| ]

or Dunning-Kruger doesn't self-correct anymore.

> TL;DR. The Dunning-Kruger effect, that is, the difference between what people think they can do
and what they can actually do, used to close and self corrects with experience. My hypothesis that I introduce in this post is that AI keeps it open: it increases confidence and splits real capability into "with the tool" and "without the tool." For companies, that turns intrinsic capability from a productivity question into a governance one, and it is the capability that quietly erodes.

  1. The ending that used to be guaranteed (more or less)
  2. About the Dunning Kruger curve
  3. What AI changes
  4. The Gap that no longer closes
  5. Does it really matter?
  6. What it means for companies

1. The ending that used to be guaranteed (more or less)

Everyone knowns "Mount Stupid". Whether it’s the co-worker who’s researched a single online thread and wants to completely upend the operations of the team, or the new hire who’s watched a tutorial video and is convinced that everyone was doing everything incorrectly, we’ve all been there at one point or another.

The great thing about Dunning-Kruger is that there really is an ending to it. In the battle of experience vs. confidence, experience always wins. The difference between what you think you can do and what you can do is going to close on its own. There’s a simple, and really quite boring iteration that explains what happens: you do it, you break things, you mess up, but you figure it out. Until the day that your perception aligns with reality, the reality of the situation is going to keep the lights on.

Figure 1. The classic picture. Perceived capability runs ahead, crashes, then converges on actual capability. The gap closes.[Thierry ZOLLER]

Figure 1. The classic picture. Perceived capability runs ahead, crashes, then converges on actual capability. The gap closes.[Thierry ZOLLER]

2. About the Dunning-Kruger curve

Here's the thing: the chart that everyone think they know is actually not what it seems. The famous Dunning-Kruger curve, with its peak of confidence and valley of despair, didn't actually come from Dunning and Kruger. You won't find it in their 1999 paper, or in any of Dunning's later work. So, where did it come from? It started spreading like wildfire through management training and the internet in the mid-2000s. But the real study is actually pretty different. It compared how people thought they'd do with how they actually scored, and it was divided into four groups. The interesting thing is, the line on the chart just keeps going up - it doesn't peak and then drop like everyone thinks.

There's a lot of debate about this effect, and experts can't seem to agree on what it really means. Some researchers think it's just a statistical illusion, a combination of people naturally rating themselves higher than average and the phenomenon of regression to the mean. They point to studies that suggest this pattern is just a mirage, not really telling us anything significant. In my opinion, the key takeaway is that the pattern itself is real - that's what matters most to my hypothesis. What it actually signifies, however, is still up for debate.

I'm using this well-known chart on purpose, because it's familiar to everyone, not because it's the 1999 data. I guess, the point I'm making doesn't rely on the curve being entirely accurate. It only needs one thing that nobody disagrees with: people are not good at judging their own abilities, and the difference between what they can actually do and what they think they can do is significant. This gap is made even wider by a tool that affects how we perceive ourselves.

3. What AI changes

Two things change according to me. Let's go through them one after the other.

1. First, the confidence goes up. A beginner with an AI assistant produces work that looks from an expert.

The delivery is the proof, and the proof says "good".  That's why the early peak of overconfidence climbs higher than it ever did on its own. The dip isn't as deep either. The moment of getting caught comes later and is softer, because the AI usage papers over the gaps that used to show you up. And the line never really drops, there is no longer a reliable point where harsh reality (failure, mistakes etc) forces a reality check, because the output keeps looking fine.

Figure 2a shows the one line changing.

Figure 2a. Same chart, one line changed. Perceived capability peaks higher, dips less, and no longer comes back to meet actual. The gap that used to close stays open. [Thierry ZOLLER]

Figure 2a. Same chart, one line changed. Perceived capability peaks higher, dips less, and no longer comes back to meet actual. The gap that used to close stays open. [Thierry ZOLLER]

2. Second, "what you can really do" stops being one thing. Before AI, your ability was a single number. Now it splits in two (Figure 2b).

