shipslides
Engineering32 slides0 views

Engineering Disasters and Lessons

When Engineering Fails, the World Learns. Slides: Engineering Disasters and Lessons · Why Study Failures? · RMS Titanic (1912) · Tacoma Narrows Bridge (1940) · de Havilland Comet Crashes (1954) · Vajont Dam (1963) · Hyatt Regency Walkway (1981) · Bhopal Gas Disaster (1984).

StandaloneDownloadMarkdown
Sandboxed deck
Open raw

About this HTML presentation

This Shipslides page presents Engineering Disasters and Lessons as an interactive HTML presentation deck in the Engineering catalog with 32 slides. The share page keeps the uploaded deck sandboxed while exposing readable context, topics, and a slide outline for viewers and search engines.

When Engineering Fails, the World Learns Key sections include: Engineering Disasters and Lessons; Why Study Failures?; RMS Titanic (1912); Tacoma Narrows Bridge (1940); de Havilland Comet Crashes (1954); Vajont Dam (1963); Hyatt Regency Walkway (1981); Bhopal Gas Disaster (1984); Space Shuttle Challenger (1986); Chernobyl (1986).

Key sections

  • 01Engineering Disasters and Lessons
  • 02Why Study Failures?
  • 03RMS Titanic (1912)
  • 04Tacoma Narrows Bridge (1940)
  • 05de Havilland Comet Crashes (1954)
  • 06Vajont Dam (1963)
  • 07Hyatt Regency Walkway (1981)
  • 08Bhopal Gas Disaster (1984)
  • 09Space Shuttle Challenger (1986)
  • 10Chernobyl (1986)
  • 11Piper Alpha (1988)
  • 12Therac-25 Radiation Overdoses (1985-87)
  • 13Space Shuttle Columbia (2003)
  • 14Deepwater Horizon (2010)
  • 15Fukushima Daiichi (2011)
  • 16Grenfell Tower Fire (2017)
  • 17Boeing 737 MAX Crashes (2018-2019)
  • 18Morandi Bridge Collapse (2018)
  • 19Texas City Refinery Explosion (2005)
  • 20Sampoong Department Store (1995)
  • 21Rana Plaza Collapse (2013)
  • 22Banqiao Dam Failure (1975)
  • 23Tay Bridge Disaster (1879)
  • 24Common Themes Across Disasters

Topics covered

Slide outline
  1. 01Engineering Disasters and Lessons
  2. 02Why Study Failures?
  3. 03RMS Titanic (1912)
  4. 04Tacoma Narrows Bridge (1940)
  5. 05de Havilland Comet Crashes (1954)
  6. 06Vajont Dam (1963)
  7. 07Hyatt Regency Walkway (1981)
  8. 08Bhopal Gas Disaster (1984)
  9. 09Space Shuttle Challenger (1986)
  10. 10Chernobyl (1986)
  11. 11Piper Alpha (1988)
  12. 12Therac-25 Radiation Overdoses (1985-87)
  13. 13Space Shuttle Columbia (2003)
  14. 14Deepwater Horizon (2010)
  15. 15Fukushima Daiichi (2011)
  16. 16Grenfell Tower Fire (2017)
  17. 17Boeing 737 MAX Crashes (2018-2019)
  18. 18Morandi Bridge Collapse (2018)
  19. 19Texas City Refinery Explosion (2005)
  20. 20Sampoong Department Store (1995)
  21. 21Rana Plaza Collapse (2013)
  22. 22Banqiao Dam Failure (1975)
  23. 23Tay Bridge Disaster (1879)
  24. 24Common Themes Across Disasters
  25. 25The Ethics of Engineering
  26. 26Safety Engineering Frameworks
  27. 27Forensic Engineering
  28. 28How Codes and Standards Evolve
  29. 29Modern Risk Assessment
  30. 30Emerging Failure Modes
  31. 31Building a Safety Culture
  32. 32Key Takeaways
Page data
Canonical
https://shipslides.com/d/engineering-engineering-disasters
Category
Engineering
Size
65.1 KB
Updated
2026-05-17
LLM text
https://shipslides.com/d/engineering-engineering-disasters/llms.txt

Presentation Transcript

Detailed slide-by-slide text content extracted from this presentation.

Slide 01

Engineering Disasters and Lessons

  • When Engineering Fails, the World Learns
  • Every code, standard, and safety protocol exists because something once went terribly wrong. These are the failures that shaped modern engineering.
  • 1 / 32
Slide 02

Why Study Failures?

  • Engineering failure analysis is not morbid curiosity -- it is the primary mechanism by which the profession advances. Every disaster reveals gaps in knowledge, and the response writes new rules.
  • Failure Categories
  • Design errors: Incorrect analysis, missed load cases, inadequate safety factors
  • Material failures: Fatigue, corrosion, brittle fracture, creep
  • Construction defects: Poor workmanship, substituted materials, shortcuts
  • Operational failures: Human error, inadequate maintenance, exceeding design parameters
  • Management failures: Schedule pressure overriding safety, ignored warnings, poor communication
  • Unknown unknowns: Phenomena not yet understood at time of design
  • The Swiss Cheese Model
  • James Reason's accident causation model: multiple defensive barriers (like slices of Swiss cheese) each have holes. A disaster occurs only when holes in multiple layers align simultaneously.
  • Layer 1: Design standards and codes
  • Layer 2: Testing and inspection
  • Layer 3: Operating procedures
  • Layer 4: Training and competence
  • Layer 5: Emergency systems
  • Nearly every major disaster involves failures at 3+ layers simultaneously.
  • 2 / 32
Slide 03

RMS Titanic (1912)

