
Roughly 95 per cent of the world’s international data travels through fibre-optic cables lying on the ocean floor, an infrastructure that is fragile, hard to repair, and increasingly contested. To make sense of what is at stake, Hegemon spoke with Dr Melanie Garson, Associate Professor in International Security at University College London and a specialist in cyber and technology geopolitics. Formerly Cyber Policy Lead and Acting Director of Geopolitics at the Tony Blair Institute for Global Change, she advises governments and industry on digital resilience and the security of communications infrastructure. She spoke to us about the fragility of the network, grey-zone sabotage in the Baltic and around Taiwan, and why the balance of power increasingly lies with the companies that own the cables.
What is the role of subsea cables in modern digital economies — in particular, which of their functions make them so hard to replace?
They are, in effect, the backbone of our digital economy. The exact figure changes, but around 95 per cent of the international data connecting continents flows through these cables that sit on the ocean floor. They underpin our access to the internet, internet phone calls and financial systems. It is a complex underwater network: the cables themselves, the tubes that hold them, and the landing stations where they connect to terrestrial fibre-optic or broadband networks. They are hugely significant to connectivity as a whole.
They are also fragile, in three respects. First, they are susceptible to severe geological movement, setting aside anything malicious for the moment. I think back to when Tonga had a volcanic eruption in 2022 and the island was unable to access the internet via its subsea cable for weeks. Second, because they lie on the seabed, they can legitimately be severed by a dragging anchor or other activity on the seabed. That would be unintentional, arguably negligent, given we know where they are, but it can happen regardless. Third, very few organisations can fix them. It is here that we begin to see the problem: those few organisations that can repair subsea cables require licensing to operate within certain maritime jurisdictions, and a suite of licences to do the actual job.
When we speak about control over a subsea cable network, what are we actually describing?
Fundamentally, it is not necessarily about who has control of the cable, because in some respects, once cables are on the ocean floor, they are out of your hands, they have to cross various jurisdictions and legal maritime domains, and you would not necessarily have an obligation to maintain or fix them either. The control element comes into play with the receiver: who owns it, how data is distributed through the rest of the network or the cable itself, and who then has access to the information flowing through that cable. It is a question of whether you have the right to route your traffic through it. That does not give you control, but it does give you access to the network.
Looking at subsea cables as digital infrastructure in the wider geopolitical arena, is access worth more than control?
Yes, I think so. We have had examples where cables have been disrupted and the questions that follow are “can another cable pick up your traffic?” and “whose cable is that?” This is where we get large technology companies, not telecommunications companies in themselves, that have invested in cable networks, either singly or in consortia, to assure their own data traffic. Google has cable; Meta has cable now. The function of that is, yes, to assure their traffic, but it also means they exist outside the standard cable network, which gives them a level of power. That is derived partly from not having to put traffic on a government network, but also through its resilience: when a cable in a network goes out, as we saw on the West Coast of Africa in 2022, someone can pick up the redundancy.
We have a huge, expansive cable network that is fragile from the outset, difficult to fix, easy to interfere with unintentionally, and can be interfered with intentionally — and there is new technology all the time that will affect the potential stability of the network.
What kinds of strategic contest have emerged around cables?
We have seen in the Baltic, quite clearly, that cables have been severed several times. The problem is the plausible deniability around whether it was simply a dragging anchor or negligence in that particular case. That is why, in some respects, it has become a tool within the grey-zone warfare toolbox: the difficulty of identifying intention. We saw the appetite for deliberate disruption stated clearly in December 2023, when the Houthis posted maps of the subsea cable network in the Red Sea across Telegram and Twitter, calling for those lines to be severed. These are critical lines, around 20 per cent of all internet traffic moves through this strait, which is something we need to think about even now. In early 2024 that cable-cutting did eventually happen, though whether it was intentional is still not clear. We have to think strategically about where our wars are taking place, such as the current tensions around the Strait of Hormuz. Only recently, Iran proposed putting a tariff on data traffic moving through the subsea cable, although how you would actually do that, I am unsure.
On espionage, the benefit of submersibles is that you can equip them to amplify and tap into signals in cables. There are also ways to tap into the landing station on the terrestrial side. There are suggestions of supply-chain backdoors as well, even through the fibre optic itself, and we have seen cases where a whole rip-and-replace operation has been staged to remove Chinese fibre optic and minimise the ability to tap. From the cybersecurity perspective, at least to secure the data, there is increasingly more technology that can secure the optics, but it remains a high-stakes arena for sabotage and espionage, especially as it sits below the threshold of war, in a grey zone that could potentially escalate.
