top of page

The Risk That Looks Like Success. The Challenger Disaster



AI generated image depicting the Space Shuttle and a hidden iceberg
Ai generated image depicting the Space Shuttle and a hidden iceberg

On the morning of 28 January 1986, millions of people around the world sat in front of their televisions waiting to watch history unfold. The Space Shuttle Challenger stood on Launch Pad 39B at Kennedy Space Center, ready to begin what was expected to be another routine mission. Schools across the United States had wheeled televisions into classrooms because one of the seven crew members was Christa McAuliffe, a schoolteacher selected to become the first ordinary citizen in space. For NASA, the mission represented more than another successful launch. It was an opportunity to demonstrate that spaceflight had become sufficiently safe and routine that teachers, and eventually perhaps many others, could travel beyond the Earth's atmosphere.


Behind the television cameras, however, the mood was considerably less optimistic. Overnight temperatures had fallen well below freezing, making it the coldest conditions under which a Space Shuttle had ever attempted to launch. Ice covered sections of the launch tower and concerns had already begun to emerge about how some of the shuttle's components might behave in temperatures they had never previously experienced. While the public saw another launch on the schedule, engineers and managers were wrestling with a much more difficult question.


Should the shuttle fly at all?


The concern centred on the rubber O-rings used to seal the joints between sections of the Solid Rocket Boosters. Their purpose was deceptively simple. They were designed to prevent superheated combustion gases from escaping as the boosters generated millions of pounds of thrust during launch. If the seals failed to perform properly, hot gases could escape through the joint with potentially catastrophic consequences.


This concern wasn't just theoretical. Previous shuttle missions had already shown evidence of O-ring erosion. On several occasions, the seals had displayed more damage than engineers expected to see, yet the flights themselves had all been completed successfully. The erosion had been documented, investigated and discussed, but because each mission ultimately achieved its objective, the issue gradually became viewed as something that required monitoring rather than something that prevented launch.


The evening before launch, engineers from Morton Thiokol, the company responsible for the boosters, joined NASA managers for what has since become one of the most scrutinised teleconferences in the history of engineering. Drawing on the data available to them, the engineers argued that the unusually cold temperatures created an unacceptable level of uncertainty. They believed the O-rings could become less resilient, reducing their ability to seal the booster joints during ignition. Their recommendation was clear. They advised that Challenger should not launch until temperatures increased.


What happened next has been analysed, debated and written about for almost forty years.


Following extensive discussion, questions from NASA managers and an internal review within Morton Thiokol itself, the recommendation changed. The engineers who had initially argued against launch found themselves overruled by senior management, who concluded that the available evidence did not justify another delay. Shortly afterwards, NASA accepted the revised recommendation and preparations for launch continued.

At 11:38 that morning, Challenger lifted off.


For just over a minute everything appeared entirely normal. The shuttle climbed away from Kennedy Space Center exactly as all launches had done before it, watched by millions of people who had no idea that anything was wrong. Then, seventy-three seconds after leaving the pad, a plume of flame escaped from the right-hand Solid Rocket Booster. Moments later the escaping gases burned through the external fuel tank, the vehicle broke apart under immense aerodynamic loads and all seven crew members were lost.


The physical cause of the accident was identified relatively quickly. The cold temperatures had reduced the ability of the O-rings to seal the booster joint, allowing hot gases to escape exactly as some engineers had feared. From an engineering perspective, the explanation appeared straightforward.


The more difficult question was never what failed. It was why the organisation had become comfortable accepting a level of risk that only a few years earlier would almost certainly have prevented the launch.


When major accidents occur, we naturally focus on the final failure because that's the part we can see. In Challenger's case it was an O-ring. In the Alaska Airlines door plug incident it was four missing bolts. In the Royal Navy F-35 accident it was an intake blank left inside the engine. The visible failure becomes the headline because it provides a neat explanation that appears to make sense of an otherwise incomprehensible event.

Unfortunately, those explanations rarely tell the whole story.


The O-ring didn't suddenly become dangerous on the morning of 28 January. It had been showing signs of erosion for years. Each occurrence prompted discussion and concern, yet each successful mission also sent a subtle message throughout the organisation. The shuttle had flown successfully despite the damage. Whatever had happened, the system had apparently coped with it. The warning remained, but the successful outcome quietly changed the way people interpreted its significance.


That process wasn't driven by complacency or carelessness. It was driven by experience.

Every successful launch became another data point suggesting that the risk was manageable. The absence of a catastrophic outcome slowly became evidence that the existing controls were adequate, even though the engineering concern itself had never disappeared. Over time, something that had originally been viewed as abnormal gradually became accepted as part of normal operations.


Nobody woke up one morning and decided that damaged O-rings were acceptable.

The organisation simply drifted there, one successful launch at a time.


By the time Challenger rolled onto the launch pad that freezing January morning, the launch decision wasn't being made in isolation. It was being made against the backdrop of dozens of previous missions, repeated operational success, growing schedule pressure and an organisational belief that experience had demonstrated the risk could be managed. That belief turned out to be catastrophically wrong.


There is a phrase that has become almost synonymous with the Challenger disaster, although it wasn't widely known until years after the accident. Sociologist Diane Vaughan, who spent years studying the organisational decision-making behind the launch, described what had happened as the normalisation of deviance. It's a phrase that has found its way into aviation, healthcare, mining, oil and gas, nuclear power and countless other safety-critical industries because it explains something many of us have experienced but struggled to describe.


The concept itself is surprisingly simple. When people deviate slightly from an expected standard and nothing bad happens, the deviation gradually becomes accepted as normal. The first time it feels uncomfortable. The second time it feels more manageable. Eventually it no longer feels like a deviation at all because experience has taught us that the system appears to tolerate it. Over time, the definition of what is considered acceptable quietly shifts, not because anyone consciously lowers the standard, but because repeated success convinces us that the original concern may not have been as significant as we once believed.


