Advertisement

The Fragile Threads Beneath the Waves: Who Really Controls the Internet's Most Vulnerable Infrastructure

Somewhere in the North Atlantic, roughly 1,700 meters beneath the surface, a fiber-optic cable thinner than a garden hose is carrying a significant portion of the financial transactions, military communications, and personal messages flowing between Europe and North America at this very moment. There is no fence around it. There is no security camera watching it. And until very recently, there was almost no coordinated plan to defend it.

The world’s submarine cable network is, by almost any measure, the most important infrastructure most people have never thought about. Approximately 600 active submarine cable systems span more than 1.5 million kilometers across the ocean floor, carrying an estimated 95% of international data traffic. This is not a backup system or a secondary route. It is the internet. Satellites, despite their prominence in public imagination, handle a comparatively tiny fraction of global data transmission, constrained by latency, bandwidth limitations, and cost. When you send an email from London to Tokyo, make a video call from São Paulo to New York, or execute a trade on a foreign exchange, the data almost certainly travels through a cable lying on the seabed.

For decades, this infrastructure operated in a kind of comfortable obscurity. The cables were laid by private consortiums, loosely regulated by international maritime law, and largely ignored by defense establishments focused on more visible threats. That era is emphatically over.

A Network Built on Sand—and Surprising Fragility

The physical reality of submarine cables is at once remarkable and alarming. A typical cable in deep water is roughly 17 to 20 millimeters in diameter—comparable to a human thumb. In shallower coastal waters, where anchors and fishing trawls pose greater risks, cables are armored with steel wire and can reach 50 to 70 millimeters in diameter. But even armored cables are not invincible, and in deep water, where protection is minimal, a single determined act of sabotage could sever a critical communications link between continents.

The vulnerability is not theoretical. The vast majority of cable outages—industry estimates consistently place the figure somewhere between 70 and 80 percent—are accidental, caused by fishing vessels, anchors, and the occasional submarine geological event. The 2006 Hengchun earthquake off the coast of Taiwan severed multiple cables simultaneously, disrupting internet service across much of Southeast Asia for weeks. In January 2022, a volcanic eruption near Tonga severed the Pacific island nation’s sole submarine cable link to the world, leaving it effectively cut off for over a month. In February 2024, multiple cables in the Red Sea were damaged amid the conflict in Yemen, causing significant disruptions to data traffic between Europe and Asia.

The repair process is extraordinarily slow and expensive. A cable repair ship—there are only around 60 such vessels operating globally—must locate the fault using sonar and remotely operated vehicles, grapple the cable to the surface, splice in a new section, and re-lay it. A single repair operation routinely takes weeks and costs millions of dollars. There is, bluntly, no rapid-response infrastructure for underwater communications crises.

The New Great Game: Geopolitics Goes Underwater

What has transformed submarine cables from a technical concern into a geopolitical flashpoint is the growing recognition that controlling or disrupting this infrastructure confers enormous strategic advantage. Intelligence agencies have long understood this. Declassified documents confirmed that during the Cold War, the United States Navy conducted covert operations—most famously Operation Ivy Bells in the 1970s—to tap Soviet military communication cables in the Sea of Okhotsk. What has changed is the scale, the actors, and the stakes.

China’s role in the global cable ecosystem has become the defining controversy of the current era. For much of the early twenty-first century, Chinese state-linked companies, most notably HMN Technologies (formerly Huawei Marine Networks), aggressively expanded their cable-laying and maintenance capabilities. By the early 2020s, HMN Technologies had built or helped build a significant share of the world’s submarine cable capacity, raising acute concerns in Washington and allied capitals about potential surveillance access or the ability to introduce vulnerabilities into the network at the hardware level.

The United States government responded with a series of measures aimed at limiting Chinese involvement in cables serving American interests. The FCC’s “Team Telecom” interagency review process began scrutinizing and blocking cable landing licenses for systems with Chinese involvement. The Pacific Light Cable Network, a project that would have connected the United States to Hong Kong, was effectively blocked in 2020, when its backers withdrew the Hong Kong portion of the application after federal reviewers recommended denial. A subsequent proposal to reroute the cable to the Philippines and Taiwan instead was itself subject to prolonged regulatory review.

The tension extends beyond hardware. Russia’s deep-sea naval activity near known cable routes in the North Atlantic and around critical chokepoints has alarmed NATO planners for years. Multiple NATO reports and assessments have documented a significant increase in Russian submarine and surface vessel activity near submarine cable infrastructure. In 2024, a Chinese vessel was linked to damage to cables in the Baltic Sea, an incident that occurred amid heightened tensions following Russia’s invasion of Ukraine. The episode—which Baltic nations and NATO members treated with deep suspicion—illustrated how the line between accident and sabotage is difficult to prove and easy to exploit.

Big Tech Takes the Plunge

One of the most significant structural shifts in the submarine cable industry over the past decade has been the dramatic entry of large technology companies as direct owners and operators of cable systems, rather than mere customers of carrier consortiums.

Google, Meta, Microsoft, and Amazon have collectively invested billions of dollars in proprietary submarine cable infrastructure. Google’s Dunant cable, connecting the United States to France, became operational in 2021. Its Equiano cable, running from Portugal to South Africa, began service in 2022. Meta has invested in the 2Africa cable, one of the longest submarine cable systems ever built, encircling the African continent with connections to Europe, the Middle East, and Asia. Microsoft has partnered in multiple transatlantic and transpacific cable projects.

The motivations are straightforward: hyperscalers require colossal bandwidth to serve their cloud platforms and content delivery networks, and owning cable capacity directly is significantly more cost-efficient than leasing from traditional carriers at scale. As of recent industry surveys, technology companies now own or have major ownership stakes in a substantial fraction of total global submarine cable capacity—a shift that represents a fundamental change from the traditional carrier-consortium model that dominated the industry for most of its history.

