• 09/04/2026

Undersea Cables: The Internet's Vulnerable Arteries

Far more than 90 percent of global data traffic is carried via undersea cables. They are the central arteries of the internet, and island nations in particular depend on them. Yet attacks on these cables reveal their vulnerability. Various measures, including international agreements, are meant to improve their protection. Just how vulnerable this global communication infrastructure really is in a crisis is examined by the article Critical Infrastructure: Global communication at risk – Rethinking cybersecurity.

Written by Uwe Sievers

Several undersea cables run across a vegetation-covered seabed in blue deep-sea water
Vulnerable lifelines: undersea cables often lie unprotected on the seabed.

Cables Are Irreplaceable

Currently, cables are irreplaceable — only a fraction of international communication runs via satellite. Satellite links have so far been slower and more prone to disruption. Undersea cables can carry far more data at lower cost. While the cables used to belong to major telecommunications companies, today it is tech giants such as Google, Amazon and Microsoft that operate their own undersea cables. The Facebook group Meta, which also owns Instagram and WhatsApp, is even planning to build its own global cable network. This growing dependence on individual tech companies is also a matter of digital sovereignty – more on this on the topic page Digital Sovereignty.

According to the online magazine Computerweekly, the cost of an undersea cable typically runs into the hundreds of millions. Laying a cable can take months. Where a cable faces particular danger, for instance near the shore or in shallow waters, a plough is often used to dig a trench up to three metres deep. But doing this along the entire length of a cable would be too costly, so even in shallow waters such as the Baltic Sea, cables mostly lie exposed on the seabed. This increases the risk from dragging anchors or fishing gear and makes sabotage easier. In November 2024, satellite images were captured showing a Russian-flagged freighter zigzagging across undersea cables in the Baltic Sea. Two important cables were damaged shortly afterwards. Because far more than 90 percent of global data traffic is carried through cables under the sea, disruptions can have devastating consequences. Given the huge number of daily financial transactions processed via this physical infrastructure, the cables are also a purely commercial necessity.

The few repair ships available worldwide are heavily booked. Repairs are hampered by weather conditions and jurisdictional issues in international waters. As a result, it can take weeks or months before a severed cable is repaired. At risk are not only data and telephone lines — power cables can also be damaged or destroyed. Geographic concentration is also seen as a problem, since many routes converge at just a few landing points, creating potential “single points of failure.” Such concentration risks are also a central issue for operators of critical infrastructure – more on this on the topic page Critical Infrastructure (KRITIS) – Importance and Protection.

 

 

GUIDE Agreement: Guiding Principles for Underwater Infrastructure Defence Exchanges

17 states, including France, the United Kingdom and Italy, but also Australia, Singapore and Qatar, recently adopted the first international agreement to protect undersea cables. The cooperation with partners in the Indo-Pacific region is based on the understanding that this is a global threat. The GUIDE agreement includes a number of planned measures. The participating states intend to set international standards for protecting cables, improve information-sharing on current threats, and have the military support civilian companies in monitoring and repairing cable routes. How technology is increasingly becoming a geopolitical weapon is examined by the Special Keynote: Technology as a Geopolitical Weapon.

Protective initiatives from NATO and the EU already existed in Europe beforehand. On 21 February 2025, the European Commission presented an action plan on the security and resilience of undersea cables. This project is complemented by a package of measures called the “Cable Security Toolbox,” which includes both strategic and technical initiatives. What additional regulatory obligations arise from this is examined in the interviewCritical Infrastructure Umbrella Act, NIS-2 and Cyber Resilience Act.

The planned measures include expanding the capacity of specialised repair ships as well as a network of underwater sensors and drone surveillance to detect sabotage more quickly. Increased military deterrence through more frequent patrols, for example in the Baltic Sea, is also part of the plan.

 

 

New Technologies Monitor Cables

The threatening developments of recent years are driving a surge in new diagnostic and defence technologies. For new cable deployments, for example, SMART cables can be used. SMART stands for “Science Monitoring and Reliable Telecommunications,” meaning these cables have built-in sensors that capture environmental data in real time. These are usually integrated directly into the signal amplifiers, known as repeaters. How similar sensor and monitoring concepts are also proving themselves in industrial practice is shown on the topic page OT Security.

The diagnostic methods focus mainly on acoustic and temperature measurements. One measurement technique that uses optical fibres as sensors is “Distributed Acoustic Sensing” (DAS). It makes local vibrations along the route visible, enabling early detection of disturbances and interference. To do this, laser pulses are sent through the optical fibre. Changes in the backscattered light allow conclusions to be drawn about events such as vibrations from ships, submarines or geological activity. This method can be used over very long cable distances.

Another method is “Distributed Temperature Sensing” (DTS), which monitors the temperature inside the cable. Its accuracy can reach one degree Celsius per metre of cable. Particularly with power cables, external influences can cause minimal temperature changes that allow conclusions to be drawn about the underlying problem.

Providers of these technologies include the Israeli company CyberRidge and the German company AP-Sensing.

Some countries are also trying to minimise risks through regulatory measures. Australia, for example, has introduced a preventive approval system for laying undersea cables, under which cables may only land in designated protected zones. This is meant to reduce risks from fishing and shipping. France has set up a central cybersecurity authority that monitors critical infrastructure, including undersea cable monitoring. Whether all these measures can effectively combat sabotage remains to be seen. How regulation and resilience currently stand across the KRITIS sector as a whole is analysed in the article Between Regulation and Resilience, the KRITIS Sector Remains Vulnerable.

How exhibitors and governments are advancing the protection of critical infrastructure beyond undersea cables is shown by the sessionSovereignty & Cybersecurity: Cybersecurity Without Compromise at it-sa Expo & Congress 2025.

Want to talk directly with experts on physical and critical infrastructure security? At the it-sa EXPO & Congress you can look forward to live talks, hands-on use cases, and direct exchange with exhibitors on physical and digital security. Visit now!

 

 

Sources:

T-Online: Nato macht am Meeresboden mobil

Heise Online: Dänemark setzt Überwasserdrohnen zur Überwachung von Nord- und Ostsee ein

Heise Online: Tiefsee-Kabelschneider: China feiert, Westen fürchtet

Frankfurter Allgemeine Zeitung (FAZ): „Der Meeresboden ist ein Schlachtfeld“

Defence Network: Norwegen: Israelische Technologie als Schutz für Unterwasser-Glasfaserkabel

APsensing: Homepage

Cyber-Ridge: Homepage

Computer Weekly:Sicherheit von Unterseekabeln: EU-Toolbox und NATO-Schutz