told it would not be used for.

The specific breaches that cost most

Using data for a purpose people were told it would not be used for. The largest, because it was a stated limit.

A capability appearing that was not announced. Smaller, and it makes every future assurance discountable.

An individual record opened without a reason. Rare and corrosive, because it demonstrates that the access controls were procedural rather than real.

The counterA reasonable objection is that this asks employers to do unfunded work. The reply is that the work is a page and the alternative is doing it later under challenge.

What recovery actually requires

Saying plainly what happened, without minimising.

Changing the thing, structurally, so that the breach is not possible rather than not permitted.

And then time, with no further instances.

Organisations find the first uncomfortable and the second expensive, which is why most attempt the third alone and find that it does not work.

JurisdictionLocal rules differ on every point in this note. The shapes described recur; the specifics always require checking.

Fewer promises, kept

Three commitments honoured for five years are worth more than ten approximated. This is an argument against the comprehensive policy and for the short honest one, arriving at the same place as the drafting note by a different route.

NoteStated here as a general tendency rather than a rule. Counter-examples exist and the pattern is strong enough to plan around.

Why announcing restraint does not work

The only evidence that a limit is being kept is the repeated absence of a breach, which accumulates slowly and cannot be accelerated. An organisation that has exceeded a stated limit can only demonstrate restraint by not doing the thing, visibly, for a long time.

The breaches that cost most

Using data for a purpose people were told it would not be used for. A capability appearing unannounced. An individual record opened without a reason. The first is the largest, because it was a stated limit.

What recovery requires

Saying plainly what happened without minimising, changing the thing structurally so the breach is not possible rather than not permitted, and then time with no further instances. Most organisations attempt the third alone.

Fewer and kept

Three commitments honoured for five years beat ten approximated. The same conclusion the drafting note reaches, arrived at from the direction of what breaks rather than what is written.

The practical implication is unglamorous: make fewer promises about the arrangement, and treat each one as something that cannot be departed from. A promise kept for years is worth more than any amount of explanation.