24

 

Joint Committee on the National Security Strategy

Oral evidence: Undersea cables

Monday 12 May 2025

4.30 pm

 

Watch the meeting

Members present: Matt Western (The Chair); Lord Boateng; Sarah Champion; Mr Tanmanjeet Singh Dhesi; Bill Esterson; Baroness Fall; Sir Julian Lewis; Mike Martin; Edward Morello; Lord Robathan; Lord Sarfraz; Lord Sedwill; Derek Twigg; Baroness Tyler of Enfield; Lord Watts.

Evidence Session No. 1              Heard in Public              Questions 1 - 12

 

Witnesses

I: Professor Kevin Rowlands, Visiting Professor, King’s College London; Matthew Bowden, Director and General Manager, Red Penguin Marine; Elisabeth Braw, Senior Fellow, Transatlantic Security Initiative, Atlantic Council; Dr Sidharth Kaushal, Senior Fellow for Sea Power, RUSI.

 

Examination of witnesses

Professor Kevin Rowlands, Matthew Bowden, Elisabeth Braw and Dr Sidharth Kaushal.

Q1                The Chair: Welcome to today’s oral evidence session of the Joint Committee on the National Security Strategy. Today is the first evidence session in our inquiry into undersea cables. The session will focus primarily on the threats that exist to our essential lines of communication, their vulnerabilities, and the extent of the UK’s reliance on this extensive network of undersea cables.

Can I thank you for joining us, witnesses? One or two members of the committee will be online, one of whom you can see currently, and another should be joining us any moment. Can I ask you first of all just to introduce yourselves?

Matthew Bowden: Good afternoon. I am currently a director of a company called Red Penguin Marine and Red Penguin Associates Ltd. My background is 26 years serving with the Royal Navy. I left in 2019. I was a warship captain and a communications, electronic warfare and information warfare specialist. The company that I now work for, Red Penguin, is a submarine cable engineering company. We are a consultancy, and we work for the owners, the operators and the insurers of submarine cables.

Professor Kevin Rowlands: Hello. My day job is the head of the Royal Navy Strategic Studies Centre, but I am here in a private capacity. I am also a visiting professor at the departments of war studies and defence studies at King’s College London.

Elisabeth Braw: I am a senior fellow at the Atlantic Council. I am based in London, although the Atlantic Council is an American think tank. I am also the author of The Defender’s Dilemma: Identifying and Deterring Gray-Zone Aggression and The Undersea War, which is upcoming.

Dr Sidharth Kaushal: Hello. I am a senior research fellow in the military sciences team at RUSI.

The Chair: Thank you again for joining us. We are very interested to hear your thoughts about the reliance that the UK has on undersea cables. We have had a lot of stories in the last several months—of course, they do date back many years—about some of the incidents that we have experienced. Can you give us an idea, Elisabeth Braw and Matthew Bowden to start with, of which sectors are the most vulnerable to such incidents?

Elisabeth Braw: The UK depends and relies on cables across the board, but, if I were to highlight one sector, it would be financial services. Without these cables, we would not have our modern economies, which rely on enormous amounts of money being transferred, not just within countries but, crucially, between countries, every second of every day. As we know, the City of London is one of the engines of the UK economy. If the UK economy were to stumble as a result of the City struggling to conduct its business through these undersea cables, it would be disastrous.

We should also remember that every aspect of our daily lives is dependent on cables, which are, in essence, the twin of the globalised economy. One would not have been possible without the other. Undersea cables grew in number as the globalised economy grew. It was possible because there was peace, and that is why we are where we are today. The expansion has taken place under an assumption that there will always be peace.

Matthew Bowden: I cannot disagree with Elisabeth. I would put a slightly different slant on it, though. When you look at the UK as an island nation, it is absolutely right that we have an economic centre of excellence, which is crucial to our economy. Should there be a significant impact on the availability of data transmission across the country, you have to recognise that this would impact all areas of the United Kingdom—everything from the emergency services and our ability to respond and to function, through to our daily life and the impact on the populace. If it is something that is so significant that is going to be affecting the City of London and our emergency services, that effect is going to be consequentially felt across the whole of the nation.

It is worth understanding that all of our supply chains, whether you are talking about Sainsbury’s or an overseas provider of services or cars, for example, are dependent on up-to-date and intrinsically linked data transmission across companies and logistics locations, and it is just something to bear in mind. It is a good answer to look at the City and at the economic side of it, but, as the Shetland Islands showed us a couple of years ago, failure of the system led to pretty much widespread panic from the moment that people could not buy fuel with their credit cards.

The Chair: Can you just elaborate on that and what happened in the Shetland Islands? Honestly, I had not heard about that. I have read about it more recently, but just give us a flavour of what happened.

Matthew Bowden: In simplistic terms, there are a couple of cables that supply the Shetland Islands, and one of those cables failed. The first impact that was felt in the islands was the loss of the internet. It raised a degree of concern and people started to react, but the island very quickly realised that it was completely dependent on that cable for its data transmission. That meant that all of its links back to banks and to its retail hubs meant that the island became frozen in time, effectively. They could not pay for anything, and the impact that that had on the population was quite significant. Certainly from the stories that were told in the press and the interviews that were given over the airwaves, it shook them quite significantly.

The cable system was restored very quickly. There was a resilience plan that was enacted, and that came back online fairly swiftly. The cable, which had been damaged, almost certainly by fishermen, was repaired quite swiftly as well. It was a really good example of how an unforeseen action on a remotely located environment with a single connecting line of importance can have quite a significant impact on the population.

Q2                Lord Robathan: I am an ignoramus on these things, but do you not get a huge amount over the net, not down a cable?

Matthew Bowden: When you say “over the net”, can you elaborate?

Lord Robathan: If I am playing with my telephone, I am not near a cable. Can you not re-route things through the internet? You are talking to an ignoramus here.

Matthew Bowden: No, I absolutely understand. I will reassure you by saying that I have to give this explanation more often than you would believe. You are absolutely right. Let us say that you are making a call from your mobile telephone to your family who are on holiday in France. You will connect to the local 5G mast, but what happens is that your call is, ultimately, routed through an undersea fibre optic cable out to the relevant mast near the phone that you are dialling to. That is how the connection is made. When you ask, “Could you not use the net?”, 96% to 99% of the internet, depending on whose numbers you believe, is passed through submarine cable systems.