Let me explain, there is what you can produce with the tool in hand, which is high and comes fast. And there is what you can do if the tool is taken away (I call it "Intrinsic"), which is lower, and which only grows through the practice the tool now does for you.


vFigure 2b. The single "actual" line splits. Assisted capability rises with the tool. Intrinsic capability, the part left when the tool is gone, settles much lower. The faint dotted line is the old single curve. [Thierry ZOLLER]

Figure 2b. The single "actual" line splits. AI assisted capability climbs with usage of the tool. Intrinsic capability, the part you contribute when the tool is gone, rests mucg lower.
The grey dotted line is the old single curve. [Thierry ZOLLER]

4. The gap that no longer closes

Le'ts have the 3 lines on the same chart and the problem shows up (Figure 3).


Figure 3. The old meeting point (faint, top right) against the AI world. Two gaps open and stay open: the dependency gap between what the tool makes and what you could do without it, and the persistent illusion between what you think you can do and what you can. Intrinsic capability itself splits, by who built it before AI showed up.

Figure 3. The old meeting point (grey, top-right) against the AI assisted cases . Two gaps open and stay open: the dependency gap between what the tool makes and what you could do without it [Thierry ZOLLER]

Explanation : Perceived ability stays high. Assisted capability, what you make with the tool as support, sits just below it. "Intrinsic" capability, what is left when there is no tool, and it sits well underneath. Unlike the classic curve, none of them bend back toward each other. 
Here is why. The old gap closed because reality punished overconfidence. You tried something, you failed where people could see, and the failure showed you where you were wrong.
AI takes some of that out of the equation, it minimises the friction and hides the failure and so the signal that used to fix your self-judgment never lands. The gap effectively does not close, simply because the thing that used to close it is the thing we handed to the AI.

There is a generational split, a split that matters most for the next generations."Intrinsic" is not the same for everyone. People who built real skill before they leaned on the tool keep most of it and lose it slowly.

"Intrinsic" is not the same for everyone. People who built real skill before they relied on AI keep most of it and lose it slowly. People who learned with the tool from day one quite possibly never build it at all. Same low line on the chart but two different reasons, and the second one gets worse over a generation.

5. Is the skill deteriating just theory?

Early scientific literature suggest the opposite and the evidence points the same way than my hypothesis, with one difference:
In a 2025 Gerlich [5] found that the more people relied on AI, the worse they scored on critical thinking, with "cognitive offloading" [8] as the mechanism. The effect supposefly highes among younger users.
A Microsoft and Carnegie Mellon survey found the same pattern from the other side: the more people trusted AI, the less critical thinking they did; the more they trusted their own skill [6]. An MIT study connceted people up to an EEG and found less brain connectivity in those who wrote with a LLM than in those who wrote without one [7].

But there is a difference : 

The same research shows the outcome depends on how the AI is used. If used to completely replace thinking, it ends up eroding the skill. If used to support thinking, where the hard stuff remains with the person and the AI just takes some of the logical work, it will leave critical thinking as-is or even improve it.

The direction of the scientific literature on this is consistent: leaning on the AI to avoid the effort is exactly what diminishes the skill.

One study addresses the DK curve directly. Fernandes and colleagues [15] had 246 people solve twenty  logical problems with AI. Performance went up by three points against a norm population, and people overestimated their score by four. So they did get better, and they overestimated themselves by more than they improved. Higher AI literacy corrolated with more overestimation, not less.

6. Does it really matter?

Handing a skill to a tool is the oldest story in recent human evolution, and most of the time it is just progress. We dropped long calculations for the calculator, stopped learning phone numbers, stopped reading maps. The skill faded and nobody missed it, because the tool was reliable. By that logic, intrinsic skill is just the next thing we are right to put down.

If the tool is always there, why keep the skill?

Because, if my hypothesis holds, handing it over stops being harmless in three places, and they are the three we should care about most.

