The Hidden Attack Surface: Why Administrative Friction Is a National Security Problem
Hatched by Ben H.
Aug 28, 2026
11 min read
2 views
93%
What if a nation could be weakened without taking down a power plant, disabling a hospital, or stealing a single classified file?
It might happen through something far less dramatic: an outdated phone number, an unanswered letter, an eligibility form that never reaches the right person, or a public system so difficult to navigate that people quietly disappear from it.
This sounds like a domestic policy problem. It is also a security problem.
The connection between Medicaid disenrollment and foreign attacks on critical infrastructure is not that health insurance databases and electrical grids are identical. They are not. The deeper connection is that both reveal the same vulnerability: a society can be disrupted by exploiting the gap between what its institutions are supposed to do and what people can actually access in practice.
The most important measure of resilience, in other words, is not whether a system exists on paper. It is whether the system continues to function when information is incomplete, people are confused, communications fail, and adversaries or ordinary bureaucratic processes introduce friction.
The Fragility of Systems That Work Only Under Ideal Conditions
Consider the mechanics of a Medicaid redetermination. A person may remain eligible, but coverage can still be lost because the state has an old address, a disconnected phone number, or a form that was never returned. In several states, more than 80 percent of people removed during the early phase of the process were disenrolled for administrative reasons rather than because officials had established that they were no longer eligible.
That distinction matters. It separates substantive failure from procedural failure. Substantive failure means the system reached the wrong conclusion about a person’s eligibility. Procedural failure means the system never successfully established the facts in the first place.
The second kind of failure is easier to overlook because it can be described as a completed transaction. A record is closed. A benefit stops. A notice is marked as sent. From the perspective of a dashboard, the process may look efficient. From the perspective of the person who loses access to a doctor or prescription, the system has failed to maintain continuity.
Critical infrastructure faces a similar problem under attack. An electric utility, water system, hospital network, or transportation system may have sophisticated defenses, but those defenses often assume that communication channels remain reliable, staff know which procedure to follow, and different organizations can coordinate quickly. An attacker does not need to destroy every component. It may be enough to create confusion at a critical junction.
A system can therefore be vulnerable even when every individual component appears competent. The weakness lies in the handoffs: between a state agency and a beneficiary, a hospital and an insurer, a utility and a vendor, or a public institution and the people who depend on it.
Resilience is not merely the ability to withstand a direct hit. It is the ability to preserve the correct outcome when ordinary signals become unreliable.
This is why administrative friction deserves to be understood as a form of infrastructure. A phone number, eligibility record, incident report, software credential, and emergency contact list may look like clerical details. In a complex society, they are connective tissue. When that tissue breaks, the larger body loses coordination.
The Same Logic Behind Disenrollment and Cyberattack
Warnings about Chinese government activity toward American critical infrastructure often focus on malicious code, espionage, and the possibility of physically disrupting civilian systems. The concern is not only that an adversary might steal information. It is that a large and persistent hacking operation could create the capacity to cause confusion, panic, and material damage at a chosen moment.
That strategy exploits a basic fact about modern societies: confidence in coordination is itself a resource. People expect the lights to turn on, hospitals to access records, financial transactions to clear, and public agencies to answer questions. If enough of those expectations fail at once, the psychological effects can exceed the technical damage.
A similar dynamic appears in benefits administration, though without a foreign attacker. When eligible people lose coverage because their contact information is outdated, the formal system may still be operating. Yet the lived system is not. The public hears that coverage is being reviewed, but individuals cannot tell whether a notice was sent, whether a form was received, or whether a decision can be appealed. Uncertainty spreads through families, clinics, and community organizations.
The key concept is trust latency, the time between a disruption and the restoration of a credible explanation. If a person loses coverage and receives a clear, rapid path to correction, trust may survive. If the person encounters silence, contradictory instructions, or an opaque portal, the disruption becomes more than an administrative inconvenience. It becomes evidence that the institution cannot be relied upon.
Cyberattacks target this latency directly. The longer it takes an organization to know what happened, communicate accurately, and provide an alternative way to operate, the more room there is for rumor and paralysis. Administrative systems often create the same latency unintentionally through rigid rules and fragmented ownership.
This suggests a useful model for evaluating public systems. Do not ask only whether the system is secure. Ask four additional questions:
- Can the system identify a failure quickly?
- Can people reach a human or trusted alternative channel?
- Can the institution maintain essential service while facts are being resolved?
- Can it restore confidence with evidence, not merely reassurance?
A state that cannot answer these questions during routine eligibility reviews is likely to struggle during a major cyber incident. Conversely, an agency that builds reliable ways to verify identity, update contact information, preserve benefits temporarily, and communicate across channels is practicing a form of national resilience, even if it never uses the language of cybersecurity.
Friction Is Not Neutral
There is a persistent temptation to treat administrative difficulty as an unfortunate but harmless byproduct of accountability. Verification rules exist for legitimate reasons. Public programs need to prevent fraud, allocate resources, and ensure that benefits reach eligible people. Critical infrastructure operators also need authentication, access controls, change management, and procedural discipline.
But friction is not neutral. It has distributional effects. Every additional form, password, identity check, deadline, and transfer between departments imposes a cost. People with stable housing, flexible work schedules, reliable internet access, and confidence navigating institutions pay a small cost. People who are sick, elderly, poor, displaced, or caring for others pay a much larger one.
This creates what might be called the friction inequality principle: the same procedural burden produces different failure rates across populations. A ten minute task is not ten minutes for someone without transportation, without broadband, or afraid that one mistake will end a vital benefit.
