I think of this incident like I do a spam firewall at my work 
Sometimes the spam emails get through because my filter wasn't tight enough to catch em, other times the filter catches legit emails to employees even tho they aren't really spam.
This is in MY mind the same thing. Their rules, policies, and procedures are designed in a flat way to look for "insert whatever it is here" and then based on those results react accordingly. This means there is always the possibility that someone can "slip by" by using a fake ID, or giving different information every time.... or that someone can get "caught" by something and fit an "x" set of circumstances set by the company and not really be the intended offending target.

Sometimes the spam emails get through because my filter wasn't tight enough to catch em, other times the filter catches legit emails to employees even tho they aren't really spam.
This is in MY mind the same thing. Their rules, policies, and procedures are designed in a flat way to look for "insert whatever it is here" and then based on those results react accordingly. This means there is always the possibility that someone can "slip by" by using a fake ID, or giving different information every time.... or that someone can get "caught" by something and fit an "x" set of circumstances set by the company and not really be the intended offending target.