Santiago Capital

Santiago Capital

Redundancy Before Returns

Why Infrastructure was Optimized for a World that has Ended

Santiago Capital's avatar
Santiago Capital
Jul 29, 2026
∙ Paid
Santiago Capital Research report cover titled Redundancy Before Returns featuring electric power grid storm
[Section Divider Image]

LETTER TO READERS

For the past year we have been making one argument in a dozen different ways. The world that produced the last four decades of investment returns is gone, and it is not coming back on the schedule most portfolios assume.

We made that case in Borders Before Balance Sheets, in The Backyard, in Triumph of Geopolitics, and as plainly as we know how in The End of Peacetime Portfolios, where we argued that the mean reversion investors treat as a law of nature is no such thing. It is a feature of one particular environment, built on cheap energy, open shipping, credible deterrence, and a quiet assumption that nobody would deliberately break the machinery everyone depends on.

This report is about one piece of that machinery.

At around 4:30 in the morning on 8 July 2026, Australia’s largest telecommunications carrier lost roughly 45 percent of the nation’s calls and data sessions. Emergency calls failed. Regional rail was suspended. Payment terminals stopped working. Nearly nine million customers were cut off.

Yet nobody had attacked Telstra.

A technician restarted a time synchronization server built roughly two decades ago and worth about thirty thousand dollars. Because of a quirk in how GPS broadcasts the date, the device came back on believing the year was 2006. Telstra ran too few of these servers for the network to outvote the one that was wrong, so systems across the network began reading their own security certificates as invalid and refusing connections.

In short, a country lost its phones because its phone network could not agree on what day it was.

The manufacturer had been warning about this specific failure since November 2020, with a reminder as recently as January of this year. Australia’s own Cyber and Infrastructure Security Centre had flagged timekeeping as a strategic vulnerability in 2024. But the patch was never applied.

This is not a cybersecurity report in the way that phrase is normally used. We have no interest in another vendor taxonomy or another threat feed summary. We are interested in a narrower question that the Telstra failure answers with unusual clarity.

How much margin is left in the systems that developed economies actually run on?

In our opinion the answer is very little, and the reason is not incompetence. It is optimization. Every redundant server, every spare transformer, and every maintained backup that never gets used is a cost that returns nothing in any quarter in which nothing goes wrong.

For thirty years, almost nothing went wrong. Operators who stripped that margin out were rewarded for capital discipline. Operators who kept it were asked why their returns trailed the peer group. The market got precisely what it paid for, and it paid for efficiency.

That was the peacetime dividend.

It was real, it was enormous, and it has already been banked. What was never priced was the other half of the trade. Those same systems now have no slack at all in an environment where someone is deliberately looking for the seam.

And now someone is.

Since 2021, a China-linked campaign that Microsoft named Volt Typhoon has been inside American communications, energy, water, and transportation networks. In a joint advisory in February 2024, CISA, the FBI, and the NSA described the activity not as espionage but as pre-positioning, meaning access held specifically to enable disruption in a future crisis. Espionage is an old game, and everyone plays it. Pre-positioning is something else. It is the quiet placement of a capability to be exercised later, at a moment of someone else’s choosing, inside infrastructure that belongs to civilians.

Meanwhile, in the Baltic, GPS jamming and spoofing has moved from occasional to routine, prompting thirteen European coastal states and Iceland to issue a joint warning in January. The same signals Telstra’s server misread are being interfered with on purpose, every day, a few hundred miles from Frankfurt. Note the failure mode because it is identical. Not a system that goes dark, which is obvious and gets fixed. A system that keeps running while being confidently wrong.

This is why we treat cybersecurity as a national security question rather than an information technology budget line, and why this report sits in a series about geopolitics rather than one about software. The distinction between an accident and an attack matters enormously to a court. It matters far less to a hospital, a freight network, or a bank.

Telstra is not the warning.

Telstra is the free demonstration, run at no cost to anyone who wished us harm, of what the cost would be.

This post is for subscribers in the Santiago Capital Pro plan

Already in the Santiago Capital Pro plan? Sign in
© 2026 Brent Johnson · Privacy ∙ Terms ∙ Collection notice
Start your SubstackGet the app
Substack is the home for great culture