Lord Robathan: Is that going to continue in that way, or will people be able to bounce things without going down cables instead?

Matthew Bowden: The propensity of the acceleration of the requirement for information means that the speed at which other technologies is moving at the moment does not present a really obvious solution in the near term, certainly, other than submarine cables.

Elisabeth Braw: I can add to that. For years, the alternative has been satellites, but they are more expensive and more cumbersome, and there is no guarantee that they would always function in a way that undersea cables do not. As Matthew said, they have always been a very small part of connectivity. That is why Starlink has been in the news a lot. It is seen as an alternative to undersea cables when regular connectivity is not available, but it is, by far, not as widespread, is more expensive and is cumbersome.

Matthew Bowden: Just using the example that we touched on just now with the economics, in terms of Starlink as a capability, a top-line Starlink satellite can run around 20 gigabytes of data through it. The oldest submarine cables running across the Atlantic that are in regular use day by day have 4 to 8 terabits of data running across them. They are also much faster, so you also have a degree of latency. The signal transmission up to the satellite, even in low earth orbit, and back down to the ground station takes a finite time and is slower than the signal passage through a fibre optic cable.

The Chair: Can I just broaden this? The statistics that you give are really striking in terms of the capacity of satellites and older cables, as you just mentioned. Am I right in thinking that there has been an exponential growth in how we use these cables, or their number, over the last 10 or 15 years? Can you give us an idea of how many cables there would have been 10 or 15 years ago? We have about 40 that are international at the moment. What would you project the number to be that we might be needing, with 5G, 6G, AI and all these other demands, in terms of the capacity that we are going to need, say, in five or 10 years’ time?

Matthew Bowden: I wish that I could remember the brilliant statistic that relates the number of miles and kilometres of cable in the world to the number of faults. I can probably look it up if you really want me to dig it out. I have it on my iPad. The proliferation of data cables and fibre optic cables has continued to grow, and they are building more of them. It is the nature of the cables that they are building. Amitié, which crosses the Atlantic, now has four times the number of fibres in it and a significant uplift in the capacity of that cable in terms of its data transmission capability. The bigger companies, such as Google, Amazon and Meta, are building these behemoth cables around the globe that are transmitting data lines and data capacity that satellites cannot get anywhere near at the moment.

The Chair: Perhaps you could drop us a line on that.

Matthew Bowden: Yes, I can do that.

Elisabeth Braw: We all contribute to the growth of the cable industry, because we all consume more and more connectivity, which is an incentive for companies to install more and more cables—as Matthew said, cables with more and more capacity and, by the way, also longer and longer cables that travel the world. That is, in a sense, the dilemma of the modern society. It is a convenience trap. The more convenient life becomes, the more dependent we are on undersea cables that may or may not have sufficient protection against whatever comes our way.

Q3                Mike Martin: I am really struck that a lot of the growth in undersea cables is going to be delivered by Amazon, Facebook and all the rest of it. We already have enough problems with tech giants in terms of the online safety of our children, and the amount of power that they have vis-à-vis national Governments. Do you not think that it is absolute insanity that a key piece of critical national infrastructure is going to be delivered and owned by tech giants, over which we have no control in the UK?

Professor Kevin Rowlands: It is a really interesting question. I would not categorise this as critical national infrastructure. It is absolutely international. As Matt knows far better than I do, working in the industry, the cables are privately owned. The information that passes through the cables is privately owned. They go through various jurisdictions, national and international. Short of having a world Government, how is that done on a national basis? There is a huge requirement for co-operation and international alignment of systems.

Mike Martin: To that point, if I may, under the law of the sea, they come through the high seas. We have privately owned infrastructure going through international space, where there are, basically, no enforceable legal frameworks, yet that privately owned infrastructure is critical for our national security. There is a huge problem there around global governance. What would that look like if that problem was adequately managed in global governance terms?

Dr Sidharth Kaushal: There are some solutions as well as problems inherent in that. For example, the privately owned capacity for cable repair far outstrips what most Governments have at their disposal. The private sector does bring solutions as well as problems.

Just to add to what my fellow speakers have said, and to a point made earlier about these very low-latency cables, the major and perhaps most worrying trend with regard to them is not their ownership, but the trend towards consolidation. Right now, undersea cable networks are quite resilient. Some 200 cables a year break due to non-malicious causes.

Mike Martin: They are owned by loads of different people.

Dr Sidharth Kaushal: Yes, but the more reliant we become on an ever smaller subset of cables for things such as cloud computing and AI—

Mike Martin: Do you have any data around the consolidation into a smaller number of companies such as Meta?

Dr Sidharth Kaushal: There are only a handful of companies, usually in consortia, involved in the construction of major cables such as SEA-ME-WE between Asia and Europe. In terms of ownership structures as well as the numbers of cables that we are reliant on, we are likely to see a system that is both more efficient and more fragile in, say, 10 to 15 years.

The Chair: That would be really interesting to know, and may be something else that could be furnished to the committee, just to understand this consolidation, the ownership, and who is defending and paying for the protection of these cables when certain companies pay so little tax, for example.

Lord Sarfraz: I have a follow-up question on demand. How much will the exponential growth of AI impact the demand for connectivity and, therefore, cable infrastructure?

Elisabeth Braw: It is continued growth, and AI is one of the aspects of that growth. The rest of that growth is not just us but people around the world using connectivity more and more. The way that the invisible hand works is that there are companies willing to provide that connectivity, as has been discussed, such as tech companies. Some companies exist only to own and operate undersea cables.

What do not exist as much as they did in the past are national telephone companies as owners. Here in the West, we have, essentially, lost all national telephone companies as companies to begin with, but also as owners of undersea infrastructure, so it is completely privately owned. Ordinarily, that would not be a bad thing. If there is a company willing to provide that connectivity, that is great, and there is, but the problem begins when there are threats to that arrangement. Who is going to pay if something goes wrong?

Professor Kevin Rowlands: AI will undoubtedly bring an increased requirement for the transmission of information. We should bear in mind that, when we are talking about cables, they are only a means of transmission. The important thing is the information. What AI will also bring is a huge requirement for energy, and so just as important is making sure that our energy supplies and means of transmission are safe. If you look at recent examples in Spain and Portugal, when there is a threat to energy, you also lose information and communications.

