What the Hell Happened (and what can I do about it?)
Something happened this week that changed the conditions your organization is operating in. Most leaders will find out too late.
What the Hell Happened? is a weekly 30-minute briefing for executives in healthcare, higher education, manufacturing, logistics, transportation, and construction. Every episode takes the week's most consequential events — policy shifts, system failures, supply chain disruptions, regulatory changes — and works through what they mean for the people making decisions at the top.
Three segments. Every episode.
Readiness — what happened and why it matters. Resilience — what it reveals about the assumptions your organization is running on. Advantage — one specific action before Monday.
Hosted by Mike McCracken, founder of Southwind Planning Solutions, with decades at the intersection of emergency management and private sector operations.
What the Hell Happened (and what can I do about it?)
Episode 3: The Dashboard Delusion
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Episode 3: The Dashboard Delusion
A senior bank attorney puts an illegal practice in writing to his board. He gets fired. The board investigates — and keeps charging the fees for two more years. Three states over, a pharmaceutical manufacturer's quality failures pile up on the production floor while leadership's dashboard stays green the whole time.
Two industries. Two completely different failure modes. The exact same ending: courts holding the people at the top personally accountable.
In this episode, we break down what actually happened inside Regions Financial's $191 million overdraft fee scandal and Teligent Inc.'s collapse into bankruptcy — and what emergency management doctrine reveals about the gap between having a warning system and having a system that forces you to act on the warning.
You'll learn:
- Why "compliant" and "functioning" are not the same thing — and why courts are starting to tell the difference
- How Business Lifelines™ break down when Information Flow, Decision Authority, and Risk Recognition stop working together
- The Delta of Decay™ — the quiet, unmeasured drift that turns a working system into a broken one, one heroic workaround at a time
- A 30-minute Monday morning exercise to map exactly how a warning would reach your desk — and what would have to go wrong before it does
If this episode raises questions about how information moves through your organization, that's exactly what a Signal Integrity Assessment is built to surface. Learn more at www.southwindplanning.com.
www.southwindplanning.com
www.bluetogray.beehiiv.com
It's november twenty nineteen. Somewhere in the legal department of a large regional bank, a senior attorney finishes typing a memo. He's just documented in precise lawyerly detail that his employer is charging customers overdraft fees on accounts that actually have enough money to cover the transactions. This is illegal and he's told management, but nothing has changed. So he puts it in writing addressed to the board. Not long after he gets fired. The board reads the memo and they hire a law firm to investigate. And then they keep charging the fees for nearly two more years. That's the story of Regents Financial. And the $191 million question it raises is one every executive and every industry needs to answer. When the warning lands on your desk, do you have a system that forces you to act on it? Or one that lets you study it until the problem solves itself? That's what we're going to get into today. Sometimes it's a policy shift. Sometimes it's a system that fails. Or it could be that a market moves. Often leaders find out too late. The signal was there, but nobody turned it into something they could act on before the moment passed. What the hell happened is a weekly briefing for leaders who would rather be ready. I'm Michael Crackett. I've spent over 30 years working in situations where planning gets interrupted by reality. This program looks at not just what the hell happened, but also what can be done about it. In March 2019, the bank's former Deputy General Counsel urged corporate leadership to stop charging the customers certain unauthorized positive overdraft fees. He warned that the practice was illegal, and after alleging this, he was terminated in late 2019 for raising these concerns. But a draft of his formal complaint was sent to the board and this created a critical paper trail proving that the corporate brass knew about the practices in 2019 but delayed on fixing them. Next, the high reliance on fee revenue. During the regulatory investigation, the Consumer Financial Protection Bureau highlighted 2019 as a peak year for that bank's reliance on these kind of practices. The overdraft and non sufficient funds fees accounted for almost 18% of the region's bank total non-interest income for 2019 alone. The regulators noted that the bank delayed changing its system because it was actively trying to find ways to replace that lost revenue. Third, the subsequent shareholder fallout, which is still ongoing. Because the internal warning signs began in 2019, a Delaware court ruled that top Regions Bank board members must face a shareholder derivative lawsuit. That lawsuit argued that the directors violated their fiduciary oversight duties by actively ignoring the twenty nineteen red flags, which were very clear and which ultimately caused massive financial and reputational trauma to the corporation. So when the deputy general counsel blew the whistle, he didn't run into a regulator first, he took it internally to management, and then directly to the board. But the board's response was classic corporate shielding. They formed an investigation committee and brought in an outside counsel and started an internal review. Meanwhile, the illegal fees just kept rolling in from August of twenty eighteen all the way through July of twenty twenty one. That's three full years of unlawful charges. Now, fast forward to September of twenty twenty two, the Consumer Financial Protection Bureau stepped in with a consent order, and that price tag, it was one hundred forty one million dollars returned to the customers and fifty million dollars in civil penalties, which came out to a total of one hundred ninety one million dollars. But that's not the end of the story. The shareholders ended up suing the directors personally to claw back some of that money. And the Delaware court refused to dismiss that case. So now those directors are facing personal