  • First, passing it on, and this is the one I care most about. Skill is handed down by apprenticeship: juniors do the boring work, struggle, fail in front of the more experienced, and pick up the know-how no one wrote down. AI now does the boring work, so the issues/struggle that made the next experts is gone, and the junior never really internalises it's AI driven learnings. The ones who built the skill before AI retire, and none form behind them.
  • Second, when things break. The tool is not always there, and it is not always right. In 1997 an American Airlines captain warned that pilots were becoming "children of the magenta line," good at managing the automation but no longer able to fly by hand [9]. In 2009 the autopilot on Air France 447 quit over the Atlantic, handed the plane to a crew who had lost the hand-flying skill, and 228 people died [10]. The same happened at San Francisco in 2013 [11]. The skill that mattered only mattered for the ninety seconds it was needed.
  • Second, oversight. The EU AI Act makes a human in the loop a legal requirement for high-risk systems. But look at what it asks of that human: understand what the system can and cannot do, catch it when it goes wrong, and know when to override it [14]. Every one of those is intrinsic skill under another name. You cannot check work you could not do yourself, so as the skill fades the human in the loop becomes a rubber stamp.

Banking has already run the test, on a delay. COBOL, written in 1959, still sits under an estimated three trillion dollars of transactions a day [12, 13]. It works. But the people who understand it are retiring/have retired, and the business rules live in their heads, not in any document. When New Jersey's unemployment system fell over in 2020, the state had to call retired programmers back [13]. You might say AI settles this: point it at the code. But the language was never the hard part. AI can read the syntax and still not tell you why one job runs before another on the last day of the month, or which exception encodes a rule from 1987 that no one wrote down. That did not live in the code. It lived in the person, and the person has gone.

7. What it all means

So, how much does intrinsic knowledge matter? What's the difference with a calculator, isn't it the same ? For everyday output, I'd say less and less, and pretending otherwise is just looking backward. For coping when things break, for oversight, and for making the next set of experts, more than ever.

What's important, if I am right, is this: intrinsic skill has moved from a productivity question to a governance one. It was about how the job gets done, now it is about trust, human in the loop, check, and survive the AI that is the actual work.

So it will become what ? Control functions, steering, guiding, directing, and like any control, it fails quietly until the day you need it.

The practical questions for companies are as simple to ask as they are uncomfortable to answer. Where in the organisation has intrinsic capability already thinned out : Who could still do the work if the tool went down tomorrow. And is your human in the loop a real check, or a signature. Who could still do the work if the tool went down tomorrow. And is your human in the loop a real check, or a signature

Who could still do the work if the tool went down tomorrow. And is your human in the loop a real check, or a signature

Put plainly: if my hypothesis is wrong, intrinsic skill is just nostalgia and the tool has freed us from it. If it is right, it is a control that erodes while the deliverable continous looking fine.

8. References

Dunning-Kruger, original and critiques

  • [1] Kruger, J. and Dunning, D. (1999). Unskilled and Unaware of It: How Difficulties in Recognizing One's Own Incompetence Lead to Inflated Self-Assessments. Journal of Personality and Social Psychology, 77(6), 1121-1134. https://doi.org/10.1037/0022-3514.77.6.1121 (The popular peak-and-valley curve does not appear in this paper.)
  • [2] Krueger, J. and Mueller, R. A. (2002). Unskilled, unaware, or both? The contribution of social-perceptual skills and statistical regression to self-enhancement biases. Journal of Personality and Social Psychology, 82(2), 180-188.
  • [3] Gignac, G. E. and Zajenkowski, M. (2020). The Dunning-Kruger effect is (mostly) a statistical artefact. Intelligence, 80, 101449. https://www.sciencedirect.com/science/article/abs/pii/S0160289620300271
  • [4] Nuhfer, E., Cogan, C., Fleisher, S., Gaze, E. and Wirth, K. (2016, 2017). Random-number simulations on self-assessment and the graphical portrayal of measured competence. Numeracy, 9(1) and 10(1). https://digitalcommons.usf.edu/numeracy/

AI, cognitive offloading and critical thinking

Automation dependency in aviation

COBOL and legacy banking systems

Regulation

Belgium published first, France went deeper. Belgium's CCB released CyFun well before the October 2024 NIS 2 transposition deadline, built on NIST CSF and officially mapped to ISO 27001/27002. France's ANSSI published ReCyF, but as of March 2026 the underlying legislation still has not passed - making it a technically superior but legally unenforceable framework.Bottom line: ISO 27001-certified organisations in Belgium are largely compliant with a manageable gap list. The same organisations in France still have significant work ahead - and no hard deadline yet to do it by.