The Chair: We will pick up briefly on that point in just a moment. Can I just ask you a final quick question? Relative to, say, Japan and other island states, are we more vulnerable or less resilient?

Matthew Bowden: It depends on where you are looking around the world. As a whole, in the current state of the world at the moment, the UK is pretty resilient. That does not necessarily mean that, in a low-risk, high-impact disaster scenario, we are any better off than anybody else.

One of the things that is really important from the UK’s perspective is that, as you have alluded to, we have a lot of cables. There are 11 transatlantic cables. That is a degree of resilience. We have an excellent repair set-up. We have ships in Brest and Portland. In terms of the ability to respond and instigate repairs, we have a great legislative framework for those repairs to take place from the telecoms side of life. In terms of looking at other nations, we are in a reasonably good place, resilience-wise.

Just to come back on a couple of earlier points, on AI, I agree 100%, bearing in mind that everything from AI to quantum computing, all of those drivers and the so-called internet of things, is all data-hungry. That is why we are seeing this demand.

It is also worth making the point that the big tech companies are not the only cable owners. To be clear, for the most part, the reason that they are building those networks is for their own use. They will almost certainly sell space on them. It does not mean that they will, but it is highly likely. Principally, they are building them for their own use, because the data requirement for transmission around the globe between data centres on their own is demanding it.

Q4                Bill Esterson: Matthew Bowden, you were just making the point about how resilient we are. How resilient is the cable network if we had moderate damage to it?

Matthew Bowden: What do you envisage by moderate damage”, if I may ask?

Bill Esterson: I was afraid that you would ask that. As you know far more than we do, how bad would it have to get before we should get worried about the level of damage?

Matthew Bowden: If you look at the normal state around the world, a cable breaks roughly every three days somewhere in the world. Quite often, that is in Europe, because we have quite a high concentration of cables. We also have quite shallow water. By and large, with the exception of scenarios such as the one in the Shetland Islands, where you are talking about a remote community, you do not notice. When Amitié broke last year, it was not really noticeable in the UK. Traffic gets rerouted, the companies support each other if necessary, and the repair instigation is quite swift.

Notwithstanding fishing, anchoring and any other cable breaks that happen through attrition and subsea movement, all of that is pretty well contained. What I think you are alluding to is, if we started to have nefarious actors, that then changes the dynamic. How far would it have to be pushed? It takes roughly four to six weeks, depending on where the cable is in the world, to repair a telecoms cable, provided that the spares are in the depot and the ships are available. We have three ships in the Atlantic Cable Maintenance and Repair Agreement—one based in Portland, one based in Brest, and one based in Curaçao at the moment. If necessary, depending on what was going on in the world, the way that the maintenance authorities and agreements work is that they would probably call upon each other to support, should they need it.

If you have three cable breaks, you have three cable ships working on them. The fourth cable break is when the problem starts. You will have to wait until a cable ship becomes free. At that point, when you start racking up additional cable breaks—bearing in mind that, if you are talking about multiple breaks in a single cable, that is a more complicated repair that takes more time—you can imagine that, if somebody is out to do something malicious, your repair capability can be used up quite quickly.

Elisabeth Braw: The Matsu Islands are a really good example. They have two cables connecting them with the rest of the world. On 2 February 2023, a Chinese ship cut one of them, and the other one picked up the traffic. That is how cables are designed. The second twin picks up the traffic of the first twin if it is damaged. Six days later, another Chinese ship cut the second cable as well, and the Matsu Islands were disconnected from the world. That is what we may face if somebody were to decide to cut several pairs at the same time.

In the case of a remote location such as the Matsu Islands, where there is only one pair, cutting that pair would completely disconnect that location from the rest of the world. It is an interesting thought exercise—or, for the people on Matsu, a real exercise—to just think about how you would spend even one hour without any connectivity. It is harder than one thinks.

Bill Esterson: What proportion of our cables being cut would make it very difficult to reroute or to maintain the network?

Matthew Bowden: You can get sidetracked by looking at the number of cables. It is the capacity of the cables that are cut, and the information that is being passed over them, that is important, as well as the ability to reroute. In theory, the UK’s transatlantic data capability is around 850 terabits. That could be, for the most part, absorbed by rerouting elsewhere.

The challenge comes, of course, if anybody else is experiencing a similar issue. To reroute 850 terabits would take quite an amount of time. If you are talking about losing four, five or six relatively low-capacity cables, you could reroute through Lisbon or Marseille, or even through other areas of Europe, and bring the cable information into the UK. It is not quite as simple as just saying, “We have had six out of our 11 cables cut. Everyone, light your hair on fire and run around in small circles”. It is a bit more complex, and that rerouting piece is fundamental to that whole repair strategy and the resilience. Does that make sense?

Bill Esterson: I hope so. Something else springs to mind. You talked about four to six weeks to repair if you are doing up to three. Presumably, that starts to get very difficult fairly quickly after that.

Matthew Bowden: Yes. It would be an interesting scenario to test. I can probably find out what the most stressful repair scenarios have been in recent years as an illustrative example. It was quite interesting for the cable ship operating off the coast of Africa post the landslide recently. There were four cables cut there, and that cable ship had to repair all of those. It is just a succession game. It is about loading the correct spares and putting the ship on task until it completes.

Bill Esterson: If I can come to the point about energy that you raised, Professor Rowlands, the NATO Energy Security Centre of Excellence has raised concerns about the threat to the Baltic undersea power cables. To what extent should we have similar concerns about the UK?

Professor Kevin Rowlands: One of the interesting things about the UK’s energy infrastructure is the move to offshore wind. We are the second biggest market in the world at the moment after China. A lot of the wind farms that we have are in places that are easily accessible and where the water is shallow, and the energy that is produced by those turbines is coming ashore through cables and pipelines. They are pretty vulnerable. That degree of reliance on offshore energy, either fossil fuel or renewable, is increasing and is vulnerable.

Elisabeth Braw: Renewable energy is a key part of the UK’s energy strategy. So much of that depends on companies having the confidence to build that infrastructure. If they now hear that offshore wind farms may be targeted or may be vulnerable to geopolitically motivated undersea activity, will they have the confidence to make those investments?

When it comes to the repair of interconnectors, which are the other form of undersea energy cables, they do not have the same brilliant repair arrangement that communications cables have. Repairs are much harder and take a lot longer, with a longer waiting time. What we have seen with the cables that have been harmed so far is that the waiting and the expenses have been considerable.

