Public warning is one of the few things a local agency does where a single keystroke reaches everyone at once and cannot be taken back. The incidents worth studying are the ones where somebody investigated afterward and published what they found, because those records point at the same small set of design problems: a template list where the exercise entry sits next to the live one, a drill script written in live language, no second person in the loop, and no correction message written in advance. This is written for anyone at an agency that holds alerting authority, or is about to.

Thirty-eight minutes in Hawaii, and what two investigations found

On the morning of January 13, 2018, the Hawaii Emergency Management Agency sent a Wireless Emergency Alert and an Emergency Alert System message telling the public that a ballistic missile was inbound, to seek immediate shelter, and that this was not a drill. The FCC’s Public Safety and Homeland Security Bureau, which published its findings at the end of that month, put the erroneous alert at 8:07 a.m. local time and the corrected message at 8:45 a.m., which is where the figure of thirty-eight minutes comes from. The State of Hawaii released its own internal investigation, conducted by Brigadier General Bruce Oliveira of the Hawaii National Guard, in the same period.

The Bureau’s account places the alert inside a no-notice internal drill conducted at a shift change. The recorded drill message played to the on-duty employee contained exercise language at the beginning and the end, and also contained the phrase from the real ballistic missile script saying that this was not a drill. The employee reported believing the threat was real. He declined to be interviewed by the Bureau and submitted a written statement instead, which the Bureau noted, and that limitation is part of the published record rather than something to paper over. The Bureau found that the agency lacked reasonable safeguards, including any requirement that a second person authorize an alert of that consequence, and that it had no template prepared in advance for correcting a false ballistic missile alert.

Within a few minutes of 8:07 the agency stopped further retransmission of the alert, which mattered for phones that had not yet been reached and did nothing at all for the phones that had. The remaining half hour went into composing and issuing something the agency had never written down. The agency’s administrator resigned and the employee’s employment ended, and I would not treat either as the lesson, because the Bureau’s recommendations were about procedure, authorization and software rather than about that one operator’s morning.

The template list, the prompt, and what the screen was actually asking

Alert origination tools present the operator with a list of saved templates, and in most deployments the drill versions and the live versions of the same alert live in that one list, distinguished by a word. Hawaii released an image of such a menu to reporters after the incident and then said the image was an illustrative example rather than the actual screen the operator saw, so I would not build an argument on the pixel detail of it. The general condition it illustrates is real and I have seen it in tools that are in service today, where two entries differ only by a prefix and the consequences of choosing wrong differ by everything.

A confirmation prompt is the usual answer to that problem, and it is a weak one when the prompt appears on every action the operator takes all shift. People learn the shape of a dialog box and answer it without reading, which is not a character flaw but a predictable result of asking a yes-or-no question hundreds of times when the answer is almost always yes. A confirmation step earns its place when it makes the operator supply something specific to the live decision, such as typing the word that identifies the alert class, or re-entering the polygon name, or reading back an authorization code that only exists when a real event is running.

The stronger design separates the modes rather than labeling them. Exercise work happens in a training environment or against a test target, so the live template list contains only live templates and the exercise templates are somewhere the operator has to deliberately go. FEMA operates a lab environment for IPAWS alerting authorities to test message composition and dissemination without touching the public, and any agency with a Collaborative Operating Group should know whether its own vendor’s tool can point at that environment and who at the agency knows how to switch it. Ask your vendor in writing, because the answer determines whether your monthly proficiency practice is a safe activity or a loaded one.

The prompt everybody clicks

If your alert tool asks the same confirmation question for a test message and for a live imminent-threat alert, that prompt is not a safeguard and should not be counted as one in your plan. A confirmation step only helps when the operator has to produce information specific to the live decision, which means typing something, reading back something, or getting a second person on the phone. Count how many times an operator answers a dialog box in a normal shift before you decide the dialog box protects anybody.

Drills run on the live system, and scripts written in live language

The Hawaii record is the clearest published example of a drill script that carried live wording, since the exercise message contained both the exercise markers and the operational phrase telling the listener that this was not a drill. Anyone who has written exercise injects knows why that happens, because realism is the point and a script full of exercise disclaimers gets read as filler. The fix is to keep the realistic wording inside the scenario narrative and keep the words that trigger action, including the phrase that tells an operator to send, distinct between the drill and the real thing.

