Common-Mode Dependency Red Team¶
An adversarial review — instantiates Black-Swan Preparedness
Attacks a system's claims of diversification by hunting the shared supplier, platform, geography, or assumption that would make nominally independent defenses fail together.
Redundancy on paper is often redundancy in name only: three "independent" providers that all sit on the same cloud region, two "diverse" suppliers that both buy from one upstream, backup systems that share the operators, the model, or the assumption that will fail first. The Common-Mode Dependency Red Team is a standing adversarial review whose sole job is to disprove independence claims — to trace every nominally-diverse defense back through its suppliers, infrastructure, data, models, geography, incentives, and authority until it either proves the diversity is real or finds the shared root[1] that collapses it under stress. Its defining stance is disbelief: it treats "we're diversified" as a hypothesis to attack, not a status to confirm, and it earns its place precisely in the tail — the moment ordinary correlation understates crisis dependence.
Example¶
A payments company advertises that its critical customer-notification path is triple-redundant: three separate SMS providers, chosen so that no single vendor outage can silence fraud alerts. The red team is asked to break that claim. It follows each provider's traffic upstream and finds that two of the three hand off to the same wholesale aggregator, and that all three terminate through one mobile carrier's gateway in one country. On an ordinary day the three look independent and the dashboards agree. Under a regional carrier disruption — the exact tail event redundancy was bought for — all three go dark together.
The output is a dependency correction: the claimed three-way independence is really one-way, and the fix is a genuinely different channel (a push path on separate infrastructure) rather than a fourth SMS vendor that would share the same root. The team also flags a non-technical common mode: all three contracts were negotiated by the same procurement lead against the same cost target, so the "diversity" was selected by a single incentive and inherited a single blind spot.
How it works¶
- Take independence as the claim to falsify. Start from each asserted redundancy or diversification and treat it as guilty until proven independent.
- Trace to shared roots. Follow suppliers, infrastructure, data feeds, shared models, geography, ownership, incentives, and decision authority looking for a common node.
- Distinguish copies from alternatives. Flag "redundancy" that is really the same design duplicated — same platform, same failure assumption — versus genuinely different ways to perform the function.
- Prescribe real diversity or accept the exposure. Either specify an independent alternative or make the retained common-mode exposure explicit and owned.
Tuning parameters¶
- Trace depth — how many tiers upstream the review follows. Deeper tracing finds fourth-party and shared-infrastructure common modes but costs time and access; shallow tracing rubber-stamps first-tier "diversity."
- Dependency breadth — whether the hunt includes non-technical common modes (shared incentives, shared regulators, shared mental models), not just shared vendors. Widening it catches the subtle roots and risks boiling the ocean.
- Independence of the team — how insulated the reviewers are from the owners whose design they attack. Real independence sharpens findings; capture turns it into theater.
- Escalation mandate — whether a confirmed common mode must be remediated, accepted at a named level, or can be quietly filed.
When it helps, and when it misleads¶
Its strength is that it targets the specific illusion that kills resilient-looking systems — diversity that dissolves exactly when it is needed. It is most valuable before an incident, when there is still time to build a genuinely independent alternative rather than a reassuring copy.
Its failure modes come from teeth and reach. A red team captured by the designers it reviews will confirm independence it should have broken; a red team with no remediation mandate will document the shared root and watch it go unfixed. It can also over-hunt, declaring everything correlated until the finding is useless, or stop at technical dependencies and miss the shared incentive or assumption that is the real common mode. The discipline that keeps it honest is structural independence from the design owners, a mandate to escalate confirmed common modes to a level that can fund the fix, and a bias toward proposing genuinely different alternatives rather than more copies.
How it implements the components¶
tail_dependence_and_common_mode_review— its core output: the traced evidence of whether nominally diverse assets, suppliers, regions, models, or defenses fail together under stress.redundancy_diversity_and_independence_design— by proving which redundancies are genuine and which are copies sharing a hidden root, it audits and hardens the independence design itself.
It does not map the system's concentrated exposures or ruin paths as a whole — that is Reverse Stress and Failure-Budget Test's work — and it does not physically rehearse cutting a component loose; that is Modular Isolation and Firebreak Drill's.
Related¶
- Instantiates: Black-Swan Preparedness — the red team supplies the independence evidence the rest of the design depends on.
- Sibling mechanisms: Reverse Stress and Failure-Budget Test · Modular Isolation and Firebreak Drill · Sentinel Anomaly and Near-Miss Register · Mutual-Aid and Substitution Agreement · Protected Contingency Reserve
Editorial Notes¶
Form Classification¶
Form family: Assessment, Review & Assurance
Rationale: Attacks a system's claims of diversification by hunting the shared supplier, platform, geography, or assumption that would make nominally independent defenses fail together, making its operative form a bounded evaluation of existing evidence or work that produces a finding or disposition.
Independent corroboration: The frozen evidence defines Common-Mode Dependency Red Team as 'Attacks a system's claims of diversification by hunting the shared supplier, platform, geography, or assumption that would make nominally independent defenses fail together', so its operative form is Assessment, Review & Assurance.
Nearest alternative: Experiment, Test & Rehearsal — It adversarially reviews independence claims by tracing shared roots, but it does not actively perturb those dependencies as a probe would.
Review outcome: Independent reviewer agreement; medium confidence.
Origin Attribution¶
Primary origin: Engineering & Design
Origin pattern: Cross-disciplinary synthesis
Present-day reach: Multi-domain
Rationale: Reliability engineering supplied common-mode failure analysis and the demand that redundancy be diverse rather than duplicated.
Related originating lineages:
- Security Studies & Intelligence Analysis — Red-team practice contributes the adversarial stance of trying to disprove claimed independence.
Encyclopedia synthesis: The exact catalogued form synthesizes established practice rather than reproducing a single standard historical label.
Review outcome: Independent reviewer agreement; medium confidence.
References¶
[1] Mosleh, A., Coyne, K., Hunter, C., and Shen, S. Basis for the Treatment of Potential Common-Cause Failure in the Significance Determination Process. NUREG-2225. U.S. Nuclear Regulatory Commission (2018). Assesses whether an observed deficiency reflects a shared cause capable of affecting multiple redundant components. registry ↩