Table of Contents

  1. Introduction
  2. Belgium - The Head Start (4 Level Architecture, Control Counts, ISO27002 clusters, What are key measure and why do they matter, self-assessment)
  3. France - The Thorough Approach (The objective and means architecture, still waiting for the law, ISO Alignement ANSSIs own assessment
  4. ISO27002 Mapping as a common Anchor
  5. The Divergences
  6. Practical Impliaction

Part I: Introduction - One Directive, Two Answers

When the EU adopted NIS 2 (Directive 2022/2555) in December 2022, it set a clear expectation: member states had until October 17, 2024 to transpose its requirements into national law. What followed, at least across the Franco-Belgian border, is a study in contrasting regulatory cultures, institutional histories, and practical philosophies.

NIS 2 expanded covered sectors from 7 to 18, lowered size thresholds, made supply chain security and multi-factor authentication explicit obligations, and - most significantly - introduced Article 21's detailed list of required risk management measures. What the directive deliberately does not do is specify how each measure should be implemented. That granularity was left to member states, producing genuine policy diversity: two technically credible frameworks that are compatible at the technical level but structurally different in regulatory philosophy, timing, and practical demands.

The timeline below tells the story at a glance. Belgium formalised an existing, mature framework and published its official cross-framework mapping nine months before the deadline. France is still working through its legislative process 18 months after that same deadline.

Figure 1 : NIS2 Transposition timeline. Belgium met the Octobre 2024 deadline, France Transposing law remains a bill of March 2026.


Introduction

For years, we’ve all heard it: “Cyber threats are on the rise.” But how much is hype, and how much is reality ?

According to the IRIS 2025 report by Cyentia, it’s not hype. Since 2008, the number of publicly reported cyber incidents has increased by over 650%, climbing from 450 to nearly 3,000 per quarter.

But here’s the nuance that matters: this rise isn’t just about more attacks. It’s also about how attackers evolve, how we detect threats, and how regulation drives transparency. From the stealthy era of APTs to the ransomware boom and the pandemic’s IT transformation, every major spike has a cause.

As risk managers and CISOs, this isn’t just trivia-it’s critical context. Understanding these shifts helps us future-proof our strategies, rather than plan for a past that no longer exists.

Europe's Most Influencial CISOs of the year 2024

The below is an interview originally conducted by CIO-World, in which I was recognized as one of Europe’s Most Influential CISOs of 2024. The discussion goes beyond technical security and focuses on leadership: the core capabilities a CISO needs today, how regulatory frameworks can be used as strategic enablers of resilience, and how security leaders can operate credibly and effectively within the C-suite. It also explores the growing convergence of technology, governance, and compliance.

The original can be found at CIO-World.

As financial technology (FinTech) evolves rapidly, it faces an increasing number of cyber threats. Cybercriminals are constantly finding new ways to exploit weaknesses in payment systems, putting billions of dollars and countless identities at risk. A staggering statistic reveals that up to 75% of customers worldwide now use at least one FinTech service, a number projected to grow as more people embrace digital payments and online banking.

Source: CIO World 

Meet Thierry Zoller, the Chief Information Security Officer at J.P. Morgan Mobility Payments Solutions S.A. (Red. now Julius Baer) , whose mission is to stay one step ahead of these digital predators. With nearly three decades of experience in cybersecurity, Zoller brings a unique blend of technical expertise and strategic vision to one of the world’s largest financial institutions. His journey from a curious teenager in Luxembourg to a leading figure in global information security is an example of the power of passion and perseverance.