  • The "unsinkable" ship that sank on its maiden voyage -- killing 1,517 people and transforming maritime safety forever.
  • What Happened
  • April 14, 1912: Titanic struck an iceberg at 22.5 knots (nearly full speed) in the North Atlantic. The collision opened the first five watertight compartments to the sea. The ship could survive four compartments flooded -- but not five. She sank in 2 hours 40 minutes.
  • 2,224 people aboard; only 710 survived
  • Lifeboat capacity: 1,178 (only 53% of passengers)
  • Water temperature: -2C (death from hypothermia in 15-45 minutes)
  • Engineering Factors
  • Brittle steel: Rivet steel contained high sulfur content; became brittle in freezing water. Rivets popped under impact rather than deforming.
  • Watertight compartments: Only reached E Deck -- open above. Water cascaded from one compartment to the next as the bow sank.
  • Insufficient lifeboats: Regulations based on tonnage, not passengers. Deck aesthetics prioritized over safety.
  • Speed: No speed reduction despite ice warnings -- commercial pressure to arrive on schedule
  • Lasting changes: SOLAS Convention (1914) -- mandatory lifeboats for all passengers, 24-hour radio watch, ice patrols (International Ice Patrol still operates today), watertight compartments extending to upper decks.
  • 3 / 32
Slide 04

Tacoma Narrows Bridge (1940)

  • The most filmed structural failure in history -- teaching the world about aeroelastic flutter and transforming bridge design forever.
  • The Collapse
  • November 7, 1940: "Galloping Gertie" -- open just 4 months -- experienced torsional flutter in 68 km/h winds. One edge of the deck rose while the other fell, the oscillations growing until hangers snapped and the deck disintegrated.
  • Main span: 853 m (third-longest in the world at the time)
  • Deck depth: Only 2.4 m (plate girder) -- ratio 1:350
  • The bridge had visibly oscillated since opening day -- known as "Galloping Gertie"
  • Only casualty: A cocker spaniel named Tubby
  • Root Cause and Legacy
  • Aeroelastic flutter: The deck's bluff cross-section generated self-excited torsional oscillations that extracted energy from the wind
  • Insufficient stiffness: Previous suspension bridges used deep stiffening trusses; Tacoma used shallow plate girders for aesthetics
  • No wind analysis: Aerodynamic forces were not considered in design -- only static wind pressure
  • Changes: All long-span bridges now require wind tunnel testing. Aerodynamic deck shapes (streamlined box girders), tuned mass dampers, and flutter analysis became mandatory. The replacement bridge (1950) has a deep open truss deck.
  • 4 / 32
Slide 05

de Havilland Comet Crashes (1954)

  • The world's first commercial jet airliner suffered catastrophic metal fatigue failures -- pioneering pressurized aircraft failure analysis.
  • The Disasters
  • January 10, 1954: BOAC Flight 781 broke apart at 27,000 feet over the Mediterranean. 35 dead.
  • April 8, 1954: South African Airways Flight 201 broke apart near Naples. 21 dead.
  • Both aircraft had fewer than 2,000 pressurization cycles
  • Entire Comet fleet grounded worldwide
  • Investigation and Findings
  • Pioneering forensics: Royal Aircraft Establishment recovered wreckage from 180m depth, reconstructed fuselage
  • Fatigue testing: Full fuselage immersed in water tank and cycled -- failed at 3,057 cycles (vs. expected 10,000+)
  • Root cause: Fatigue cracks initiated at corners of square window cutouts (high stress concentration) and rivet holes
  • Punch-riveted holes: Created micro-cracks that propagated under cyclic pressurization stress
  • Lasting changes: All aircraft now use oval/round windows (stress concentration factor 1.5 vs 4.0 for square corners). Fail-safe design (crack-stopping structure). Mandatory fatigue testing to 3x design life before certification. Regular non-destructive inspection programs for all pressurized aircraft.
  • 5 / 32
Slide 06

Vajont Dam (1963)

  • The dam held -- the mountain did not. A landslide into the reservoir created a 250-meter wave that overtopped the dam and killed 1,917 people.
  • What Happened
  • October 9, 1963, 10:39 PM: A massive landslide (260 million cubic meters of rock -- roughly the volume of Mount Blanc's summit) slid into the Vajont reservoir in the Italian Alps at 110 km/h. The resulting wave overtopped the 262-meter double-arch dam by 100+ meters and destroyed the town of Longarone below.
  • 1,917 dead in less than 7 minutes
  • The dam itself survived intact -- testament to its engineering
  • Wave height: 250 m above reservoir surface
  • Warning Signs Ignored
  • 1960: 700,000 m3 landslide into reservoir during initial filling
  • 1960-63: Slope monitoring showed accelerating creep (up to 3.5 cm/day before collapse)
  • Animals fled the mountainside days before the landslide
  • Geologists warned: Reports identified the risk, but commercial pressure to fill the reservoir prevailed
  • Operator response: Tried to lower water level -- too slowly. The saturated slope became unstable during drawdown.
  • Legacy: Transformed reservoir geotechnics -- slope stability analysis now mandatory for all dam projects. No dam built since has caused comparable loss of life from a landslide.
  • 6 / 32
Slide 07

Hyatt Regency Walkway (1981)

