Go back

Cables Under Pressure: Securing Europe’s Subsea Cables

23m 44s

Cables Under Pressure: Securing Europe’s Subsea Cables

The podcast discusses the importance of subsea cables as the backbone of global internet infrastructure, enabling data, telecommunications, and energy services. Over 95% of international data traffic flows through these cables, underlining their critical role. Risks to subsea cables range from accidental damage, like fishing activities, to deliberate sabotage and espionage by state actors. The incident in the Baltic Sea, where subsea cables were severed, raised concerns about potential sabotage and espionage. Measures such as prevention, detection, response, and recovery are crucial to ensure the security and resilience of subsea infrastructure. The EU's Cable Security Action Plan outlines steps to address risks and enhance monitoring. Cooperation at the EU and global levels, involving private sector engagement, is essential to safeguard subsea cables from potential threats. The discussion also highlights the concept of hybrid warfare and the need for comprehensive approaches to protect critical infrastructure from malicious activities.

Transcription

3929 Words, 23711 Characters

Welcome to Cash Me If You Can, I'm your host Matt Pearl, director of the Strategic Technologies program at CSIS. In this podcast, we take a closer look at the technologies and policies driving tomorrow and how the United States can stay ahead in the global innovation phase. Welcome to Cash Me If You Can, where we explore the global forces shaping innovation, competition and tech policy. I'm your host Matt Pearl, and today we're looking at the infrastructure that makes the internet possible, subsea cables. Often referred to as the world's information superhighways, these networks on the ocean floor form the foundation of global connectivity. At the end of 2024, several subsea cables in the Baltic Sea were mysteriously severed. The identified ships claimed it was an accident caused by dragging anchors across the seabed. But just last month, Finnish prosecutors charged the captain and two senior officers of a Russian-linked oil tanker with sabotage. Authorities suspect the vessel is part of Moscow's shadow fleet, raising fears of a covert campaign to target Europe's critical infrastructure. To help us understand what's at stake, we're joined by someone who is very familiar with these issues. Ana Maria Asula is the cyber and economic counselor at this Estonian embassy in Washington, DC, where she works on issues related to cybersecurity, digital affairs, and technology. She previously served as a global digital governance fellow at Stanford University, as a senior researcher at Tallinn University of Technology, and as a legal researcher at NATO's Cooperative Cyber Defense Center of Excellence. With a PhD in law and years of experience bridging academia, policy, and international security, she brings deep expertise on how countries like Estonia think about cybersecurity and digital governance. We're very excited to have her on the podcast. Ana Maria, welcome. So to set the stage, Ana Maria, could you start by explaining what subsea cables are and what role they play for a country like Estonia? Yeah. Thank you, Matt. Like you alluded to before then, subsea cables can really be regarded as the backbone of the global internet infrastructure. According to statistics, more than 95% of international data traffic goes through the undersea cables. But here I'd like to underline that we really need to look at not only the undersea cables, but the whole set of subsea infrastructure, such as pipelines. That means that all in all, the subsea infrastructure is really relevant for data and telecommunication, electricity, and energy. We know that we have around 500 active undersea cables worldwide, spanning over 1.4 million kilometers in miles that's 870,000. These undersea cables take a lot of time to build, roughly one to three years, and they may cost more than hundreds of million dollars. In short, for Estonia, as for all the countries worldwide, the subsea infrastructure is crucial for data, internet, telecommunications, and also relevant for energy. As we discussed, subsea cables have a lot of consumer uses and uses for businesses, but as you say, we should take a holistic view. For a country like Estonia, how would you describe the economic and national security stakes if something goes wrong with subsea cables and the country is effectively cut off from that traffic? Yeah, sure. Given that our economies are very interlinked and that we depend increasingly on ICTs as well as energy, then in the circumstances where we have a rise of geopolitical tensions, we definitely need to acknowledge the risks. So, like with all critical infrastructure, I think the infrastructure providers really need to assess the risks, need to think of plan Bs. The operators need to analyse what the provision of their service is dependent on, what are the alternatives and how to act in case of an incident. So here the crisis management and exercising possible scenarios are really crucial. With data cables, many countries have a multitude of them. So if one is wiped out or cut, then most probably it does not have a significant influence on the services. However, when we think of energy and in let's say cold climates like Estonia, if during hard winter an energy pipeline is cut and severely damaged, this may definitely have significant consequences. And of course we need to also think about risks related to supply chain, risks related to other physical and technical incidents that may occur. So I think this is why for European Union in general, but also worldwide, the security and resilience of undersea infrastructure and cables is increasingly a relevant topic and on the top of the agendas for those countries. So what about espionage? Are there concerns that malign state actors could use techniques to monitor the data flowing through this infrastructure? Yeah, there is a lot of discussion on that. If you look at different studies, however, then you see that the main