I've seen plenty of projects that choose not to design or think about handling "unknown unknown" failure vectors because YAGNI