Severed Submarine Cables: Network Resilience Is Physical
6 min read
99% of intercontinental internet traffic travels along fibre-optic cables laid on the seabed. The European Commission makes this point at the very opening of its cable security plan — a document that exists because, between 2024 and 2025, those cables began breaking with a frequency that alarmed governments and operators alike. The events in question concern the Baltic and the Red Sea, but the lesson concerns anyone designing a network: resilience is physical before it is logical. It holds true for a continent, and it holds true for a warehouse in the province of Modena.
Two seas, the same fragility
In the Baltic Sea, the sequence is well documented. On 17–18 November 2024, two data cables were damaged: the BCS East-West Interlink between Lithuania and Sweden and C-Lion1 between Finland and Germany; investigations focused on the anchor of the cargo ship Yi Peng 3, which had passed over both break points. On 25 December 2024, the tanker Eagle S dragged its anchor for tens of kilometres across the Gulf of Finland, severing the EstLink 2 power cable and several data cables between Finland and Estonia. In January 2025 it was the turn of a cable between Sweden and Latvia — and here Swedish authorities concluded it was an accident, not deliberate sabotage. In February 2025 the operator Cinia reported yet another fault on the Finland–Germany route, east of Gotland.
In the Red Sea, on 24 February 2024, three systems — AAE-1, SEACOM and EIG — were damaged in the Bab el-Mandeb Strait; the most widely accepted theory points to the anchor of the cargo ship Rubymar, struck by a Houthi missile and left adrift. According to estimates circulating among operators, roughly a quarter of traffic between Europe and Asia was affected. On 6 September 2025 the scene repeated itself off Jeddah: SMW4 and IMEWE were severed, degrading connectivity from India to the Emirates.
Sabotage or negligence, the technical point does not change: most submarine cable faults are caused by anchors and fishing gear. Physical objects meeting a physical object. No firewall comes into it.
The European plan: prevent, detect, repair
On 21 February 2025 the European Commission and the EU High Representative published the EU Action Plan on Cable Security, built on four pillars: prevention, detection, response and repair, and deterrence. This was followed by a risk assessment with route mapping and stress tests on key sections (October 2025) and, in February 2026, a €347 million package under the CEF Digital programme: repair equipment to be pre-positioned in ports, underwater surveillance tools, and €267 million for priority routes, with 13 “Cable Projects of European Interest” identified to steer investment.
It is worth noting where the EU is putting its money: not into software, but into alternative routes, repair capacity and knowledge of cable paths. It is the same hierarchy that should guide any network project, at any scale.
Redundancy is measured in metres of trench
When a submarine cable breaks, routing shifts traffic to other routes within seconds. The Baltic did not go offline: it lost capacity and gained latency. The logic worked because genuinely separate alternative physical routes existed. This is where many corporate and regional networks discover their fragility.
The classic case: two “redundant” links from two different operators that, for the final 800 metres, run through the same duct, cross the same bridge, enter the building through the same conduit, and terminate in the same cabinet. On paper they are two lines. For a mechanical digger, they are a single blow. Logical redundancy — dynamic routing, failover, dual equipment — is necessary, but it comes second: if the physical paths coincide, no protocol will save you.
True diversity is engineered on four levels:
- Separate routes along the entire path, not just at the origin: different trenches, different directions, different crossings. This must be verified metre by metre, not simply declared.
- Rings instead of trees, where geography allows: a fibre ring between sites, or between the nodes of a territory, survives a cut at any single point.
- Dual entry at critical sites: two building entry points on opposite sides, separate risers, terminations in distinct rooms. In data centres this is the standard; in many industrial and healthcare sites it is still missing.
- Documentation of actual routes: as-built records, georeferenced paths, OTDR certification of the routes. If you don’t know where your fibre runs, you cannot know whether your redundancy actually exists.
And an Emilian company with a single connection?
Let’s scale down. A company between Modena and Reggio Emilia with a single fibre route running alongside the provincial road: no anchors, but mechanical diggers, roadworks, subsidence, a lorry hitting a cabinet. A physical fault on a single feed means days of downtime, not minutes — because the repair requires permits, excavation and field splicing, and in the meantime the ERP system, telephony and connected production are down.
The sensible path is a gradual one. First: know where your fibre runs — ask the operator for the actual route through to the exchange and check the entry point at your site. Second: assess a second connection from the opposite direction, with a different operator and infrastructure; it often costs less than you’d think, and alternatively a professional radio link offers total diversity from trenching. Third: test failover under real load, because redundancy that has never been tested is a hope, not a plan. These are the same assessments we carry out during a site survey, with real numbers: metres, permits, the hourly cost of downtime.
Operational checklist
- Ask your operator for the actual route of your fibre (KMZ or as-built) through to the exchange.
- Identify the entry point at your site: a single conduit means a single point of failure.
- If you have two “redundant” lines, check that they do not share a trench, duct, entry point, cabinet or exchange.
- At critical sites, plan for dual entry: entry points on opposite sides, separate risers and rooms.
- Consider a different technology (radio link, business FWA) as a second path: diversity of medium is the most robust form of separation.
- Document and certify your internal routes: without measurements and as-built records, every fault starts from zero.
- Test failover at least on a regular schedule, under real load, and record the outcome in a report.
Do you have a single fibre connection, or two lines you’ve never truly verified? Talk to a technician: free site survey and quote, to find out what your network physically rests on.