VIEW THIS AS

Auto mode follows the Route Engine until you choose a viewpoint.

YOU ARE HERE

ROUTE CHECK

CONNECTED TO

WHAT NEXT

Use the canonical route for this room, or HELP if you are unsure.

Lights Out | When Systems Fail Together — How One Failure Becomes Another System’s Problem

The first failure may not be where the biggest consequence appears.

A power problem can become a communications problem. A communications problem can become a coordination problem. A transport problem can become a staffing problem. Interdependence allows trouble to cross boundaries.

Interdependence means a failure can leave the system where it began.

The one-sentence answer

A cascading failure occurs when the loss or degradation of one system changes the operating conditions of another dependent system, which can then pass further consequences onward.

The word can sounds small.

It matters enormously.

Interdependence creates routes for propagation.

It does not guarantee that every disturbance becomes a cascade.


Begin with electricity

Electricity is useful because so many other systems use it.

That usefulness also creates dependency.

Water pumps may need electricity.

Telecommunications equipment needs power.

Traffic signals need power.

Data centres need power and cooling.

Hospitals need power for lighting, imaging, ventilation, refrigeration and many clinical systems.

A power interruption therefore does not remain “an electricity problem” simply because electricity was the first system affected.

But dependencies can run both ways

Electricity systems also depend on communications.

Operators need data.

Remote equipment needs control signals.

Maintenance crews need coordination.

Fuel deliveries need logistics.

CISA’s Infrastructure Dependency Primer uses energy and communications as an example of mutual dependency and notes that infrastructure dependencies can have cascading effects across systems.

CISA — Infrastructure Dependency Primer

A system can be upstream in one relationship and downstream in another.

Four kinds of dependency

CISA distinguishes several broad kinds of infrastructure dependency. Readers do not need the technical taxonomy to use the idea, but the categories are helpful.

Physical dependency

One system requires a material output from another.

A water plant needs electricity.

A generator needs fuel.

Cyber dependency

A system depends on information, software or communications from another.

Geographic dependency

Several systems occupy the same place and can be affected by the same flood, fire, earthquake or physical disruption.

Logical dependency

One system changes because of rules, markets, expectations, finance or other non-physical relationships.

Real events often combine several kinds at once.


A cascade is a story of changed conditions

Suppose telecommunications degrade.

The water-treatment plant may still have electricity.

The pumps may still be intact.

But remote monitoring may be limited.

Maintenance teams may have less information.

Coordination may become slower.

The water system has not “failed because telecoms failed.”

Its operating conditions have changed.

If it has local controls, trained operators and fallback procedures, it may continue well.

If it has no workable degraded mode, risk rises.

Cascades are shaped by the strength of the dependency and the quality of the fallback.

Buffers interrupt cascades

A dependency does not always transmit failure immediately.

Batteries provide temporary power.

Fuel tanks keep generators running.

Water storage allows supply to continue while a pump is repaired.

Inventory keeps production moving while deliveries are delayed.

Local controls keep a process safe when the network is unavailable.

Manual procedures preserve limited operation when automation is lost.

Buffers therefore create time between the first failure and the next consequence.

That time is where repair lives.

Isolation can be a feature

Some systems are deliberately designed so one problem does not automatically spread.

Electrical protection isolates a faulted section.

Network segmentation limits cyber propagation.

Valves can isolate damaged pipe sections.

Fire compartments slow the movement of fire and smoke.

Separate suppliers can prevent one production failure from stopping every source.

Isolation can look inefficient because it duplicates boundaries.

Its purpose is to stop one failure from becoming everyone’s failure.


Degraded mode is civilisation’s middle gear

Systems are often described as working or failed.

Real resilience often lives between those states.

A rail service runs less frequently.

A hospital postpones elective work but preserves emergency care.

A network drops non-essential traffic.

A factory reduces product variety.

A water system restricts non-essential demand.

Degraded modes reduce performance so essential function can continue.

Resilience is often the ability to become less capable without becoming non-capable.

The same dependency can help recovery

Interdependence is usually discussed as risk.

It is also how repair travels.

Communications help dispatch crews.

Transport moves replacement parts.

Finance pays suppliers.

Digital systems identify available stock.

Mutual-aid agreements bring people from outside the affected area.

The network that transmits stress can also transmit assistance.

Cascades can be social as well as technical

Suppose a payment system is unavailable.

People may still have money in an accounting sense.

But shops may not be able to complete ordinary transactions.

If uncertainty grows, people may change behaviour.

They buy earlier.

Withdraw cash.

Queue.

Share rumours.

Behaviour then changes demand on other systems.

A technical disruption has become a social flow problem.


Why “everything is connected” is too vague

Everything is not equally connected to everything else.

Some dependencies are strong.

Some are weak.

Some are immediate.

Some have hours or days of buffer.

Some can be bypassed.

Some have no easy alternative.

Useful analysis therefore asks for the actual dependency.

What does A need from B?

How much?

How quickly?

What happens if it is degraded?

What alternative exists?

A cascade can cross geography

A storm damages production in one country.

A factory elsewhere loses an input.

A manufacturer reduces output.

A hospital or workshop in a third country waits for the product.

The final receiver may be thousands of kilometres from the original event.

This is why the Hidden Geography of Singapore matters.

Dependencies carry causation across maps.

The Lights Out Event is an artificial mega-cascade

The main Lights Out Event deliberately removes many external relationships at once.

That is not how most real disruptions happen.

Real shocks are partial.

Some routes remain.

Buffers operate.

Substitutes appear.

External help arrives.

The thought experiment is intentionally extreme because it helps readers see every dependency that normal resilience usually hides.

How to interrupt a cascade

  • Buffer: store enough of a critical input to buy time.
  • Isolate: prevent one fault from spreading physically or digitally.
  • Diversify: create alternatives that do not fail for the same reason.
  • Degrade gracefully: preserve essential function at lower performance.
  • Prioritise: protect receivers whose failure would create larger harm.
  • Communicate: ensure operators share an accurate picture.
  • Repair early: restore the upstream function before downstream buffers are exhausted.

A cascading-failure reading test

  1. What system failed first?
  2. Which other systems consume its output?
  3. How long can each dependent system continue without it?
  4. Which buffers interrupt propagation?
  5. Which dependencies are mutual?
  6. Which alternative routes exist?
  7. Can the dependent system operate in degraded mode?
  8. Where could the next consequence appear?
  9. Which receiver is most exposed?
  10. Which repair breaks the largest chain of downstream consequences?

What this article does not claim

  • It does not claim every infrastructure failure cascades.
  • It does not claim interconnected systems are inherently fragile.
  • It does not claim local failure always becomes national failure.
  • It does not claim redundancy eliminates all risk.
  • It does not claim technical dependencies alone determine human outcomes.

The narrower claim is that interdependent systems can transmit changed conditions across boundaries, and resilience depends partly on knowing where those routes exist before a failure begins.

The civilisational lesson

Civilisation gains enormous capability by connecting systems.

Power helps water.

Data helps transport.

Finance helps trade.

Education supplies specialists.

Connections are productive.

They simply need boundaries, buffers and repair paths.

A resilient civilisation is not one where systems never depend on each other. It is one where dependence does not have to become uncontrolled propagation.

Continue the Lights Out branch

Previous: The Bottleneck Problem.

Next: Civilisation Must Make Things Disappear.

Deep connections

For repair and recovery, continue to Repair Systems.