Request a Consultation

HomeNews › Critical Infrastructure Lightning Resilience

Critical Infrastructure

When the Grid Can't Blink: Keeping Critical Infrastructure Online Through a Strike

A remote water-utility control cabinet with surge protection devices and a bonded earth bar, the electronics that a lightning event has to leave running

For most buildings, the measure of a good lightning protection system is simple: the structure survives and nobody is hurt. For critical infrastructure, that bar is far too low. When you run a water network, a telecommunications backbone, or an electricity distribution system, availability is the product. A protection scheme that lets the building stand but takes the control system offline has still failed at the only thing that matters.

This is the distinction that reshapes lightning protection for utilities and infrastructure operators. The strike that does no visible damage can still trip a plant, corrupt a controller, or drop a communications link for long enough to matter. Resilience here is measured in continuity of service, not in scorch marks avoided.

The failure that leaves no scorch marks

A lightning event rarely needs to physically destroy anything to cause an outage. A nearby strike induces a surge on power and signal cabling; that surge reaches a programmable logic controller, a SCADA remote terminal unit, or a telemetry radio, and the device faults, resets, or latches into a safe state. The concrete is untouched. The service is down.

For an operator, the consequence is the same whether the equipment was vaporised or merely confused. A pumping station that stops pumping, a substation that isolates, a base station that drops its backhaul: each is an availability failure. This is why lightning protection for critical infrastructure has to be designed around the survival of the electronics and the continuity of the process, not just the integrity of the structure.

Why the electronics fail before the structure does

Modern infrastructure is dense with sensitive, low-voltage electronics, and those are the most vulnerable link in the chain. A direct strike delivers tens of thousands of amperes, but even the electromagnetic field from a strike hundreds of metres away can induce damaging transients on the long cable runs that infrastructure depends on. Those long runs, between a control room and a remote asset, between a mast and its equipment shelter, act as antennas for lightning energy.

IEC 62305-4, the part of the standard dealing with electrical and electronic systems, addresses exactly this. Its approach is to divide a facility into lightning protection zones, progressively reducing the electromagnetic threat as you move from the exposed exterior toward the protected heart of the system, and to coordinate protection at every boundary a cable crosses.

The point that gets missed: protecting the structure and protecting the systems inside it are two different design problems. A down-conductor network can safely carry a direct strike to earth and the control system in the same building can still be knocked out by the induced surge. Availability depends on solving the second problem, not just the first.

Coordinated surge protection, not a single device

The instinct to fit one surge protection device at the incoming supply and consider the job done is where many schemes fall short. Effective protection is a coordinated cascade: a high-energy device where services enter the site to divert the bulk of the surge, and progressively finer devices closer to the equipment to clamp the residual voltage to a level the electronics can tolerate. Each stage has to be energy-coordinated with the next, so the sequence shares the load correctly rather than leaving one device to absorb more than it is rated for.

That coordination has to cover every path into the sensitive equipment, not only the mains supply. Signal lines, data links, and instrumentation cabling are common and often overlooked entry points for lightning energy. A single unprotected signal pair can carry a transient straight past a well-protected power feed and into the controller.

Earthing as the reference everyone shares

Underneath the surge protection sits the earthing and bonding system, and for infrastructure it does more than provide a path to ground. It establishes the common reference that every connected system measures against. When lightning current flows, a well-bonded site rises and falls in potential together, so no damaging voltage differences open up between a controller, its sensors, and its communications equipment. A poorly bonded site develops exactly those differences, and the resulting transient voltage is what destroys interfaces between one subsystem and another.

This is why a single common bonding network, tying the structural earth, the electronic system earth, and the incoming services together, is central to keeping SCADA and communications alive through a strike. The goal is not merely a low resistance to earth, it is a stable, shared reference that the whole facility holds in common.

Where this leaves an operator

For critical infrastructure, lightning resilience is an availability engineering problem wearing the clothes of a lightning protection problem. The structure surviving is the baseline, not the objective. The objective is that the pumps keep running, the substation stays closed, and the network stays up while the storm passes overhead.

Our work in critical infrastructure protection starts from the service the site has to deliver and works back to the bonding, surge coordination, and zoning needed to keep it delivering. A structured risk assessment identifies which systems carry the availability, and resiliency planning turns that into a protection scheme built around uptime rather than around the building alone. Where minutes of forewarning are worth having, advance thunderstorm warning lets an operator switch to backup supply or a controlled safe state before a strike rather than reacting after it.

Would your control systems survive the next strike?

The structure standing is not the same as the service staying up. We can assess where a lightning event would actually take your operation offline.

Discuss a Resilience Assessment