How Much Cybersecurity Depends on Cables

Quanta cyber-security passa dai cavi

by Marco Braccioli

Co-Director of Cybersec at the Icsa Foundation

As with other domains, the underwater environment is becoming increasingly shaped by human activity and, as a result of growing hybrid competition among global and regional powers, is turning into a theater of confrontation between threats and deterrence. The targets are easy to identify, excluding purely military ones: offshore oil & gas platforms, power distribution and transmission networks, optical fiber cables, offshore wind farms (fixed and floating), and innovative renewable energy platforms. The damage assessment process follows a well-defined sequence: detect and confirm the damage, locate it, access the area for investigation, limit its consequences, respond to the emergency, and restore operations.

So far, everything seems straightforward, but how can these critical infrastructures be predicted or monitored? In the case of gas pipelines, for example, protection measures range from anti-corrosion coatings to submarine anti-buoyancy weighting systems, while pressure, temperature, and flow rates are continuously monitored digitally through remote control systems.

According to a recent study, there are globally 2.7 million kilometers of data and power cables and 1.2 million kilometers of oil & gas pipelines. The underwater market is estimated to reach €400 billion by 2050, with more than €30 billion in innovative solutions and €10 billion in underwater communication technologies. Most innovation spending will focus on data collection and analysis, underwater drones for infrastructure monitoring and repair, multi-sensor nodes equipped with acoustic modems, and underwater gateways integrated with telecommunications and space networks. The main communication requirements for both the civilian sector (critical infrastructures) and the military sector (multi-domain operations) include strategic communications for deep-diving underwater units, high-speed data exchange at the surface, low-latency bidirectional tactical communications with underwater units in all operational scenarios, monitoring and control of critical underwater infrastructures, and the Internet of Underwater Things. The technological challenge is primarily related to underwater transmission, which can be achieved through three different methods.

The first is radio frequency communication, which easily crosses the air-water boundary and is not affected by turbidity, salinity, or pressure gradients. It is also immune to acoustic noise and provides high bandwidth (up to 100 Mb/s) over very short distances. However, it is sensitive to electromagnetic interference and has limited range underwater, making it more suitable for shallow waters. Acoustic communication, by contrast, is a well-established technology capable of reaching distances of up to approximately 20 kilometers, but it experiences significant reflection and attenuation when signals cross the air-water boundary and performs poorly in shallow waters. Furthermore, it is negatively affected by turbidity, environmental noise, salinity, and pressure gradients, with bandwidth typically ranging from a few bits per second up to around 20 kb/s. Finally, optical communication offers extremely high bandwidth, on the order of gigabits per second, but does not easily cross the air-water boundary, is highly sensitive to turbidity, suspended particles, and marine fouling, and requires a direct line of sight, precise node alignment, and operates over very short distances.

Turning to the cyber dimension of threats against submarine cables, these can be grouped into several broad categories: data exfiltration, hijacking and takeover of unmanned assets for malicious purposes, phishing, attacks against underwater data centers and pipelines, and disruption of communications. A recent study by the International Cable Protection Committee found that between 2010 and 2024 approximately 42% of submarine cable failures were caused by fishing activities and anchoring, while an additional 44% were at least partially attributable to deliberate acts of sabotage.

The European Union has established a security framework around submarine cables based on the CER and NIS 2 Directives. The former calls on Member States to adopt measures to strengthen the resilience of critical entities and protect critical infrastructures. The latter requires providers of digital infrastructure and services operating submarine cables to protect their information systems, networks, and physical environments against all hazards. The European Commission has also issued Recommendation 2024/779 to enhance the security and resilience of submarine cables through the mapping of existing cables (updated at least annually), risk, vulnerability, and dependency assessments, and specific attention to supply chain risks. Within this framework, the development of a Cable Security Toolbox is also envisaged, defining risk mitigation measures, particularly regarding high-risk suppliers, regular information sharing on incidents, awareness and best practices, and the deployment of innovative solutions for detecting and deterring threats against submarine cable infrastructures. An increasing number of recent incidents in the Baltic Sea, the Mediterranean, and the Red Sea are suspected to be deliberate acts of sabotage against communication cables or pipelines. Although difficult to attribute with certainty, they are consistent with seabed warfare operations. State actors may employ submarines, mini-submarines, AUVs, and civilian vessels operating as cover to cut or damage cables at strategic points, creating targeted or demonstrative disruptions as part of hybrid warfare campaigns. Beyond physical cutting, a key threat is the clandestine interception of traffic: advanced military capabilities enable the installation of probes or devices along cables or inside repeaters to monitor or redirect data flows. At the same time, cyber espionage campaigns against operators aim to gain access to management networks in order to monitor or copy sensitive communications without interrupting services.

The most exposed points are landing stations, where power systems, optical equipment, routers, and SCADA/NOC systems converge, often accessible remotely from central facilities. Vulnerabilities within these systems may allow threat actors to alter configurations, disable cable segments, manipulate routing paths, or prepare more precise physical sabotage operations. The main risk vectors include attacks against network control and supervisory systems (with impacts on service continuity and load balancing), physical sabotage of cables or landing stations (often difficult to attribute with certainty), and dependencies on data centers, consortiums, and third-party suppliers that expand the attack surface. Key defense measures include asset discovery and comprehensive mapping of routes and sensitive points, centralized controls and continuous monitoring of security systems, maritime surveillance and rapid response capabilities, including repair operations and network redundancy, as well as cooperation among States, the EU, and private operators, because protection is not merely a technical issue but also an organizational and strategic one. As for physical cable protection, the trend is toward increasingly sophisticated sensor technologies, including distributed fiber-optic sensors (useful for detecting vibrations, deformations, and disturbances along cable routes), tension and strain sensors (for identifying abnormal traction on cables), acoustic and vibration sensors at critical points (particularly near landing sites), and perimeter sensors and CCTV systems at landing stations (to detect unauthorized access or physical tampering).

Finally, considering the current relevance of the topic, attention turns to the Strait of Hormuz and the cables that pass through it. This represents a genuine strategic weapon in Iranian hands: the vulnerability of submarine cables. Sources identify systems such as AAE-1, Falcon, Gulf Bridge International, SEA-ME-WE, and TGN-Gulf among those potentially exposed in the area. Damage to these connections could slow Internet services, disrupt banking transactions, logistics operations, telemedicine services, and emergency communications. In practical terms, the Hormuz crisis highlights a hybrid warfare vulnerability: the most likely consequence is not a total collapse of the Internet, but rather a severe and localized degradation of networks with significant economic and financial repercussions—another risk that, in the current geopolitical context, we can scarcely afford.