1 · Concept overview
A digital chokepoint is a place where the internet stops being a network and becomes a small number of physical objects. Three kinds exist and they fail differently: the cable layer, where fibre crosses oceans and funnels through a handful of straits and landing stations; the repair layer, where a specialised and ageing fleet of ships decides how long a fault lasts; and the logical layer, where a few cloud regions, content networks and domain-name providers concentrate services that are physically dispersed.
Established The joint question none of the neighbouring briefs owns is how these three interact. Infrastructure Resilience establishes that resilience claims are unfalsifiable without a published time-to-restore distribution, and that the data sits inside operators. Economic Resilience establishes that the dominant resilience policy of the decade — localisation — measures out as resilience-reducing. Energy Corridors establishes that nobody publishes what a finished submarine link costs. This brief applies all three findings to the digital layer and reaches a sharper conclusion than any of them, because here the fault record is unusually good and the restoration record is unusually bad.
Frontier The headline claim is that route redundancy is the wrong variable. Cable cuts are routine — the industry counts them in the low hundreds each year — and the network absorbs almost all of them. What determines whether a cut is an inconvenience or a national outage is how fast it is repaired, and repair is supplied by a fleet whose size, age and committed availability are not published by anybody. Every national cable-security plan written since 2024 is a statement about a repair-time distribution its authors have not seen.
Scope. This brief owns the digital layer of physical concentration: cables, landing stations, repair capacity, cloud and network-service concentration, and the satellite substitution argument. It does not restate the cascade-modelling literature, the reshoring evidence, or the transmission-cost question, each of which belongs to a brief named above. Where it needs the method for measuring restoration, it borrows it explicitly rather than reinventing it.
Established A note on sourcing. This brief was commissioned in September 2026 from the Institute’s research base. Reading-list entries without links are cited from the bibliographic record rather than re-fetched, and claims are dated no later than early 2026 unless carried by a linked source.
2 · Current scientific position
Established The physical network is small enough to count and is counted by a commercial vendor rather than a public register. Industry censuses put the world’s active and planned submarine cable systems in the mid-hundreds, totalling well over a million kilometres of fibre, and carrying the overwhelming majority of intercontinental data traffic — the figure usually quoted is above 95%, sometimes 99%, and the variation is definitional rather than empirical. No government maintains the authoritative list. The most-cited map is a data product sold by a private research firm.
Established Faults are frequent, and most of them are ordinary. The cable-protection industry’s own long-running statistics put global faults in the range of roughly one to two hundred per year, with the large majority caused by fishing gear and ship anchors in shallow water, a minority by natural abrasion, earthquakes and submarine landslides, and a small remainder by component failure. The base rate matters for every argument about sabotage: a cut is not evidence of hostile action, and a cluster of cuts in one small sea over two winters is not explained by the base rate either.
Frontier The incident record since 2023 is the closest thing the field has to a natural experiment, and it runs in the Baltic. The Balticconnector gas pipeline and adjacent telecommunications cables were damaged in October 2023; two cables between Finland, Germany, Lithuania and Sweden were cut in November 2024; the Estlink 2 power link and several telecom cables were cut on Christmas Day 2024, after which Finnish authorities boarded and detained a tanker and pursued a criminal case over a dragged anchor. NATO began a dedicated surveillance mission in the Baltic in January 2025. Attribution has been contested in every case, and at least one prosecution ended without a conviction on jurisdictional grounds — which is itself the most important finding in the sequence.
Established The Red Sea incident of February 2024 is the clearest demonstration of geographic concentration. Three systems carrying Europe-Asia traffic were cut in the same corridor within days, attributed to the dragging anchor of a vessel abandoned after an attack, and a Hong Kong carrier estimated that roughly a quarter of traffic between Asia and Europe was affected. Repairs took months rather than weeks because the repair ship needed permissions to work in contested water. The chokepoint was not the cut; it was the permit.
