The Reactors Didn’t Fail. The River Ran Too Low.
What record-low Danube levels in Romania and Hungary show about the outside dependencies that can stop an otherwise functioning operation.
Nothing had to break. The water just had to fall far enough.
On August 13, Cernavodă Unit 2 began a controlled shutdown as the Danube continued to decline. [1] Meanwhile, Unit 1 was already offline after low river levels triggered its own controlled shutdown in late July. [2] [3]
When Low Water Became an Operating Constraint
Together, Cernavodă’s two 706-megawatt reactors normally account for about one-fifth of Romania’s electricity production. [3]
However, the reactors were not reported to have failed. Instead, falling Danube levels were the stated reason for the controlled shutdowns. [1] [2]
A falling river had become an operating limit.
Hungary faced the same problem
Romania was not alone. Further upstream, Hungary’s Paks nuclear plant was dealing with the same dependency.
Paks normally generates around half of Hungary’s electricity. Earlier in August, output fell to just over 10% of capacity. By August 14, the plant was operating at around 25%. [3] [4]
As a result, Hungary moved beyond plant-level measures and began work around the river itself.
A submerged riverbed sill is being built near Paks to help manage water flow. Meanwhile, authorities announced plans to sink two 80-metre barges as a temporary measure while that work continued. [4]
The barges were expected to raise the local water level by about 20 centimetres. The riverbed sill could raise it by up to one metre. [4]
The change is visible from space
European Space Agency imagery from August 2026 shows noticeably lower water and exposed sandbanks north of Budapest compared with the same stretch of river one year earlier. [5]
ESA reported that the Danube had reached a record low in Hungary during severe drought in Central Europe. At the same time, record-low levels were also reported in Romania. [5]
The reactors are the headline. The dependency is the real story.
The Problem May Sit Outside the Operation
That is where the Danube story becomes relevant far beyond nuclear power.
Cernavodă and Paks depend on river water for cooling. [3] As a result, when that resource became constrained, operating capacity became constrained with it.
What sits outside direct control?
The same question applies elsewhere: what does the operation rely on that sits outside the equipment, systems, and people under direct control?
Depending on the operation, that may include:
- Water
- Electricity
- Fuel
- Road or rail access
- Ports and shipping routes
- Telecommunications
- Specialist contractors
- Single-source suppliers
- Public infrastructure
- Critical equipment or replacement parts
However, simply knowing that a dependency exists is not enough.
Instead, what matters is what happens when it becomes harder to access, slower to respond, less reliable, or available at only part of its normal capacity.
Connect the dependency back to the work
For example, a mine may rely on one rail corridor. A facility may depend on one utility connection. A major project may need specialist support that cannot be replaced quickly.
In each case, the exposure becomes clearer when the dependency is connected back to the activity it supports.
Ventari Global’s approach starts with operating reality. That includes how systems work together, how decisions are made, where accountability sits, and where exposure can build.
The question is not only, “What could fail here?” It is also, “What do we depend on that could stop us from operating?”
Knowing the Dependency Is Not Enough
Saying “we depend on power” or “we depend on this supplier” does not tell leadership very much.
Instead, the important question is what happens as that dependency changes.
What happens at reduced capacity? How long can the operation continue? What has to slow first? Which controls become harder to maintain? At what point does continuing no longer make sense?
Follow the dependency into the operation
A useful review connects the outside resource or service to the process that relies on it.
- Which activities depend on it?
- How much availability is actually required?
- What changes when capacity begins to fall?
- How long can reduced conditions be sustained?
- Which controls are affected?
- What would force a reduction or stop?
- Who else would be affected?
- What alternative is genuinely available?
As a result, the organization moves from simply listing a dependency to understanding what it means for the operation.
Look for single points of dependence
In addition, the risk changes when a critical activity relies heavily on one route, connection, provider, location, or specialist skill.