conclusions tend to be that while such interception or espionage might be theoretically possible, then it is challenging to carry it out in practice. But that said, I think nevertheless we need to be aware of different possibilities, especially given the fact that new technologies and new ways that the malicious actors could use to cause damage or intercept could be developed soon. So we've talked about some of the risks, and the other side of it is that US and allied officials have warned that if there are cable cuts, that the repair process could make them vulnerable to disruption, espionage, and other malign activities. And it seems as though in terms of addressing these risks, there's both an offensive and a defensive side to cables that you're in a unique position to talk about. So on the offensive side, there's the importance of laying more cables, right, both for security and resiliency. We rely on private companies to lay cables, as you've already noted. Are there policies that the Estonian government or other countries have adopted to ensure that we create an environment in which companies consistently lay more cables in order to create that resiliency? Yeah, that's a great question. I think I'd be careful when framing the narrative, saying that when talking about undersea cables, we have the offensive and the defensive viewpoint. If we look at the statistics, then we see that the large majority of incidents that have occurred with undersea cables, roughly 70% of them, are due to fishing activities, anchors, etc. In other words, because of human error or negligence or accidents. Other causes for such damage may be natural causes related to seismic activities, weather, etc. And then of course, yes, the possibility of deliberate sabotage. So that means that we have had to deal with incidents to subsea cables and subsea infrastructure for a long time. In that sense, there's nothing new here. What is new here is that at least in the Baltic Sea region, we see a pattern of these incidents occurring more frequently than we have seen before. Your question was about private sector and how can we incentivize them to lay more cables? Then I think here, it is a multi-layered approach. Countries need to look at their policy and regulatory frameworks that do not only incentivize the private sector, but in general offer protection for the critical infrastructure. This includes multiple activities starting with prevention. How do you react to these incidents and how do you deter possible attacks? So you started with a really good point in terms of the fact that in most cases, these cable cuts are accidental, right? But doesn't that make it very difficult to distinguish between intentional malicious cable cuts and these phishing accidents or these cable cuts due to other causes? And how is Estonia, both on its own and working with its allies and partners, attempting to address some of the challenges in terms of figuring out whether these cable cuts are intentional? Yeah, that's a great question. And you're absolutely right. It is one of the challenges. So the activities that are being undertaken in the Baltic Sea, European Union and also in Estonia and among our closest neighbors, they start with preventing these attacks already at the early stage, right? So there are different capacities for monitoring the situation, for creating an up-to-date threat assessment, which then needs to be shared with partners, with neighbors. And it is really relevant that here we wouldn't have multiple different approaches, but we would have a comprehensive EU level approach that would help us to address these issues. When it comes to your question, how do we understand what is the intent of a certain incident? Then here, it really depends on the amount of evidence that is available to be gathered. This can be gathered through criminal procedure. We have seen cases where countries such as Estonia and Finland have started specific criminal procedures and are gathering evidence as part of that. And for evidence, you would need to ask other international partners for evidence with the help of mutual legal assistance requests. And of course, let's say, putting the bigger picture together, right? Taking also into account the geopolitical tensions in the area. And often what we see is really that different incidents are related to one another. So they are linked, so in the broader setting and broader tensions in the region. So shifting specifically to some of the concerns about the activities that Russia may be engaged in in terms of cable cuts, could you explain what hybrid warfare means in the context of cable cuts and how Russia might be targeting subsea cables as part of a larger strategy involving hybrid warfare? Yeah, sure. I think that's a very valid point because throughout Europe, there are concerns regarding hybrid operations. So when we say hybrid warfare, we often mean a military and political strategy that is blending different operations and actions. These could be, for example, cyber attacks, disinformation, economic pressure, creating physical damage. Lately, we've heard a lot about drones. So all of these can be examples of activities that fall below NATO's Article 5 threshold, but nevertheless include the aim of sabotage, influence, sometimes often with the broader aim for intimidation and creating fear. So these activities we see are undertaken with a broader goal of destabilizing Europe and we are really concerned about this. And in this context of today's discussion, a lot of attention is paid in Estonia and in the Baltic Sea region for Russia's shadow fleet. We see that Russia's shadow fleet is increasingly a threat to our maritime security, including subsea infrastructure as well as environmental security. The vessels in the Russian shadow fleet are often substandard. They are uninsured. It is not clear under what flag they are sailing. They do not respond often to requests for cooperation. And we see that this shadow fleet is evading Western sanctions, essentially undermining the oil price cap and overall challenging the rule-based global trading