Established The Egyptian isthmus is the single most concentrated point on the map. The large majority of cable systems linking Europe with Asia and East Africa make landfall in Egypt and cross by land between the Mediterranean and the Red Sea, on routes controlled by the national incumbent. This is a chokepoint in the strict sense: a correlated failure domain that no amount of cable-building elsewhere diversifies, because the alternatives to crossing Egypt are the long way round Africa or terrestrial routes across Eurasia that carry their own single points of political control.
Frontier Island and near-island systems show what happens when the count is one. Tonga lost its only international cable to a volcanic eruption in January 2022 and spent weeks on satellite fallback. The Matsu islands lost both of their cables in early 2023 and waited months, because no repair ship was available and the replacement schedule was set by vessel availability rather than by urgency. In both cases the restoration time was set by a ship, not by a network.
Frontier The repair fleet is the least documented critical asset in modern infrastructure. Industry counts put the world’s cable ships at roughly five to seven dozen, of which only a subset — commonly put at about twenty — is committed to maintenance under regional zone agreements, with the remainder engaged in installation, which pays better. The trade body and trade press have warned repeatedly that the maintenance fleet’s average age is over twenty years and that replacement is not being ordered at replacement rate. None of these numbers comes from an audited register, and the definitional question of what counts as a repair-capable vessel is doing real work in the disagreement.
Frontier Repair time is governed by three things, of which the fault is the least important. Vessel availability and transit, weather windows, and permission to work in a coastal state’s waters dominate the clock; the splice itself is a day’s work for a skilled crew. Published anecdotes span days for a well-served North Atlantic fault to several months where permits or security intervene. What does not exist anywhere is the distribution — the same absence that Infrastructure Resilience identifies for electricity restoration, reproduced in a sector with far fewer operators and therefore far fewer excuses.
Established Policy has moved faster than measurement. The European Union published a cable-security action plan in early 2025 proposing surveillance, faster permitting, a reserve of repair vessels and funding instruments for route diversity. It is the most serious governmental response to date and it was written without a published repair-time distribution, a public vessel register or a public inventory of landing-station dependencies. The plan is sound in direction and unfalsifiable in effect, for exactly the reason its own annexes imply.
Established At the logical layer the concentration is measured, and it is high. Analyst estimates consistently put the three largest cloud providers at roughly two thirds of global cloud infrastructure spending, with the largest at around thirty percent — figures produced by commercial research firms using their own definitions, and broadly consistent across them. Concentration of services is tighter still: a few content-delivery and authoritative-DNS providers sit in front of much of the web, and a handful of cloud regions host control planes for nominally global services.
Established The outage record shows the failure mode is correlation, not unreliability. A content-network configuration error in June 2021 removed a large fraction of major websites for under an hour. A flawed security-software update in July 2024 disabled millions of Windows machines worldwide — the vendor of the operating system put the figure at about 8.5 million devices — grounding flights and stopping hospital systems, with insurance analysts estimating direct losses to large US firms in the billions of dollars. Regional cloud failures have repeatedly taken down services whose owners believed they were multi-region. Hyperscale platforms are individually more reliable than what they replaced; what they changed is that everyone now fails at the same moment.
Established Physical concentration at the logical layer is measurable and local. Data-centre clusters concentrate in a handful of metropolitan areas for reasons of power, land and fibre, and the grid consequences are now the binding planning constraint: in Ireland data centres consume around a fifth of national metered electricity and new connections in the Dublin region have been restricted, while in the United States local opposition has blocked or delayed tens of billions of dollars of projects and build times for gigawatt-scale sites run to years. Cloud geography is not chosen for resilience; it is chosen for electricity and permits, and the resulting correlation between compute and grid chokepoints is unmanaged by either sector.
Frontier The satellite substitution argument fails on arithmetic, not on principle. A modern cable system is designed for hundreds of terabits per second between two points. A large low-orbit constellation delivers, in aggregate across the entire planet, a throughput that operators do not publish in audited form and that independent estimates place one to three orders of magnitude below a single trunk cable’s design capacity, with the fraction available over any one ocean basin a small share of that. Latency is not the problem — low-orbit paths are competitive with fibre over long routes — and cost per delivered bit is. Satellite is an excellent emergency restoration layer for an island and is not a substitute for a trunk route, which is what the Tonga restoration actually demonstrated.
