On 28 February 2026, in the opening hours of the US–Israeli bombing campaign against Iran, a missile struck Shajareh Tayyebeh elementary school in Minab, killing roughly 168 people, most of them children.
The big question: When the information that could stop a catastrophe exists somewhere in the system, why does it so reliably fail to reach the point where a decision is actually made?
Devin Savage
dnaofdisaster.com | August 1, 2026
Two catastrophes, same architecture
On the night of 14 April 1912, the wireless operator aboard Titanic had, at various points, everything he needed to keep the ship out of the ice. He didn’t act on most of it. He wasn’t careless, and Captain Smith wasn’t negligent in any way a court would recognise. The problem was structural: the pathway between “information exists” and “information reaches the people steering the ship” was never built to carry that vital information.
More than a century later, a Tomahawk missile struck a school in Minab, southern Iran, in the opening hours of the war with Iran, and killed roughly 168 people, most of them children. The US government had intelligence that the building — once a military site — had been converted to a school. That intelligence never reached the people who planned the strike. The pattern is identifiable by its design. It’s the same failure, wearing different uniforms, more than one hundred years apart.
The Mesaba message
Captain Smith wasn’t hiding anything in his pocket out of malice. Early-twentieth-century wireless telegraphy was a novelty, not a command-and-control system, and it was staffed accordingly. The Baltic’s ice warning reached him and got filed away as background knowledge rather than a hazard requiring a course change. The Mesaba’s warning — the one that actually described the ice field Titanic was about to steam into — never reached him at all. It lacked the “MSG” prefix that would have flagged it as a priority message for the bridge, so Jack Phillips, buried under a backlog of passenger telegrams, put it under a paperweight and kept working the commercial traffic. A formatting convention — the absence of four letters — is the entire distance between a warning and a memo nobody reads in time.
This is less a control failure than a veto-node failure: a point in the system that had the standing to stop the ship, but no reliable mechanism forcing the critical information through that system: a human system which barely had time to congeal since it was Titanic’s maiden voyage. The node existed. It just wasn’t wired to the circuit breaker it was supposed to trip. In the end the effect was the same if the information had never been available in the first place. Cognitive Control — the C-Suite, didn’t get the information, and the catastrophe happened anyway.

The only picture of the Marconi radio room onboard the Titanic. Harold Bride is seated at the desk. 1912.
Same building, different purpose
The Minab strike has the same shape and the same flowchart. US intelligence had established that a site once occupied by Iran’s military had been converted into a school. That update — arguably the single most important fact about the target — never made it to the people planning the strike. There’s no evidence of suppression. The update never crossed the threshold from known-somewhere-by-someone to known-by-cognitive-control. This flowchart is intact from more than 100 years prior: the Mesaba message never made its way from the wireless room to the bridge.
Layer onto that the fact that, months before Minab, the Pentagon had gutted roughly 90 percent of the staff whose entire job was to catch exactly this kind of gap — the people who cross-checked targeting intelligence against civilian presence before a strike went out. That’s not an unrelated policy detail. That’s the removal of the redundancy that exists precisely because messages get lost. You don’t need Phillips to be lazy or Smith to be reckless for a ship to hit an iceberg; you just need there to be no second system checking the first one. Safety and success is designed into the system. You need someone checking the accuracy of the maps. Someone to look at the source of the information and check the DATE ON THE MAP. The school in Minab didn’t have a Marconi radio room because it didn’t need one. But those who should have known the building’s true identity were eliminated. (Human Folly #3: Trojan Horse) Those who sent the ‘iceberg’ into the path of the school should have had their Marconi room operational. But the Marconi room was declared redundant. The Pentagon’s entire layer of the modern equivalent of the Titanic’s Marconi radio room was either reassigned or fired the year before. DOGE cannot operate a system it doesn’t understand. When you blindly hack away at a system you don’t understand, it’s just a matter of time before you hit an artery.
Veto nodes without veto power
A veto node is a point in the system that has the authority to stop an action. There are many cases where the veto node exists theoretically but lacks a guaranteed channel for receiving the information that should trigger that stop. Here’s where the parallel sharpens instead of just rhyming: even where the civilian-harm advisers still existed, they were never given actual veto authority over a strike. They could advise. They could flag. But they could not stop anything. That’s the wireless room in 1912 all over again — a position with visibility into the hazard and no formal power over the ship’s course. A veto node without veto power isn’t a safeguard; it’s a brake pedal- but it’s not actually connected to the brakes.
This is the recurring Human Folly in both cases: mistaking the existence of a warning system for the authority of a warning system. White Star Line had wireless technology on board and believed, culturally, that this made Titanic modern and safe — without anyone examining whether the technology had been given the standing to actually change the ship’s behaviour. The Pentagon, similarly, had built up two decades’ worth of civilian-harm infrastructure after Iraq and Afghanistan, and its removal was treated as a housekeeping decision about “wokeness” rather than the deletion of a veto node that never had veto power to begin with — which made it, ironically, an easy thing to cut, since nobody could point to a moment it had actually stopped a strike. Here we go again with this mechanism: the only way to prove the necessity of such crosschecks is to eliminate them and allow the catastrophe to unfold.
The illusion of monitoring: From Titanic to OceanGate
This dynamic isn’t limited to human chains of command—it is frequently engineered into modern hardware. Consider the Titan submersible, which imploded in 2023. OceanGate heavily marketed its “Real-Time Monitoring” (RTM) system, which used acoustic sensors and strain gauges to listen for micro-cracks in the carbon-fiber hull during descent. On paper, it was a sophisticated safeguard designed to give early warning.