Examples of single points of dependence include:
- One critical supplier
- One transport route
- One utility connection
- One specialist contractor
- One piece of critical infrastructure
- One operating location
- One specialist skill or capability
The Danube example matters because the river did not disappear. Instead, its availability changed enough to reduce what the plants could do. [1] [3]
Know the Limit Before the Limit Makes the Decision
The disruption developed over time.
At Paks, output was reduced as water conditions deteriorated. [3] Meanwhile, at Cernavodă, river levels, forecasts, equipment, and safety margins were being monitored before Unit 2 entered controlled shutdown. [1]
Nuclearelectrica’s earlier Unit 1 notice was even more explicit. If parameters linked to the low Danube reached allowed operating limits, the response could include shutting down one or both units. [2]
Therefore, knowing the line before reaching it matters.
Turn warning signs into decisions
A limit only helps if the organization knows what happens as it approaches.
- When does monitoring need to increase?
- When should operating conditions change?
- When should contingency arrangements begin?
- When does the issue require senior leadership attention?
- When should production or service be reduced?
- What condition requires a stop?
- Who has authority to make each decision?
Of course, those limits need to reflect the organization’s actual hazards, technical needs, systems, and operating conditions.
Therefore, the right operational, engineering, HSEQ, and specialist teams need to help set them.
If nobody knows where the line is until the operation is already crossing it, the organization has left a critical decision too late.
A Backup Plan Is Only as Good as Its Real Capacity
“We have a backup” can sound reassuring.
However, it tells leadership very little unless the organization also knows what that backup can carry, how quickly it can start, and how long it can last.
For example, backup arrangements may include another supplier, emergency power, spare stock, manual processes, alternate transport, or specialist support.
Even so, the real questions begin after the backup has been named.
- How much capacity does it provide?
- How quickly can it be activated?
- How long can it continue?
- Who has authority to activate it?
- What does the backup itself depend on?
- What part of normal operation will still be lost?
- Has it been tested under realistic conditions?
- What happens if the disruption outlasts the plan?
The backup may face the same problem
This is where assumptions need to be tested.
An alternate supplier may also be serving other organizations affected by the same disruption. A second transport route may have limited spare capacity. Backup power may support critical loads without supporting normal production.
Having an alternative does not prove that it can support the operation when needed.
Test more than the equipment
The test is not only whether the generator starts or whether the second supplier exists.
Instead, the real test is whether the full backup arrangement works at the scale, speed, and duration the operation actually requires.
An independent Audit & Assurance review can examine controls, responsibilities, operating practice, and the available evidence to identify gaps or weaknesses.
The operation can be functioning and still have to stop.
Internal controls matter. At the same time, organizations need to know whether the services, infrastructure, suppliers, and resources around the operation can continue to support them.
Leaders Need the Decision, Not the Data Dump
When a critical dependency starts to deteriorate, more information is not automatically better information.
Instead, senior leaders need a clear view of what is changing, what it means for the operation, how much time remains, and what decision is approaching.
Make the pressure visible
Depending on the issue, that may mean showing:
- Which dependency is deteriorating
- Which operations rely on it
- How much capacity remains
- Which controls or activities are becoming constrained
- Which contingency measures are already active
- How long those measures can continue
- What the next trigger is
- What decision will be required
- Who has authority to make it
However, that is very different from sending leadership a large dashboard and assuming visibility has been achieved.
Ultimately, the test is whether the information makes the operating condition and the next decision easier to understand.
Through Enterprise Advisory, Ventari Global works with boards and executive teams on operational risk, controls, governance, assurance, reporting, and the way complex operating conditions are turned into decisions.
A dashboard cannot create resilience if the decision-maker still cannot see what is about to change.
Do Not Leave a Critical Dependency in One Department
The team responsible for a service is not always the team carrying the full impact if that service is lost.
For example, water may sit with facilities. Power may sit with engineering. Suppliers may sit with procurement. Transport may sit with logistics.
However, if losing one of those dependencies can seriously affect safety, service, production, or performance, the issue is no longer confined to that department.