  • A simple connection detail change -- never recalculated by the engineers -- caused the deadliest structural collapse in US history until 9/11.
  • The Collapse
  • July 17, 1981, Kansas City: Two suspended walkways (2nd and 4th floor) in the hotel atrium collapsed during a dance party, crashing onto the crowded lobby below.
  • 114 dead, 216 injured
  • 2,000 people in the atrium at the time
  • Both walkways fell simultaneously
  • The Fatal Design Change
  • Original design: Single continuous rod from ceiling through both walkways -- each walkway hung independently
  • Fabricator's change: Two shorter rods -- upper rod supports 4th floor walkway, which then supports 2nd floor walkway via a separate rod through its box beam
  • Effect: The 4th floor connection now carried BOTH walkways' weight -- double the design load
  • Even the original design was inadequate: Only supported 60% of code-required load
  • Review failure: The change was approved without recalculation by the structural engineers
  • Legacy: Engineers of record lost their licenses -- first major case of professional accountability for structural failure in the US. Led to reforms in engineer-of-record responsibility for shop drawing review, clearer chains of responsibility, and mandatory continuing education for licensed engineers.
  • 7 / 32
Slide 08

Bhopal Gas Disaster (1984)

  • The world's worst industrial disaster -- 40 tons of methyl isocyanate (MIC) leaked from a pesticide plant, killing thousands and injuring hundreds of thousands.
  • What Happened
  • December 2-3, 1984: Water entered MIC storage Tank 610 at Union Carbide's Bhopal plant. The exothermic reaction generated heat and pressure, venting 40 tons of MIC gas into the surrounding slum neighborhoods.
  • 3,800+ immediate deaths (some estimates: 8,000-16,000)
  • 500,000+ exposed; 200,000+ with permanent injuries
  • Ongoing health effects in subsequent generations
  • Site remains contaminated 40 years later
  • Multiple Safety Failures
  • Refrigeration unit: Shut down to save costs -- MIC should have been stored cold
  • Gas scrubber: Undersized and not operational
  • Flare tower: Under maintenance, disconnected
  • Water spray system: Inadequate height to reach gas
  • Overfilled tank: Stored well beyond safe capacity
  • No community warning system: Residents had no idea what was happening
  • Management: Safety audits had identified problems; no corrective action taken
  • Legacy: EPA's Emergency Planning and Community Right-to-Know Act (1986). India's Environment Protection Act (1986). OSHA's Process Safety Management standard (1992). The concept of "inherently safer design" -- minimize inventory of hazardous materials. Corporate accountability for overseas operations.
  • 8 / 32
Slide 09

Space Shuttle Challenger (1986)

  • A rubber O-ring, cold weather, and management pressure combined to destroy the shuttle 73 seconds after launch -- killing all 7 crew members.
  • The Failure
  • January 28, 1986: Challenger launched in 2C (36F) weather -- the coldest launch in shuttle history. An O-ring seal in the right Solid Rocket Booster (SRB) failed to seat properly, allowing hot combustion gases to escape (a "blow-by"). The resulting flame impinged on the external tank, causing structural failure and breakup at 14.5 km altitude.
  • Root Causes
  • O-ring resilience: Viton rubber O-rings lost elasticity below 12C -- could not seal the gap in time after ignition pressure
  • Known problem: Engineers at Morton Thiokol had documented O-ring erosion and blow-by on previous cold-weather launches
  • Night-before teleconference: Thiokol engineers unanimously recommended against launch. Managers overruled them under NASA pressure.
  • Normalized deviance: Previous blow-by events were reclassified as "acceptable risk" rather than triggering redesign
  • "For a successful technology, reality must take precedence over public relations, for Nature cannot be fooled."
  • -- Richard Feynman, Appendix F to the Rogers Commission Report
  • 9 / 32
Slide 10

Chernobyl (1986)

  • The world's worst nuclear disaster -- a reactor design flaw combined with operator error and safety culture failure to cause a steam explosion and meltdown.
  • What Happened
  • April 26, 1986: During a safety test at Reactor 4 of the Chernobyl Nuclear Power Plant (Ukraine, then USSR), operators disabled safety systems and operated the reactor in an unstable, low-power state. A sudden power surge caused a steam explosion that blew the 1,000-ton reactor lid off and exposed the core to the atmosphere.
  • 2 immediate deaths (explosion), 29 within months (acute radiation)
  • 350,000 people relocated permanently
  • 2,600 km2 exclusion zone (still in effect)
  • Long-term cancer deaths: disputed (4,000-60,000 estimated)
  • Design and Human Factors
  • Positive void coefficient: RBMK design -- when coolant boils, reactivity INCREASES (opposite of most Western reactors). Inherently unstable at low power.
  • Control rod design flaw: Graphite tips on control rods caused a brief power spike when inserted (the fatal "positive scram" effect)
  • No containment building: Unlike Western reactors, no robust containment dome
  • Safety systems disabled: For the test -- operators shut down automatic shutdown systems
  • Culture of secrecy: Operators not told about the positive void coefficient risk
  • Legacy: IAEA safety conventions, international peer review, safety culture as a defined concept, passive safety systems in all new reactor designs, inherent stability requirements (negative reactivity feedback). No RBMK-type reactor has been built since.
  • 10 / 32
Slide 11

Piper Alpha (1988)

