There are roughly 50 undersea cable systems connecting the United Kingdom to the rest of the world’s internet and financial infrastructure. That sounds like a lot until you look at a map and realise how many of them converge on the same half-dozen landing stations, the most critical of which sit in Cornwall, along the Thames Estuary, and on the south coast. I’ve been watching this space for a couple of years now, and the more you dig into it, the clearer it becomes that UK subsea internet cable resilience is less of a policy priority and more of a politely-ignored structural vulnerability.
The cables themselves carry an extraordinary share of economic activity. SWIFT transaction data, FX clearing, cloud replication traffic, voice-over-IP, equities trading feeds. The vast majority of Britain’s cross-border digital commerce rides these fibres. When the Shetland Islands’ single subsea link was damaged in October 2022, cutting the archipelago off from the mainland internet for several days, it was treated largely as a curiosity. It should have been a wake-up call.

How fragile is the network, actually?
The honest answer is: more fragile than the official reassurances suggest. Academic and think-tank research points to a consistent pattern. Cable faults are more common than most people realise, with the International Cable Protection Committee logging between 150 and 200 faults per year globally. The majority are accidental, caused by trawler anchors and dragging fishing gear, which tells you something about how much of this critical infrastructure sits in unprotected shallow water.
What makes the UK’s position particularly exposed is geography combined with geopolitical reality. A significant proportion of cables connecting Britain to North America, Europe, and the broader internet cross the North Atlantic and the Irish Sea in corridors that are relatively easy to access. NATO has tracked increased Russian submarine and surface vessel activity near cable routes since at least 2021, and the sabotage of the Nord Stream pipelines in 2022 demonstrated that actors willing to accept escalatory risk can reach deep-water infrastructure without much difficulty. The UK’s National Security Strategy has acknowledged the threat in broad terms, but concrete protective measures remain patchy and, frankly, underfunded compared to the scale of the exposure.
Landing stations are the real chokepoint
Most of the discussion about subsea cables focuses on the cables themselves. The more interesting vulnerability, to my mind, is the landing stations where those cables come ashore and connect to the terrestrial fibre network. Widemouth Bay in Cornwall is one of the busiest cable landing points in Europe. Secure, critical national infrastructure, yes. But it is also a relatively accessible coastal location, and the physical security arrangements at stations like this are not subject to the same public scrutiny as, say, a nuclear facility.
This matters for businesses because the concentration point risk is severe. A deliberate or accidental incident at a small number of landing stations could simultaneously affect a large proportion of Britain’s international internet capacity. Rerouting around such failures takes time, international co-operation, and in some cases is simply not possible at the speeds financial markets require. For context, Ofcom’s 2023 Connected Nations report noted that the UK’s international connectivity relies on a relatively small number of physical routes for the bulk of its capacity. The exact numbers are not published for security reasons, but the implication is clear enough.
The gap between policy intent and operational reality
The UK government has taken some steps. The National Protective Security Authority provides guidance to operators of critical communications infrastructure, and the Telecommunications (Security) Act 2021 extended obligations to telecoms providers to manage supply chain and infrastructure risk. These are genuine improvements. But there is a meaningful gap between the legislative framework and what actually happens when a cable fails at 3am on a Sunday.
Military protection of cables in transit is effectively impossible to guarantee. The Royal Navy has limited dedicated assets for this type of persistent patrol work, and NATO burden-sharing agreements do not translate into a guaranteed response capability for every relevant cable route. The honest position is that deterrence through ambiguity and the diplomatic costs of attribution are the main protections in place. That is a reasonable posture in peacetime, but it leaves businesses exposed to incidents that may never be publicly attributed to any actor at all.
I’d also point out that the policy conversation tends to focus on state-level threats, which is understandable but incomplete. Accidental damage from commercial shipping, unintended consequences of seabed mineral extraction activity, and even fishing vessel anchor dragging remain statistically the most likely causes of faults. The mundane risk is the one most businesses have done the least to plan for.
What UK businesses should actually build into their resilience planning
For anyone running a UK business with meaningful dependence on cross-border data flows, the first thing worth doing is understanding your actual connectivity topology. Most IT teams know what cloud regions they use. Fewer know which physical cable routes their traffic traverses to reach those regions, or where the contingency routing goes if the primary path fails. Getting visibility of this is not as hard as it sounds, and your ISP or connectivity provider should be able to give you at least a high-level answer.
Diversity at the provider level does not always equal diversity at the physical infrastructure level. Two different ISPs may share the same landing station or even the same cable system under commercial agreements. Genuine path diversity requires asking specific questions, not just signing contracts with two suppliers. This is the kind of infrastructure consideration that sits alongside the broader debate about UK data centre geography and resilience, where physical concentration risk is equally underappreciated.
For financial services firms and anyone operating with latency-sensitive cross-border workloads, the question of which processes genuinely need real-time international connectivity and which could tolerate a degraded-mode operation for a period of hours or days is worth working through in advance. Building that into your business continuity planning is not catastrophising; it is the same logic that drives having backup power for your server room. The shift away from legacy infrastructure that many UK firms are currently undergoing is a good moment to bake these questions into architectural decisions before they get locked in.
Satellite as a partial answer
Low Earth orbit satellite connectivity, with Starlink being the most visible provider in the UK market right now, does offer a genuine alternative path for some traffic. It is not a replacement for subsea fibre in terms of capacity or latency for high-volume financial data, but it is a credible secondary path for many business applications. The catch is that satellite capacity is also finite and would likely be under considerable demand pressure in any scenario serious enough to cause significant cable outages. It is a useful addition to a resilience stack, not a complete answer.
The UK government and Ofcom have been relatively slow to produce public guidance on resilience planning for businesses that are exposed to cable-level risks. There is more nuanced thinking available in NCSC publications and in sector-specific guidance from the FCA for financial services firms, but pulling together a coherent business continuity approach still requires more effort than it should. Given how much of the UK economy runs on international data flows, that gap is worth taking seriously before an incident forces the conversation.
Frequently Asked Questions
How many undersea cables connect the UK to the internet?
There are approximately 50 cable systems serving the UK, though the number of active routes and landing stations is considerably smaller. A significant proportion of international traffic is concentrated through a handful of landing points, primarily in Cornwall and the south-east of England, which creates meaningful concentration risk.
What are the biggest threats to UK subsea cable infrastructure?
Statistically, accidental damage from fishing vessels and commercial shipping anchors causes the majority of cable faults globally. Beyond that, geopolitical actors including state-sponsored submarine activity near cable routes have been flagged as a growing concern by NATO and the UK government’s own national security assessments.
Would a subsea cable failure actually affect my business?
It depends on your international data dependence. Businesses relying on real-time cross-border transactions, cloud services hosted in European or North American data centres, or international voice and video would likely experience degraded performance or outages. UK-only operations with local hosting would be far less affected.
Is the UK government doing enough to protect undersea cables?
The Telecommunications (Security) Act 2021 strengthened obligations on operators, and the National Protective Security Authority provides guidance. However, independent assessments consistently note that military patrol capacity is limited and physical protection of cables in transit remains largely aspirational rather than operational.
How can businesses improve their resilience to subsea cable disruption?
Start by mapping which physical cable routes your international traffic actually uses, as provider diversity does not always mean physical path diversity. Then assess which workloads genuinely require real-time international connectivity versus those that could operate in a degraded mode for hours or days, and build that distinction into your business continuity plans.