liability. Just sit that sequence for a moment in your head because those facts carry all that weight. So let's look at a completely different industry now at the exact same failure architecture. This one is from Telligent Incorporated. They're a generic pharmaceutical manufacturer and they're heavily regulated by the FDA at all of their different levels of production. But on the production floor, manufacturing deviations started accumulating. So the manufacturing deviations at Telligent Incorporated primarily stemmed from chronic failures to investigate failed drug batches that were releasing out-of-specification medications to the market and neglecting stability testing protocols. These are severe violations of current good manufacturing practice regulations, and they culminated in an FDA warning letter in November of 2019 and a wave of product recalls that ultimately triggered the company's financial collapse. So, according to federal regulators and subsequent court findings, the manufacturing failures at Telegent's Buena, New Jersey facility centered around four main structural violations. The first one was that they failed to investigate out of specification batches. In this instance, Telegent repeatedly ignored its own data. For instance, the company released a cream for eczema treatment to the public despite the batch failing internal impurity tests at release and during subsequent stability checkpoints. They also had inadequate drug stability programs. They failed to follow written protocols designed to track how their products held up over time, and this allowed drugs to sit on the market without sufficient data that confirmed their long-term efficacy and their safety. They also ignored product complaints. There were submissions regarding drug defects and customer complaints that were routinely left unreviewed, unapproved, and open past the time limits mandated by the company's standard operating procedures. And finally, there was poor production quality control. The facility lacked the standardized written procedures that guaranteed that manufactured generic drugs consistently retained their expected identity, strength, quality, and purity. So what does all this mean? Because Teligent failed to correct these manufacturing deviations, its products were legally deemed adulterated. The systemic issues eventually forced a series of major high-stakes market interventions. The first was their recall of their superpotent lidocaine. Between September and December 2021, Teligent had to issue widespread voluntary recalls of its 4% lidocaine solution. The stability testing had revealed that the medication was far stronger than it was originally and actually labeled. This carried high risks of several different things that could be caused by using the solution, even up to cardiovascular collapse. The other thing was the 2020 production halt, which was prompted by an ongoing regulatory pushback that came when the company was forced to perform an exhausting review of its entire topical portfolio, leading to a temporary production halt for several of its critical product lines. That was the production side. Let's talk about the impact it had on its board and its leadership. So these manufacturing deviations didn't just destroy their production capacity, they created immense legal liabilities. Despite the FDA responding in August 2020 that televisions corrective proposals were completely inadequate, the company executives failed to properly notify the board of directors. There was a landmark ruling in court that allowed bankruptcy administrators to sue their former leadership under the KARMARC claims. It found that the board had made virtually no effort to monitor mission critical compliance risks regarding years of known manufacturing failures. So the frontline staff knew it and middle management knew it, but when the board looked at their summary reports, everything looked completely fine. There was no dedicated board committee for FDA compliance, there was no formalized escalation requirement, and there was absolutely no direct line from the manufacturing floor to the executive suite. So by the time the board finally understood the scale of their regulatory exposure it was too late, and the company had already filed for bankruptcy. The Delaware court in that case ruled that because the board had failed to build a system to verify what was actually happening on the ground, this was a breach of the fiduciary duties that it had, leaving the directors personally exposed in this case. These are two entirely different industries, but the results were exactly the same pattern. Neither one of these companies failed because they had a bad strategy, and neither one failed because the market had shifted. In the case of Regents Financial, they failed because the board had received a verified warning and treated it as a project to manage rather than a system that needed to be shut down. For Telligent, they failed because a board never built the pipeline to receive those warnings in the first place. So one organization was blind and the other could see, but they simply chose not to act. The outcome and the personal exposure for the people at the top was exactly the same. So now the real question. The question is whether you have a system that surfaces these problems before they become irreversible, and whether your governance structure actually forces you to do anything or to take action when they do. So that's what the hell happened. Now, once you see the underlying structure of these failures, you're going to start recognizing it everywhere. It's hard not to see. In my background, which is emergency management, we have a foundational principle. You do not manage an active scene based on filtered reports. For instance, a fire chief would never sit in a command post two miles away and rely on a handwritten memo delivered every six hours. You've got to have direct, unvarnished telemetry and information from the people who are on the ground. Because by the time that a filtered summary finally reaches your desk, the situation has likely already changed. We call this maintaining situational awareness. You need to know exactly what's happening and what's going on, not what someone else has decided that you needed to know about what's happening or what's going on. So what failed at Regions Intelligent is the corporate equivalent of that fire chief refusing to monitor the radio. The warning signs were there, but the infrastructure to