• Our new ticketing site is now live! Using either this or the original site (both powered by TrainSplit) helps support the running of the forum with every ticket purchase! Find out more and ask any questions/give us feedback in this thread!

Marylebone Fire 28th Aug 26

Sponsor Post - registered members do not see these adverts; click here to register, or click here to log in
R

RailUK Forums

Benjwri

Established Member
Joined
16 Jan 2022
Messages
3,264
Location
Bath
The fire is all the way down in Wembley yet Chiltern have completely thrown in the towel as usual and suspended the MET line service, no shuttle to Amersham or even just Great Missenden, nothing!
Although I shouldn't be surprised, even the littlest of issues and Chiltern gives up on this line.
I would to be fair suspect their control is extremely overworked and very short of crew and units given the Marylebone chaos. Running a short shuttle will not be high on their priorities.
 

800002

Member
Joined
19 Jun 2019
Messages
1,079
At the same time as the Met lines were shut, Marylebone and its signallers were evacuated. Nothing was able to move, nor plans established.

Try to consider the need to restart a full joint/ main line service after having stranded trains before you start to think about starting another potential failure in the met line.

Has the traction been turn off?

Would Amersham be able to accept the traffic?
 

150219

Member
Joined
24 Nov 2009
Messages
469
The fire is all the way down in Wembley yet Chiltern have completely thrown in the towel as usual and suspended the MET line service, no shuttle to Amersham or even just Great Missenden, nothing!
Although I shouldn't be surprised, even the littlest of issues and Chiltern gives up on this line.
Apart from this thread is talking about something unrelated to the fire at Wembley. Trying to operate a service with the signalbox closed is a little difficult.
 

800002

Member
Joined
19 Jun 2019
Messages
1,079
There were four concurrent incidents affecting Chiltern.
Three on going, one resolved with residual delays.

Linesinde Fire, Neasden / Wembley area as per the BBC.
Station fire alarm activation and subsequent station (and ASC IECC Marylebone) evacuation.
Track defect at Claverdon.
(And my personal favourite as I'm stuck in it) Signal / Trackcircuit failure at Leamington Spa. Talking past two signals, I believe.

Happy bank holiday weekend folks!
 

plunet

Member
Joined
30 Aug 2025
Messages
15
Location
UK
Do you feel services should have still operated from Marylebone?, What would be your priority and how would you activate such a plan?
No. I was just confirming that from previous failure scenarios there is no resilience for the Marylebone signalling cabin. When it's down, it's down, and nothing is going to move until it's back up in service.

I would suggest it would be sensible for Network Rail to build in some resilience for Marylebone, and the priorities for any service operated in a resilience scenario needs to be informed by the capability of the resilience, plans to fail over and fail back, and any operating procedures that are tested and agreed.
 

High Dyke

Established Member
Joined
1 Jan 2013
Messages
4,995
Location
Yellabelly Country
No. I was just confirming that from previous failure scenarios there is no resilience for the Marylebone signalling cabin. When it's down, it's down, and nothing is going to move until it's back up in service.

I would suggest it would be sensible for Network Rail to build in some resilience for Marylebone, and the priorities for any service operated in a resilience scenario needs to be informed by the capability of the resilience, plans to fail over and fail back, and any operating procedures that are tested and agreed.
Where or how would you suggest that resilience resource to be sited?

In regards the larger control centres like York, there was a suggestion that it could be easy for another centre to take over running their area during such a scenario. Imagine someone in Derby or Edinburgh trying to operate trains in/out of King's Cross (as an example). On paper it sounds easy, but the reality is far more complex and unachievable.

Bringing the discussion back to the incidents today. The two main things were the fire alarm activation at Marylebone Station (affecting the signalling centre), which prevented services operating over the wider network, and the fire in a premises adjacent to the railway. The industrial unit affected is at the point where the Chiltern line (via Wembley) and Metropolitan/Chiltern route diverges; so it was highly likely services wouldn't be operating past that location.
 

takno

Verified Rep - Traksy
Joined
9 Jul 2016
Messages
6,574
No. I was just confirming that from previous failure scenarios there is no resilience for the Marylebone signalling cabin. When it's down, it's down, and nothing is going to move until it's back up in service.

I would suggest it would be sensible for Network Rail to build in some resilience for Marylebone, and the priorities for any service operated in a resilience scenario needs to be informed by the capability of the resilience, plans to fail over and fail back, and any operating procedures that are tested and agreed.
I think you might have picked up some of the commentary around the Cross Country control centre and run a bit far with it. A TOC control centre is very broadly speaking a load of desks with computers and a decent connection to the internet.
Providing a disaster recovery solution for that isn't incredibly complex.

A signalling centre is full of relatively specialist highly certified equipment, with (non-internet-connected) linkage to all the the interlockings and level crossings. Casually keeping a backup lying around, and maintaining certification on i,t would be maybe 3 orders of magnitude more complex and expensive. it isn't going to happen
 

MarkyT

Established Member
Joined
20 May 2012
Messages
7,549
Location
Torbay
No. I was just confirming that from previous failure scenarios there is no resilience for the Marylebone signalling cabin. When it's down, it's down, and nothing is going to move until it's back up in service.

