This figure illustrates the secondary risks due to automation.

The original design

In the original design, the operator controlled the boiler temperature, using an On-Off switch, based on LED indication of the boiler temperature.

This design appeared to be error prone, because the operators might not always have the required mental resources to handle situations of overheating. It also fault-prone, as the operators might not be aware of burnt LED and of malfunction of the On-Off switch.

Resilience add-ons

The improved design is by adding safety add-ons:

Secondary risks

The secondary risks are due to the resilience add-ons:

Updated on 21 Jul 2016.