What can we reasonably say about Russia’s relationship to the recent pattern of cable damage in the Baltic?
There has been an increase in cable sabotage in the Baltic since the beginning of the Ukraine war. That is notable, and it is not a claim made against nothing. It has been a question of the shadow fleet, and of the Eagle S incident, which was the one with complications around maritime law. It raises questions: under what flag is the ship, who is on board, and in what jurisdiction is it? The case would have been brought in Finland, but it could not be, because they did not have jurisdiction under maritime law, so it becomes quite difficult to work out who, from a commercial perspective, is liable for the repair. From an insurance perspective, I would also say one would be unlikely to want to declare an act of war, as that would often trigger the war-risk exclusions found in most standard policies. In dealing with those cases of negligence and damage, it becomes much more difficult, because we are dealing with the law of the sea, which is harder to reason about given its unique boundaries and the question of where these incidents actually happened.
We can reasonably say that cable-cutting has increased since the start of the Ukraine war, and that the shadow fleets operating across the Baltic have been making use of complex jurisdictional and maritime law to obstruct serious investigation.
Have there been any examples of successful, cooperative remediation of cable disruption in this area?
I am not sure how many successful cooperative remediation operations there have been, but it comes back to the remediation problem as a whole, because there are so few companies that can come in and do the work. I know this is one of the things NATO has been talking about: how do you create that resilience and cooperation? We tend to get coordination in the investigatory realm; the Nordics work very well together anyway and would collaborate to investigate a disruption as far as possible.
There are talks at EU level through the Joint Communication on subsea cables released earlier this year, part of which envisages some kind of cooperative remediation framework. Formal cooperative remediation is not quite there yet, but the right organisations are now discussing it. NATO is, for example, with Baltic Sentry, although that is more of a preventative mechanism than a remediation one.
Shifting perspective from Europe to Asia: Russia is not alone in these grey-zone tactics, and China has focused a good deal of its grey-zone activity on Taiwan. At the most basic level, what would the purpose of cable disruption around Taiwan be?
From a Chinese perspective, it would completely disrupt the Taiwanese economy, the effect would be dramatic. Taiwan relies on around 14 cables. It is worth visualising Taiwan in a “triple-threat” position: first, it produces a key asset in the supply chain of the global economy; second, it sits in an extremely bad place for geological activity; and third, there is the threat of a great power looming over it. China carries out maritime exercises all the time and has recently unveiled, quite publicly, two different types of autonomous and semi-autonomous submersible with cutting capabilities. One, it claimed, was for subsea engineering works, and comes equipped with a diamond-headed cutting tool. While these could be used for genuine deep-sea engineering, there is a clear dual use. With this kind of technology there is a claim on both sides, prevention and disruption, where autonomous submersibles can serve as surveillance and deterrent, but are also capable of cutting cables. So it comes back to perception and misperception, and to traditional international relations, about what this technology signals. It is a deterrent, or a warning, against upsetting China in the South China Sea; and for people wondering how China could move against Taiwan, this is one of the ways it could be done.
Given the differing commercial contexts of Russia and China in subsea cables, are there clear strategic differences in the control they seek through this kind of disruption — or is that too simple?
I think both have the potential to use cables as part of their strategic, holistic operating approach. We have to consider how they operate strategically. Russia has a very holistic approach to achieving its objectives in a hybrid or multi-domain way. Adding the interference, or significant discomfort, of persistent disruption on an ally, and because it sits below the threshold of warfare, well within the grey zone, it is a good way for Russia to express displeasure at the Baltic states without going full-force against them. Russia is very much using it as a tool in its arsenal, but one that comes with a lot of plausible deniability about intent, so it works as an act of either mass disruption or minor disruption. If you add an element of information warfare and ask where that sits, you begin to get a convergence between the two states, and the strategy behind it.
China and Taiwan are slightly different, because you could isolate Taiwan, but that would also impair your own ability to conduct information warfare. If you cut Taiwan off entirely from the internet and all digital communications, and then interfere with whatever rescue satellite capability might become available, you lose the surveillance and information-warfare capability. So from an operational perspective there is a definite trade-off for China, and it is actively balancing that.
Is it possible to separate China’s commercial expansion from its strategic goals?