Thierry’s fascination with technology began early, driving him to explore the inner workings of systems and networks. This curiosity led him to dive deep into reverse engineering and system vulnerability analysis, skills that would become invaluable in his future roles.

His career has been marked by a series of high-profile positions, including Head of Security Risk and Compliance Europe for Amazon and CISO for Amazon Payments. These experiences have honed his ability to navigate the complex intersection of technology, finance, and security.

At J.P. Morgan, he faces his most challenging task yet: securing the future of mobile payments in an increasingly cashless world. His approach combines futuristic technology with a deep understanding of human behavior, recognizing that the weakest link in any security system is often the user.

Thierry’s impact extends far beyond his corporate role. As a prolific blogger and researcher, he has coordinated the disclosure of over 100 vulnerabilities and released numerous free security tools. His work has been cited in books and peer-reviewed papers, cementing his status as a thought leader in the field.

The 45-year-old security expert’s commitment to knowledge sharing has been a cornerstone of his career. This philosophy drives his continued efforts to educate and empower the next generation of cybersecurity professionals, contributing significantly to the global information security community.

N-Th Party Risk (Thierry ZOLLER)
The responsibilities of vendors, suppliers, and service providers have grown increasingly important in the dynamic digital economy. The growing digitalisation and reliance on third-party entities significantly enhances business operations while concurrently introducing a spectrum of security risks. 

Recognising these challenges, regulatory supervisors have been actively creating frameworks over the years to make sure that financial entities in particular appropriately handle and mitigate the risks of security incidents that could directly affect their operations.

The adoption of specific guidelines by the European Banking Authority (EBA) in marked a substantial acceleration of the shift towards a more security-conscious approach when interacting with third parties. These guidelines were a significant advancement in highlighting the important security aspects to take into account while working with third parties. 

However, with the recent final Regulatory Standards published, the Digital Operational Resilience Act (DORA) is further evolving the requirements and expectations in light of multiple high-profile breaches involving third parties and the supply chain. The entry into force of this European Regulation, which takes effect in January 2025, marks the beginning of a new era in third party security management. 

It signals a time when strict compliance and proactive risk management are more important than ever in third-party contacts, and it also emphasises the significance of operational resilience and indicates a heightened response to the changing threat landscape.

While researching the state of the Art in "Third Party" risk management I came across an Report recently published by Wade Baker, Ph.D. and the Cyentia Institute titled “Risk to the Nth-Party Degree: Parsing the Tangled Web".

In true Cyentia Institute fashion the report is a data driven and provides plenty of opportunity for the data science geeks amongst us to rejoice - for the others it's one of the first publicly available reports providing us with data analysis on the matter with.

The Report highlights a crucial aspect that is often overlooked in risk management: vendor risk extends beyond direct third parties.

What really is "third party" risk ?


What is Psychological Safety ?

Psychological safety is a concept that refers to an individual's perception of the consequences of taking an interpersonal risk in a work environment. It involves feeling safe to express oneself without fear of negative consequences to self-image, status, or career. In a psychologically safe team, members feel accepted and respected. This environment allows for open communication, creativity, and innovation, as individuals feel comfortable sharing their ideas, questions, concerns, and mistakes without fear of ridicule or retribution.

Amy Edmonson - TED Talk (Building a psychologically safe workplace)
https://www.youtube.com/watch?v=LhoLuui9gX8


 


Cybersecurity in M&A 


A Growing Priority for Decision Makers


In the dynamic landscape of mergers and acquisitions (M&A), decision-makers are increasingly prioritizing cybersecurity risks. 

A detailed survey by Forescout provides key insights into the current state of cybersecurity in mergers and acquisitions, the survey that involved nearly 3,000 IT and business decision makers reveals a growing emphasis on cybersecurity in M&As. 

The study found that 81% of respondents now prioritize a target's cybersecurity posture more than in the past with 62% agreeing cyber risk is their biggest concern post-acquisition.

This trend highlights the recognition of cyber risks as potential deal-breakers, capable of causing significant financial and reputational damages.

