FEATURE STEPPING UP TO MEET SUBSEA SECURITY CHALLENGES
BY KATHY KIRCHNER
B
ack in February, new recommendations from the EU Commission on making submarine cables more secure and resilient highlighted concerns around the increased risk of attacks by malicious actors against critical maritime infrastructure. It follows a growing number of reports around subsea security, revealing a creeping anxiety in the US and Europe about how dependent economies have become on cables that carry 99% of international data traffic. The anxiety mirrors geopolitical tensions, conflicts in Ukraine and Gaza, where vulnerabilities in the pipes and cables that span the world’s oceans have become clearer. Both war zones have seen undersea infrastructure destroyed or damaged: the Nord Stream gas pipeline in the Baltic Sea and internet cables in the Red Sea. Such attacks expose one kind of risk, while cyberattacks on critical infrastructure. What’s raised the stakes around the significance of such incidents is the high volume of business-critical data routinely travelling over subsea cables, because of accelerating demand for cloud services. Hyperscale internet providers like Amazon, Google, Meta and Microsoft have become key players in the market, transitioning from high bandwidth buyers to capacity providers, building lucrative business mod-
40 SUBMARINE TELECOMS FORUM MAGAZINE
els that have made them prime targets for cybercriminals. What they also bring to the market is a need for cybersecurity awareness that was badly needed in the sector. They demand service providers up their game and become more proactive when it comes to network monitoring, consigning more passive approaches to history. As a company that has been providing engineering services for 25 years, Indigo was ready for the challenge of subsea security when we entered the market a few years ago.
IMPROVING NOC CAPABILITIES
What has become clear is that a new best-practice approach to cyber security is essential to minimize the risk of state-sponsored attacks taking out cables that connect continents. The Network Operation Centre (NOC) has had to evolve to become security-aware, providing hyperscale internet companies with a combination of fault and threat identification capabilities. As well as implementation of ITLV4 as the methodology for our processes to ensure best practice. A modern NOC must be able to cross-reference data when tracking an incident and ascertain if there are any security implications. Similar sets of data must be analyzed in different