It was always part of backing its own Chinese telecom operators, as part of the Digital Silk Road and the expansion that provides that kind of data network. Huawei underpins a huge amount of cable network, connected in some way to around a third of the world’s countries, so many would be linked through a Huawei network. You would have to check, as many of these are owned or co-owned, but it is all part of network expansion. You could not really separate the commercial expansion from the strategic goals: with China, they come in the same package.
Can we say the same for Western states, the growth of hyperscalers, and the nature of their relationship with the American executive?
I think this predates the current relationship with the executive in the US. These things take time to build, so you have to think about the mapping process and the licences. Anything being built today was conceived years ago. Almost everything we see now was already thought out. The only real difference now is that it is less focused on the relationship with the executive and more about hyperscalers being able to pump data at scale. They have built it more for themselves than as part of a US sovereign project. That is different from the Chinese model, where the state has investment in many of these companies and there are few genuinely private companies at this level.

How has the shift from state-linked telecommunications companies and consortia towards private, hyperscaler-led projects altered the state’s ability to govern or exploit cable networks?
It definitely affects the ability to exploit them, because you would be acting on something that is not your own, and that would be a criminal act. You also have to consider that these things are expensive and cross-jurisdictional; many of them are built through public–private partnerships, so you have to think about who you are acting against, and what permissions you may or may not have among the consortium partners. We know espionage occupies a sticky position under international law, it is not expressly forbidden, thinking of the Lotus principle, but the question with something like a subsea cable is whether you are doing any damage to it, and whether that has physical ramifications, such as taking out the actual network.
Look at what has happened recently because of the war involving Iran, and some of the networks due to begin development. There was, for instance, an extension of a cable from the African continent that would have connected the Gulf with India. Alcatel had to invoke force majeure, and that has affected India, which had spent years trying to get this consortium together. India is an interesting example when considering cable resilience, because it has no indigenous repair capability, it has to go outside the country whenever it needs repairs. It also has an interesting position on choke points, as all its cables land within the same six-kilometre stretch outside Mumbai. Around 60 per cent of the traffic coming through that landing point goes through the East–West corridor via the Red Sea, and India was severely affected by the severing in 2024 that we mentioned earlier.
Would it be fair to say that networks are becoming less geographically concentrated but more centralised at the level of corporate ownership? If so, what practical control does that grant?
It depends from country to country, and you will still find that a lot of them are funded through consortia, with different telecommunications networks and private-sector elements involved, so I would not go that far. Google has around 30 systems and Meta somewhere around 20, but that is still not a majority stake in the overall global network. What it does for them is give them a measure of independence for their own data. As I say, it is difficult, it is a long process, it is expensive, and cables are hard to maintain; and because most are done by consortium, ownership does not really translate into that kind of control. With China it may do, as it has a large sovereign stake in its system, but even then, not entirely. India has Tata Communications and quite a lot of systems, but most are funded by consortia between telecom and technology firms to split the cost. The only real practical control I can imagine it granting would be if a state found an amenable party to build its network, it could then have the ability to cut off internet access if it wanted to.
What could happen when the interests of states and corporations diverge, under the current arrangement or in a future with more corporate ownership?
The state would have to look hard at where, and with whom, the majority of the cables coming into their country sit, and how reliable that is. The question is whether you end up with a particular sovereign pain point, much as people worry about Starlink and its role in connectivity. Do we have the potential pain point that, if something happened to your network, the only party you could call would be a hyperscaler? And what does your relationship with the US look like, are you insulated from any kind of tariff or belligerent activity from them? Further, is it possible for the US to get itself into a position, as it did with Anthropic, and disallow any use of its network? You could then have a problem, but that is a lot of ifs.
There are places in the world where it would be genuinely problematic, the Bahamas, and island states often served by only one cable. Their resilience planning is a completely different picture, and the odds are you are looking at some kind of backup satellite network. That is when you get questions of sovereignty and pain points.
So perhaps the real issue with diverging interests is a second-order one: the cables are built and the infrastructure is there, but it is when something goes wrong that diverging interests cause a problem?