I would suggest it would be sensible for Network Rail to build in some resilience for Marylebone, and the priorities for any service operated in a resilience scenario needs to be informed by the capability of the resilience, plans to fail over and fail back, and any operating procedures that are tested and agreed.
No signalbox or control centre has a backup site.

There's a lot of engineering resilience built into the system, however: Duplicated power feeders, uninterruptible supplies for the main systems, twin diversely routed trackside datalink cables, etc, but none of that can help in an evacuation.

Older relay-based remote interlockings often had local emergency panels that could be used, though this was typically operated by an agent under the direction of the signaller when the remote telemetry wasn't working as there were no train describer, signal post telephone or train radio facilities at the remote site. SSI, with all interlocking usually housed within the control centre, doesn't support such local panels.

Perhaps within a station is not the best location for a major control centre covering a wide area.
 

Brush 4

Member
Joined
25 Nov 2018
Messages
714
Yet another 'don't put all your eggs in one basket' scenario. Like software on trains that fails the whole unit for some minor fault that doesn't physically prevent the train running, except the computer says no. Like Cross Country a few days ago. Like banks, supermarkets and airports having a failure that stops everything. Progress is supposed to improve things and make them more resilient to problems, not less so.
 

The Planner

Veteran Member
Joined
15 Apr 2008
Messages
19,630
Yet another 'don't put all your eggs in one basket' scenario. Like software on trains that fails the whole unit for some minor fault that doesn't physically prevent the train running, except the computer says no. Like Cross Country a few days ago. Like banks, supermarkets and airports having a failure that stops everything. Progress is supposed to improve things and make them more resilient to problems, not less so.
But what is new here? Its been the case since the 60s with the addition of PSBs etc.
 

Benjwri

Established Member
Joined
16 Jan 2022
Messages
3,264
Location
Bath
Yet another 'don't put all your eggs in one basket' scenario. Like software on trains that fails the whole unit for some minor fault that doesn't physically prevent the train running, except the computer says no. Like Cross Country a few days ago. Like banks, supermarkets and airports having a failure that stops everything. Progress is supposed to improve things and make them more resilient to problems, not less so.
Except there is no realistic alternate option in many of these cases. These costs of these alternatives, particularly in something safety critical like signalling, would be extraordinary, both in initial installation and in maintenance.

Not to mention there are few buildings a fire can in for the signal box to close, there are tens of thousands that can be on fire next to the railway and have the same effect. How do you sort that?
 

Brush 4

Member
Joined
25 Nov 2018
Messages
714
Manual signal box problems were just for that box.

The section would bypass that box until it was fixed. Older diesels could have problems that didn't disable it, although sometimes there were total failures of course. Mechanical ones, not computer systems having a fit over a dirty windscreen or something equally trivial. Clean it and carry on.

If they had had air con in the first place, it could fail without knocking out the whole loco, as seems to happen now. Dawlish waves didn't knock out whole trains as they do the delicate little darlings that are modern units. Even less so in steam days. the crew got wet, but they carried on.

Keep Calm and Carry On as it used to be. Now it is stop everything and panic. The passenger comes last in the priorities.
 
Last edited by a moderator:

Benjwri

Established Member
Joined
16 Jan 2022
Messages
3,264
Location
Bath
Manual signal box problems were just for that box. The section would bypass that box until it was fixed. Older diesels could have problems that didn't disable it, although sometimes there were total failures of course. Mechanical ones, not IT having a fit over a dirty windscreen or something equally trivial. Clean it and carry on. If they had had air con in the first place, it could fail without knocking out the whole loco, as seems to happen now. Dawlish waves didn't knock out whole trains as they do the delicate little darlings that are modern units. Even less so in steam days. the crew got wet, but they carried on.
Keep Calm and Carry On as it used to be. Now it is stop everything and panic. The passenger comes last in the priorities.
What units have you been on that an aircon fault has knocked them out? Discounting when they are taken out of service because the temperature is unsafe.

If Marylebone was a manual signal box you'd have the exact same issue, there is nowhere to turn as many trains are there are without severe disruption.
 

MarkyT

Established Member
Joined
20 May 2012
Messages
7,549
Location
Torbay
What units have you been on that an aircon fault has knocked them out? Discounting when they are taken out of service because the temperature is unsafe.

If Marylebone was a manual signal box you'd have the exact same issue, there is nowhere to turn as many trains are there are without severe disruption.
The old mechanical signalbox at Marylebone was out in the throat, not in station buildings closely surrounded by public areas and station traders.

An evacuation of the station caused by an alarm fault probably wouldn't have closed the SB, but clearly they wouldn't be running any more trains into the platforms, though they might still run departures already loaded as an expedient evacuation method.

Boxes further north would still be operational, and I expect they could turn back a limited service, though there'd still be chaos no doubt.

An anonymous dedicated building in a secure compound in the suburbs is a more resilient location for a wide area control centre.
 

