Restoring customer supply is not the same event as restoring a process plant. Sarnia’s 2003 outages show why power-system resilience has to be carried through safe shutdown, utilities, environmental controls, and staged restart.
The Grid Event Was Only the First Failure State
At 4:11 p.m. on Aug. 14, 2003, the Northeast blackout began to pull large portions of Ontario and the northeastern U.S. off the grid. Roughly 61,800 MW of customer load was interrupted across the event. Ontario’s power system was restored within about 30 hours, but the provincial state of emergency remained in effect until Aug. 22 while generation returned to full capability.
That timeline is useful for grid history. It is not enough for industrial resilience. A refinery, cracker, or chemical plant does not move directly from “energized” to “normal production.” The process first has to reach a safe state, preserve or restore utilities, confirm controls and environmental systems, inspect equipment, re-establish inventories and flows, and then restart in an order the process can tolerate. The grid can be back while the plant is still very far from back.
Sarnia-Lambton had already demonstrated that distinction twice before the continental blackout. On April 14, 2003, a major local power failure affected the petrochemical complex and triggered emergency conditions. On June 9, another power failure forced shutdowns at Imperial Oil, Dow, Bayer, and NOVA. Ontario Hansard records that the electrical outage was restored within about 20 minutes, yet the plants took hours to return to operation. Two months before Aug. 14, the region had already supplied the lesson in miniature: outage duration and recovery duration are different variables.
A 20-Minute Outage Can Become a Multi-Hour Process Event
For power-system planners, interruption duration is a central measure. For plant operators, interruption duration is only one input. A short loss of off-site power can trip rotating equipment, interrupt cooling or instrument air, change flare load, stop wastewater treatment, break process sequencing, or leave equipment in a state that has to be inspected before it is re-energized. Backup power can protect critical loads without preserving full production. A generator that keeps a control room alive does not necessarily keep every pump, compressor, scrubber, or treatment train in its normal state.
That difference explains why the August blackout produced an industrial event larger than the dark interval itself. A contemporaneous economic-impact record filed with the Ontario Energy Board described more than 30 chemical, petrochemical, and refining facilities in Sarnia’s Chemical Valley and reported that all experienced some form of outage, with flaring at most facilities. NOVA Chemicals later estimated that the blackout-related production interruption reduced third-quarter earnings by roughly $10 million and cost about 150 million pounds of ethylene and co-products, polyethylene, styrene, and expandable polystyrene production before its affected facilities returned to normal.
The operational point is not the exact dollar loss. It is that restarting a coupled industrial system has a path. If one utility, control system, feedstock condition, environmental safeguard, or downstream unit is unavailable, electrical restoration may only reveal the next constraint.
Royal Polymers Shows Where the Boundary Can Fail
The clearest Sarnia example sits at the boundary between process recovery and environmental control. Ontario’s Ministry of the Environment later charged Royal Polymers over an August 2003 vinyl chloride monomer discharge. The ministry said the Aug. 14 blackout shut down equipment at the PVC facility and ultimately contributed to water containing vinyl chloride monomer entering a drainage system leading toward the St. Clair River. The company did not notify the ministry until Aug. 19.
The later prosecution record adds a more precise operational detail: after the outage, plant personnel failed to restart the cooling-water system in accordance with the facility’s approval, and unmonitored cooling water was discharged to the cut-off drain. The case should not be generalized into a claim that every blackout causes a spill. It demonstrates something narrower and more useful: an environmental safeguard can depend on the restart state of equipment that is not visible from the grid control room.
That is why industrial resilience cannot stop at “critical load on backup.” A site needs to know which environmental and safety barriers remain valid in every transition state: loss of grid, emergency power, partial utility restoration, electrical return, process restart, and return to normal operations.
A Restart-Readiness Map
A useful plant-side resilience model treats restoration as a sequence of verified states rather than one timestamp. The exact systems vary by facility, but the control logic can be made explicit.

Transmission Reinforcement Is Necessary, Not Sufficient
The present-day relevance is not that the 2003 event is about to repeat in the same form. Southwestern Ontario’s grid is changing. Hydro One is now constructing the St. Clair Transmission Line, a roughly 64-kilometer double-circuit 230-kV connection from Lambton Transformer Station through Wallaceburg to Chatham Switching Station, with associated station work and an expected 2028 completion. The Ontario Energy Board approved the project in 2024, and construction began in 2025.
It is important to describe that project accurately. Its primary planning case is bulk-system reinforcement for rapid load growth farther south and east, including Windsor-Essex and Chatham-Kent, while also improving the deliverability of resources in the Lambton-Sarnia area. It is not a dedicated Sarnia petrochemical-reliability project. That distinction actually strengthens the lesson. Transmission investment can improve the external system while a plant’s internal restart dependencies remain a separate engineering problem.
The IESO’s current planning approach increasingly preserves flexibility as demand materializes. Industrial facilities can use the same principle behind the meter: identify the dependencies that have to survive a disturbance, identify the ones that can be restored in stages, and design the transition states instead of treating “power available” as the final condition.
Measure Recovery, Not Only Outage
A resilience dashboard for a continuous-process site should therefore include more than outage frequency and duration. It should measure time to safe state, time to stable utilities, time to verified environmental-control availability, time to first restart authorization, time to stable production, and time to full normal operation. It should record which dependency controlled each interval.
That turns a blackout from an anecdote into an engineering dataset. If cooling-water restart repeatedly controls recovery, that becomes a capital or procedure question. If wastewater treatment, instrument air, feedstock logistics, or inspection capacity governs the delay, the resilience program can target the actual bottleneck instead of buying more backup generation and hoping the rest of the process follows.
Sarnia’s 2003 record is valuable because it refuses an easy ending. The lights returning did not finish the event. In June, a 20-minute outage took hours to unwind. In August, the provincial grid recovered faster than many industrial processes, and one facility’s post-blackout equipment state contributed to an environmental violation. The practical lesson is not that every plant needs to become an islanded power system. It is that every plant should know, in advance, what “recovered” means at each layer of the operation.
Restoration Is a Chain of Permissions
The power system can say yes before the process can say yes. The process can say yes before the environmental controls can say yes. A sound restart architecture makes those permissions explicit and refuses to collapse them into one green light.
That is the blackout behind the blackout: not darkness, but the long sequence of interdependent states after electricity returns. Grid reliability remains foundational. Plant resilience begins where the grid’s restoration timestamp ends.
—Joshua W.J. Brown is a Toronto-based writer, filmmaker, and independent systems researcher raised in Sarnia-Lambton, Ontario. His work examines infrastructure, industrial memory, public systems, and how failure states become operational design problems.