SPECIAL SECTION | Valves & Actuators
Designing for Failure
The value of fail-safe electrohydraulic actuation in critical water and wastewater infrastructure.
Gregory Asselta | Trident Actuators
| IMAGE 1: Fail-in-place electrohydraulic actuators installed on stainless steel slide gates at a wastewater treatment facility in New York City. (Images courtesy of Trident Actuators)
Reframing the Role of Actuation
Historically, water infrastructure relied on stable weather patterns as a reliable design baseline. Today that approach is outdated. Utility owners are evaluating their systems with the understanding that they must withstand severe hydraulic loading, prolonged power outages and extreme flood events. This new reality demands a shift in mindset: designing for failure.
True resilience is not just about how a system performed on a good day; it is measured by how it handles a crisis. During outages, floods or equipment malfunctions, actuator reliability can determine whether a facility maintains control or suffers a cascading failure. For critical valves and gates, failure is not merely an operational inconvenience; it poses significant risks to equipment, the environment, regulatory compliance and public safety. As a result, engineers are increasingly prioritizing emergency-scenario performance alongside normal operation.
This article examines the role of fail-safe electrohydraulic actuation in resilient design, including common failure scenarios, fail-safe philosophies, environmental robustness, redundancy and the management of hydraulic transients during emergencies.
Defining Critical Applications
In some applications, temporary loss of operation is inconvenient but manageable. For many of these, standard pneumatic or electromechanical actuators—which rely on external supplies of clean, compressed air or steady, grid electrical supply—are completely acceptable.
Critical applications can be evaluated two ways: They include equipment that cannot afford operational downtime during normal operation or they include flow control systems (gates or valves) that absolutely must operate during an emergency situation.
In short, they are defined by the consequences of failure, where the inability to operate leads to equipment damage, environmental releases, service disruptions or public safety threats. In these instances, the actuator is much more than a means for positioning a gate or valve. It is a fundamental component of the facility’s risk management strategy. Accordingly, actuators must offer reliability and a long, multidecade lifespan without the need for frequent maintenance or upkeep.
Examples of critical applications include pump discharge valves, surge control valves, raw water intake gates, flood control gates, combined sewer overflow (CSO) diversion structures and critical process isolation valves. Identifying these assets is the first step in developing an effective fail-safe philosophy, enabling engineers to tailor failure modes, operational risk assessments and emergency response plans to each specific asset.
Common Failure Scenarios in Water Infrastructure
Designing a resilient system requires knowing what threatens it most. In water and wastewater applications, failure scenarios typically fall into three categories:
- Power loss: The most common and immediate threats to water infrastructure are localized or regional outages, often caused by severe weather or storm surges. They disrupt normal treatment plant and pump station operations, leaving pipelines vulnerable to backflow and uncontrolled flow.
- Emergency overflow: Intense rainfall can overwhelm treatment capacity, forcing system bypasses. In these critical moments, valves must actuate reliably to divert excess flow and prevent structural damage or CSOs.
- Debris loading and mechanical binding: Extreme weather and runoff carry sediment and debris that can jam gates or valves. If an actuator lacks the thrust or torque capability and control logic to overcome these blockages, the affected facility segment becomes incapacitated.
Fail-Safe Philosophies
When a power failure occurs, a facility’s control architecture must seamlessly transition to a defensive state. This requires a clearly defined fail-safe philosophy for every critical asset. A fail-safe actuator automatically moves a valve or gate to a predetermined “safe” position upon the loss of power or control. The ideal mode depends on the specific application:
- Fail-closed: Primarily used to prevent back-flow. In pumping applications, a fail-closed action prevents mechanical damage if power is lost while fluid is being moved. Similarly, influent gates use this mode to isolate treatment facilities during flood events.
- Fail-open: Essential for emergency bypass and overflow scenarios. If a plant loses power during a storm, these gates divert floodwaters away from sensitive equipment and into designated channels.
- Fail-in-place: In specific distribution networks, the safest action is to lock the valve in its current position to maintain system pressure. This could be managed via a secondary control signal. This special design is referred to as “fail-on-command.”
To achieve these transitions during a power outage, actuators rely on stored energy systems. Spring-return mechanisms provide a mechanical solution, though they are subject to fatigue over time and are unable to accommodate nonlinear closing speeds. Hydraulic power units (HPUs), conversely, use accumulators to store high-pressure hydraulic fluid. Upon power loss, the accumulator acts as a reserve, releasing this fluid to drive the valve or gate to its fail-safe position without requiring external electricity.