system. So again, we tend to take this holistic approach, so not to only focus on subsea infrastructure, but the activities of the Russian shadow fleet on a whole, how we can deter these possible incidents and how we can establish comprehensive understanding in the European Union how to deal with these situations. So you make a good point that this is a European problem. I mean, it's really ultimately a global problem, right? But in terms of some of Russia's activities, this is really a problem that the EU needs to address. What has the EU done or considered doing in order to address this at a European-wide level? Yeah. EU is taking this issue very seriously, because as you noted in the beginning of your remarks, we have had serious, concrete incidents with concrete damage to our societies. So for the EU, this is a serious concern. And there are a number of steps that have been taken. Perhaps one of the most comprehensive one from the EU is a communication that is called Cable Security Action Plan. This is a great document for reference for anyone who wants to read further, because it includes a number of concrete steps that the EU is doing or will be doing, and also ideas such as new technologies that the EU is looking into. And in short, the goals can be divided into four parts. First, prevention. Prevention includes mapping subsea infrastructure, mapping the cables, risk assessment, what cables or what infrastructures more in risk than others, updating legal frameworks, which is really important because our national frameworks may not be ready for such damages. Steps also include addressing risks arising from the shadow fleet. That means that we should start dealing with those uninsured and substandard vessels already before they enter the Baltic Sea. The second group of activities is detection. This includes enhanced situational awareness, enhanced joint threat assessment, and enhanced monitoring and information sharing. Again, many of our countries are doing these activities as a given already, but really to get this information together and to have a more coordinated approach and understanding. And detection also underlines the need for capacities that really would allow us to detect possible incidents or, if possible, already before they actually even take place. And here, I would like to underline the role of new technologies because there is a lot of interesting R&D going on, concepts related to undersea sensors, soray and drones, etc. So I think new technology will help us be better in that. It also seems like that's an area where AI could really come in handy for detecting essentially like anomalies and vessels that purport to be fishing vessels, but aren't. Is that potentially a technology that could be really useful for the detection side of things? For sure. And there are already companies offering such services. Exactly like you said, you identify a pattern and then you see certain movements that are outside of that pattern that may give a reason, for example, for patrols to go and check certain vessels or to try to coordinate or be in communication with these vessels before they reach, for example, an area where you have a very concrete subsea cable. But in addition to prevention and detection, there is also important activities under response and recovery. So this is really relevant because what are the capacities for cable vessels to come and secure the incident? Often this takes time. Often you need spare parts. Often you don't have enough vessels exactly when you need them, etc. So we have had incidents where this has taken months before the undersea infrastructure has been mended. And then of course, forcefully deterrence. So what can we do to deter the malicious actor in undertaking such activities? And here we talk about sanctions, talk about clear communication, about consequences. I already mentioned the legal frameworks, also international law and the interpretation of international law so that we would have a common understanding and really holding the malicious actor accountable. Like you mentioned before, the case where the captain of a vessel that was actually responsible for damage was brought to court. So that's what Europe is doing and it's super helpful because it provides really a comprehensive framework for addressing some of these issues. What do you think needs to be done at a more global level? Because we have this happening in and around Taiwan where there are a suspicious number of cable cuts. I think other countries are going to start to see some of these activities. What do you think needs to be done even beyond the EU in order to make sure that this is addressed by allies and partners more broadly? Yeah, for sure. I think here is where countries with concrete experience such as Estonia can really share their best practices and lessons learned from our experience. Estonia was chairing in 2024 to 2025 the Council of the Baltic Sea States and really bringing this topic to the table. Our efforts resulted also in a memorandum of understanding in this regard. And I think these activities can really be taken as examples for other regions as well. When we talk about other cooperation mechanisms, we'd also like to underline the vital role of NATO because I think also here when we look at NATO activities, for them this is increasingly important and the member states of NATO and EU largely are the same. And we are also happy to see more and more international discussions on this. One example I'd like to bring out is the New York principles on the very same topic that were signed last year and really underline the need for a coordinated effort to protect the security and resilience of undersea cables. Then of course we need to talk with other actors, international organizations, international maritime organization for example, very relevant in this regard and also would like to really underline the role of the private sector. We see that private sector is not only a stakeholder with whom to discuss things or exchange information, but they are really valuable actors with whom to engage when developing