  • The deadliest offshore oil disaster -- 167 dead on a North Sea platform -- transforming offshore safety regulation worldwide.
  • Chain of Events
  • Maintenance error: A condensate pump's pressure safety valve was removed for maintenance. A blind flange was loosely fitted but not adequately communicated to the night shift.
  • Night shift started the pump: Condensate leaked from the unsealed opening and ignited
  • Gas risers: Interconnected pipelines from other platforms fed the fire continuously -- creating 300MW of thermal energy
  • Firewater system: Disabled (set to manual to protect divers working underwater)
  • Structure collapsed: Steel supports failed at 600C+ temperatures in 22 minutes
  • Systemic Failures
  • Permit to Work system: Inadequate communication between shifts -- the critical information didn't transfer
  • Connected platforms: Continued pumping oil/gas to Piper Alpha even as it burned -- operators reluctant to shut down without authorization
  • Emergency response: Platform's evacuation systems pointed toward the fire
  • Survivors: Those who survived largely jumped 53m into the sea rather than following official muster procedures
  • 167 of 226 crew members died. Only 61 survived.
  • Cullen Inquiry: Led to the UK Offshore Installations (Safety Case) Regulations 1992 -- operators must demonstrate safety rather than merely comply with prescriptive rules. Goal-setting regulation. Temporary refuge requirements. Emergency shutdown philosophy. Fire and blast protection standards.
  • 11 / 32
Slide 12

Therac-25 Radiation Overdoses (1985-87)

  • A computer-controlled radiation therapy machine that killed 3 patients and seriously injured 3 others -- the case that launched software safety engineering.
  • What Happened
  • The Therac-25 medical linear accelerator delivered radiation doses up to 100x intended -- massive overdoses of 15,000-25,000 rads (lethal dose: 1,000 rads) in a fraction of a second. Six known overdose incidents between 1985-1987 at clinics in the US and Canada.
  • Patients reported feeling "an electric shock" or "burning"
  • Operators saw "MALFUNCTION" messages but manual said these were common and to retry
  • Machine reported delivering normal dose -- no hardware interlock detected the error
  • Root Causes
  • Race condition: If operator typed corrections fast enough, software entered inconsistent state -- electron beam fired without spreading foil in place
  • Removed hardware interlocks: Previous models (Therac-6/20) had hardware safety interlocks. Therac-25 relied entirely on software -- no independent safety check.
  • Integer overflow: Counter variable rolled over every 255 cycles, creating a window for the fault
  • No independent safety system: Single software controlling both beam and safety
  • Inadequate testing: Race conditions are nearly impossible to find by normal testing
  • Legacy: Foundation of software safety engineering. FDA software validation guidelines. Defense-in-depth for safety-critical systems (hardware interlocks independent of software). IEC 62304 (medical device software lifecycle). Never rely on a single software check for safety.
  • 12 / 32
Slide 13

Space Shuttle Columbia (2003)

  • Foam insulation -- lighter than a sponge -- struck the wing at 900 km/h during launch. Sixteen days later, the shuttle disintegrated on reentry.
  • The Sequence
  • Launch (Jan 16): 82 seconds after liftoff, a briefcase-sized piece of foam insulation broke from the external tank and struck the left wing's leading edge
  • In orbit (16 days): NASA engineers identified the foam strike on launch video. Analysis suggested it might be a concern. Management declined to request imaging of the wing by military satellites.
  • Reentry (Feb 1): Superheated gas (1650C) entered through the breach in the Reinforced Carbon-Carbon (RCC) wing panel, destroying internal structure. Columbia broke apart over Texas. 7 crew members killed.
  • Organizational Causes
  • Normalized deviance (again): Foam shedding had occurred on every shuttle flight -- reclassified from "safety of flight issue" to "maintenance concern"
  • Institutional culture: Engineers' concerns were dismissed up the management chain -- same pattern as Challenger 17 years earlier
  • Schedule pressure: Columbia's flight supported the International Space Station assembly timeline
  • Can-do culture: Burden of proof on those claiming danger, not those claiming safety
  • "NASA's organizational culture had as much to do with this accident as the external tank foam."
  • -- Columbia Accident Investigation Board (CAIB) Report, 2003
  • 13 / 32
Slide 14

Deepwater Horizon (2010)

  • The worst environmental disaster in US history -- 11 workers killed, 4.9 million barrels of oil spilled into the Gulf of Mexico over 87 days.
  • The Blowout
  • April 20, 2010: During temporary abandonment of the Macondo well (5,000m depth), hydrocarbons surged up the wellbore through failed cement and barriers. Gas reached the rig floor and ignited. The Blowout Preventer (BOP) -- the last line of defense -- failed to seal the well.
  • 11 workers killed in the explosion
  • 4.9 million barrels spilled over 87 days
  • BP paid $65+ billion in cleanup and penalties
  • Took 5 attempts and 87 days to cap the well
  • Cascading Failures
  • Cement job: Halliburton's cement barrier at well bottom was inadequate -- failed negative pressure test was misinterpreted as "passing"
  • Negative pressure test: BP well-site leader accepted anomalous results -- "bladder effect" explanation was physically impossible
  • BOP failure: Shear rams could not cut the off-center drill pipe. Dead battery on one control pod. Blind shear rams had insufficient force.
  • Mud gas separator: Overwhelmed -- gas diverted to rig floor instead of overboard
  • Management decisions: Multiple time-saving choices each removed a barrier
  • 14 / 32
Slide 15

Fukushima Daiichi (2011)