receive them either didn't exist or got completely ignored. So in my advisory practice, I use a framework called Business Lifelines. This is adapted from the emergency management concept that's widely used based on community lifelines. They map out the critical baseline systems that a community needs to survive during a disaster. I've applied these same lifelines and converted them to business. The same logic holds true in both cases. There are a small number of living, interdependent flows that keep an enterprise viable. Decision authority, information flow, operational execution, and risk recognition are all the keys. The key word here is that they're interdependent. These are not isolated or siloed, so when one degrades or breaks down, it immediately puts pressure on the others. So when I'm talking about business lifelines, I'm not talking about things like your Slack channels or your internal email routing. What I'm talking about is actual real-time situational awareness. A lifetime is a real time pulse check on whether a core capability is stable or degrading or collapsing. It's a check on the status. At Telligent, when the information flow started to break down, the skies became cloudy and gray, it didn't mean that their phones had stopped working. It actually meant that the integrity of the data that they were receiving was completely compromised before it ever hit the executive suite. If your lifelines are just passive conduits for whatever filtered story the middle management wants to tell you, then you don't have situational awareness. What you have is a fairy tale. Again, for Telegent, their information flow went gray first. The executive visibility was completely obscured because the FDA deviations on the manufacturing floor were being softened and sanitized before they ever reached the board. And then because the information flow was compromised, their decision authority had no accurate data to act on, and the risk recognition completely and quickly collapsed behind it. By that time the system could no longer compensate and the failure was total. On the other hand, in the case of regions, their risk recognition failed despite having accurate information. The warning was right there and the pathway existed, and the board literally received a memo, but in this case they chose a passive and delayed response. This isn't a visibility failure, it's a governance failure. Their decision authority actually stalled out just to protect a short-term revenue line. So one company couldn't see the hazard, the other company saw the hazard and left the gas main wide open. So this brings us to a concept that I call the delta of decay. This is a measurable rate at which an organization drifts away from its operational baseline before a catastrophic failure becomes visible. It's usually never dramatic at first. It's a checklist that stopped getting run, or it's a key vendor relationship that went quiet. It's a team member who walked out the door and took critical institutional knowledge with them or a board committee that was simply assumed rather than firmly established. So let's be honest about what happens in many organizations. You have a mid-level manager who sees a bottleneck or a compliance glitch, and instead of halting operations and sounding the alarm, they just fix it themselves. They'll build a spreadsheet as a patch for the software gap, or they'll reallocate the staff manually. Generally we praise these people and we call them go getters and problem solvers. But in reality, are they really masking the systemic failure or are they solving a problem? Are they turning your dashboard green while the foundation of your organization is actually starting to rot? So every heroic workaround is an unrecorded line item in your delta of decay. So maybe instead of rewarding the heroes who hide the truth, even though it's well intentioned and they think they're making the organization stronger, we should consider taking a step back and look at this situation from a larger perspective. Let's consider starting to fix the architecture that forces these overachievers to be heroes in the first place. When you look at Telligent, this drift happened over multiple years and the FDA deviations were piling up at the plant level while the board's dashboard stayed perfectly green. The system was compensating. That meant that the middle managers were running informal workarounds to keep their production numbers acceptable. Until they finally couldn't control the weight anymore. That compensation behavior is always your biggest tell. When your people are heroically holding things together through informal or ad hoc workarounds, that is not organizational resilience. That is a leading indicator of systemic fragility. The delta of decay was not measured by a single event, it was a slow, quiet drift that eventually crossed a fatal threshold. The trap here is the compliance mirage. Both of these organizations were at various points fully compliant with their regulatory requirements. Telligent had FDA oversight structures in place, and Regions had formal compliance reporting channels in place. But in reality, compliance is really just historical bookkeeping. It tells you whether you satisfied a checklist at any specific point in time, but it tells you absolutely nothing about whether your systems are currently functioning under real, degrading conditions. It also works the same in other sectors healthcare, higher education, manufacturing, they all have rules and regulations that they have to follow. But the courts are increasingly beginning to understand this distinction. The Delaware court in these cases didn't ask whether Telligent had a compliance program on paper, it asked whether the board had built a system that actually delivered the ground truth information, and in this case the answer was no. The court didn't ask whether regions had an investigation process, they asked whether the board used that process as a genuine mitigation strategy or as a convenient cover to protect their revenue. The answer in this case was the latter. The legal standard isn't did you have a program? It's actually did you have a functioning system? There's a massive difference between these two things. So before we move into some action steps, I want you to hold up a mirror and look at your own operation. Where does critical operational information get filtered or sanitized before it reaches you? Who is deciding what makes it into the executive summary and what gets