This concentration of private ownership in critical national infrastructure has itself become a policy concern. When a handful of American corporations control a disproportionate share of undersea bandwidth, questions arise about regulatory oversight, equitable access for smaller nations and carriers, and what happens to that infrastructure during a geopolitical crisis or conflict. The cables are private property, but their disruption would constitute a national security emergency.

Who Is Actually Guarding the Seabed?

The honest answer, as of today, is: not enough people, with not enough resources, and without adequate legal frameworks to do the job properly.

International maritime law, particularly the United Nations Convention on the Law of the Sea (UNCLOS), provides some protections for submarine cables. Deliberately damaging an international submarine cable in international waters is a criminal offense under the convention. Most nations that have ratified UNCLOS have enacted domestic legislation criminalizing cable sabotage. But UNCLOS enforcement depends entirely on individual nation-states, there is no international body with meaningful enforcement authority over the high seas, and the attribution challenges in investigating deep-water cable incidents are immense.

NATO formally designated submarine cable protection as a priority concern, and the alliance has expanded its maritime patrol activities in sensitive areas, particularly the North Atlantic and the Baltic and North seas. The alliance’s Maritime Centre for the Security of Critical Undersea Infrastructure, established in response to the sabotage of the Nord Stream pipelines in 2022, represents an attempt to build a more systematic approach to undersea infrastructure defense.

Individual nations have taken their own steps. The United Kingdom has invested in dedicated naval capabilities and intelligence resources focused on undersea infrastructure threats. Norway, acutely aware of its exposure given the concentration of cable routes and energy pipelines in the North Sea, has increased surveillance operations. The United States, through a combination of Navy assets, intelligence community resources, and the cable licensing review process, has attempted to build a more integrated defensive posture.

But significant gaps remain. Monitoring the entirety of the world’s cable network is essentially impossible with current technology and resources. The cables traverse international waters, exclusive economic zones, and territorial seas across dozens of jurisdictions. A coordinated multilateral response to a sophisticated state-sponsored attack would face daunting legal, diplomatic, and technical challenges. And critically, there is currently no true rapid-response repair capacity that could restore a severed cable in anything less than several weeks.

The Repair Gap and the Race to Build Resilience

The shortage of cable repair vessels is a structural vulnerability that has received growing attention from policymakers and industry analysts. The roughly 60 ships in the global repair fleet are aging, unevenly distributed geographically—with relatively few vessels serving the Pacific and Indian Ocean regions—and operated primarily by a small number of specialized companies.

Efforts to address this gap have accelerated. Subsea cable companies and technology giants have committed to expanding the repair fleet. There have been discussions within NATO and among allied governments about the potential for military or government-operated repair vessels that could respond to strategic cable damage outside the commercial repair timeline. Some analysts have proposed pre-positioning repair ships and equipment in strategic locations.

On the infrastructure design side, there is growing emphasis on resilience through redundancy. More cable landings, more diverse routing, and the development of additional cable systems connecting regions through multiple paths reduce the catastrophic risk of any single cable failure. The Pacific region, in particular, has seen significant investment in new cable routes to reduce the concentration risk that the 2006 Taiwan earthquake so dramatically exposed.

Advances in cable monitoring technology also offer some hope. Fiber-optic cables can be used as distributed sensors: seismic activity, pressure changes, and even the acoustic signatures of vessels and submarines can be detected by analyzing the behavior of light transmitted through the cable itself. This distributed acoustic sensing technology is increasingly being incorporated into cable network monitoring, offering a potential early-warning capability for both natural and human threats—though its practical deployment at scale remains a work in progress.

For those who work in telecommunications security or network operations and want to better understand the physical layer of internet infrastructure, resources like submarine cable network reference books can provide valuable technical grounding in how these systems are engineered and maintained.

A Reckoning That Cannot Be Deferred

The conversations that should have happened twenty years ago about submarine cable security are happening now, with urgency that reflects how much time has been lost. The infrastructure that carries virtually all of the world’s international data traffic was built on assumptions—of cooperative international relations, of technical obscurity as a form of protection, of private market solutions being adequate—that no longer hold.

The challenge is compounded by the intersection of several simultaneous pressures. The US-China technological rivalry has injected strategic calculation into decisions about cable routing, equipment procurement, and landing rights that were once made purely on engineering and commercial grounds. Russia’s demonstrated willingness to target critical infrastructure—on the seafloor as in other domains—has moved undersea sabotage from theoretical to documented risk. And the accelerating concentration of cable ownership among a small number of technology corporations has created a peculiar situation in which the fate of global communications infrastructure depends in significant part on the business decisions of companies whose primary accountability is to shareholders, not governments.

There are no easy solutions here, and anyone offering them should be viewed skeptically. Meaningful improvement in submarine cable security will require sustained international cooperation among nations with competing interests, substantial investment in monitoring and repair capacity, more rigorous governance frameworks for cable licensing and oversight, and genuine progress on the technical challenges of deep-sea surveillance. It will also require political will that has, historically, been easier to summon after a crisis than before one.

The cables are still there, in the dark, carrying the world’s conversations. The question is not whether this infrastructure will eventually face a serious attack or catastrophic failure. It is whether, when that moment arrives, anyone will be prepared.


For policymakers and analysts tracking infrastructure security who want to build deeper institutional knowledge, critical infrastructure security policy guides offer systematic frameworks for thinking through protection strategies. Network engineers working on resilience planning may also find fiber optic network design references valuable for understanding the technical constraints that shape security decisions.

As an Amazon Associate, The Rough Idea earns from qualifying purchases.

Advertisement