3 · Frontier questions
Frontier Can deliberate damage be distinguished from anchor-dragging at all? The evidentiary record so far says rarely, and the Baltic cases turned on vessel tracking, anchor wear and crew testimony rather than on anything observable at the cable. A method that discriminated reliably would change deterrence, insurance and treaty enforcement simultaneously; without one, the base rate of accidental damage provides permanent cover.
Frontier Does concentration raise or lower expected outage cost? The honest answer is that it does both, on different terms: hyperscale operators achieve per-unit availability that individual enterprises never matched, while making failures simultaneous across previously independent organisations. Nobody has published the joint distribution that would let a regulator compare the two effects, and the question is tractable with data the operators already hold.
Frontier What is the correlation length of a cable failure? Cables laid in the same corridor, landing at the same station, or repaired by the same regional vessel share failure modes that route-count metrics do not capture. A defensible concentration metric would weight by shared corridor, shared landing site and shared maintenance zone, and no regulator currently collects the inputs.
Speculative Can repair capacity be financed as a public good? Repair ships are expensive, idle by design and profitable only in installation work. A standing reserve therefore requires somebody to pay for availability rather than activity, which is the structure of a capacity market. Whether that can be built across jurisdictions without collapsing into a subsidy for incumbent operators is an open policy design question.
4 · Technological bottlenecks
Established The binding physical bottleneck is vessels and the people on them. A cable repair ship is a specialised build with a multi-year lead time, a global market of a few yards, and crews whose jointing skills take years to develop. No amount of capital deployed in a crisis produces a repair ship inside the window in which it is needed, which makes fleet capacity a stock problem rather than a flow problem.
Established Permits are a bottleneck with no engineering component. Repair inside a coastal state’s waters requires that state’s consent, and consent regimes were written for cable-laying rather than emergency repair. Delays measured in weeks are routine and delays measured in months have occurred. This is the cheapest fixable constraint in the entire subject and it requires no technology at all.
Frontier Spares are a hidden single point of failure. Repair requires cable of matching type held in regional depots, plus jointing consumables and repeaters. Depot stocks are held under consortium agreements and are not public; a multi-cable event that exhausts a regional depot has no documented recovery path.
Established At the logical layer the bottleneck is electricity and land, not silicon. Region placement is dictated by where power can be interconnected and where a community will accept a building, which is why compute concentrates in a few metropolitan clusters and why substitution between regions is slow even when a provider wants it.
5 · Research dependencies
Frontier The first dependency is a method already worked out elsewhere on this map. Infrastructure Resilience establishes that a resilience claim without a published time-to-restore distribution cannot be scored, and that the obstacle is institutional. The digital layer inherits the finding with two differences that make it easier here: there are tens of maintenance-zone operators rather than thousands of utilities, and every fault is already recorded contractually.
Frontier The second is an audited asset register. Cables, landing stations, repair vessels and depot stocks are known to the industry and to nobody else. A public register with corridor and landing-site identifiers would make the correlation-length question answerable, and it is the input every national security plan currently substitutes assertion for.
Frontier The third is failure-domain disclosure at the logical layer. Cloud customers are told about regions and availability zones; they are not told which control planes are global, which dependencies cross regions, or which services share a failure domain. Without that, multi-region architecture is a purchase rather than a property.
Established The fourth is arithmetic that a satellite operator could publish tomorrow. Audited aggregate and per-basin capacity, with the gateway and backhaul constraints stated, would settle the substitution argument in one document. Its absence is why the argument is conducted in adjectives.
6 · Required experiments
Frontier The decisive measurement is a published distribution of time-to-restore for submarine cable faults, by cause, sea area and permitting regime, produced by the consortia that already hold the records. Every claim made about cable resilience is a claim about that distribution: whether a second cable helps depends on how long the first one stays down, and whether a repair fleet is adequate depends on the tail rather than the mean. The maintenance-zone operators log every fault, every mobilisation and every permit delay as a matter of contract. Nobody has published the distribution and no regulator has required it, which means the decisive result needs no new instrument, no new ship and no new science — only a disclosure rule.