Bill Esterson: Gas pipelines are a threat as well, but we are talking about cables. What is the answer to this? What should the authorities and the private sector be doing to address the concern with energy cables?

Professor Kevin Rowlands: There is not one single answer. There is a range of steps to take that are all possible. The offshore installations and critical maritime infrastructure, whether that is information or energy, can be made more resilient. Matt will know far better than me that the durability of a cable close to shore in shallow water is greater than ones that are further offshore and less likely to be targeted. In terms of the layout of wind farms, for example, you can put the central tower to be the one that is of most importance. You can put it in the middle to make it the least vulnerable, and so to get at it will take more manoeuvring.

I would go back to what the main thing is that we can do, which is greater information sharing and co-operation between the private sector, the public sector and different jurisdictions within the country, and departmental oversight and international agreements. All of that is really important.

Bill Esterson: We should certainly be concerned about it. That is your main point.

Q5                Sir Julian Lewis: Having, by sheer coincidence, recently visited the marvellous museum at Porthcurno in Cornwall, which celebrates the history of cable and, indeed, wireless undersea communications, as far as the cable is concerned, I was impressed by the fact that, from the earliest days, whenever an international conflict has broken out, these cables have been systematically targeted. I believe that the first week of the First World War saw Britain cutting German communications to the continent very effectively.

Of course, this has been hugely multiplied in the modern era, but the question I want to put to you is whether I am right in thinking that, if a major power put its mind to it, there is no possibility that the existence of any number of cables could be concealed from a potential adversary. No matter how many you build, whether it runs into the low hundreds or even a thousand or so, if a major country set its mind to it, it would know where they all are and, theoretically, could mount a concerted attempt to make it impossible for the system simply to take up the slack whenever some cables were cut and others were not. Is that correct?

Professor Kevin Rowlands: I would not say that anything is impossible. I would accept that it is extremely unlikely that you would be laying a network of cables that no one knows about. Just in terms of the way that the systems work, the more cables there are, probably the more redundancy that there is.

There are a couple of ways of finding out. The first thing that a potential adversary, or a defender, will need to do is understand the system and what it is that they are trying to either protect or target. There are a couple of ways of doing that. A lot of the information about cables and pipelines is freely available. There are publicly available websites that you can go on today. KIS-ORCA is a really good one. You can have a look and see exactly where the stations, cables and routes are. It is geographically very accurate. You can just look online and see where they are.

You can also go out and search for them, which is what some of our potential adversaries are and have been doing for some time. They will map the network and understand the vulnerabilities.

Sir Julian Lewis: Presumably, they are doing that on the basis that they feel confident that it is worth doing it, because, if they can cut enough of these cables, it will not be possible simply to reroute the traffic. Otherwise, they would not be bothering to conduct these surveys, would they?

Professor Kevin Rowlands: It depends on what the motivation is and whether this is for all-out total war or grey-zone hybrid activity, whatever you want to call it, and whether it is going for financial hits, or hits on civic society that will cause internal disruption.

Sir Julian Lewis: I appreciate that they could do it on a graduated scale as a nuisance factor, sending political messages and all the rest of it, but the real question is about what happens in an all-out conflict between major states. Can the grid survive?

Dr Sidharth Kaushal: In some ways, in an all-out conflict, this becomes a simpler problem, if you look at some of the capabilities that an adversary state might use to target cable. If we take Russia, for example, some of its deep-diving submarines such as the “Losharik” are hosted on larger motherships such as the “Belgorod”, a stretched Oscar-class submarine. Oscar-class submarines are not something that NATO navies are unfamiliar with. The real challenge in peacetime is, if one detects one near a cable and suspects it of malign activity, what are the Navy’s rules of engagement?

In some ways, that challenge becomes a lot simpler if you are in a shooting war, because the capabilities that are being employed are improvised and quite innovative variants of capabilities that allied navies are already quite familiar with. For all the ingenuity that has gone into them, they are not something fundamentally novel.

I would also point out that the systems themselves are relatively scarce. To dive to extreme depths, submarines such as the “Losharik” need to be titanium-hulled. The crews that man them, who are drawn from the 29th separate submarine division in Gadzhiyevo, are comprised of officers from the ranks of Russia’s submariners who have both served for five years and then gone through a rather rigorous training regimen based on cosmonaut training, all of which is to say that both the platforms and the people manning them are very difficult to replace. If even a handful of them are lost in a conflict, the odds of large cable networks with a lot of redundancy being disrupted at scale dip precipitously, so it is a bigger challenge in peacetime.

Equally, in peacetime, the attacker has a dilemma between impact and deniability. Attacking a single cable is deniable but it is also low-impact. Attacking multiple in quick succession may have a system-wide impact, but you no longer have a deniable activity.

In some ways, the threat to more resilient systems can be mitigated, both in peacetime and conflict. Where there is more risk is when systems are reliant on a relatively small number of fragile nodes. I would say that gas is a good example, where individual pipelines, such as the Langeled pipe, comprise a massive portion of the UK’s energy mix.

I would also signpost, within cable networks, military cables, which are secure cables that transmit military data, the locations of which are more secure or secret, but which are also much smaller in number and which you could, in theory, disrupt in peacetime in a deniable way, with serious impact, without having to damage a huge number of targets on a non-deniable basis, essentially.

Q6                Mr Tanmanjeet Singh Dhesi: With regard to undersea cables and critical infrastructure, I want to now go into deniable threats and capabilities, which is something that, Dr Kaushal, you were touching upon just now. Our Defence Committee has an ongoing inquiry into defence in the grey zone—things happening just beneath the threshold, but with that ability to deny. Ms Braw and Dr Kaushal, could you briefly talk us through the various options available for attacking cables with deniability? Also, going further with regard to what you were saying, Dr Kaushal, how do you see the capabilities available to the likes of Russia, China and others evolving in the next five to 10 years?

Elisabeth Braw: Defending against grey-zone aggression is a defender’s dilemma, which is, unfortunately, why I had to write a whole book describing exactly what the dilemma is. Part of the dilemma is that the events that we are defending against can occur in a non-hostile way. When it comes to cables, they are sometimes cut—in fact, between 150 and 200 times a year. It is a growing number, because we are getting more cables. That occurs naturally as a result of accidents and mistakes by fishermen and other maritime practitioners.

