@sj Sometimes it's both. (story from pre-LLM era)
We had an IT support contractor who was the odds-on favorite to win the follow-on contract (as incumbents typically are).
One day (thanks to a whistleblower) we discovered they were an insider threat: we had another contract up for bid that they had no experience in, but they wanted to compete for. So they tasked a few people with copying our copies of *that* incumbent's files, so they could copy the processes and look like they knew what they were doing.
No one wanted this contractor to have the follow-on IT support contract, but under federal acquisition regulations we had to use the rubric, and they kept ticking box after box. Finally, I pointed out that the contract requires notifying us within 48 hours of detecting an intrusion.
"Logically, they detected their own intrusion immediately upon performing the intrusion. They didn't 'notify' us until we called them on it a week later. Therefore, they have demonstrated that they cannot satisfy at least one part of the contract."