" Take the Verizon acquisition of Yahoo in 2017 as an example. Following Yahoo’s security breach disclosures, there was a $350 million acquisition price cut."

The study highlights this shift, noting the importance of continuous cyber assessment throughout the M&A process. It's no longer a one-time check but a critical, ongoing evaluation.

Key Findings


Transparency 🚫 - An undisclosed data breach is a deal breaker for most companies: 73% percent of respondents agreed that a company with an undisclosed data breach is an immediate deal breaker in their company’s M&A strategy

Plan for continuous assessments 🔄 - Decision makers sometimes feel they don’t get enough time to perform a cyber evaluation. Only 36% of respondents strongly agree that their IT team is given time to review the company’s cybersecurity standards, processes and protocols before their company acquires another company. The results emphasize the importance of proper evaluation and time in ensuring successful M&A outcomes.

Acquisition Regrets🤦- 65% of respondents regret their M&A decisions due to cybersecurity concerns. Failure to address cyber risk can lead to major acquisition regrets: Nearly two-thirds of respondents (65%) said their companies experienced regrets in making an M&A deal due to cybersecurity concerns.

Integration Delays⏲️- 49% encountered unknown or undisclosed cybersecurity issues, causing M&A timeline delays. 54% reported minor delays and losses under $1 million; 50% faced major delays with similar financial impact.

Significant Losses💸 - 22% experienced losses over $1 million due to cybersecurity incidents.



Introduction
As many of you know the Schengen Agreement (Named after the Luxemburg City "Schengen" where the initial contract was signed) introduced the free flow of goods and people across the European Union. Many claim it to be on of the core backbone agreements of the European Union.

Synopsis
Germany decided to introduce border controls following the SARS-CoV-2 epidemic during  March-Mai 2020. Luxembourg has a particular situation that is best displayed via this illustration: every day over 1/3 of the entire working population enters the country via Germany, France, and Belgium to drive home in the evening thus passing these very borders every day. 



This blog post will be updated periodically as I come across new practical information and experiences. You can subscribe to my blog if you wish to be kept updated.

Updates : 
  • 24.07.2020: Added number of reported data breaches to Statistics
  • 25.07.2020: Added the Role of the DPA as captured within the GDPR and added references
  • 25.07.2020: Added the section "Parliamentary Oversight" capturing parlamentary enquiries
  • 26.07.2020: Corrected the part about getting a copy of your original complaint. In fact, I only have received parts of it and am still waiting to receive the rest.
  • 27.07.2020: Due to popular demand I added a section "Legal Procedure".

I thought it is useful for the general audience to summarise my experience working with the CNPD as a Data Subject. Aligned with many other administrative procedures in Luxembourg: they have a nice appearance at the frontend but are tilted against your interest in the backend.




RTL  published [1] an Interview (8th of July 2020)with Paul Wilmes a Full professor in "Systems Ecology" at Uni Luxembourg.

Paul Wilmes [2] is quoted as saying:

  • LU: "Et hätten ni Deeg ginn zu Lëtzebuerg, an deene keng Nei-Infektiounen derbäi sinn."
    EN: "There has not been a single day in Luxembourg that we did not have new infections"

    Ed. : Unfortunately, that's just a basic fact of life (and science for that matter). There won't be any day that there are no (0) new viral infections in Luxembourg. It is dangerous to think or portray the short term (or even long term) goal as having no (0) infections. That's a matter of impossibility. If interested see my prior post about some of the dynamics [3]
  • LU: "D'Zuelen schwätzen eng kloer Sprooch an d'Wëssenschaft kann nëmmen weider un d'Leit appelléieren, d'Mesuren anzehalen a sech testen ze loossen "
    EN:  The numbers speak a clear language and science can only continue to plead to the people, follow the measures.

    Ed. : This diatribe has 0 content that is convincing or conveying the "Why". If anything, what follows points to science not speaking a clear language.