Bald Rick

Veteran Member
Joined
28 Sep 2010
Messages
35,581
No. I was just confirming that from previous failure scenarios there is no resilience for the Marylebone signalling cabin. When it's down, it's down, and nothing is going to move until it's back up in service.

Yet another 'don't put all your eggs in one basket' scenario.

But this has been the same for just about every signalbox, ever.
 

800002

Member
Joined
19 Jun 2019
Messages
1,079
But this has been the same for just about every signalbox, ever.
Indeed.
Boxes with routes that can be 'switched out' or bypassed are designed from inception or modified after to allow individual, pre set, routes to be set from and to the boxes either side of it without any input or control from the box containing said route.

There is no duplication of electronic mainline signalling control function that I can think of which would enable the signalling on a failed / evacuated pannel to be operated from an alternative panel location.

I think they (chiltern) were lucky enough to be able to contact the drivers stopped/ stranded via the GSMR from their end as the drivers calls to the signaller would all have gone unanswered.
 

Dave61

Member
Joined
8 Mar 2026
Messages
152
Location
Long Eaton
It really feels like there are many people on these forums who seem to think that money grows on trees and that we should hava an absolutely perfect railway system where everything is duplicated (also XC, York control etc), breakdown and PW recovery/rebuilding teams are dotted around the country just waiting for the call to action (Wickford, Lewes, Bedford etc).

Sadly this is not reality. All the above costs money - lots of money - and the government who is funding all this is flat broke and deep in debt (which also costs money to service), indeed it has a constant scramble to see where it can rob money from to shuffle around from pot to pot to meet both the demands of the moment and also keep it electable on the next general election (never forget that this is its primary aim!).

Sure you *could* have all the above but you will be paying much higher fares as a passenger and taxes as a taxpayer (and both are too high for comfort already). And something somewhere else would have to do without and suffer accordingly.
 

150219

Member
Joined
24 Nov 2009
Messages
469
Let's put this into perspective.

It's a fire alarm activation that was false alarm. 30 minutes for the fire service to respond, search and declare everything safe is (I would say) a reasonable response time for a London terminus.

It's happened before without comment and will happen again, I'm sure. Yes, it's inconvenient for customers and staff alike, but demanding change as a knee jerk reaction won't result in the change that's asked for here.
 

MarkyT

Established Member
Joined
20 May 2012
Messages
7,549
Location
Torbay
Indeed.
Boxes with routes that can be 'switched out' or bypassed are designed from inception or modified after to allow individual, pre set, routes to be set from and to the boxes either side of it without any input or control from the box containing said route.
For Absolute Block lines, some boxes are designed for signallers to clear signals for main through routes in both directions, then switch out, which literally means using a big switch to disconnect the local block instruments, bells and telephones and connect the block lines on either side together to create a long block section. All managed by a series of bell codes exchanged and register entries made by all parties.

For early remote relay interlockings, remote control telemetry using TDM (time division multiplex) was fairly expensive cutting-edge technology, and schemes did not typically duplicate this equipment. Instead, it was common to have backup 'overrides', usually a select few control channels sent by an alternative diverse comms medium.

Direct wire was used if the remote site was fairly close, or more commonly, Reed FDM (frequency division multiplex) technology. Remote interlockings typically had an All Signals At Red control via the separate control medium. If using Reed, this would be a vital channel (higher integrity but fewer channels available). Other commands could use non vital channels (more numerous). The other common function is 'Through Routes', setting the most important routes across the interlocking and switching the signals to automatic mode. At important geographical junctions, 'Selective Overrides' were provided, where limited control of the strategic junction was still available when the TDM was down.

As electronics prices tumbled, duplication of TDM systems became the norm and separate overrides were abandoned, apart from the All Signals At Red control, which is seen as an important safety feature.

There is no duplication of electronic mainline signalling control function that I can think of which would enable the signalling on a failed / evacuated pannel to be operated from an alternative panel location.
It's impractical on many levels.

Engineering
As processor-based interlockings are typically housed at the control centre along with all the workstation systems, a complete duplicate set of equipment would be required at the backup site. Very expensive.

The switchover process is risky. While it might be possible to develop protocols and equipment that allowed a trackside datalink to be switched live from one interlocking to another in hot standby at another site, it could plausibly trigger software fuse blows if there's any ambiguity in input states and timings in the first few cycles after switchover. That's a complete shutdown, fuse swap, and restart required. Even in concept, it's extra complexity in a critical part of the system, a new common mode failure point.

How would the backup site know about operational restrictions applied to the interlocking before switchover. E.g. Signallers' collars, aspect and route restrictions on the technicians terminal etc.

Staffing
Clearly it's not practical to employ a backup team of signallers at the alternative site, so the personnel from the primary site would need to get there.

How long will that take before any service could run? As the employees at Marylebone had to leave the building in a hurry, we can assume they didn't stop to carefully pick up all their half filled out possession forms, other notes, aide memoirs, etc. So they'll arrive at backup site with only an outline memory of precisely what was going on at the time of the emergency. That means starting up again is going to be time consuming as they methodically confirm the state of everything.
 

Top