When “Lessons Learned” Isn’t Enough: What the NATS Meltdown Teaches Us About Crisis Readiness

On 8 September 2026, the UK’s air traffic control system buckled again. A fault in NATS’ flight-data processing software at Swanwick grounded nearly 1,000 flights, disrupted around 330,000 passengers, and left travellers sleeping on terminal floors at Heathrow, Gatwick, Stansted and Luton. Knock-on delays reached as far as Ibiza. Airlines warned it could take days to unwind the damage to crew rosters and aircraft rotations.

For most people, this was a miserable travel story. For anyone in our line of work, it was something more familiar: an organisation that had already been told what was wrong, had already promised to fix it, and still couldn’t stop it happening a third time.

A pattern, not an accident

This wasn’t NATS’ first failure at Swanwick. In August 2023, a data glitch involving two identically named waypoints took down both the primary and backup systems at once, affecting over 700,000 passengers. In July 2025, a radar fault triggered 150+ cancellations. And just three months before this latest collapse, the Civil Aviation Authority had formally signed off NATS’ completion of all 34 recommended reforms.

Ryanair’s chief operating officer put it bluntly: “We were told lessons would be learned. We were told resilience would improve. We were told the systems had been fixed. Yet here we are again.” Wizz Air went further, calling NATS “not fit for purpose in its current form.”

That is the line that should make every leadership team sit up — not because of what it says about air traffic control, but because of what it says about the gap between having a crisis plan on paper and having one that actually holds under pressure.

Three lessons every organisation should take from this

1. A backup that fails alongside the primary system isn’t a backup. The 2023 incident showed that NATS’ primary and secondary systems shared the same underlying flaw, so both went down together. Many organisations discover the same thing about their own contingency plans only when it’s too late — the “backup” supplier, server, or manual process turns out to depend on the very thing that just broke. True resilience means stress-testing your fallback independently, not just assuming it exists.

2. Certification is not the same as capability. NATS had ticked every box the regulator asked for. All 34 reforms, signed off. And it still failed. Passing an audit tells you a process exists on paper; it doesn’t tell you whether your people can execute it at 6am on a bank holiday weekend with 330,000 passengers depending on them. The only way to know is to rehearse the real thing — under realistic pressure, with the decisions and trade-offs that a live incident actually forces.

3. The response is remembered as much as the failure. Passengers “bedding down on camp beds overnight” and facing an “extraordinary circumstances” classification that limits compensation is now as much a part of this story as the technical fault itself. Communication, welfare, and visible leadership during the first hours of a crisis shape public and client trust for years afterwards — often more than the root cause does. A strong technical fix with a poor human response still reads as a failure.

Why exercises matter more than plans

The uncomfortable truth is that NATS almost certainly has a crisis plan. What it evidently doesn’t have — at least not one that holds — is a tested, rehearsed, organisation-wide muscle memory for executing that plan when systems and backups fail simultaneously and the pressure is real.

That’s the gap our work exists to close. A document in a drawer doesn’t tell you whether your leadership team can make fast decisions with incomplete information, or whether your frontline staff know what to say to a stranded customer in the first ten minutes. Only a properly run exercise does that — and doing it once, three years ago, isn’t the same as doing it regularly.

There’s a subtler trap here too. Even organisations that do exercise regularly tend to keep rehearsing the same handful of scenarios — the ones their own planners find easiest to imagine, or most comfortable to run. It’s a natural human bias: we design tests around the failures we already understand. This is part of why we built Crisis Cloud AI, our self-service exercise platform: because scenarios generated with it aren’t filtered through any one planner’s instinct for what’s “realistic” or manageable.

It’s worth asking a simple question of your own organisation: when was the last time you actually tested your plan thoroughly?

Crisis Solutions has spent 25 years helping organisations — from major airlines and financial institutions to global manufacturers — build and rehearse the crisis response capability that plans alone can’t provide. Get in touch to talk about testing your own resilience, or take a free, no credit-card trial of Crisis Cloud AI, before an incident does it for you.

Leave a Comment

Your email address will not be published. Required fields are marked *