Ontario provides a second documented case. On the morning of January 12, 2020, an alert about an incident at the Pickering Nuclear Generating Station went to the public across the province, and the Government of Ontario stated that it had been issued in error during a routine training exercise and ordered a review. Press reporting at the time put the follow-up alert telling the public there was no danger at roughly an hour and three quarters after the first, and I flag that as reported rather than as a figure I have verified against the province’s own timeline, which is the document to consult. The province subsequently announced procedural changes, and the mechanism of the original failure was training conducted with access to the live dissemination path.

The Common Alerting Protocol has fields for exactly this distinction, with a status value that marks a message as Actual, Exercise, System or Test, and message types including Alert, Update, Cancel and Error. Those fields work only if the downstream systems honor them and the humans in the chain notice them, and the useful question at your agency is which of your paths displays the status to a person and which one drops it. Verify that with whoever administers your alert tool rather than assuming, because a message marked Exercise that reaches a broadcast crawl or a phone as ordinary text has done real damage regardless of what the field said.

The message nobody wrote in advance

The oldest documented version of this problem in American practice is the Emergency Broadcast System activation of February 20, 1971, when the operator at the national warning center at Cheyenne Mountain transmitted a live Emergency Action Notification, carrying the authenticator word hatefulness, in place of the scheduled weekly test. Accounts of the next forty minutes differ in their detail and the FCC’s own review of the incident is the record to consult, but the shape of the failure is consistent across them: the activation was authenticated and the cancellation had to be authenticated too, and the people who needed to stop broadcasting had no verified way to know that stopping was legitimate. Roughly forty minutes passed before a valid termination reached stations, and some stations had already gone off the air while others had ignored the notice entirely.

Half a century later Hawaii spent thirty-eight minutes on the same problem in a different technology, because the Bureau found the agency had no pre-prepared correction template for a false ballistic missile alert. Writing a message in a text box while the phones in your own building are ringing and your own family is calling is not a task anybody performs well, and it is not a task that needs to be performed at all. Every alert type your agency is authorized to send should have a matching correction saved next to it, with the wording already agreed by your public information officer and your counsel, so the operator’s work is limited to selecting it, confirming the geography and sending.

There is a hard limit on what a cancellation can accomplish that people building plans should say out loud. A WEA message that has already been displayed on a handset does not get recalled, so a cancel stops further distribution and a correction is a new message competing for attention with the first one. That asymmetry is why the pre-written correction matters so much, since the only variable your agency actually controls is how many minutes elapse before the second message exists.

Write the correction before you need it

For each alert template your agency can send, save a matching correction template in the same tool, with the wording already cleared by your PIO. Say plainly that the earlier message was sent in error, name the agency, state that no action is needed, and give one place to check for updates. The FCC’s Hawaii findings identified the absence of a prepared correction as a direct contributor to the thirty-eight minute gap, and it is the single cheapest thing on this list to fix.

How long a correction really takes, and who is still repeating the first message

The correction clock does not stop when your second message leaves the alert gateway, because the first message has by then been forwarded, screenshotted, read on the air, pushed by weather apps, repeated by out-of-area news desks and posted by people who will never see your follow-up. In Hawaii the agency used social media well before the corrected alert went out, and Governor David Ige told reporters later that month that he had not known the credentials for his own Twitter account, which delayed his post. That detail gets treated as a joke and it is actually a planning finding, because the correction path includes accounts, phone numbers and relationships that have to work on the worst morning without anybody hunting for a password.

Build the notification fan-out for a false alert the same way you build one for a real incident, with named roles and current numbers. The 911 center takes the call volume first and needs a recorded greeting and a supervisor decision about what telecommunicators say. Broadcast partners, the state warning point, adjacent county EOCs and the school district all get a direct call rather than being left to read your Facebook page. Whoever holds your agency’s social accounts has to be reachable, and more than one person has to hold them.