  • A beyond-design-basis tsunami overwhelmed nuclear safety systems -- causing three reactor meltdowns and the largest nuclear disaster since Chernobyl.
  • Sequence of Events
  • March 11, 14:46: Magnitude 9.0 earthquake (4th largest ever recorded). All reactors scrammed successfully.
  • 14:47-15:35: Tsunami waves up to 14m overtopped the plant's 5.7m seawall
  • Seawater flooded: Emergency diesel generators, switchgear, and cooling pumps destroyed
  • Station Blackout: No AC or DC power to cool reactors or spent fuel pools
  • Decay heat: Even shut-down reactors generate 1-2% of full power from radioactive decay -- enough to melt fuel in hours without cooling
  • March 12-15: Three reactors melted through their pressure vessels. Hydrogen explosions destroyed reactor buildings.
  • Design and Regulatory Failures
  • Seawall too low: Based on outdated 1960s tsunami modeling. Historical records showed larger tsunamis had occurred (869 AD Jogan tsunami)
  • All backup power at sea level: Diesel generators, batteries, and switchgear in basements vulnerable to flooding
  • No portable backup: No pre-staged mobile equipment for beyond-design-basis events
  • Regulatory capture: Nuclear Industry and Safety Agency (NISA) had close ties to industry -- failed to enforce upgrades
  • Multiple units sharing resources: Common-cause failure affected all 4 operating units simultaneously
  • Legacy: Global nuclear safety stress tests. "FLEX" portable equipment stored above flood level at all US plants. Filtered containment vents. Hardened DC power. Defense against "beyond design basis" events became mandatory -- not optional. Japan shut all 54 reactors for review.
  • 15 / 32
Slide 16

Grenfell Tower Fire (2017)

  • A kitchen fire on the 4th floor of a 24-story London tower block killed 72 people -- spreading rapidly via flammable cladding that should never have been installed.
  • How the Fire Spread
  • Origin: Hotpoint fridge-freezer fire on 4th floor (June 14, 2017, 00:54)
  • Exterior cladding: Fire reached the outside and spread up the building in minutes via ACM (Aluminum Composite Material) rainscreen cladding
  • ACM core: Polyethylene (PE) -- highly flammable. Installed during 2015-16 refurbishment for aesthetics and insulation
  • Cavity: Air gap behind cladding acted as a chimney, accelerating upward flame spread
  • Entire building engulfed within 30 minutes
  • Systemic Failures
  • Cladding selection: PE-core ACM saved 293,000 pounds over fire-resistant alternative -- 5,000 per life lost
  • "Stay put" advice: Residents told to remain in apartments (appropriate for compartmentalized fires) -- not revised as external fire spread
  • Building regulations: Approved Document B requirements were ambiguous -- allowed interpretation that ACM was acceptable
  • No sprinklers: Not required for existing residential buildings (only new builds over 30m)
  • Fire doors: Many had been removed or propped open during refurbishment
  • Legacy: UK banned combustible cladding on buildings over 18m. 480+ buildings identified with dangerous cladding requiring remediation (est. cost: 16+ billion pounds). Building Safety Act 2022 created new regulator. Fundamental reform of building control system.
  • 16 / 32
Slide 17

Boeing 737 MAX Crashes (2018-2019)

  • Two nearly identical crashes killed 346 people -- exposing how automation, certification shortcuts, and production pressure can create catastrophic system failures.
  • The Crashes
  • Lion Air 610 (Oct 29, 2018): Jakarta -- 189 dead. Aircraft dove into the Java Sea 13 minutes after takeoff.
  • Ethiopian Airlines 302 (Mar 10, 2019): Addis Ababa -- 157 dead. Aircraft crashed 6 minutes after takeoff.
  • Both: MCAS system erroneously pushed the nose down based on a single faulty Angle of Attack sensor
  • Pilots fought the system repeatedly -- but MCAS reactivated every 5 seconds
  • MCAS and Design Decisions
  • MCAS: Maneuvering Characteristics Augmentation System -- added to compensate for larger engines' effect on pitch characteristics
  • Single-sensor: MCAS relied on ONE AoA sensor with no redundancy or cross-check
  • Hidden from pilots: Not mentioned in flight manuals or training -- to avoid costly simulator requirement
  • Certification basis: 737 MAX certified as a variant of 1967 design -- avoiding full recertification
  • "Common type rating": Business requirement that 737 NG pilots could fly MAX with just iPad training
  • FAA delegation: Boeing employees certified Boeing's own work
  • Legacy: 20-month global grounding (longest in commercial aviation history). MCAS redesigned to use two sensors and limit authority. Congressional hearings exposed cozy FAA-Boeing relationship. Aircraft Certification Reform Act (2020). Cultural reckoning at Boeing on safety vs. financial pressure.
  • 17 / 32
Slide 18

Morandi Bridge Collapse (2018)

  • A cable-stayed viaduct in Genoa, Italy collapsed without warning during a rainstorm -- killing 43 people and severing the city's main traffic artery.
  • The Collapse
  • August 14, 2018: A 200-meter section of the Polcevera Viaduct (Morandi Bridge) collapsed during a thunderstorm. Tower 9, along with its stay cables and 200m of roadway, fell 45m onto railway tracks, a river, and industrial buildings below. 43 people in vehicles on the bridge were killed.
  • Technical Factors
  • Unconventional design (1967): Riccardo Morandi used only two pairs of stay cables per tower (vs. typical 30-60 in modern cable-stayed bridges)
  • Concrete-encased cables: Steel strands embedded in prestressed concrete -- impossible to visually inspect for corrosion
  • Known deterioration: Previous repairs in 1990s found severe corrosion of stay wires. One tower's cables were replaced in 1993.
  • Inspection limitations: The encased design made NDT extremely difficult -- hidden corrosion progressed unseen
  • Overloading: Traffic volumes far exceeded 1967 design assumptions
  • Legacy: Replacement bridge (Renzo Piano design) built in record 2 years using steel. Italy mandated reassessment of all similar-era infrastructure. Highlighted the global problem of aging infrastructure and hidden deterioration. Reinforced the critical importance of inspectability in design.
  • 18 / 32
Slide 19

Texas City Refinery Explosion (2005)