policies and frameworks. And here I mean these policies and frameworks on the local level, the domestic level, regional level and also international level. Yeah, I think that's really an important point because you can adopt all the policies in the world, but if the companies that are making investments and really ultimately own and control a lot of this infrastructure, if it somehow doesn't work with the technology or doesn't work with some of the realities on the ground right, then those policies aren't going to be effective. Yeah, for sure. So thank you Anna-Maria. Let me try to reflect back to you some of the lessons that perhaps we should take away from this conversation and you can let me know what we should add to it. So you talked about how subsea cables are the backbone upon which all of us depend and that we should really look at this in a holistic way, that of course there's telecommunications subsea cables which are important for carrying data and other traffic, but that there are other subsea cables that carry gas, electricity and so on and that we need to look at all of this because they all are essential infrastructure upon which we depend. We talked about the role of the private sector, how they generally it's companies that own and control the subsea cables, that it's critical for the private sector to acknowledge the risks, to assess the risks, to have backup plans in the event that there are cable cuts, alternatives and so on. Just given the consequences and that there are also, it's very important to look at supply chain risks and sort of broadly at how you secure and make sure that subsea cables are something that we can depend on and that we have both security and resiliency. You also talked about the role of espionage and how it's theoretically possible. It's not something that we've necessarily seen, but that we do need to really be aware of all the different possibilities and to acknowledge all the potential risks and to keep monitoring it because just because something has not been successfully done before doesn't mean that it won't be done in the future. Then we talked about some of the incidents and how the large majority of incidents are actually accidental, phishing activities, weather and so on, but that it's really critical to monitor and have an up-to-date threat assessment because we need to be able to distinguish between some of the accidental cuts and some of the more malicious cuts that we're seeing. We talked about the importance of the policy and regulatory framework, how you need to incentivize the private sector to lay subsea cables, to make those investments so that when there are cuts, there are alternative cables available and also for governments to offer protection of critical infrastructure in the event of problems. And then we talked about specifically with Russia and how this is part of their deliberate strategy of hybrid warfare and to really harass and try to intimidate European countries, NATO allies using subsea cable cuts as one part of a number of tactics that they're exercising, including drones and other things. Then we talked about what the EU is doing with the Cable Security Action Plan, how it's taking concrete steps that involve four areas, prevention, detection, response and recovery, and deterrence, and we talked about the importance of technology to some of that and the use of sensors, surveillance, AI in order to detect and respond to cable cuts. And then we talked about the importance of not only Europe and NATO doing what it needs to, but also more broad sharing of best practices and agreements. You talked about the role of international maritime organizations as well as large international discussions such as the New York principles that were signed last year. And finally, we ended discussing the role of the private sector, how it's not just a matter of perhaps, and sometimes discussing this with the private sector, that they're not just any stakeholder, but that we need to engage with them in a way that ensures that the policy frameworks that we develop on these issues really incentivize the right types of behavior and are really consistent with what technology and facts on the ground mean. So, does that capture the issues that we're dealing with and is there anything that I've missed? No, that was an excellent summary, Matt. Thank you so much. And I mean, there's so much more to discuss there's a lot of research going on when it comes to new technologies, a lot of policy discussions with the goal to develop a coherent and comprehensive understanding of the threat. There are also different regional patterns and kind of threat assessments that we need to take into account. But as said, I think we should exchange information with our international partners, exchange best practices, really work on the level of EU and NATO and with international partners and also with the private sector. And perhaps one of the most important things to underline is to make sure that the malicious actors understand that their activities will be met and that there will be responses to their malatent. Yeah. And so I'll just end in terms of my view and these are really important issues. It's clear that the EU is doing a lot on this and would really encourage the administration and the US government to ensure that it's playing an integral role. The US hasn't necessarily seen a lot of cable cuts that have affected it. But as we've discussed, we've seen cable cuts that are affecting its close allies and partners, both in Europe as well as in the South Pacific. And so these are going to be issues that are going to increase over time, unfortunately. And so that proactivity is going to be really critical in terms of working both with other governments, but as we discussed the private sector. So really want to thank you for your time on a Maria and for a really critical discussion that I would encourage our listeners to stay engaged on. Thank you. That's it for this episode of Cash Me If You Can. Don't forget to subscribe and follow CSIS for more deep dives into the technology shaping our future.