  • LU: Déi nei Fäll sinn haaptsächlech duerch Infektiouns-Cluster gedriwwen, dat heescht duerch grouss Usammlungen vu Leit. Manner an de Schoulen, mä éischter op de Partyen. Et gëtt awer och sporadesch Fäll vu Persounen, déi sech am enke Kontakt mat Aneren ugestach hunn. Dat Ganzt wier ebe gedriwwen duerch sozial Kontakter
    EN: The new positive tests are mainly rooted in infection clusters, meaning a big gathering of people. It is less the Schools but more partys. There are however also "sporadic" cases of people that infected each other through close contact. The pandemic is driven through social contacts.

    Ed: We learn that the Virus prefers Partys, and the Virus dislikes Schools. We also learn that "social contacts" are the problem. It is evidently the physical distance, not social contact.
    N.B this follows right after the "science speaks a clear language" diatribe.
  • LU: Eng Tracing- App wier en effikasst Instrument, confirméiert de Mikrobiolog.
    EN: He confirms that a tracing app is an efficient/effective mechanism

    Ed:  We learn that tracing-apps are effective - although all data points to the Opposite. As an example, the Germany Corona app had over 14 million downloads. It alerted 310 people, of which we do not even know the percentage actually was that ended up being infected.
Disclaimer: I do think the Pandemic is a Problem, this series is solely looking at the state of reporting and journalism in Luxembourg. There is no intent to downplay the consequences of the Pandemic. It is, however, laughable how the Government and Press fail to communicate consistently, truthfully, and logically. Giving births to deniers as a result of losing trust.

The R number points to weeks where we will need to be cautious in Luxembourg, but it is not through such journalism that we will succeed in winning over the population to do the right thing. A totalitarian draconian political approach won't work either. Be honest/truthful, humble, try your best to be neutral and say what the things are that we/you do not know. That wins trust and that wins the reader because it is truthful. We never were in such a situation, there are a lot of known unknowns and unknown unknowns. Just say it, there is no shame in not knowing.

[1] https://www.rtl.lu/radio/invite-vun-der-redaktioun/a/1545684.html (08.07.2020)
[2] https://wwwfr.uni.lu/lcsb/people/paul_wilmes
[3] https://blog.zoller.lu/2020/07/luxembourg-press-coverage-on-sars-cov-2.html


"The amount of cases in the last 3 weeks has increased 10 fold!"  That's what I read in the article [1] published by RTL today on the 7th of July 2020. There is no indication or thoughts as to what could be the reasons for that increase and the conclusion is left to the reader.

Hoping to see press coverage that went a bit further than just relaying official statements I had a read and also opened up [2] Ben Elsen's excellent statistical analysis.

According to the article, there was apparently a 10 fold increase in the last three weeks - so let's take a look at the percentage of positive tests in that time period :



I am unable to see a 10 times increase in relative Positive Test numbers, so what can that possibly mean?



In the graph above, we can see that the number of tests have increased roughly 10 fold over the last 3 weeks aswell.

And that's what we don't call journalism my friends you cannot just communicate such numbers without any context or even attempt at explanation. This article is throwing a bunch of copied figures at the reader, without any additional insights or analysis. Worse, it leaves us with the thinking that all hell will break loose soon.

20 years ago we called that "spreading FUD" (Fear Uncertainty and Doubt). It's the self-feeding journalistic echo chamber that lets the clicks coming and the paranoia rise. It is unfortunately also what creates the very people that ignore the requirements to wear masks because they believe that everything that they read is a bunch of BS and loose trust. (In my humble opinion, such reporting  deserves that judgment).

In all fairness, the R number points to weeks where we will need to be cautious in Luxembourg, but it is not through such journalism that we will succeed in winning over the population to do the right thing. A totalitarian draconian political approach won't work either. Be honest/truthful, humble, try your best to be neutral and say what the things are that we/you do not know. The result is trust because the message is truthful. We never were in such a situation, there are a lot of known unknowns and unknown unknowns. Just say it, there is no shame in not knowing everything at 100% at this stage.


[1] https://www.rtl.lu/news/national/a/1545407.html
[2] https://donneeen.lu/covid19/overview/