Time this in practice rather than assuming it. Start the stopwatch at the moment somebody in the room says the alert was wrong, and stop it when a correction has been submitted and the first outbound phone call to a broadcast partner has been answered. Do the exercise in a lab environment so nothing reaches the public, write the number of minutes on the after-action report, and treat that number as the performance measure for your warning program.

Coded as a test, delivered as real: the 2017 tsunami message

On February 6, 2017, a routine tsunami test message from the National Weather Service reached the public through at least one commercial redistributor as what looked like an actual tsunami warning along parts of the East Coast and the Gulf. The National Weather Service said publicly that the message had been identified as a test. AccuWeather said publicly that the coding in the message it received indicated a live warning. Those two accounts disagree, both parties published their positions at the time, and I am not going to adjudicate between them here, because the design lesson survives either version.

The lesson is that your message travels through systems you do not administer, operated by people who did not attend your training, and each of those systems makes its own decision about which field to trust. If a test indicator lives in one part of a message and the actionable content lives in another, a parser somewhere will eventually honor the second and ignore the first. The practical implication for a local agency is to put the word TEST in the visible text of a test message and not only in a protocol field, so that a human at the end of any path can see it even if the machinery lost it.

Message integrity belongs in the same section, at awareness level. In February 2013 several broadcast stations transmitted a bogus EAS message about the dead rising from their graves, and the FCC’s Public Safety and Homeland Security Bureau issued an urgent advisory directing EAS participants to change factory default passwords on their encoder and decoder equipment and to keep those boxes off the open internet behind a firewall. Nothing about that episode was sophisticated, and nothing about the remedy was either, which is why the question to ask your engineer this month is whether every alerting appliance and workstation at your agency still carries a default credential.

Two-person rules, permissions, and what they cost at three in the morning

The FCC’s Hawaii findings recommended safeguards including a requirement that more than one person be involved in issuing an alert of that severity, and that recommendation is easy to write into a plan and hard to honor at 0300 on a holiday weekend with one person on duty. A two-person rule that cannot be executed by the staffing you actually have will be bypassed the first time it is inconvenient, and it will be bypassed quietly, which is worse than not having it. Decide by alert class instead: an alert that instructs the public to take irreversible action, such as sheltering from a ballistic missile or evacuating a corridor, gets a second authorizer, while a boil water notice or a road closure message does not need one.

Make the second person reachable by design. That means a named on-call role with a number that rings a phone somebody is holding, a documented fallback if the first number does not answer inside two minutes, and explicit authority for the on-duty operator to send without the second signature when a specified life-safety condition applies and to document that decision afterward. If your plan does not say what happens when the second person cannot be reached, your plan has decided that the alert waits, and nobody involved in writing it intended that.

Permissions are the other half of the control. Alert origination tools support role-based accounts, and most agencies I have looked at have more accounts with live-send authority than they can account for, including people who have transferred, retired or moved to another agency. Print the list, reconcile it against the current roster, remove what should not be there, and check the training records at the same time, since alerting authorities operate under an agreement with FEMA that carries training expectations and you want to know the state of that before somebody else asks.

The common mistake in the two-person rule

Writing “two persons shall authorize” into a warning annex without naming who the second person is at every hour of the day produces a rule that gets skipped rather than followed. Name the on-call role, give the number, give the fallback, and state in the same paragraph what the operator does when nobody answers within a stated number of minutes. Then have the shift supervisor call that number cold on a random night to see whether it rings a human.

What a false alert does to the next real one

Wireless Emergency Alerts let subscribers turn off every category except the national alert, so a false alert on a Saturday morning gives thousands of people a concrete reason to reach into their phone settings and remove themselves from imminent threat messages before the next hurricane. That is a documented feature of the system rather than a speculation about human nature, and it is the reason a false alert is a structural problem for a warning program and not just an embarrassment. Nobody sends you a report on how many handsets opted out in your county last month, which means the damage is real and invisible at the same time.