In reality, it was a veto node designed to fail. The acoustic crackling of carbon fiber under pressure occurs milliseconds before total collapse, offering zero functional lead time to abort the mission and begin the long ascent back to the surface. Furthermore, the system lacked automated audible alarms, allowing operators to manually adjust alert thresholds and dismiss previous structural warnings as routine “settling.”
Like White Star Line’s wireless telegraph or a defunded civilian-protection department, OceanGate built a monitoring system that provided the feeling of oversight without the mechanics of prevention. It was an exercise in dangerous reassurance: a sensor suite wired to an interface, but decoupled from actionable control.
Outdated maps in real time
The Titanic chapter (The DNA of Disaster: Catastrophe by Design) makes the case that intelligent design must account for its environment, and that the quality of any embedded design — a shipping lane, a navigation chart, a targeting protocol — is entirely dependent on how current the underlying picture of reality is. A map of ice reported yesterday is not a map of ice tonight. A target list built on last year’s occupancy is not a target list for a building that’s been a school for months.
The tragedy in both cases isn’t that the information didn’t exist. It’s that neither system was designed with any urgency around the latency between a fact changing in the world and that change reaching the people with their hands on the controls. Titanic had no protocol forcing an unmarked ice warning to the bridge in real time. The Pentagon, having spent it down to a skeleton crew, had no functioning layer whose job was to keep target intelligence current against civilian reality in real time. (see link to The Intercept below) Both systems assumed the map was close enough. Both were wrong in the specific ten minutes it mattered.
The narrative vacuum after the strike
One more echo worth naming: in both disasters, the silence afterward did almost as much damage as the event itself. Silence by an actor or an agent after a catastrophe is often viewed as a confession. Mistakes were made, but the silence confirms the mistake and signals the coming cover-up. After Minab, the initial US response was confusion and finger-pointing — was it the Israelis, was it Iran’s own weapon — before the facts settled. Iran, for its part, wasted no time turning 168 civilian deaths into a fixed symbol, worn as pins, invoked at ceremonies, printed alongside rows of children’s backpacks at the World Cup. Whoever controls the explanation of why the map was wrong ends up controlling what the disaster means. White Star Line lost that fight over Titanic within weeks. The Pentagon is still losing it over Minab.
The uncomfortable symmetry
None of this requires believing Hegseth is a war criminal or that Captain Smith was a fool. That’s precisely the point of the DNA of Disaster framework: these are structural failures — intelligent systems that stopped accounting for their environment, veto nodes stripped of veto power (or removed altogether), and maps that went stale exactly when staleness was fatal. The 1894 Merchant Shipping Act didn’t sink Titanic on its own, and a staffing cut at the Pentagon didn’t, alone, kill 168 people in Minab. But both were the required-but-not-sufficient failure sitting quietly upstream of the one that was devastatingly fatal. Trump has reduced the collective institutional knowledge-base (the deep state perhaps?) by thousands of years. Those DOGE cuts mattered — they had real-world consequences, and we must not let that fact slide into oblivion.
Sincerely,
Devin Savage
Tübingen, Germany & Dublin, Ireland
Research assistance using Claude.ai and Google’s Gemini.
—
Notes
US intelligence had established that a site once occupied by Iran’s military had been converted into a school. That update — arguably the single most important fact about the target — never made it to the people planning the strike.
Months before Minab, the Pentagon cut by roughly 90 percent the staff whose job was to cross-check targeting intelligence against civilian presence before a strike went out.
The fatal strike on a Minab elementary school resulted from AI targeting systems (Maven, AskSage) processing decade-old, unverified data that misidentified the site as a military facility. Commanders bypassed automated system warnings to accelerate strike velocity, a process compounded by reduced human oversight. Read a detailed investigation at: https://edition.cnn.com/2026/07/07/politics/us-commanders-intelligence-iran-school
https://theintercept.com/2026/07/20/hegseth-civilian-harm-deaths-war/ -Hegseth’s War Department Slashed Civilian Protection Staff.
Further reading:
OceanGate
The Titan submersible had such a warning system
- Name: Real-Time Monitoring (RTM) system.
- Purpose: Constantly assess the structural integrity of the carbon-fiber hull.
- Marketing Claim: OceanGate claimed it could detect hull flaws and provide early warning to abort the dive safely.
- Reality: Marine safety investigations revealed the system was fundamentally flawed and failed to prevent the fatal 2023 implosion.
System Design
- Acoustic Sensors: Piezoelectric sensors glued to the hull interior to “listen” for micro-cracking noises in the carbon fiber.
- Strain Gauges: Connected along the hull to measure physical stretching and compression under deep-sea pressure.
- Data Logging: Sampled acoustic emissions and structural stress data multiple times per second during descent.
- Display Interface: Visual readouts on a screen inside the sub, showing real-time stress levels to the pilot.
Why It Failed
- Reactive, Not Proactive: Acoustic crackling in carbon fiber happens milliseconds before catastrophic structural failure, leaving zero time to abort.
- No Audible Alarms: OceanGate CEO Stockton Rush explicitly refused to install an automated audible alarm system.
- Manual Thresholds: Alert levels were set manually, allowing operators to misinterpret or adjust baseline safety limits.
- Dismissed Red Flags: Data anomalies and loud cracking sounds from previous, shallow test dives were ignored as normal hull “settling.”
- Progressive Fatigue: The system failed to track the cumulative, permanent damage caused by repeated deep-sea pressure cycles.