What do we do when we suspect that it is done intentionally? That happens across the board with grey-zone aggression, whereby something that can be the result of just common criminality or human error can also be done as a hostile state activity. How do we identify that that is what is happening? Should we just tolerate that it is happening when done by a hostile state because it occurs in other ways too? That is where we are when it comes to undersea cables.

If we frame it as an issue of how many cables are cut and how many are cut with ill intent, potentially at the behest of a hostile state, we may be missing the real problem, which is that one or more hostile states seem to already be harming our undersea infrastructure as a way of harming our societies. If it were to be the case that an energy plant on land, or a water plant, was sabotaged by a hostile state or by an actor that we think is linked to a hostile state, we would not just say, “We can fix it”. We would say, “What should we do about it?” That is the point that we should get to when it comes to undersea cables.

Mr Tanmanjeet Singh Dhesi: Dr Kaushal, could you just expand upon the capabilities, especially of the likes of Russia, for example, with Spetsnaz GRU and GUGI, et cetera? Could you just talk us through that?

Dr Sidharth Kaushal: In terms of Russia’s capacity for undersea sabotage, it would be broken down organisationally between two groups. The first is GUGI, the main directorate for deep sea research, which is an organisation that is staffed partially by, but not subordinate to, the Russian navy. It answers directly to the Russian MoD. The directorate operates platforms such as deep-diving mini submarines such as the “Losharik”, a titanium-hulled submarine that can dive to a depth of several thousand metres.

It is likely to be the organisation involved in, in particular, sabotage against cables conducted at depths and in areas where, by design, repair is made very difficult. It should be said that sabotage is not GUGI’s primary or only function. It also has roles such as maintaining Harmony, Russia’s undersea surveillance network, particularly in the High North, as well as a very important espionage and surveillance role.

The second organisation would be the Russian navy itself. Through the main intelligence directorate of the Russian naval staff, which is typically headed up by the deputy director of the GRU, the Russian, and before it the Soviet, navy has historically been involved in the use of auxiliaries or civilian vessels for tasks such as surveillance. Some of its military assets, such as the Akademik “Vladimirsky”, are also equipped with some sensors that could be used for surveillance. Finally, of course, the regional Spetsnaz units are subordinate to the GRU and so would fall indirectly under the naval staff’s control.

Conceptually, subdividing that, you might say that GUGI is more likely to be involved in sabotage in deeper water, with more exquisite capabilities, whereas something such as dragging an anchor over a cable in the Baltic involves the sorts of organisational frameworks and capabilities that the GRU and the Russian navy might operate. Maybe that is a good way to separate the different components of the Russian system.

Elisabeth Braw: Just to add to that, it does not have to be the Russian state. As we have seen, Russia is quite willing and able to recruit freelancers, which is what seems to be happening with undersea cables, and all kinds of other activities, and Ken McCallum, the head of MI5, warned of exactly that a few months ago.

Mr Tanmanjeet Singh Dhesi: Mr Bowden and Professor Rowlands, the European Subsea Cables Association has remarked that there are approximately 150 to 200 incidents per year. In your opinion, are Government and industry doing what should be done? If not, what could they do better?

Matthew Bowden: Government and industry in the UK are making really good strides, particularly in recent years. The SCCIG, which is the subsea communications cable industry group, has taken forward a number of initiatives. It has done some workshops and an exercise to look at the impact and how it would affect that department, for example, in its translation of information to COBRA. That conversation happens on a regular basis and involves people across the submarine cable community in the United Kingdom and from wider afield, because they all have other responsibilities.

It is, however, embryonic. They know that—I say “they”; I am part of it—and are working hard to address that and take forward all the work that is needed to fully understand. It is a very big task, and it is just worth pointing out that we are talking about the cables and focusing on the wet part, so just bear in mind that, when you talk about the cable, it lands on the beach and goes through what we call a beach manhole. That beach manhole can have several cables connected into it and is equally, if not more, vulnerable than the cable that it is connecting to. There is then a fronthaul that connects that beach manhole to the cable landing station. The cable landing station then has a backhaul that connects it to the requisite data centre or repository for information that the cable leads to. Every single one of those links in that chain at both ends of the cable system is a vulnerability that needs to be addressed and secured.

The Chair: We will come back to that in just a moment.

Mr Tanmanjeet Singh Dhesi: Professor Rowlands, if you could answer with regard to malicious damage, are the Government and industry doing enough? What more could they do?

Professor Kevin Rowlands: Are they doing enough? What is enough? They are making huge strides in co-operation.

The Chair: I am afraid we are interrupted by votes in the House of Lords, so the sitting is suspended, and we will resume very shortly.

Sitting suspended.

The Chair: Our session in our inquiry on undersea cables resumes. I would like to bring in Edward Morello.

Q7                Edward Morello: My question is for Professor Rowlands. I am interested to know whether we have any lessons to learn from the effectiveness or otherwise of NATO’s Baltic Sentry mission, and what those should be that the UK can adopt.

Professor Kevin Rowlands: We need to learn lessons from all incidents and operations around the world and see what they are. There are lessons that we are thinking about at the moment in looking at what is happening with Baltic Sentry. Of course, there have been different national responses to events within the Baltic Sea region.

One of the things that we need to think about is the approach that we take nationally to this type of incident. As I said earlier, the first thing that we need to do is know how to understand the situation and the networks that we are trying to either defend—or to potentially attack ourselves, which is an idea that we should not dismiss.

We need to think about how deterrence works. At the moment, we do not really have a good handle on that. How do you deter malign activity in the underwater environment when it comes to critical international infrastructure? It is quite complicated.

We need to know how to detect malign activity, which will take equipment, capabilities and more mass than we have at the moment. The Baltic region is constrained. It is small. It is very well mapped, and we know what is happening. That is quite different to the North Atlantic, which has very different oceanography and topography.

How do you protect? You may detect something happening, but how do you protect against that thing happening? Again, we are not necessarily good at that at the moment.

One of the important things that we need to be able to do is attribute responsibility. We have the technical capabilities to do that, but, with due respect to the people in the room, it is ultimately a political decision to attribute responsibility when we know, or when we think we know, who has done it. Then it is about responding, including repairing. There is a whole series of things to go through from understanding before you get to repairing. We need to take each of those individually, and they are quite complicated.

The Chair: I am conscious that we are not sure whether there is going to be another vote, but perhaps we could press on. Please bear with us. Lord Sedwill?

