During the Cold War, CIA officers stationed in Moscow operated inside what was, by most accounts, the most heavily surveilled city on the planet.
The KGB monitored diplomatic compounds, logged contact between Soviet citizens and foreigners, and staffed embassy buildings with informants. There was no assumption of privacy and no benefit of the doubt extended to anyone. The tradecraft that let officers operate anyway, later documented publicly by former CIA officers Antonio and Jonna Mendez in their book "The Moscow Rules: The Secret CIA Tactics That Helped America Win the Cold War," wasn't built around clever tricks. It was built around a single, unglamorous discipline: never letting a track record of success become a reason to stop checking.
That discipline has a business lesson buried inside it, one that has nothing to do with espionage and everything to do with why the parts of a company that feel safest are so often the parts nobody has looked at closely in years.
Operating in a City Where Everything Was Already Compromised
Soviet-era Moscow presented American intelligence officers with an environment where the default assumption had to be that the opposition was already inside every system, every conversation, and every plan. That baseline shaped everything about how officers behaved. Meetings, communications, and movements were all treated as potentially exposed until proven otherwise, and "proven otherwise" was never a permanent status. It had to be re-earned every time.
This is a genuinely different posture than the one most people, and most businesses, default to. The natural instinct is to treat a system as safe once it's demonstrated it's safe. Moscow-era tradecraft rejected that instinct outright, precisely because the stakes of being wrong were unrecoverable.
Surveillance Detection Routes: The Discipline That Never Got Easier
One of the most concrete practices to come out of this environment was the surveillance detection route, a deliberately long, circuitous path through the city that officers walked or drove before any sensitive meeting, designed specifically to expose a KGB tail before that tail could expose the meeting itself.
What makes this practice notable isn't the route itself. It's that officers ran it in full every single time, regardless of how many previous routes had come back clean. A route that had worked ten times in a row wasn't treated as evidence the officer was no longer being watched. It was treated as, at most, evidence that the last ten checks had gone well, with the eleventh check still fully required. The discipline had no expiration date and no threshold of past success that allowed it to be skipped.
The Real Lesson Isn't About Spies, It's About When Defenses Actually Drop
Here's the part of the Moscow Rules mindset that translates directly into business, and the part most retrospectives on Cold War tradecraft skip past. The officers who got caught over the decades of this conflict were rarely the newest or least experienced. They were disproportionately the ones who had run a particular route, contact, or process cleanly enough times that the discipline started to feel unnecessary. Confidence built from a genuinely strong track record was, paradoxically, the exact condition under which vigilance eroded.
This is a documented pattern in high-stakes fields well beyond intelligence work. Aviation safety researchers have long identified something similar: pilots and maintenance crews are statistically more likely to skip or rush a checklist item after a long stretch of uneventful, successful flights, not because they've become careless people, but because sustained success quietly recalibrates the felt sense of risk downward. The system hasn't gotten safer. The people checking it have gotten more confident, and those are not the same thing.
Business systems follow the identical pattern, just on a slower timescale. The revenue stream that's performed reliably for three years is, by definition, the one least likely to have had its assumptions stress-tested recently. The vendor relationship that's never caused a problem is the one whose contract terms nobody has reread in years. The pricing model that's worked since the company was founded is the one least likely to have been checked against how the market has actually changed. Success doesn't make a system safer. It makes the system less examined, which is a very different thing wearing the same clothes.
1. Identify your most successful system, not your riskiest one
Most audits instinctively target what feels shaky: the newest product line, the client that's been difficult, the process everyone already complains about. The Moscow Rules framework points somewhere counterintuitive instead: your best-performing system, the one generating the most confidence and the least scrutiny, is exactly where an unexamined weak point is most likely to be sitting undisturbed.
2. Run the check regardless of how clean the last one was
The surveillance detection route was run in full every time, not on a schedule determined by how the last few checks went. Apply the same standard to a recurring business review: a quarterly cadence that happens regardless of how well the previous quarter performed, not a review that gets quietly skipped because "everything's been fine."
