Engine-room explainer
Why do ships black out?
The full answer, written by an engineer rather than assembled from press summaries. What a blackout is, what causes it, why protection removes healthy machines, what the record shows before it happens, and what actually prevents it.
What is a blackout on a ship?
A blackout is the loss of the main switchboard: every consumer fed from it stops at once. Unlike a shore power cut, it removes several unrelated capabilities in the same instant — steering gear, main engine auxiliaries, deck machinery, lighting and often the very services the emergency plan assumed would still be there.
SOLAS Chapter II-1 treats this as a survivability question, not a convenience one, which is why an emergency source of power and a dead-ship recovery capability are mandatory rather than optional.
What actually causes most blackouts?
Very rarely a single dramatic failure. The usual shape is a small defect on one machine, followed by a protection system doing exactly what it was designed to do, followed by the remaining machines being unable to absorb the resulting load step.
The common first defects: loss of excitation control (a failed or drifting automatic voltage regulator), a governor or fuel-rack problem causing a machine to shed or hog load, a blocked fuel or lube filter starving an engine, an earth fault on a distribution feeder, or a large consumer starting into a plant with insufficient spinning reserve.
The common second step: reverse power (ANSI 32), loss of field / under-excitation (ANSI 40), over-current or under-voltage protection isolating the affected machine. Protection is not the fault. Protection is the symptom telling you what the fault was.
Why does one generator tripping take the whole board?
Because the load does not disappear when the machine does. When a set is removed, its share transfers instantly to the machines still on the bus. If that step exceeds what they can absorb inside their governor and excitation response, frequency and voltage dip, under-frequency or under-voltage protection operates on the remaining sets, and the board is lost.
Preferential trip (load-shedding) exists precisely to break this chain by dropping non-essential consumers first. When a blackout happens anyway, one of three things is usually true: the shedding did not operate, it operated too slowly for the size of the step, or the plant was running with too little spinning reserve for the condition it was in.
Why are blackouts more common at arrival, departure and manoeuvring?
Because that is when the electrical plant is at its most loaded and its most dynamic: thrusters, steering, mooring machinery and pumps cycling, with large motors starting into a bus already carrying a high load. It is also when more machines are in parallel, which means more sharing controls interacting at once.
It is simultaneously the point of least sea room and least tolerance for a loss of propulsion or steering, which is why a manoeuvring blackout is treated as a serious casualty even when the plant is recovered in minutes.
What warns you beforehand? What is in the record?
Almost always something, and almost always something quiet. In practice the recurring leading indicators are: an alarm that appears and self-clears (an excitation or voltage alarm above all), one machine consistently slower to pick up load than its sisters, a widening spread in reactive load sharing between machines in parallel, filter differential pressure trending up between changes, and insulation resistance drifting down on a feeder.
None of these stop a ship, so none of them get escalated. They are visible only to someone reading the machine against its own history rather than against an alarm threshold — which is the whole argument for condition trending over threshold alarms.
Does the emergency generator solve the problem?
It limits the consequences; it does not prevent the event. And its weekly test is one of the most reliably misread records at sea: a test that proves the machine starts is not a test that proves it supplies the emergency switchboard under load.
If the recorded test method never includes taking load, the ship has evidence of starting, not evidence of supply. That distinction is findable in a records review in minutes, and is very rarely looked for until after an event.
What does a blackout cost, and why is it so much more at sea?
The engineering content is often small. The cost is in what the sea adds: a spare that must reach a specific hull in a specific port, a specialist who needs a flight, a visa and a gate pass, a class surveyor's availability that behaves like a queue, and reporting obligations to flag, class and the port state that each run on their own clock.
That is why the same defect is a shift's work ashore and can be weeks afloat. The delay after a casualty is very often an evidence-assembly delay wearing an engineering costume.
How are blackouts actually prevented?
Four things, in order of how much they return. Keep genuine spinning reserve for the condition the ship is in, not the condition the plan assumed. Trend the machines against their own history so excitation, sharing and filter drift are seen while they are still cheap. Prove protection and load-shedding settings by test, including the emergency source under load. And treat crew attention as finite — do not stack attention-heavy work onto arrival, a survey week or the first days after a relief.
The first three are engineering. The fourth is the one most plans get wrong, and it is the cheapest to fix.
Read it in the record yourself
Can you read a blackout?
Five alarm-log snapshots. Call the cause before you open the answer.
The Casualty Files
Published investigations, read the same way — sources cited on every case.
One fault, three weeks
Why the same repair is a day ashore and a casualty at sea.
Catching the drift
How the quiet leading indicators above are trended from records a ship already keeps.