Skip to content
STOIntelligence
All insights

Lightning was the ignition source, not the cause

Tom MankowskiFounder & PrincipalJuly 11, 20265 min read

Early in my career, at my first industry employer, I watched a lightning strike set a refinery storage tank on fire. It was a summer afternoon with a thunderstorm moving through, and the bolt found the roof of a fixed-roof tank holding a flammable product. The vapor space inside ignited, the roof lifted off exactly as it was engineered to, and, remarkably, no one was hurt. Then I was asked to lead the investigation, and that assignment shaped how I think about cause more than any classroom has.

The ignition source is rarely the cause

Lightning was the obvious answer, and it was the wrong one. You cannot manage the weather. What you can manage is everything that turned a predictable summer storm into a fire, and a real investigation refuses to stop at the spark. The discipline that matters is separating three different kinds of cause: physical, human, and latent. The ignition source lives at the surface. The reasons it was able to do damage live underneath.

Physical, human, latent

Peeling the event apart, three layers came into view.

  • Physical. A fitting on top of the tank that was designed to be spark-proof had quietly lost the small component that made it so. When the strike hit, it found bare metal-to-metal contact and threw sparks into a flammable vapor space.
  • Human. Years earlier, the tank had been put into a service that placed a flammable product into a vapor space sitting inside its explosive range for much of the year. The change was reasonable on its own terms, but no process ever asked whether it had quietly raised the risk.
  • Latent. The routine monthly inspection had marked that fitting satisfactory for years. Not because anyone was careless, but because the deficiency had been there so long it had become the definition of normal. That is normalization of deviance, and it is the layer that matters most.

The most dangerous hazard is the one you have stopped seeing

This is the pattern I have seen in almost every serious event since, and it rarely looks dramatic in advance. It is not the exotic failure mode. It is the small wrong thing that everyone has walked past so many times that it has stopped registering as wrong. A checkbox marked satisfactory. A workaround that became the procedure. A number that has always looked like that. The hazard is not only that people miss it. The hazard is that they no longer see it.

Make the lesson outlive the event

A good investigation is worthless if it dies in a binder. The value is not the report. It is whether the finding actually changes the system: the inspection rewritten to say exactly what to look for, the risk review run across every similar asset, the standard given a new question so the next person cannot make the same quiet mistake. One well-investigated event can measurably lower risk across an entire organization, but only if someone insists the lesson travels.

That is the same discipline that belongs at the back end of a major event. A closeout is not paperwork. Done honestly, it separates what happened from why it happened, captures the lessons in a form the next team can actually use, and feeds them into how the next event is planned. It is the quiet, unglamorous work that turns a bad day into a permanent improvement.

It is also why the assurance arc does not end at startup. Readiness on the front end and closeout assurance and structured lessons-learned capture on the back end are two halves of one idea: surface what was knowable while it can still change the outcome. Lightning was the ignition source. The cause was everything we had stopped seeing. The work, every time, is to see it before the next strike finds it.

Want a defensible read on your next event?

Start a conversation