handled at the layer that's below you? What assumptions are you currently treating as verified capabilities? And when a warning finally lands on your desk, what does your governance structure actually require you to do with it? You don't need to have a crisis to answer these questions, but a crisis will certainly answer them for you if it shows up. So here's what I'd like for you to do when you go into your Monday meeting next week. It's not a broad framework overview, it's just one concrete exercise that'll probably take less than 30 minutes, but it could tell you more about your organization than any quarterly report ever could. You start by running your organization through a spot check, which consists of three direct questions. First one, for each of your mission critical operations, who is required to tell you when it's in trouble? Not who can tell you, but who's legally or operationally required to tell you? Second, when was the last time that you verified that this requirement actually works? Not reviewing the policy document, but testing it, or running a real world scenario and watching what happens. And third, when a warning arrives, do you have a governance structure that forces immediate action or one that automatically routes it to a committee? So here's your concrete Monday action for next week. Pick just one mission critical function in your business, one of your single business lifelines, and map the exact path that that information takes from the ground level all the way to your desk. Count the layers and identify exactly who makes the decisions about what gets escalated at each stage. Once that's done, ask yourself what would have to go wrong before a problem in that function reached me directly? If the answer to that question is a lot, you are running a telegent type structure. The information exists on the floor, but the pathway to the top is completely broken. Or maybe your answer is nothing because we have an automatic escalation trigger built in. If you do, then test it. Run a surprise scenario and find out whether that trigger actually fires, or if it just lives in a forgotten policy document somewhere that nobody has touched in two or more years. So the lesson from Regions Financial is distinct from Telligent and different, and frankly it's a lot harder to hear. Telligent didn't know, so that's a system design failure. But regions knew that's a governance failure, and the courts treat those very differently. Think about this as if you were a municipal engineer and you'd discovered a structural crack in a major bridge. In the public safety world, you would never leave the bridge open to rush hour traffic for another two years while an outside consulting firm writes a four hundred page report on the economic impact of a detour. You'd close the bridge instantly. You take the political heat, you deal with the traffic gridlock, and you stabilize the threat. In the case of Regents Financial, they discovered a structural crack in their legal architecture bridge, but they decided to keep running semi trucks over. It for another twenty-four months because the toll revenue was just too good. That's why the court didn't care about their investigation committee. They cared that the bank had left a known hazard wide open. So in emergency management, when there's a specific hazard and it's confirmed, the protocol is not up to question. It's absolute. You stabilize the threat first. You don't calculate the economic impact of closing the bridge before you shut it down. You have to isolate the hazard. You have to deny entry and you stabilize the scene, and then you figure out what the financial implications are and how you're going to manage those. When a verified warning lands in a corporate boardroom, the exact same logic has to apply. An investigation is not a mitigation strategy. Studying a confirmed hazard while continuing to run the exact operation that's causing the damage is not due diligence. In the eyes of a court, this is explicit evidence of bad faith. And the question isn't whether you have a process for receiving warnings, it's whether your governance structure instantly shifts into an incident response posture once the moment arrives. If today's episode has surfaced a concern about how operational information moves through your organization or whether your leadership would actually be forced to act when a warning lands, that is the exact gap that a signal integrity assessment is designed to expose. This isn't an administrative audit, it's actually a highly structured evaluation of whether your critical lifelines are actually functioning the way that your green dashboards say that they are. If you're interested in finding out more about this, you can check out our website at www.southwindplanning.com. To wrap things up for today, let's look at the baseline facts. There's two organizations, two entirely different industries, and both had clear warning signals. One never built a system to receive them, and the other received the warning loud and clear, but chose not to act. In both of these cases, the courts bypassed corporate shields and held the people at the top personally accountable. So green dashboards are not always an indicator of operational health. They're simply a representation of what your reporting structure has decided to tell you. Thanks for listening. If you found this information interesting, drop me an email and let me know what you think. If there are things that you would like to hear on future episodes, give me some suggestions, give me your thoughts, talk to me about some of your pain points or things that you would like to see discussed will apply the principles of business lifelines, the delta of decay, and information hygiene, and see how they might apply. What the Hell Happened is produced by Southwind Planning Solutions LLC. If this episode was useful, a blue-to-gray newsletter goes deeper into this and many other topics each week. You can subscribe for free on Beehive. The link is in the show notes. If you're sitting on an assumption that you have not verified in longer than you'd like to admit, or maybe there are other challenges where reality has interrupted your planning, there's a starting point for that in the show notes as well. You can find us on Apple Podcasts, Spotify, or anywhere else at two listen to podcasts. You can also find me on LinkedIn and on our website at www.southwindplanning.com. I'm Mike McCracken. Thanks for listening, and I'll see you next time.