The reaction inside agencies can cost as much as the reaction outside them. After the 2017 Northern California wildfires, the decision by some local officials not to send wireless alerts became the subject of after-action review and legislative attention, and California directed its Office of Emergency Services to develop statewide alert and warning guidelines in response, which you should verify in their current form with Cal OES rather than from my summary. The concern those officials expressed, that a broad alert would move people who were not in danger and clog the roads for people who were, was a real concern that pre-2019 geotargeting made worse. The FCC has since required more precise geographic targeting from participating carriers, and the current requirements are worth confirming with the Commission’s WEA pages before you plan around them.

Every agency that holds alerting authority is therefore managing two failure modes at once, and the honest way to hold them is to write the thresholds down in advance. Decide now, in daylight, which conditions justify an imminent threat alert in your jurisdiction, who approves each class, what the polygon looks like, and what the correction says if you get it wrong. An agency with those decisions written down sends faster when it should and recovers faster when it should not have, and the record from Hawaii, Ontario and 1971 all points at the same missing paperwork rather than at missing technology.

What to do at your agency

  • Have the person who administers your IPAWS Collaborative Operating Group print the list of accounts with live-send permission and the date of each holder’s last IPAWS training, reconcile it against the current roster this month, and remove the accounts that belong to people who have left.
  • Sit at the alert origination workstation with your warning coordinator, read the saved template list out loud, and identify any two entries that differ only by a word such as drill or test, then ask the vendor in writing how to rename, reorder or move them out of the live list.
  • Have your public information officer draft correction wording for each alert type you are authorized to send, and have the tool administrator save each one as a template alongside the alert it corrects, so that issuing a correction is a selection rather than a writing exercise.
  • Run one timed drill in FEMA’s IPAWS lab environment rather than on the live system, starting the clock when somebody announces the alert was wrong and stopping it when the correction is submitted and a broadcast partner has answered the phone, and write that number of minutes into the after-action report.
  • Add one item to the next EOC or communications committee meeting already on the calendar: who is the second authorizer for a life-safety alert at 0300, what number reaches that person, and what the on-duty operator does if nobody answers in two minutes.
  • Ask your engineer or IT lead to confirm in writing that no alerting appliance or workstation, including EAS encoders and decoders, still carries a factory default password or is reachable from the public internet.
  • Write one paragraph into your existing warning annex listing the roles notified within five minutes of a suspected false alert, naming the 911 center, the broadcast partners, the adjacent EOCs and the schools, with current numbers attached as an appendix somebody updates quarterly.

Takeaways

  • The FCC’s Public Safety and Homeland Security Bureau report on the January 13, 2018 Hawaii false ballistic missile alert put the erroneous message at 8:07 a.m. local time and the correction at 8:45 a.m., and found that the agency had no prepared correction template and no requirement for a second person to authorize the alert.
  • The Hawaii drill script contained both exercise markers and the live phrase telling the listener that this was not a drill, which is why exercise realism belongs in the scenario narrative and not in the words that trigger a send.
  • The Government of Ontario stated that the January 12, 2020 Pickering nuclear alert was issued in error during a routine training exercise and ordered a review, and press reporting put the follow-up alert at roughly an hour and three quarters later, a figure worth checking against the province’s own published timeline.
  • The February 20, 1971 Emergency Broadcast System activation shows that the cancellation path needs as much design attention as the activation path, because the stations that needed to stop had no verified way to know that stopping was authorized.
  • A confirmation dialog that appears on every action is not a safeguard, and a confirmation step only helps when it requires information specific to the live decision, such as typing an alert class or reading back an authorization from a second person.
  • A WEA message already displayed on a handset cannot be recalled, so the only variable an agency controls is the number of minutes before a correction exists, and a pre-written correction template is the cheapest way to shorten it.
  • In the February 6, 2017 tsunami message incident the National Weather Service said the message was identified as a test while AccuWeather said the coding it received indicated a live warning, the two accounts disagree, and the practical response is to put the word TEST in the visible text and not only in a protocol field.
  • Because subscribers can opt out of every WEA category except the national alert, a false alert removes people from your warning audience permanently and silently, which makes written thresholds, named approvers and a rehearsed correction path part of the warning system rather than paperwork around it.
Questions or a different view?

Reach me through the contact page. I read every message.