That's exactly what made Challenger such an important case study. NASA didn't ignore the O-ring erosion. They talked about it. They monitored it. They investigated it. The problem was that every successful mission subtly changed the meaning of the evidence they were seeing. Instead of asking, "Why are we seeing damage?", the organisation gradually found itself asking, "How much damage can we accept?", which a fundamentally different question. It's also one that many organisations ask without realising it.


How many times have you heard people say, "We've always done it this way,"? Sometimes they're talking about maintenance practices. Sometimes it's a briefing that has gradually become shorter because everyone knows each other. Sometimes it's a workaround that was introduced during a busy period and quietly became the new normal. Rarely does anyone make a deliberate decision to lower the standard. More often, the standard simply drifts because the system keeps delivering successful outcomes.


That is why the normalisation of deviance can be so dangerous. It doesn't feel dangerous. In fact, it often feels like experience.


When somebody says, "We've done this dozens of times," they're usually trying to reassure you. The statement sounds like actual evidence that the process is safe. Occasionally it is. Occasionally it's evidence that the process has simply never been tested under the combination of conditions that expose its weaknesses. The distinction only becomes obvious with hindsight, and hindsight is a luxury leaders never have in the moment.


We should become uneasy when organisations measure the health of their operation purely by outcomes. If the project finished on time, the aircraft landed safely, the patient recovered or the production target was achieved, it's tempting to conclude that the system must be working well. Success certainly feels reassuring, but successful outcomes don't always validate the decisions that produced them. Sometimes they simply tell us that the holes in the Swiss cheese didn't line up today. Were we lucky or were we good?


That creates a difficult challenge for leaders because success can be remarkably persuasive. Every time a shortcut works, it becomes a little easier to justify using it again. Every time a briefing is shortened without consequence, it becomes slightly harder to argue that the full briefing is really necessary. Every time an alarm activates and turns out to be insignificant, the next alarm feels just a little less urgent. Before long, the discussion has shifted away from whether the deviation is acceptable and towards whether it's worth changing something that appears to be working.


The irony, of course, is that Challenger wasn't the result of one poor decision made on one cold January morning. The launch decision was simply the final link in a chain that had developed over years. Every previous successful launch helped shape the beliefs, assumptions and expectations that existed on 28 January 1986. When viewed in isolation, the decision to launch can appear astonishing. When viewed as part of a much longer organisational journey, it becomes much easier to understand how experienced professionals reached the conclusion they did. However understanding is not the same as agreement.


One of the principles we talk about regularly at On Target is the idea of local rationality. People generally do what makes sense to them at the time, given the information they have, the goals they're trying to achieve and the environment they're working within. If we genuinely want to improve performance, we have to understand why decisions made sense before we can decide whether the system needs to change. Simply dismissing those involved as complacent or reckless teaches us very little, because it encourages us to believe we would never make the same mistakes.


History suggests otherwise.


Every industry has its Challenger. It may not involve rockets, but almost every organisation can identify examples where repeated success gradually reduced sensitivity to warning signs. In healthcare, it might be bypassing an identification check because the patient is well known to the team. In mining, it could be accepting a piece of equipment that has "always been a bit unreliable." In aviation, it may be treating an unstable approach as recoverable because previous crews have managed it successfully. In business, it could be a project approval process that becomes steadily less rigorous because deadlines are tight and nothing has gone wrong so far.


The details change. But human behaviour doesn't.


Perhaps the most valuable lesson from Challenger is that leaders should spend less time asking, "What went wrong?" and more time asking, "What are we succeeding despite?" It's a deceptively simple question, but it forces us to look beyond outcomes and examine the resilience of the system itself. It encourages us to look for weak signals while they're still weak, challenge assumptions before they become embedded and have conversations about uncomfortable issues while there is still time to do something about them.


I appreciate that isn't always easy. Success has a habit of silencing concern because success creates confidence, and confidence can make curiosity feel unnecessary. One of the hardest things a leader can do is question a process that appears to be working. Unfortunately, that's often exactly when those questions matter most.


The next Challenger in your organisation almost certainly won't involve a space shuttle. It may be an informal workaround that has become routine, a maintenance task everyone assumes has been completed, a risk assessment copied from the previous job or a briefing that now takes five minutes instead of fifteen because "nothing ever changes." None of those things will attract headlines today. They probably won't even be discussed tomorrow.


Until one day they are.


The legacy of Challenger isn't a lesson about O-rings or rocket science. It's a reminder that organisational drift is usually slow, almost always well intentioned and remarkably difficult to recognise from the inside. High-performing organisations don't protect themselves by waiting for failure to reveal where the boundaries are. They create cultures where people are encouraged to question success just as much as they question failure, recognising that the biggest risks are often the ones that no longer feel like risks at all.


Sometimes the most dangerous warning sign isn't an accident. It's a long history of everything appearing to go exactly as planned.




On Target Co-Founders. Mike Mason and Sam Gladman

Mike Mason and Sam Gladman help leaders and teams perform under pressure. Drawing on decades of experience in military aviation, Human Factors, accident investigation and organisational learning, they work with safety-critical organisations to improve decision-making, teamwork and leadership when conditions are uncertain. Through On Target Teaming, they combine practical tools, immersive simulations and real-world case studies to help teams perform at their best when it matters most.


If you'd like to learn more about how On Target can help your team, contact Mike and Sam at info@ontargetteaming.com.

 
 
 

Comments

Rated 0 out of 5 stars.
No ratings yet

Add a rating
bottom of page