Frontier The natural experiment is already running in the Baltic and nobody is scoring it. A dense sequence of incidents since 2023 in a small, heavily surveilled, jurisdictionally crowded sea has produced repeated observations of detection, attribution, prosecution and repair under the most favourable conditions anywhere on Earth. The measurable outputs — time to detect, time to identify a vessel, time to restore, and whether any prosecution succeeds — are the empirical base for every deterrence argument being made, and they have not been assembled into a record.
Speculative A cheap and unrun experiment is a regional multi-fault exercise. Simulate the simultaneous loss of the three systems serving one landing region and require the participating operators to demonstrate, rather than assert, restoration: vessel mobilised, depot stock matched, permits obtained. The exercise costs a fortnight of ship time and would produce the first evidence anyone has about whether the reserve concept works.
Frontier At the logical layer the decisive disclosure is a failure-domain map. A provider publishing which control planes are global and which dependencies cross regions would let customers test their own architectures against the failure mode that has actually occurred. The 2024 endpoint-software outage showed the same gap outside the cloud: a dependency present on millions of machines was invisible to the organisations that carried it.
7 · Engineering requirements
Established Cable protection is a burial and armouring problem with known economics. Shallow-water segments are armoured and buried because that is where fishing gear and anchors are; burial depth trades directly against installation cost and against the difficulty of subsequent repair. Nothing about the engineering is unsolved. What is unsettled is who pays for protection on routes whose value is national rather than commercial.
Established Diversity has to be specified as corridor diversity, not cable count. Two systems in one trench, landing at one station, maintained by one vessel are one system for the purposes that matter. Real diversity means separate corridors, separate landing sites, separate terrestrial backhaul and separate maintenance zones, and it costs proportionally more than buying a second fibre pair on an existing route.
Frontier Monitoring is now genuinely improving. Fibre-sensing techniques that read strain and acoustic signatures off the cable itself can localise disturbance without additional hardware in the water, and state-of-polarisation monitoring has been used to detect events on live systems. Whether this yields attribution or only detection is unresolved, and the operators who could test it at scale have no obligation to publish.
Established At the logical layer the engineering requirement is boring and rarely met: secondary authoritative DNS with a second provider, multi-provider content delivery, tested regional failover with data-plane independence, and a dependency inventory that includes vendors installed on endpoints. Each is well understood, each costs money against a risk that materialises rarely, and the 2021 and 2024 outages both found large organisations that had bought none of them.
8 · Adjacent technologies
Established The nearest neighbours on this map supply the method and the counter-argument. Infrastructure Resilience supplies the restoration-distribution test this brief applies to cables. Economic Resilience supplies the strongest caution against the obvious policy response: measured evidence that localisation reduces rather than increases resilience, which should be read directly against proposals for sovereign clouds and domestic-only routing. Energy Corridors supplies the observation that submarine infrastructure costs are not published, which holds for data cables as it does for power links.
Frontier Two further adjacencies are load-bearing and usually missed. Autonomous Supply Chains owns the logistics systems whose failure modes now run through the same cloud regions as everything else, which converts a digital chokepoint into a physical one. Civilization Resilience Planning owns the tail this brief stops short of: what a simultaneous, sustained loss of several trunk corridors would actually do.
9 · Institutional requirements
Established The protective legal regime is old, thin and almost never enforced. Deliberate or negligent damage to a submarine cable has been an offence under an international convention since 1884, restated in the modern law of the sea, which obliges flag states to legislate and to prosecute their own vessels. Enforcement depends on the flag state of the ship that dragged the anchor, which in the contested cases is exactly the state with the least interest in prosecuting, and the penalties available are trivial against the damage caused.
Frontier The industry’s coordinating body is a private club doing a public job. Fault statistics, protection guidance and maintenance-zone agreements are produced by a membership organisation of cable owners and suppliers. It does the work competently and publishes selectively, and there is no public body anywhere with the mandate, the data or the staff to check it.
