That's the UTB syndrome at work and is why, any time a manager told me that such and such was "unlikely to break", I felt a strong desire to get into the life boat, pronto.
The more critical a system is, the more you need to allow for it breaking. You
must assume that failure will always occur at the worst possible time and always in the most obscure way. That's why sensible people, who are running critical systems, accept the need for two entirely independent systems.
Managers, on the other hand, would rather save money, because they'll be long gone when the brown stuff starts bouncing off the fan.