Q8                Lord Sedwill: I would like to pick up the conversation that we have started about moving to, essentially, a more overt, low-probability but higherintensity conflict where adversaries are less concerned about attribution, rather than necessarily full-scale armed conflict. We know that the Russians are working very hard at this in the Atlantic, the Chinese in the Indo-Pacific, and presumably the Iranians in the Middle East. There are choke points all over these places.

Mr Bowden, perhaps I can just start with you, because you touched on this already. What is the balance of vulnerability between cables, on which we spent most of the time, and hubs, nodes and choke points coming ashore? Also, how vulnerable are the providers and the people maintaining and having to repair any of those facilities if we were in a more overtly hostile situation?

Matthew Bowden: What I am hearing is a question about the supply chain. Oh, do I need to hold that thought?

The Chair: The session is suspended momentarily.

Sitting suspended.

The Chair: Sorry for that brief suspension. You can blame the Lords.

Lord Sedwill: Mr Bowden, you touched on the range of vulnerabilities. I was asking about the blend of those cables and the onshore landing point hubs, choke points, et cetera, versus those people and capabilities that are involved in maintaining, repairing and managing the cables.

Matthew Bowden: It is a really interesting question. I will be very honest and say that it is probably worthy of quite an in-depth look. My gut instinct is that, if you asked me today, I would say that the cables are probably better protected than some of our onshore infrastructure.

One of the drumbeats that we keep hitting is that it is all very well designating the submarine cable as critical national infrastructure, but, if you have not designated all of the intervening links that take it back to the data centre, for example, as critical national infrastructure as well, and are not affording them the same level of protection, whether it is a non-state actor or a state actor acting in a grey-zone manner, those are equally vulnerable.

The other piece that I was just touching on before we went to the break was about supply lines and personnel. It is worth bearing in mind that the industry is ageing. Most of its people are very experienced. That is the way that we like to talk about it. It is quite difficult to get youth into the sector, although the sector is now actively trying to address that.

It is also not a very big industry globally. When you understand the nature and the significance of the global infrastructure, and then you look at the number of people, I remember somebody saying that there are about 50,000 to 55,000 people globally involved in the submarine cable industry, which is not very many.

There are new cable ships coming online, but most are not young. The three cable ships I alluded to are those nominated to ACMA, so it does not take a rocket scientist to work out that, if you can do something that takes one of those cable ships offline, you have lost 33% of your repair capability. We do not have any UK-owned repair capability. Global Marine, which was a UK company, has just been bought by Singapore. What are the ramifications of that? Orange Marine runs the vessel out of Brest. Global Marine runs the one out of Curaçao at the moment. With the greatest respect to our French allies, if it comes down to an order of priority between a significant number of breaks over whose cable is getting repaired, I would bet quite a lot of money that the French Government would influence Orange Marine in terms of their prioritisation, and it would not necessarily be in our favour.

Lord Sedwill: How hard is it to protect those ships conducting repairs if we were in a more overt situation?

Matthew Bowden: The Navy and NATO practise the protection of assets and what we call high-value units all of the time. It is a relatively straightforward scenario from their perspective. Interestingly, the cable ships never practise it, and so operating in that scenario would be quite tricky.

The other problem is that, if you have broken a cable, you know where the cable ship is going to go to repair it. Therefore, while you have a high-value unit that is potentially being protected by a number of military assets, you know exactly where that unit is, it is not going to be going very fast, and it has no defensive mechanisms at all of its own, so you would need quite a significant effort to ensure its survivability.

Lord Sedwill: If we can just come back to the onshore, how concentrated are those onshore landing points? I know that Bude, for example, is often spoken of as the primary one in the south-west. How many others are there, for example, around the UK of that scale?

Matthew Bowden: There are a number of others around the UK. We have quite a few landing points. A lot of them are because we have a number of internal fibre point-to-point fibre networks within the UK.

In terms of major landing points, off the top of my head, depending on how many you consider to be major, I would say that there are five or six significant ones. The south-west approaches, both Bude and Porthcurno, are significant. The south coast connecting to France and then the south-east peninsula connecting across to the Netherlands and Belgium, et cetera, are significant, as well as the one on the eastern coast connecting across to Norway and Denmark.

Lord Sedwill: Presumably, from your earlier answer, if undersea cables are a natural point of vulnerability for deniable operations, were we in a more overt confrontation where onshore facilities might be targeted, your point about them being perhaps more vulnerable and less well protected becomes more pertinent.

Matthew Bowden: Yes, absolutely, and the supply depots would be a key point. Just going back to the power cables that we were talking about, it is worth highlighting that spare power cable is in very short supply. If somebody attacked and damaged any of the power cable spares, trying to replace those to effect repairs to interconnectors would be a significant challenge. I would just reiterate that we should not underestimate the impact of losing our nine interconnectors on the United Kingdom power grid.

Lord Sedwill: Other witnesses may wish to add something, but I wanted just to keep us moving. Professor Rowlands and Dr Kaushal, you might want to pick this one up. What do we know about the extent of our adversaries’ capabilities, covert and overt, to carry out the kind of activity that we have just been discussing, whether that is against the cables themselves or against onshore facilities and the rest of the network?

Professor Kevin Rowlands: We have already mentioned GUGI, the Russian main directorate of deep sea research. We know that it has over 50 vessels. It has submarine capabilities. It can reach depths of about 6,000 metres, which is pretty deep and will cover all approaches around the UK, and certainly the North Sea and beyond the continental shelf. In capability terms, they have it.

That is not necessarily the same as the ability to effect damage without being detected. Of course, we know which ships they are. We can track them. I would be as concerned by the less attributable actions of dragging anchor cables, sabotage on a beach with an axe and so on. There is a range of things that can happen.

Before I hand over, rather than look at the systems that adversaries may have, we need to look at the types and the techniques that any adversary around the world might be able to use. Dragging an anchor over a wellplotted cable is easy and deniable. Pre-positioning any timed charges is difficult and risky for whoever is doing that. The seabed moves, there are weather effects, and it can probably be found. Using divers is difficult and, again, is trackable. In the future, one-way uncrewed underwater vehicles are probably a way ahead for any adversary.