  • BP's Texas City refinery explosion killed 15 workers and injured 180 -- revealing how cost-cutting and normalization of deviance can erode process safety over decades.
  • What Happened
  • March 23, 2005: During startup of the isomerization unit, a distillation tower (raffinate splitter) was overfilled with flammable hydrocarbons. Liquid overflowed through a blowdown drum and stack (not designed to handle liquid), raining hydrocarbons around the unit. An idling diesel pickup truck ignited the vapor cloud.
  • 15 killed (all in temporary trailers too close to the unit)
  • 180 injured
  • Largest refinery explosion in the US in decades
  • Root Causes
  • Level instruments: Failed -- operators didn't know the tower was overfilling
  • Blowdown system: Atmospheric blowdown stack (1950s design) -- modern refineries use closed systems
  • Trailer placement: Temporary buildings placed within blast zone during construction project -- violated BP's own guidelines
  • Budget cuts: BP had cut maintenance spending 25% over 5 years despite known equipment problems
  • Safety culture: Focus on personal safety metrics (slip/trip/fall) masked deteriorating process safety
  • Baker Panel (2007): Found BP's corporate culture prioritized cost-cutting over safety investments across all US refineries
  • 19 / 32
Slide 20

Sampoong Department Store (1995)

  • The deadliest structural building collapse in modern history (excluding terrorism) -- 502 dead in Seoul, South Korea, due to systematic construction fraud and negligence.
  • What Happened
  • June 29, 1995: The five-story department store collapsed progressively in 20 seconds, pancaking into the basement. Cracks had been visible for days; management kept the store open to avoid losing revenue.
  • 502 dead, 937 injured
  • 6 people rescued alive after up to 17 days trapped
  • Warning signs visible for hours/days before collapse
  • Building management refused to evacuate
  • Engineering Failures
  • Original design: Was for a 4-story office building -- converted to department store (heavier loads) during construction
  • 5th floor added illegally: After initial permits, with reduced column sizes
  • Column slab connections: Flat plate without adequate shear reinforcement -- punching shear failure
  • Air conditioning units: Moved across roof, damaging already-overstressed slabs
  • Corruption: Building inspectors bribed to overlook code violations
  • Cracks visible for months: Gas lines snapping, ceiling cracking -- store remained open
  • Legacy: Complete overhaul of South Korean building inspection laws. Korea Infrastructure Safety Corporation established. President Kim Young-sam used the disaster to fight corruption -- "modernization without sacrificing safety." Influenced building codes across Asia.
  • 20 / 32
Slide 21

Rana Plaza Collapse (2013)

  • An 8-story garment factory building in Bangladesh collapsed, killing 1,134 workers -- the deadliest garment industry disaster and a global reckoning with supply chain responsibility.
  • What Happened
  • April 24, 2013: Rana Plaza in Savar, Dhaka collapsed at 8:45 AM -- shortly after thousands of workers entered for the day shift. Cracks had been discovered the previous day; an engineer warned the building was unsafe. The owner ordered workers back inside.
  • 1,134 dead, 2,500+ injured
  • 5 garment factories inside (producing for Primark, Walmart, Benetton, others)
  • Most victims were young women earning $38/month
  • Structural Failures
  • Built on filled-in pond: Poor bearing capacity soil
  • Illegal upper floors: Originally permitted for 5 stories; grew to 8 without approval
  • Heavy machinery: Vibrating garment sewing machines and generators on upper floors -- not designed for dynamic loads
  • Substandard materials: Low-strength concrete, inadequate reinforcement
  • No building inspection: Effectively no enforcement of building codes in Dhaka's garment district
  • Legacy: Bangladesh Accord on Fire and Building Safety (2013) -- binding agreement between 200+ brands and unions to inspect all 1,600+ garment factories. Over 100,000 safety issues remediated by 2018. Global supply chain transparency movement. Proved that brands bear responsibility for factory conditions.
  • 21 / 32
Slide 22

Banqiao Dam Failure (1975)

  • The deadliest structural failure in human history -- a cascade of 62 dam failures killed an estimated 85,600-240,000 people in China's Henan Province.
  • What Happened
  • August 8, 1975: Super Typhoon Nina stalled over Henan, dumping a year's worth of rain in 24 hours (1,060mm -- world record at the time). The Banqiao reservoir (492 million m3) filled far beyond capacity. When the dam overtopped, it collapsed -- releasing a wall of water 10 km wide and 3-7m high traveling at 50 km/h.
  • 62 dams failed in cascade
  • 11 million people affected; 5.96 million buildings destroyed
  • China classified the disaster as a state secret until 2005
  • Causes and Context
  • Design rainfall underestimated: Designed for 300mm/day; received 1,060mm
  • Sluice gates blocked: Sedimentation had reduced discharge capacity by 40%
  • Communication failure: Downstream warnings not delivered due to destroyed telephone lines
  • Construction era: Built in 1951 during the Great Leap Forward with Soviet assistance -- quality concerns raised by hydrologist Chen Xing (who was silenced as a "rightist")
  • Legacy: China massively upgraded dam safety programs. Probable Maximum Precipitation (PMP) standards adopted. Dam safety monitoring made mandatory. Spillway capacity requirements increased globally.
  • 22 / 32
Slide 23

Tay Bridge Disaster (1879)