3. Separate the outcome from the process that produced it
A good result doesn't automatically mean the process behind it was sound; it can just as easily mean the process had a flaw that hasn't been triggered yet. When reviewing a successful quarter or a strong client relationship, evaluate the underlying mechanics independently of the favorable outcome, rather than letting the good number stand in as proof the process is fine.
4. Fix the vulnerability before it's found by someone else
The value of finding a weak point in a currently successful system isn't diagnostic satisfaction. It's the window to fix it while it's still your discovery instead of a competitor's, or a client's, or a regulator's. Treat what the audit surfaces as a time-sensitive repair, not a note for someday.
What The Capitalista Does
Auditing your own best-performing systems is genuinely difficult to do objectively, largely because the confidence that comes from strong results is exactly what makes those systems hard to see clearly from the inside. That's where an outside financial perspective earns its value.
- We stress-test your strongest revenue stream, not just your weakest one. The line item generating the most confidence is often the one that's gone longest without independent scrutiny.
- We separate a good number from a sound process. A strong quarter can mask a fragile mechanism underneath it, and we help you tell the difference before it matters.
- We build a recurring review cadence that doesn't get skipped. Consistency is the entire discipline; a check that only happens when something feels wrong isn't the same check.
- We find the vulnerability before a competitor or a client does. A pressure test run internally, on your terms, on your timeline, is a very different experience than having the same weakness surface in a lost deal.
- We keep this current as your business changes. A system that was sound last year isn't guaranteed to still be sound under this year's volume, market, or team.
Frequently Asked Questions
Is "The Moscow Rules" a real, documented source, or is this a fictionalized account?
It's real. Antonio J. Mendez and Jonna Mendez, both former CIA officers with the agency's Office of Technical Services, published "The Moscow Rules: The Secret CIA Tactics That Helped America Win the Cold War," documenting the tradecraft developed for operating in the hostile surveillance environment of Soviet-era Moscow. This article draws on that documented history and the informal set of tradecraft maxims that circulated among intelligence officers of the period.
Is the claim that officers with clean track records were more likely to get caught scientifically verified for spies specifically, or is it an analogy?
The specific claim as applied to Cold War espionage draws on the broader documented pattern in the intelligence and tradecraft literature that complacency, not inexperience, was frequently the failure point. The more rigorously studied version of this same phenomenon exists in aviation safety research, where the erosion of checklist discipline after long stretches of success is well documented. This article uses the espionage framing to illustrate a pattern with stronger direct evidence in other high-stakes fields.
How is this different from a standard annual business review?
Most annual reviews are structured around identifying what's underperforming and needs attention. This framework deliberately points the review at what's succeeding, on the premise that success is precisely what suppresses scrutiny, not evidence that scrutiny is unnecessary. It's a difference in where you aim the audit, not how often you run one.
Won't constantly re-auditing something that's working waste time and create unnecessary doubt?
The discipline isn't about doubting a good result. It's about verifying the mechanism behind the result independently of how the result felt. A system that passes the audit again simply confirms it's sound, at low cost. A system that fails it reveals a problem while it's still cheap and private to fix, which is the entire value of running the check on a fixed schedule rather than a reactive one.
What's a reasonable cadence for auditing a currently successful system?
There's no universal number, but treating it as a standing quarterly or biannual practice, applied specifically to your best-performing systems and not just your struggling ones, mirrors the "run it every time" discipline central to the Moscow Rules framework. The specific interval matters less than the commitment to running it regardless of how well things have been going.
The Bottom Line
The officers who survived decades of Cold War tradecraft weren't the ones who assumed they'd earned safety through experience. They were the ones who ran the same check, in full, after every single success, on the premise that a clean track record is a result, not a guarantee. Most businesses do the opposite by default, reserving scrutiny for what's already struggling and leaving their strongest systems the least examined asset on the balance sheet.
What's the system in your business that's performed the best over the last year, and when's the last time you actually pressure-tested it instead of just trusting it?