Frontier The new institutional proposals all reduce to paying for availability. A European reserve of repair vessels, national cable-security funds and flagged-fleet programmes are all attempts to make a standing capability exist where the commercial market supplies only an occasional one. None had demonstrated committed, contracted, exercised availability by early 2026, and the proposals should be judged on whether they produce a ship on station rather than a strategy document.
Speculative The regulatory lever with the shortest arm is licensing. Landing-station licences and cloud-procurement contracts are both renewal-based instruments that could require corridor-diversity disclosure, depot-stock declarations and failure-domain publication as conditions. That is an administrative change available to any large jurisdiction without new legislation, and no jurisdiction has made it.
10 · Ethical & societal considerations
Established The cost of a cable break falls where the redundancy is thinnest, which is where the money is thinnest. Small island states and remote territories have one or two systems, no domestic repair capability and no negotiating power over vessel scheduling; a fault that is a routine ticket in the North Atlantic is a national emergency in the Pacific. Repair priority is set by commercial maintenance contracts, not by need.
Frontier Cable security and cable surveillance are the same capability. The sensing, mapping and inspection technologies proposed for protecting cables are the technologies for finding, tapping and cutting them, and the naval assets deployed to guard them are the assets that would interdict them. A protection regime therefore hands states a capability whose defensive character is a matter of intent rather than design.
Frontier Sovereign-cloud policy is where the ethical and the empirical collide. The demand for domestic data residency is legitimate and the measured evidence from the neighbouring brief is that localisation reduces resilience. Both can be true: residency is a jurisdictional good and diversity is a resilience good, and a policy that conflates them buys the first while claiming the second.
Speculative Attribution in public has consequences the evidence rarely supports. Naming a state as responsible for a cut, on the strength of vessel tracking and a plausible motive, is an act with escalation risk taken on evidence that would not sustain a prosecution. Restraint here is not credulity; it is proportion.
11 · Civilizational implications
Established The founding myth of the internet is doing real harm to planning. Packet switching routes around a failed router; it does not route around a missing ocean crossing, a landing station or a control plane. The logical layer’s genuine robustness has been repeatedly mistaken for physical redundancy that was never built, and the mistake is visible in procurement documents, continuity plans and national strategies alike.
Speculative The consequential scenario is not a severed continent but a slow, expensive degradation. A corridor lost for months forces traffic onto longer routes at higher latency and lower capacity, which degrades the services that assume neither — financial settlement, remote operations, model training and inference across regions — without producing the visible outage that would mobilise a response.
Handwave The strong version of the argument, that a coordinated attack on cables could sever a continent, is where the reasoning stops being supported. It requires simultaneous action across dozens of systems in multiple jurisdictions, sustained against repair, without triggering the response that a campaign on that scale would guarantee. The realistic threat is targeted damage to thin routes at the moment they matter, which is both easier and far less discussed.
12 · Timelines
These horizons track institutional capability and published evidence, not cable technology, which is mature and improving steadily on its own.
- 10 yr: Frontier At least one jurisdiction contracts standing repair availability and exercises it; permitting for emergency repair is streamlined somewhere, being the cheapest available gain; fibre-sensing monitoring becomes standard on new systems; a public cable and landing-station register exists in at least one region, probably as an annex to a security programme rather than as a transparency measure.
- 25 yr: Speculative Corridor-diversity requirements appear in landing-station licences and large cloud procurements; failure-domain disclosure becomes a contractual norm after an outage large enough to force it; satellite capacity grows enough to matter for restoration and remains far short of trunk substitution.
- 50 yr: Speculative The chokepoint map is redrawn by where power and compute concentrate rather than by where ships can lay fibre, and the binding constraint on digital geography is grid interconnection rather than seabed.
- 100 / 250+ yr: Handwave Claims that free-space optical, orbital relay or entirely new physical layers will retire the submarine cable rest on cost-per-bit assumptions no current evidence constrains, and the historical record of predicted cable obsolescence is unbroken failure since the 1960s.