Podcast Summary

Key Points:

  1. Subsea cables are crucial for global internet infrastructure, carrying over 95% of international data traffic.
  2. Subsea infrastructure is vital for telecommunications, data, energy, and other services.
  3. Risks to subsea cables include accidental damage, deliberate sabotage, and espionage by state actors.

Summary:

The podcast discusses the importance of subsea cables as the backbone of global internet infrastructure, enabling data, telecommunications, and energy services. Over 95% of international data traffic flows through these cables, underlining their critical role. Risks to subsea cables range from accidental damage, like fishing activities, to deliberate sabotage and espionage by state actors.

The incident in the Baltic Sea, where subsea cables were severed, raised concerns about potential sabotage and espionage. Measures such as prevention, detection, response, and recovery are crucial to ensure the security and resilience of subsea infrastructure. The EU's Cable Security Action Plan outlines steps to address risks and enhance monitoring.

Cooperation at the EU and global levels, involving private sector engagement, is essential to safeguard subsea cables from potential threats. The discussion also highlights the concept of hybrid warfare and the need for comprehensive approaches to protect critical infrastructure from malicious activities.

FAQs

Subsea cables are the backbone of global internet infrastructure, carrying over 95% of international data traffic and supporting data, telecommunications, electricity, and energy services.

Disruptions to subsea cables can have significant consequences on data, internet, telecommunications, and energy services, highlighting the need for risk assessment, contingency planning, and crisis management.

While espionage is theoretically possible, practical challenges exist in carrying it out. There is a need to remain vigilant and monitor for evolving threats and technologies that could facilitate interception.

The EU has implemented a Cable Security Action Plan focusing on prevention, detection, response, and recovery measures, including mapping infrastructure, enhancing situational awareness, and promoting deterrence through legal frameworks and sanctions.

Collaboration, information sharing, and coordinated efforts among countries, international organizations, private sector, and technology advancements are key to enhancing security and resilience of subsea cables worldwide.

Chat with AI

Loading...

Pro features

Go deeper with this episode

Unlock creator-grade tools that turn any transcript into show notes and subtitle files.