I would agree, though it is in their interest to keep these networks functioning, as with Google stepping in to offer cables where they have been functional and others have not. Look at the wider picture: when connectivity goes down in a country, presumably everything in that economy goes offline too. If you are Google, weighing whether to step in, then irrespective of who owns the cable, people will likely be using your services and benefitting from that traffic anyway. There is also the other issue: if China steps in offering its cable, your data is likely being siphoned off somewhere, and that is when you weigh your options. So it is not really in anyone’s interest, except China’s, for whom it is an opportunity to step in, to leave a country without connectivity. There is also the amicable element: people usually respond to these kinds of disasters fairly well.
Do you think we have seen the extent of disruptive action against subsea cables? How might coercion against subsea networks evolve beyond the ambiguous physical damage we have seen so far?
I certainly do not think we have seen the end of it. As I say, we see things like Iran’s call for tariffs on data traffic, the practicalities are ambiguous, but the fact that someone has come up with the idea signals the potential. People are always trying to create new leverage with subsea cables, and I think the use of autonomous surveillance on cables, and the increased use of submersible autonomous drones or vehicles of some sort, creates a new level of potential threat.
The biggest element within this is not having sufficient repair capacity globally, which is massively under-invested in, although it is a difficult thing to supercharge. There are something like 200 breaks in cable being repaired at any given moment, but how many companies can that really support, especially as it is an expensive process for the repair firms? One also has to ask what they do to make money when they are not repairing cables, and I think that is a big pain point.
Disruption is still quite easy, and a change in strategy may well come. Looking at the alternatives, direct-to-device services via satellite are not really there yet, the latency is not low enough and the speed is not there, so I think we have a good few years before we reach an alternative. And we are trying to deal with all this in an age where global governance, and the mechanisms for joint remediation or information-sharing, are quite sticky.
If complete protection is impossible, what should a credible resilience strategy prioritise?
It should certainly look at diversification of your cables, you would not, ideally, have all of them landing within a six-kilometre stretch. People do forget about the ground stations and physical infrastructure; it is not just what happens at sea. There are significant opportunities for disruption and tampering, and you have to ensure sufficient security at the end point, not just the middle. We need to think about that diversification, and also about which relationships can pick up redundancy, who, or what, can take over. Do you have access to a sovereign satellite network? Do you have commercial relationships? What does that picture look like, and how do you activate it?
The point is that in today’s data-fuelled economy, for most people, networks and systems cannot afford to go down. A good example to draw on is what happens with accidents, I think of the fires across the Iberian Peninsula and the havoc they caused. So the question, at government, company or societal level, is: do you have a plan for any kind of outage, irrespective of the source? Bear in mind that 95 per cent of data goes through the cables, and the exposure varies dramatically depending on the size of your country, whether you are an island, and whether there is geographic concentration of your landing points.
So there is a heavy emphasis on relationships — whether commercial, or between states or their agencies?
Yes, exactly, and also on the intentionality of where you land your cables. You could land somewhere remote, like the Outer Hebrides in rural Scotland, so it is safer, but that is not useful for servicing London, so you have to weigh the commercial decisions and the trade-offs. Whether it is a company or a country, investing in redundancy is often a very hard ask.
Much of the redundancy required for national resilience may be commercially inefficient. Would you agree — and if so, who should pay for it?
That will vary from country to country, as it is closely linked to the telecom network, who is providing your broadband, your connectivity, and to what the wider picture looks like. This is one of the things we look at when considering the power of technology companies, and the way they have acquired greater autonomy. If Google is running and paying for its own network, connected to its own interests, then were something to happen to a government-level cable, Google would remain operable. That might be for its own interests and data centres, whatever the picture is, but that is where such companies gain a little more power within the ecosystem than a state does. They do not have to go to anyone else and ask. If you are Amazon, you have both cable and satellite, so from a connectivity point of view you are entirely independent. When you take a holistic picture of the geopolitics, of where power lies within a communications stack, it is the companies that can capitalise on, or hold, positioning at every single layer that gain the serious advantage.
Will efforts to secure subsea cables preserve a resilient global network, or accelerate its division into competing political and technological systems?
The competing technological systems sit at a level above the network layer. Yes, there will be the option, as a nation, to choose from a sovereignty perspective which system transmits your data between points A and B. That is what China has intended as part of its Digital Belt and Road, and how it has been borne out commercially as well. But from the point of view of technological fragmentation, I do not think this is the biggest part of the picture, it sits at a slightly higher layer. And countries would always want diversification as part of their system, rather than keeping it all in one pair of hands.
Dr Melanie Garson is Associate Professor in International Security at University College London. This interview appears in Hegemon No.1 – Chokepoints.