One substation fire closed Europe's busiest airport
Heathrow had backup power. The review found the issue was not whether resilience existed, but whether anyone had modelled the switchover.
We were not in the room. Every reading on this desk is an outside analysis of public reporting, written to show how the method is applied — not to allege what any organisation knew or decided. Where we go beyond the public record we say so in the text.
On 20 March 2025 a fire at the North Hyde electrical substation cut power to Heathrow Airport. The airport closed for most of the day, with well over a thousand flights disrupted. The UK's National Energy System Operator conducted a review of the incident and the airport commissioned its own.
Heathrow was not without redundancy. It had multiple supply points. What it did not have was a rehearsed understanding of how long a reconfiguration takes across a site of that complexity, and which of several hundred interdependent systems come back in what order. Resilience existed on paper as capacity. It failed in practice as sequence.
- Immediate: roughly 1,300 flights disrupted, passengers stranded across multiple continents, knock-on crew and aircraft positioning problems lasting days.
- Sectoral: every critical national infrastructure operator with a comparable single-site dependency had the same question asked of it within a week.
- Insurance and regulatory scrutiny of what 'resilient' means contractually, rather than aspirationally.
The class here is redundancy that has never been exercised end to end. It appears in hospitals, data centres, ports, steelworks and telecom cores — anywhere a backup exists as an asset on a register but the switchover has only ever been reasoned about, never run. The failure is almost never the backup. It is the order of operations around it.
One decision: if this supply point goes, what comes back, in what order, and how long until the site is operational? That is a simulation question about a specific network, on a specific site, with specific dependencies. It cannot be answered from a diagram, because a diagram has no time in it.
- Run the switchover thousands of times against the real topology before it is ever needed once.
- Find the dependency nobody documented — the ordering constraint that only appears when you actually sequence it.
- Give operations a rehearsed sequence instead of a plan, and give the board a recovery time that was measured rather than assumed.
- Re-run it after every change to the site, so the answer stays current instead of ageing quietly.
Level 3 connects your systems and can show you the current state. Level 4 lets you ask what happens next and get a defensible answer. Redundancy documented but never simulated is the classic level 3 ceiling.
Score your own position in five minutes — same model, no email wall. Or read what the levels mean.
Same seven steps, your asset, your data, your decision. That is the first half of a scoping workshop.