  • When the world's longest bridge collapsed in a storm, it killed 75 people and shook confidence in Victorian engineering -- leading to profound changes in structural design practice.
  • The Disaster
  • December 28, 1879: During a violent storm (estimated 80+ mph winds), the central "high girders" section of the Tay Bridge collapsed as a passenger train crossed. The train fell 27m into the Firth of Tay. All 75 passengers and crew were killed.
  • Engineering Failures
  • Wind loading: Designer Thomas Bouch claimed he designed for 10 lb/ft2 wind pressure -- Court of Inquiry found no evidence it was actually incorporated
  • Cast iron quality: Columns had hidden blow holes (casting defects) filled with a putty called "Beaumont Egg"
  • Lugs and bolts: Cross-bracing attached by lugs cast integrally with columns -- brittle connections
  • Inadequate bracing: Lateral bracing insufficient for wind-induced rocking
  • Construction quality: Workers had been dismissed for reporting defective castings
  • Direct legacy: The Forth Bridge (1890) was deliberately over-engineered to restore confidence -- using 10x the material needed, with every rivet visible for inspection.
  • 23 / 32
Slide 24

Common Themes Across Disasters

  • Despite spanning 150 years and every engineering discipline, the same patterns emerge repeatedly.
  • Organizational Patterns
  • Normalized deviance: Small deviations from safety become accepted as "normal" until catastrophe (Challenger, Columbia, Texas City)
  • Schedule/cost pressure: Management overrides engineering judgment for commercial reasons (Challenger, 737 MAX, Deepwater Horizon)
  • Siloed communication: Critical information doesn't reach decision-makers (Piper Alpha, Hyatt Regency)
  • Regulatory capture: Regulators too close to industry to enforce safety (737 MAX, Fukushima, Chernobyl)
  • Ignored warnings: Engineers raise alarms that are dismissed by management (Challenger, Vajont, Grenfell)
  • Technical Patterns
  • Single point of failure: No redundancy in critical systems (737 MAX single AoA sensor, Therac-25)
  • Unknown unknowns becoming known: Phenomena not understood at design time (Tacoma Narrows flutter, Comet fatigue)
  • Hidden degradation: Corrosion, fatigue, and wear invisible to inspection (Morandi Bridge, Silver Bridge)
  • Cascade failures: One failure triggers others in unexpected chains (Piper Alpha, Fukushima, Banqiao)
  • Design basis exceeded: Events beyond what was designed for (Fukushima tsunami, Banqiao rainfall)
  • 24 / 32
Slide 25

The Ethics of Engineering

  • Engineering disasters raise profound ethical questions about responsibility, risk, and the obligation to protect public safety.
  • The Engineer's Obligation
  • NSPE Code of Ethics (US): "Engineers shall hold paramount the safety, health and welfare of the public"
  • The Iron Ring (Canada): Engineering graduates receive a ring (inspired by the Quebec Bridge disaster) as a reminder of professional responsibility
  • Whistleblower protection: Engineers who raise safety concerns must be protected from retaliation
  • Roger Boisjoly: Morton Thiokol engineer who tried to stop Challenger launch -- shunned by employer, honored later
  • Ethical Dilemmas
  • How safe is safe enough? Zero risk is impossible -- what probability of failure is acceptable?
  • Cost vs. safety: Every dollar spent on safety has diminishing returns -- where to stop?
  • Known risks vs. unknowns: How much margin for things we haven't thought of?
  • Individual vs. corporate: When management overrules engineers, who bears responsibility?
  • Duty to report: Professional obligation to disclose dangers -- even at personal cost
  • "The public cannot be expected to know what risks are acceptable. That is why engineers have professional obligations -- and why those obligations must sometimes override commercial interests."
  • -- Henry Petroski, "Design Paradigms" (1994)
  • 25 / 32
Slide 26

Safety Engineering Frameworks

  • Modern safety engineering uses systematic frameworks to identify, analyze, and mitigate risks before disasters occur.
  • Key Methods
  • HAZOP: Hazard and Operability Study -- systematically examines deviations from design intent (high/low/no flow, temperature, pressure)
  • FMEA: Failure Mode and Effects Analysis -- catalog every possible failure, rate severity, occurrence, detection
  • Fault Tree Analysis: Top-down logic tree from undesired event to root causes (AND/OR gates)
  • Event Tree Analysis: Forward analysis from initiating event through barrier success/failure
  • Bow-Tie Method: Combines fault tree (left) and event tree (right) around a central hazard
  • Defense in Depth
  • Inherent safety: Eliminate hazard entirely (substitute, minimize, moderate)
  • Prevention: Control systems, interlocks, procedures
  • Detection: Alarms, monitoring, inspection
  • Mitigation: Relief valves, containment, fire suppression
  • Emergency response: Evacuation, rescue, damage control
  • No single layer is relied upon -- each must be independent, so a common-cause failure cannot defeat multiple barriers simultaneously.
  • 26 / 32
Slide 27

Forensic Engineering

  • The discipline of investigating failures after they occur -- combining detective work, materials science, and structural analysis to determine root causes.
  • Investigation Methods
  • Fractography: Microscopic examination of fracture surfaces reveals whether failure was fatigue, brittle fracture, overload, or corrosion-assisted
  • Metallography: Cross-sectioning and polishing to examine grain structure, heat treatment, inclusions
  • Chemical analysis: Verify material composition matches specifications
  • Finite Element Analysis: Reconstruct stress state at time of failure
  • Witness interviews: Sequence of events, sounds, visual observations
  • Document review: Design calculations, inspection records, maintenance logs
  • Telltale Signs
  • Beach marks: Concentric rings on fracture surface = fatigue crack growth
  • Chevron patterns: Point toward crack origin in brittle fracture
  • Cup-and-cone: Ductile overload failure (necking before break)
  • Intergranular fracture: Grain boundary attack -- often hydrogen embrittlement or SCC
  • Rust staining: Pre-existing crack exposed to environment before final failure
  • Deformation patterns: Direction and sequence of collapse events
  • 27 / 32
Slide 28

