Daily Ex - 13 September 2026

Three items, one question: has something changed that affects a barrier the plant depends on? New EU cyber reporting duties pull firmware and vulnerability handling into the Ex lifecycle wherever digitally connected protective functions are involved. An Ohio resin plant shows how a stopped agitator, continued solvent addition and an altered manway assembled a fatal explosion in a low-pressure vessel. And a product change in an existing inerted tank illustrates the case where nothing physical changes while the demonstrated safe operating envelope does. If the new basis cannot be demonstrated, STOP is also an operational decision.

An operations engineer looks at an inerted, Ex-marked tank labelled T-101 while weighing a product change, with sample bottles of the current and new product, a change assessment checklist, reference binders and a laptop showing the inerting system, framed by a panel of key questions on explosion characteristics, oxygen limits and procedure validity.

What changed + what happened + one Operational Ex decision

1. What changed - cybersecurity can now become an Ex lifecycle issue

From 11 September 2026, the EU Cyber Resilience Act reporting obligations are in force. Manufacturers must report actively exploited vulnerabilities and severe security incidents affecting products with digital elements, with an early warning generally within 24 hours and a fuller notification within 72 hours.

This is not an ATEX amendment. But it matters increasingly for equipment associated with hazardous areas: gas detection, ventilation control, inerting systems, remote I/O, interlocks and other digitally connected protective functions.

Operational Ex comment:

A firmware or cybersecurity update should not automatically be treated as “IT work”.

If it can affect an Ex-related barrier: vulnerability/update → identify affected safety function → MoC → test → verify → document → return to service

For the Head of Operations: “Do we know which digitally connected systems are actually part of our Ex-safe condition?”


2. What happened - low pressure did not mean low consequence

At the Yenkin-Majestic resin plant in Ohio, flammable solvent was added to a process kettle while its agitator was unexpectedly not operating. When the agitator was later started, rapid vaporisation pressurised the kettle. A mixture of resin and flammable naphtha vapour escaped through the closed manway, formed a vapour cloud and ignited.

One worker died and eight were injured. The CSB found that the low-pressure kettle and its altered manway had not been designed and tested appropriately for the hazardous service.

Operational Ex comment:

“Low pressure” and “simple vessel” can create dangerous assumptions.

agitator running → process behaves as expected

agitator stopped → process condition changes

solvent addition continues → hazard develops

containment inadequate → release

release + ignition source → explosion

For Operations: “Which process safeguards are assumed to be available, but are not actually interlocked with the operation they protect?”


3. Today’s Operational Ex use case - “We are changing the product in the same tank.”

Yesterday we looked at optimizing nitrogen consumption.

Today: product change.

Operations wants to use a different product in an existing inerted vessel.

The tank is the same.

The nitrogen system is the same.

The procedure already exists.

So the tempting answer is: “Nothing physical changed - continue.”

But the new material may have different explosion characteristics and a different allowable oxygen concentration. The existing target oxygen level and purge-cycle requirement therefore cannot automatically be carried over.

The Head of Operations decision should follow: “new material → obtain relevant explosion data → determine allowable oxygen condition → reassess inerting → compare old/new state → authorize change → update procedure → verify before production”

If the necessary material data are missing: That might be a MoC issue.

Operational Ex comment:

Sometimes the equipment does not change at all - but the demonstrated safe operating envelope does.


🔆NOTE🔆: here we have introduced an Ex Flashcard toolkit to support all these decisions coming from Head of Operations - happy to introduce

What Operations should take away today: cybersecurity → vessel explosion → product change

Has something changed that affects a barrier we depend on?

The Head of Operations does not need to personally calculate every detail.

But someone(!) must be able to answer: What changed? → Which barrier is affected? → Is our previous Ex basis still valid? → Who verified it? → Can we authorize operation?


And if that cannot be demonstrated: STOP is also an operational decision.