The principle also applies to organizations. A major utility may be able to absorb a complex security protocol. A small contractor with limited staff may not. A large hospital may have a backup communications center. A rural clinic may rely on one vendor and a single internet connection. Security that ignores these differences can become least effective where the system is most dependent on small, poorly resourced participants.
This is where the proposed role of large managed care or administrative companies becomes complicated. Organizations with scale may be able to improve outreach, data matching, call center capacity, and operational consistency. They may also introduce new layers of opacity, incentives to minimize costs, and dependence on concentrated private infrastructure. Outsourcing a difficult process does not automatically make it resilient. It may simply relocate the failure point.
The real question is not whether government or large contractors should perform the work. It is whether the arrangement produces observable continuity for the person or institution at the edge of the system. Can someone correct a bad address before losing coverage? Can an operator continue essential services if a vendor is compromised? Can officials switch providers without losing the underlying records and procedures?
A resilient design must prevent what engineers call a single point of failure. That applies to databases and power substations, but also to contractors, portals, call centers, identity systems, and institutional knowledge. Concentration can create efficiency in normal conditions while magnifying disruption in abnormal ones.
Efficiency asks how cheaply a process can complete its usual task. Resilience asks whether the process can preserve its purpose when its assumptions break.
Designing for the Person Who Falls Through the Gap
The most revealing test of a public system is not its performance for the average user. It is what happens to the person who is difficult to reach, difficult to classify, or difficult to reassure.
Imagine two versions of a benefits renewal system. In the first, the agency sends one notice to the address on file. If the notice is not returned, coverage ends. The process is simple, measurable, and brittle. In the second, the agency uses multiple channels, checks for changes through authorized data sources, gives the person a temporary continuity period, and makes it easy for clinics or community organizations to flag a likely error. The second system may cost more and produce more administrative work. It is also much harder to break through silence.
Now imagine two hospitals responding to a cyber incident. The first has a security policy, but no paper medication workflow, no tested downtime procedure, and no clear public message. The second has practiced manual processes, independent communication channels, prioritized clinical functions, and a way to tell patients what remains safe and available. Both may suffer the same initial intrusion. Only one has converted preparation into continuity.
These examples point toward a practical framework: grace, redundancy, and legibility.
Grace means the system does not impose irreversible harm immediately after a missed signal. A missed renewal form should trigger outreach and a chance to correct the record, not an instant loss of essential care. A compromised account should be isolated without bringing an entire hospital to a halt.
Redundancy means there is more than one path for communication, verification, and operation. Postal mail, phone, text, in person assistance, and authorized intermediaries can reinforce one another. Manual clinical procedures, segmented networks, backup vendors, and independent records can do the same for infrastructure.
Legibility means people can understand what is happening and what they can do next. A notice that technically satisfies a legal requirement but cannot be understood or acted upon is not resilient communication. Nor is a vague cyber incident statement that leaves patients, workers, and partner organizations unable to distinguish safe functions from unavailable ones.
These principles also provide a better way to assess technology investments. A new portal may reduce processing time, but does it improve recovery when the portal fails? A machine learning system may identify likely eligibility, but can a person challenge its conclusion? A security platform may detect malicious activity, but can frontline staff operate while the investigation continues?
The most valuable technology is often not the most sophisticated. It is the technology that creates more reliable paths between an institution and the people depending on it.
Key Takeaways
-
Audit the handoffs, not just the core system. Map every transition between agencies, vendors, workers, and users. Identify where an outdated record, missed message, or unclear responsibility can terminate service.
-
Measure false exits. Track how many people or institutions are removed from a system because they could not complete a procedure, rather than because they were affirmatively found ineligible or unsafe. This reveals hidden failure that completion rates conceal.
-
Build grace periods around essential services. When the cost of interruption is high, give people and operators time to correct errors, switch channels, and preserve the most important functions while facts are being resolved.
-
Require independent fallback paths from contractors and technology vendors. Public institutions should retain usable records, operational knowledge, communication channels, and transition plans. Outsourcing capacity should not mean outsourcing resilience.
-
Practice recovery as a public communication task. Test not only whether systems can be restored, but whether ordinary people can understand what happened, what remains available, and how to obtain help.
The New Definition of Critical Infrastructure
Critical infrastructure is usually imagined as something physical: a bridge, a pipeline, a substation, a hospital, a water treatment plant. But the more revealing definition is functional. Anything that allows people to coordinate around essential needs is infrastructure.
A benefits database is infrastructure because it connects eligible people to medical care. A contact record is infrastructure because it connects an institution to the person it serves. A call center is infrastructure because it converts confusion into correction. A clear notice is infrastructure because it preserves trust during uncertainty.
This expanded definition changes the security agenda. Protecting systems does not mean locking them down until no one can make a mistake. It means designing them so that mistakes, outages, attacks, and missing information do not automatically become abandonment.
Foreign adversaries may seek to exploit the seams in American infrastructure. Domestic institutions often expose those seams through routine bureaucracy. The strategic lesson is the same in both cases: a society is weakest where its formal systems stop and its human relationships begin.
The goal, then, is not to build institutions that never fail. That is impossible. The goal is to build institutions whose failures are visible, reversible, and survivable.
A missed letter should not become a lost medical future. A compromised network should not become a breakdown in public confidence. And a nation should not confuse a process that reaches its administrative endpoint with one that has actually protected the people it was built to serve.
The quietest vulnerabilities are often the most important ones. They do not look like attacks. They look like paperwork. Until enough people discover that the system no longer knows how to find them.
Sources
Hatch New Ideas with Glasp AI 🐣
Glasp AI allows you to hatch new ideas based on your curated content. Let's curate and create with Glasp AI :)
Start Hatching 🐣