13 · Technology tree & dependencies
- Depends on One method and one negative result, both produced elsewhere on this map. From Infrastructure Resilience, the finding that a resilience claim is unscoreable without a published time-to-restore distribution and that the data sits inside operators — this brief’s decisive measurement is that test applied to a sector with far fewer operators. From Economic Resilience, the measured result that localisation reduces resilience, which is the direct counter-argument to sovereign-routing and sovereign-cloud proposals and is attributed there rather than re-derived here. Energy Corridors supplies the parallel observation that submarine infrastructure costs go unpublished.
- Requires (not on this map) Five constraints, none of them a scientific discovery. A published time-to-restore distribution for submarine cable faults, because every resilience claim in the sector is a claim about its tail and the consortia that hold the records publish none of it. A maintenance fleet with contracted standing availability, since the commercial market pays for installation and supplies repair as a by-product, and availability is a stock that cannot be bought during the event. Emergency-repair permitting inside territorial waters, which is the cheapest fix in the subject, needs no technology, and has produced month-scale delays where it is absent. An audited register of cables, landing stations and depot stocks, without which corridor concentration cannot be measured and national plans substitute assertion for inventory. And audited per-basin capacity figures from satellite operators, because the substitution argument that underwrites much complacency about cables is currently conducted without a single verifiable number.
- Enables Any programme that assumes reliable intercontinental connectivity through a disruption, which by now is most of them: cross-border financial settlement, remote industrial operation, distributed model training and inference, and the logistics decision layers owned by Autonomous Supply Chains. It also enables something narrower and more immediately useful — a corridor-weighted concentration metric would let a regulator tell a genuinely diverse route portfolio from an expensive one, which no current metric does.
- Adjacent Maritime law and flag-state enforcement; offshore survey and construction; marine spatial planning; naval surveillance; the insurance market that prices cable loss; and within this map Infrastructure Resilience, Economic Resilience, Energy Corridors and Civilization Resilience Planning.
14 · Common misconceptions & speculative claims
Established “The internet was designed to survive attack and routes around damage.” The routing layer does exactly that within the capacity that remains. It cannot manufacture capacity: when a corridor is gone, traffic takes a longer path at higher latency, and when enough of a region’s capacity is gone, it queues. Robustness at the logical layer has been repeatedly mistaken for redundancy at the physical layer, and the physical layer is where the money was never spent.
Established “Satellites have made cables obsolete.” Constellations deliver an aggregate throughput that independent estimates place orders of magnitude below the design capacity of a single trunk cable, spread across the whole planet and constrained by gateways and backhaul. They are a genuinely transformative access technology and an excellent emergency layer for an island. No operator has published audited per-basin capacity, which is the number that would settle this, and none has been asked for it.
Frontier “The Baltic cuts were obviously sabotage” and “the Baltic cuts were obviously accidents” are both overclaims. Anchor-dragging damage is genuinely common; a cluster of events in one small sea over two winters is not explained by the base rate; and attribution has repeatedly failed to survive legal test, including a case dismissed on jurisdiction rather than on facts. The correct position is that the evidence supports suspicion and has not yet supported conviction, and that this gap is itself the policy problem.
Established “The answer is more cables.” More cables in the same corridor, landing at the same station, maintained by the same vessel, add capacity and not diversity. Where the repair fleet is the constraint, an extra system adds an extra thing to repair. Redundancy is only redundancy if the failure modes are independent, and corridor, landing site and maintenance zone are the three couplings nobody counts.
Frontier “Cloud concentration means the cloud is unreliable.” The opposite is true per unit: hyperscale operators achieve availability that the enterprise data centres they replaced did not approach. What concentration changes is correlation — independent organisations now fail together, at a moment none of them chose. A correct risk statement compares a distribution of correlated failures with a distribution of independent ones, and no regulator has published either.
Speculative “A sovereign cloud fixes this.” Data residency is a jurisdictional property and diversity is a resilience property; buying the first does not deliver the second, and the measured evidence from the neighbouring brief on economic localisation runs the other way. A national cloud with one region, one grid connection and one cable corridor is a concentration policy wearing a resilience label.