Connect ownership to the impact
Leadership should be able to see:
- What the dependency supports
- What happens if it is constrained
- Who manages the service or relationship
- Who owns the wider operating risk
- What controls are in place
- What evidence shows those controls are working
- What backup arrangements exist
- What triggers escalation
Not every supplier, road, utility, or service requires executive attention.
However, those that can seriously change operating conditions need clear ownership and visibility.
Connect the risk instead of managing it in pieces
The Ventari Summit™ Framework connects risk and critical controls, governance and assurance, operational control and performance, HSEQ and ESG value integration, and leadership and culture within one enterprise model.
As a result, risks that cross functions can be considered as part of the wider operating picture.
Look Beyond the Site Boundary
The lesson from the Danube is not that an organization should somehow control every outside condition.
It cannot.
Instead, the better question is whether the organization understands which outside conditions can seriously change the way it operates.
Test what actually keeps the operation running
A resilience review can follow those dependencies beyond the site boundary and bring the operating picture back together.
For example, a review may examine:
- Critical services, resources, suppliers, contractors, utilities, and infrastructure
- The activities that rely on them
- Single points of dependence
- Operating limits and warning points
- Escalation triggers and decision authority
- Backup capacity and duration
- Dependencies hidden inside the backup plan
- The evidence supporting critical controls and backup arrangements
As a result, leaders can get a clearer view of which dependencies matter, where the operating limits sit, and whether the controls and backup arrangements are supported by evidence.
Ultimately, the objective is not to predict every disruption.
Instead, it is to know which dependencies matter before one of them starts making operating decisions for you.
What Can Your Operation Not Afford to Lose?
Along the Danube, the dependency is unusually easy to see.
Both Cernavodă and Paks draw water from the river for cooling. [3] As water levels fell, Paks cut output and both Cernavodă units entered controlled shutdown under low-water conditions. [1] [2] [3]
The weak point may be harder to see elsewhere
It may be a supplier that has never missed a delivery. A utility connection that has always been available. A specialist contractor that cannot be replaced quickly. Or a transport route with no practical substitute.
Reliability can make a dependency easy to overlook. But the fact that something has always been available does not mean the operation is prepared to lose it.
What matters is whether leadership understands the consequence if that dependency is constrained, disrupted, or gone.
The biggest exposure may not be the dependency most likely to fail. It may be the one the operation assumes will always be there.
References
Plant updates and current reporting
- S.N. Nuclearelectrica S.A., Important Event to Report: Controlled Shutdown of Unit 2 at the Cernavoda Nuclear Power Plant on the Morning of August 13, 2026. August 13, 2026. Filed with the Bucharest Stock Exchange and Financial Supervisory Authority. Accessed August 14, 2026.
- S.N. Nuclearelectrica S.A., Important Event to Report: Controlled Shutdown of Unit 1 at the Cernavoda Nuclear Power Plant. July 27, 2026. Filed with the Bucharest Stock Exchange and Financial Supervisory Authority. Accessed August 14, 2026.
- Reuters, Record-Low Danube Exposes Climate Risk to Hungary’s and Romania’s Nuclear Power. August 13, 2026. Accessed August 14, 2026.
- Reuters, Hungary to Sink Two Barges Near Nuclear Plant to Ensure Cooling. August 14, 2026. Accessed August 14, 2026.
Danube conditions
- European Space Agency, Danube’s Waters Fall to Record Lows. August 7, 2026. Copernicus Sentinel-2 imagery comparing conditions in August 2025 and August 2026. Accessed August 14, 2026.
Disclaimer: This article provides general commentary on operational resilience, governance, critical dependencies, and assurance. Site-specific operating limits, technical decisions, and response measures should be determined using the organization’s own operating conditions, legal requirements, and qualified specialist input.
What Does Your Operation Depend On to Keep Running?
Ventari Global helps organizations understand operational exposure, strengthen controls, test assumptions, and make clearer decisions in complex operating environments.