Beyond Power Loss
Infrastructure resilience requires more than just electrical backup. Some of the most catastrophic failures occur when equipment is compromised by flooding, debris or corrosive environments. Designing for failure requires looking beyond power availability and ensuring the equipment itself can survive the harsh conditions that triggered the outage.
Actuators in valve vaults and treatment plants are increasingly facing challenges that exceed historical design assumptions. As a result, engineers are placing greater emphasis on environmental robustness, prioritizing flood protection, corrosion resistance and the elimination of vulnerable external support systems.
In many critical applications, self-contained, unitized electrohydraulic actuators have emerged as an effective approach to addressing these requirements. By integrating power, control and stored energy into a single sealed housing, these systems can eliminate reliance on centralized air or hydraulic infrastructure, which may itself become compromised during a disaster. When developing a fail-safe strategy, this level of integration—alongside stored-energy capability, maintenance accessibility and redundancy—can be as important as the operational logic itself.
Hurricane Sandy (2012) demonstrates the value of this approach. During the storm, self-contained electrohydraulic actuators at a major New York City wastewater pump station remained submerged under several feet of water for approximately ten days. Once the waters receded, these units were returned to service without requiring repair or replacement, and they are still in operation to this day.
This performance confirms why utilities now prioritize equipment capable of withstanding extreme disruptions: Because critical infrastructure is built to last for decades, designing for these high-consequence events is a baseline requirement, not an optional feature.
Design Consideration: Redundancy, Logic & Response Time
Designing for failure and integrating fail-safe actuators into the broader system requires a holistic approach to reliability. For critical applications, this foundation begins with the hardware itself. Relying on external support systems, such as centralized hydraulic supply lines or compressed air, introduces vulnerabilities.
To mitigate these risks, engineers are increasingly specifying self-contained, unitized electrohydraulic actuators. By integrating power, control and stored energy into a single, sealed housing, these units eliminate reliance on external infrastructure, ensuring the system remains operational even if the surrounding utility networks fail.
With that foundation in place, the supporting design elements must be equally robust:
- Intelligent control logic: Supervisory control and data acquisition (SCADA) integration must go beyond basic commands. The system should be intelligent enough to distinguish between localized component faults and grid-wide outages, triggering specific, reliable fail-safe protocols rather than a generic response.
- Calibrated response times: While emergencies often demand rapid action, valve closure speeds must be calibrated carefully. Closing too quickly on large-diameter or long-distance pipelines can trigger dangerous hydraulic transients, a risk that must be balanced against the need for immediate flow control.
- Hardware redundancy: For critical assets, redundancy is nonnegotiable. Utilizing dual power sources, backup pumps, independent control paths and redundant feedback devices ensures that no single point of failure can compromise the facility’s ability to respond during an emergency.
Mitigating Water Hammer
Designing for failure involves more than just defining a fail-safe position; it requires awareness and management of the resulting emergency action. When a valve closes suddenly, the kinetic energy of moving fluid is halted abruptly, transforming into a high-pressure shockwave known as water hammer (or hydraulic transient). This force can easily exceed pipeline pressure ratings, resulting in blown gaskets, ruptured pipes or catastrophic system failure.
To manage this risk, actuators must be calibrated to close the valve rapidly enough to mitigate flooding or pump back-spin, but slowly enough to dissipate pressure safely. Modern actuator systems allow for modulated, nonlinear closure rates. For instance, an electrohydraulic actuator can be programmed to close a valve rapidly 80% of the way to isolate the bulk of the flow, then gently taper off for the final 20% to safely manage the remaining momentum without requiring external input or auxiliary infrastructure, even during an emergency fail-closed scenario.
Shifting Perspective
Designing for failure requires a deliberate shift in perspective. When infrastructure fails, the costs are not merely operational—they are measured in expensive equipment damage, environmental degradation, heavy regulatory fines and risks to public safety. The difference between a manageable disruption and a catastrophic event often comes down to the actuator’s ability to perform under the worst possible conditions.
For many critical applications, electrohydraulic actuation offers a compelling approach to resilient infrastructure design. By reducing reliance on vulnerable external support systems and incorporating local stored-energy capability, these systems can help ensure fail-safe actions are executed when they are needed most—during the very events the infrastructure was designed to endure.
As climate volatility and aging infrastructure continue to challenge utilities, the question is no longer whether a system will experience disruption, but whether that system is designed to respond when it occurs. In that environment, fail-safe actuation is not an optional feature—it is the cornerstone of resilient, reliable infrastructure design.
Gregory Asselta is the national sales manager for Trident Actuators. He may be reached at gasselta@tridentactuators.com or 445-456-4135. For more information, visit tridentactuators.com.
In This Issue