Dr Sidharth Kaushal: I would just add to what has already been said by saying that the capabilities that are at the disposal of an adversary such as Russia are very much dependent on both geography and the scale of an ongoing conflict. If you look at auxiliary vessels dragging anchors as an example of some of the cheaper and more deniable tools at Russia’s disposal, this can be done in a very specific geography in places such as the Baltic Sea, which are comparatively shallow. It is also typically the sort of thing that one can do only in peacetime, because the auxiliary vessel is hiding in maritime traffic, which, as we have seen in the Black Sea and the Red Sea, tends to disappear once a shooting war begins, so that needle in a haystack quality is lost.

Some of the more exquisite capabilities, such as the deep-diving submarines that Professor Rowlands mentioned, are certainly usable in a wartime scenario, and the damage that they could inflict at the depths at which they can operate would be considerably harder to repair.

However, when we discuss vulnerability to those capabilities, in some ways, we are not having a conversation about cables per se, but about anti-submarine warfare. There is a legitimate conversation to be had about whether the “Belgorod” could slip through the Greenland-Iceland-UK gap and support sabotage operations in the Atlantic, but that applies just as clearly to, for example, a Yasen-class submarine slipping through the gap and launching cruise missiles at the UK.

In some ways, in a conflict scenario, the capability mix that an adversary can use narrows down and the conversation about protecting CNI becomes a sub-component of the conversation about anti-submarine warfare.

Q9                Lord Robathan: I am sorry to have missed the beginning of this question, but I think I have the drift of it. I have a couple of questions. One comes from Mr Bowden’s answer, because he has already told me how he is used to people who do not know anything. Without destroying the cable, could you fix something on to it to hack the cable?

Matthew Bowden: It is an excellent question and one that we are, again, often asked.

Lord Robathan: I thought you would be.

Matthew Bowden: I would posit that there is another part of that question, which is “without anybody knowing”. The answer is that nothing is impossible. It is entirely feasible that you could hack into an optical fibre cable and put a device in there that can look at the transmission and pick up signals going through that cable.

However, doing so without it being detected by the operating company is virtually impossible. If you ask the industry, their response will be, “You cannot do it”, because, as soon as you touch the cable, the variations in the signals that are detectable at the other end are so apparent that, if you then start to manipulate the cable in a significant way, it becomes very obvious.

Lord Robathan: That is extremely full. Thank you very much indeed. This is about another question you have been asked before. I know that my colleague asked about Russia and you spoke about Russia. What about China? Do they have the same capabilities?

Matthew Bowden: Yes. There was a lot made of the recent patent that was filed for a Chinese “cable cutter”. Actually, it is a device that could be used in normal industry practice. I would not say that they would have any less capability than Russia, not excepting the fact that their submarine fleet is not as advanced. It is not as capable in deep water.

There is a whole conversation about how deep the cable has to be before it is protected from a submarine or a USV threat, which is worth bearing in mind. There are stories of cable ships dragging for days to try to find cables that they have the exact locations of, because cables move. It is just worth bearing that in mind as well. I would absolutely say that China has similar capabilities.

Q10            Lord Sarfraz: I have just a quick follow-up, which is in regards to onshore landing infrastructure. Who is responsible for keeping that infrastructure safe? What sort of measures are taken at these facilities? I assume that they are manned, with security guards there. Do they receive any specialist training or are they the same sort of security guards you would find at a Tesco?

Matthew Bowden: My immediate answer is that the security of those facilities, by and large, rests with the cable owners and the operators. Bear in mind that we have designated these systems as critical national infrastructure, but they have been procured and built on a commercial scale and on a commercial model.

Therefore, security against a hostile state actor was not at the top of their list when they built these systems and put them in place. They may be considering those aspects now. That is not to say that systems are not secure, because all of the companies that build cable systems have secure facilities, but they are secure from a commercial perspective, to protect their infrastructure from malicious attack, rather than from a hostile state act. Does that make sense?

Lord Sarfraz: Yes, thank you.

Matthew Bowden: It varies greatly.

Professor Kevin Rowlands: Could I add something very quickly? I am afraid it is almost a question back, because I do not know the answer. I would question whether our local constabularies around the country have the same amount of knowledge about these parts of critical infrastructure as they do for other valuable parts of the state, where they may be required to respond to an incident.

For example, we know that if, in a local area, there is a power plant or an oil refinery, the local emergency services will know about it and practise responding to events that happen there. I am not aware that that is the case for data landing sites on beaches and so on.

The Chair: Can I just intervene on that? There was an incident where a Times journalist went and explored around a particular facility. Could that still happen today?

Matthew Bowden: I am not aware of that incident.

Professor Kevin Rowlands: I am not aware either.

The Chair: It was 2018. Does that ring a bell?

Professor Kevin Rowlands: No.

Elisabeth Braw: I can give you an anecdotal answer. Just after the Nord Stream incident, I went to Lubmin, which is where the Nord Stream pipelines come ashore. It was indeed the case that the landing site was pretty unprotected. I was with the mayor of the town and he said, “Let us go this way, away from the landing site”, but, if I had been there on my own with hostile intent, I could have approached that landing site.

Matthew Bowden: I will just very quickly add that more landing sites in the UK, both internal links and external, are unprotected than are protected.

Q11            Baroness Fall: What has emerged is a sense of national security infrastructure, commercial focus, some lack of resource in terms of fixing these cables, an increasingly volatile geopolitical landscape, economic nationalism, with tech at the heart, and decoupling. We might see more of that with AI, especially with China. My question focuses a bit more on that. It is a bit like the cyber issue, when it was beginning to come to our attention. Do we know who is responsible, between the government response and the commercial response, when a cable is cut? Is that clear?

Elisabeth Braw: The operators themselves are responsible when there is damage to the cable. If there seems to be hostile intent in the damage, the Government, the coastguard, in most cases, and the police will go out and investigate. I am glad you brought this up, because this is where the criminal justice system collides with geopolitics. If the coastguard and the police decide that it seems to have been intentional damage, they cannot do very much with that.

They can only take it through the criminal justice system, which is why we have seen the recent cases in Finland, Sweden and other countries go nowhere, essentially, because it is extremely hard to pursue that case through the criminal justice system when it is actually may be geopolitically motivated. On top of that, we have the commercial aspect of who pays for the repairs. When it is naturally occurring damage or human error, it is settled by the operator and the insurer.