How Codes and Standards Evolve

  • Building codes, design standards, and safety regulations are "written in blood" -- each requirement typically traces back to a specific disaster.
  • Disaster-to-Code Examples
  • DisasterResulting Standard
  • Titanic (1912)SOLAS Convention
  • Triangle Shirtwaist (1911)NYC fire codes, OSHA
  • Tacoma Narrows (1940)Wind tunnel testing requirements
  • Comet crashes (1954)Fatigue testing certification
  • Ronan Point (1968)Progressive collapse resistance
  • Silver Bridge (1967)National Bridge Inspection Standards
  • Bhopal (1984)OSHA PSM, EPA RMP
  • Challenger (1986)NASA safety culture reform
  • The Code Development Cycle
  • Disaster occurs: Lives lost, public attention
  • Investigation: Root cause analysis (months to years)
  • Research: Fill knowledge gaps identified
  • Committee deliberation: Standards bodies draft new requirements
  • Code update: Published, typically 2-5 years after disaster
  • Adoption and enforcement: Local jurisdictions adopt into law
  • Compliance: Industry implements changes
  • The cycle averages 5-10 years from disaster to widespread code change -- too slow for some critics.
  • 28 / 32
Slide 29

Modern Risk Assessment

  • How contemporary engineering quantifies and manages risk -- accepting that zero risk is impossible, but informed decisions about acceptable risk are essential.
  • Risk Matrix
  • NegligibleMinorMajorCatastrophic
  • FrequentLowMedHighExtreme
  • ProbableLowMedHighHigh
  • RemoteLowLowMedHigh
  • ImprobableLowLowLowMed
  • Quantitative Risk Assessment
  • Individual risk: Annual probability of death from a hazard (typically acceptable: 10^-4 to 10^-6)
  • Societal risk: F-N curves plotting frequency vs. number of fatalities
  • ALARP: As Low As Reasonably Practicable (UK approach) -- reduce risk until cost of further reduction grossly disproportionate to benefit
  • SIL (Safety Integrity Level): 1-4 classification of safety system reliability (SIL 4: failure probability Target reliability: Structural codes target 10^-4 to 10^-7 annual failure probability depending on consequence class
  • 29 / 32
Slide 30

Emerging Failure Modes

  • New technologies bring new failure modes -- challenges the engineering profession is grappling with right now.
  • AI and Autonomy
  • Self-driving car accidents, AI decision-making in critical systems, algorithmic bias in safety-critical applications. Who is responsible when an algorithm fails? How do you test systems that learn?
  • Cybersecurity
  • Stuxnet attacked centrifuges. Colonial Pipeline shutdown. Hospital systems held hostage. As all infrastructure becomes networked, cyberattack becomes a new failure mode for physical systems.
  • Climate Change
  • Infrastructure designed for historical climate now faces beyond-design-basis events: unprecedented floods, heat waves (road/rail buckling), wildfires, sea level rise. The design basis itself is moving.
  • Aging Infrastructure
  • 600,000+ US bridges, 90,000+ dams, millions of km of pipes -- much designed for 50-year life and now reaching 75-100 years. FIU pedestrian bridge (2018), Surfside condo (2021), East Palestine derailment (2023) all involved aging systems.
  • Complex Systems
  • Modern systems (aircraft, nuclear plants, autonomous vehicles) have so many interacting components that emergent failures become unpredictable. Charles Perrow's "Normal Accidents" thesis: in sufficiently complex, tightly-coupled systems, catastrophic accidents are inevitable.
  • 30 / 32
Slide 31

Building a Safety Culture

  • The most effective safety improvement comes not from technology but from culture -- how organizations think about and prioritize safety.
  • High-Reliability Organizations (HROs)
  • Preoccupation with failure: Near-misses investigated as seriously as accidents
  • Reluctance to simplify: Resist easy explanations; probe deeper
  • Sensitivity to operations: Management stays connected to front-line reality
  • Commitment to resilience: Assume surprises will happen; develop capacity to cope
  • Deference to expertise: In a crisis, authority migrates to whoever has the most knowledge -- regardless of rank
  • Examples: Nuclear aircraft carriers, air traffic control, nuclear submarines -- organizations that operate in high-hazard environments with remarkably low accident rates.
  • Practical Measures
  • Just culture: Distinguish between honest errors (learning opportunity) and willful violations (discipline)
  • Reporting systems: Non-punitive near-miss reporting (aviation's ASRS catches 80,000+ reports/year)
  • Stop-work authority: Any worker can halt operations for safety -- without fear of reprisal
  • Pre-job briefings: Discuss risks before every task begins
  • Management walk-arounds: Leaders visibly prioritize safety by presence on the floor
  • Incident learning: Share lessons across the organization and industry
  • 31 / 32
Slide 32

Key Takeaways

  • Recurring Lessons
  • Disasters are never single-cause -- always multiple simultaneous failures
  • Management culture and organizational pressure kill as surely as bad materials
  • Warnings exist before nearly every disaster -- the challenge is hearing them
  • Codes and standards lag behind knowledge -- they codify past failures, not future ones
  • Redundancy and defense-in-depth are the engineer's best weapons against the unknown
  • The Engineer's Responsibility
  • Public safety is the paramount obligation -- above profit, schedule, or convenience
  • Speak up when safety is compromised -- whistleblowing is an ethical duty
  • Design for failure -- assume components will fail and ensure the system survives
  • Stay humble -- every structure is an hypothesis about how forces will flow
  • Learn from others' failures -- the lessons are freely available to those who study them
  • "To engineers, the lessons of failure are more important than the successes. Success teaches us little; failure teaches us everything."
  • -- Henry Petroski, "To Engineer Is Human" (1985)
  • 32 / 32
Remove this deck