Operational notes Security

Fibre-Optic Tapping: the Risk Sits in the Splice, Not in the Cable.

5 min read

An open-air fibre-optic splice closure, with labelled, unprotected cable bundles
An exposed splice, with no surveillance: this is where the physical security of a network is decided.

A commonplace has held for years: optical fibre is supposedly impossible to tap without cutting it, and any attempt would show up immediately. That is only partly true. Techniques exist that do not cut the fibre and, without active monitoring, leave no visible trace whatsoever. The real risk does not lie in the transmission medium: it lies in physical access to splices, closures and cabinets that nobody checks.

The myth of the inviolable fibre.

Optical fibre does not radiate a signal the way a copper cable does, and for this reason it is often said that “tapping it is impossible”. But extraction techniques have existed for decades and do not require interrupting transmission. The difference from copper is not the absence of risk: it is that the risk always requires direct physical access, not a remote attack.

How a fibre is actually tapped.

The documented techniques are few and well known to network specialists. The simplest is controlled bending: a clip-on coupler, available commercially, bends the fibre to its critical radius and forces a fraction of the light out of the core, without interrupting the connection. A bend of this kind typically introduces a loss of around 1 dB or more — measurable, but only if someone is looking for it.

The second route is optical splitting: a tap coupler, the same component described by ITU-T Recommendation G.671 for legitimate monitoring uses, with a typical split ratio of between 1% and 20% of the power, draws off a copy of the signal without cutting the fibre. More invasive, and rarer because they require precision instrumentation, are V-groove cleaving and evanescent coupling.

This is not abstract theory. In 2003 an interception device was found installed on the optical network of a US carrier, connected to access a fund’s quarterly data ahead of its official publication. The motive was financial, not geopolitical: a useful reminder for anyone who thinks the risk applies only to strategic infrastructure.

The weak point is the splice, not the cable.

None of these techniques works on an intact cable in a protected run. All of them require direct access to bare fibre: in a street cabinet, in a manhole, in a splice closure, in a patch panel in an unattended technical corridor. It is the very same point that determines the quality of a fusion splice: wherever the fibre is opened to work on it, it can also be tapped.

The physical security of a network must be designed alongside its installation, not afterwards. Closures with tamper-evident seals, cabinets locked with an access log, labelled and documented patch panels: these are cabling measures, not IT-department measures. It is no accident that data-centre cabling standards (the ISO/IEC 11801-5 and EN 50173-5 family) mandate organisation and traceability of cabinets: disorderly cabling is also cabling in which one extra splice goes unnoticed.

How to detect an attempt.

Here there is good news. Every extraction technique introduces a measurable optical loss. If a run has a certified attenuation baseline — the same one produced at handover by a bidirectional OTDR test — any subsequent deviation is a concrete warning sign, not a hypothesis.

It must be said just as clearly what is not enough. ITU-T Recommendation X.805 on end-to-end security architecture describes protection schemes against cutting the fibre to insert an inline tap, but those schemes, by the text’s own admission, do not detect an extraction carried out through a monitoring port that does not interrupt the connection. A network design that is “secure” on paper can remain blind precisely in the face of the simplest technique, bending. Continuous optical power monitoring, not just a one-off test, is the control that closes this gap.

Checklist: what to do.

  • Have every splice and closure in the network mapped, with a georeferenced as-built: knowing where the intended splices are is the first line of defence against unintended ones.
  • Lock critical cabinets and manholes, and, where the risk justifies it, fit tamper-evident seals on splice closures.
  • Record a certified attenuation baseline for every critical run, with a bidirectional OTDR test.
  • Activate continuous optical power monitoring on the runs that matter — backbones, data centres, links to remote sites — and investigate every anomalous variation.
  • Limit the use of splitters and monitoring couplers to what is strictly necessary, and document them like any other splice.
  • Train maintenance staff to recognise signs of tampering: reopened closures, broken seals, bends that do not match the design.

The bottom line.

Optical fibre remains the hardest medium to tap without leaving a physical trace, but “hard” is not “impossible”, and the difference comes down to the physical security of splices, not a firewall. That is why we certify every run with a verifiable OTDR baseline and document every splice at the installation stage: without that baseline, a tapping attempt goes through and no one will ever know.

Do you have critical runs whose every splice you cannot account for, or an attenuation baseline that does not yet exist? Talk to an engineer: a free site survey and quote, to find out exactly what is going through your fibre, and who might be able to reach it.

Sources