However, in recent cases, including in Estlink 2, which was damaged on Christmas Day, the operator and the insurer will take diverging viewpoints on the damage that occurred. The insurer may say—and has said in several cases—“This is geopolitically motivated aggression. It is not covered by standard commercial insurance”, and we get court cases. We already have court cases and will get many more, because insurance companies, unsurprisingly, are reluctant to pick up the tab for geopolitically motivated aggression.

That is where we are today. By the way, we are already seeing a case go through here in the UK, in the London High Court, involving Nord Stream, its insurers and £400 million in damages that somebody has to pay for. We will see more of this. I do not know what gives. I just know that the commercial arrangement is not enough to handle these incidents on its own.

Baroness Fall: Presumably, it is quite difficult to tell whether it is a state actor who has done it.

Elisabeth Braw: Yes, and that is why we are seeing undersea operators and their insurers trying to define what constitutes an act of war. It is extraordinary. We have been fighting wars for many centuries and we thought we knew what a war was. Now, it turns out we do not know what constitutes an act of war. Undersea operators and their insurers are having to define what constitutes an act of war.

Dr Sidharth Kaushal: If I could just add two things on that, in terms of the difficulty of knowing whether a state-backed actor is involved, where an act of sabotage happened matters a lot. In a theatre like the Baltic, given the shallowness, you can use capabilities that are at the disposal of a lot of actors, such as a commercial vessel dragging its anchor. In the North Sea, or the Atlantic even more so, given the depths involved, the capabilities that would be relevant to sabotage would only possibly belong to a state-backed actor. It is worth just caveating the problem on that basis.

Matthew Bowden: I just want to say two things very quickly. The lack of resources that I was specifically alluding to is in the eventuality of a heightened threat scenario. Please bear that in mind. Day to day, now, there is not an issue. We can repair cables.

In terms of the responsibility piece, it absolutely rests with the operators and the owners. One of the things to bear in mind is that the speed at which they respond and the speed at which the ships are activated is so far inside the OODA loop of government that the ship has sailed before you have convened COBRA. Bear that in mind.

Q12            Lord Boateng: Reference has been made to the lack of resources, the absence of clarity around who is responsible for what and different private and public sector actors, hostile or otherwise. Given the resources are always going to be limited, what should the Government prioritise to improve the security and resilience of the UK’s subsea cable infrastructure?

In terms of the role of the Treasury in bringing together both public and private resources to this question, how does the current comprehensive spending review that is taking place play into seeking an answer to this need for interdepartmental and public/private co-operation and additional resource?

Professor Kevin Rowlands: Those are a series of points that are all very well made and quite difficult to answer. Undoubtedly, the UK lacks some mass in capability terms to respond to events and incidents. Whether that should be the most important thing for us at this moment is a political question and hopefully the NSS and the SDR will provide some clarity on that.

From a personal perspective, the most important thing that the UK Government can do now is provide that clarity on ownership and interdepartmental, interagency, international and public/private cooperation, so that we do not have this misunderstanding or different understanding of who is responsible to do what at what point. As we have heard, private property carrying private property is a private company’s responsibility to deal with if there is a natural break. If it is a result of hostile action, no one in the country is going to believe that the Government should not do something in response. Understanding ownership and how we can do that is a first step.

Our next step should be learning how to deter malign activity—stop it happening in the first place, rather than waiting to respond to it when it has already happened.

Elisabeth Braw: If I could continue, the NATO Maritime Centre for the Security of Critical Undersea Infrastructure, which is located right here in London, is a brilliant example of public/private co-operation. The monitoring is only that. It is not a response centre. It is not going to take action if malign activity or suspicious activity is detected. That brings us to your point. What are we going to do?

I should interrupt myself here. One other thing that companies can do is put more sensors on their installations, which is a good step. They are doing that. It will reassure their owners, customers and Governments, but the fundamental question when it comes to undersea cables and other undersea installations is, if we notice that suspicious activity is occurring, what we are going to do with that information. Not just when it occurs, but before it occurs, what are we going to signal in our deterrence signalling to other countries? What are we going to say about our efforts? The signalling should be, “If we notice suspicious activity, we are going to do X”. What is that X? Nobody has decided what it is going to be, considering that the hostile activity may, in many cases, involve fishing boats and similar.

Lord Boateng: There is now an international advisory body on submarine cable resilience arising from the US-UK joint statement on the security and resilience of undersea cables. It met in March of this year in Abuja in Nigeria. Has that body begun to produce any help and guidance in this area? What is the role of international co-operation in this regard?

Matthew Bowden: You are right. It did meet, and it is a really good step forward, but bear in mind that that was almost exclusively industry bodies meeting and talking. Although everything that has been said is really positive and really important, right now, from the sector’s perspective, communication and discussion is probably the most important thing. I am not talking about internally within the United Kingdom; I am talking about externally.

Our territorial waters extend to 12 miles. Our contiguous zone extends to 24 miles. Beyond that, we are really limited in the amount of authority and extraneous power we can exert. Having conversations with our allies, particularly those that have companies that operate our cables, that have the platforms that repair our cables and that have cable landings that extend into the UK, is really important. This is not a lone game. There is a lot of consolidated effort that needs to be put together to make sure that a whole bunch of nations do not go off half-cocked, putting together a whole bunch of legislation that counteracts each other. We have seen that in the industry. It needs to be a coherent, cohesive approach.

Do not get me wrong: national interest is really important and that is why we are all sat here today but, as Kevin alluded to earlier on, this is an international game. Our international partners have levers that we can utilise. Likewise, we have levers for them. We are a massive pathway for European data from the continental United States and Asia, because not all of it comes up through the Red Sea. Some of it does come across the Americas and across the Atlantic, into Europe through the UK. That is a really important point to make.

The Chair: Can I thank you for your time today and for sharing your knowledge and expertise with our Committee? I always find these sessions particularly not just informative but terrifying as well, or maybe alarming. As often, when you start drilling into these sorts of topics, you realise just what the reality is on the ground. We hope to explore, over the coming weeks in other witness sessions, the capabilities that are out there from adversaries and potential adversaries, but also those that we have. We touched just then on NATO. We will be hearing from various individuals from a military perspective about some of the challenges they face. In terms of what capacities we have, some of those challenges with the onshore stations and the reality there, this session has been hugely helpful and informative.

Can I thank you all for your time once again? I am sorry that it was interrupted. It is always a problem with these sessions. Thank you for your patience in that.