Rising Threats to Undersea Infrastructure
Russia has been intensifying its undersea sabotage operations, particularly targeting the United Kingdom. In April, the Defence Secretary disclosed that three Russian submarines conducted a month-long surveillance mission in northern UK waters, focusing on undersea cables and pipelines. A British warship and aircraft were deployed to monitor the Russian fleet, ultimately ending the operation. This mission was likely aimed at mapping critical infrastructure, according to John Healey.
The operation was notably more sophisticated than usual, involving distraction tactics such as deploying an Akula-class submarine to divert British forces. Experts have raised concerns that such sabotage operations are becoming more frequent, with the possibility of taking the UK offline increasing.
As an island nation, the UK relies heavily on around 60 undersea cables, which carry over 90% of daily internet traffic. There is growing concern that Russia could attempt to sever or damage these vital channels in the event of conflict, leading to widespread political and economic disruption. A September report by Parliament’s Joint Committee on National Security Strategy highlighted the risks associated with attacks on the limited number of cables around the UK's outlying islands, which are prime targets for sabotage. The report cited previous damage to cables connecting the Shetland Islands, Orkney, and Banff, which caused mobile, landline, and internet issues.

The report also warned about the concentration of essential data in high-capacity subsea cables. It emphasized that the government and industry were not adequately prepared for potential attacks, highlighting a "strategic vulnerability in the event of hostilities." The committee expressed a lack of confidence in the UK's ability to prevent such attacks or recover within an acceptable time frame.
Strengthening Defences
In response to these threats, the UK has implemented several measures in recent years. These include the Cyber Security and Resilience Bill, which proposes new laws for essential businesses in managing risks, and the Atlantic Bastion blueprint, launched in December. This initiative aims to create a hybrid force comprising autonomous vessels, AI technologies, warships, and aircraft to defend British waters and protect undersea cables.
However, these efforts are progressing slowly and are far from comprehensive. Recently, the Defence Secretary brought together telecoms companies to discuss collaboration on defence, but no concrete plans for public and private collaboration have been implemented yet. Experts are also warning that the UK needs better recovery plans.
Lessons from Estonia
A small state in Europe’s far east could provide a model for how Britain protects its infrastructure lifelines. Estonia has revolutionized cyber security and is leading the way in defending against Russian cable and cyber sabotage. The Estonian navy has sent patrol ships to protect its cables, and telecoms companies have duplicated their connections to avoid being fully cut off in the event of attacks. Estonia would also be able to use other sea cables – or land cables – through neighbouring Latvia.

Estonia is also prepared for attacks through a broad and deep approach to cybersecurity. Known as e-Estonia, the country of just over one million people has been a pioneer in creating a digital society. The Republic of Estonia’s Information System Authority report on cyber security 2026 argued that “cybersecurity should be layered, like a millefeuille,” embracing both the protection of cables and wider connections in case these fail.
Baltic Sea Vulnerabilities
Bordering Russia, Estonia stands on the front line of Moscow’s threats. Like Britain, Estonia and its NATO neighbours have been grappling with attacks on undersea cables in the Baltic Sea, which they share with Russia. There are over 35 cables in the Baltic Sea, a shallow body of water that makes it easier to attack. It is also a region integral to global shipping, leaving it even more vulnerable. Since Russia’s full-scale invasion of Ukraine in 2022, there have been numerous reports of damage to cables and gas pipelines, including those connecting Finland and Estonia, Sweden and Estonia, and Sweden and Lithuania. In the latter case, a fifth of Lithuania’s internet capacity was reduced as a result of the cut cable.

The threat of damage to Baltic Sea infrastructure is particularly significant given Russia’s geopolitical ambitions. The Baltic states – Lithuania, Latvia, and Estonia – were annexed by the Soviet Union in 1940, although this was not recognized by the West. Ukraine has recently warned that these tiny states might face a Russian attack so Moscow can regain influence in the east.
Estonia’s Cybersecurity Journey
Estonia was the first nation to face cyber warfare and sabotage attacking an entire country. By the early 2000s, it was leading in cyber capabilities, after the restoration of its independence in 1991 prompted digital modernization. But in 2007, there was a series of devastating attacks on government, banking, and media websites. These coincided with a disagreement with Russia on the relocation of a Soviet-era grave marker. In late April of that year, the online services of government institutes, banks, and media faced blackouts, with cash machines brought down, emails disrupted, and spam disseminated. The attacks peaked on 9 May, Victory Day in Russia.
After that, Estonia embraced cybersecurity as a necessity. The Ministry of Defence developed a cybersecurity strategy – one of the first to be written in the world – which promoted cooperation between the public and private sector, an awareness of cyber threats, and improvement in cyber training. Programmes on cybersecurity were launched at Estonia’s universities in the capital, Tallinn, and second-largest city, Tartu, and a NATO-accredited Cooperative Cyber Defence Centre of Excellence was also created. A Cyber Defence Unit of the Estonia Defence League – a voluntary national defence organization – was also established in 2010. It includes IT professionals who practice cyber defense by modeling attacks. The Unit also networks between the public and private sector to defend the nation’s cyber connections.

Innovative Cybersecurity Measures
Estonia has also developed a blockchain-based technology to protect its digital infrastructure. This technology shows if any information has been altered – protecting against attacks. It also enables the Government to handle large amounts of data with speed. Estonia also operates the world’s first “data embassy” in Luxembourg – allowing backups of data if the nation were attacked.
Estonian public services are now 100 per cent online, 24/7, meaning cyber security is essential.
Despite its tiny size and threats of war, Estonia’s model offers a useful lesson for the UK. The Estonian recognition of threat from government, and the rapid implementation of nationwide protection plans – including innovations in technology and defense, public and private collaboration, and recovery plans – are what the UK needs to protect its essential cables. Britain’s current approach, as experts warn, is too slow in implementation, and too limited in focus: a widespread awareness of dangers, and a cross-government approach, is required to ensure valuable resources are protected.
Juliette Bretan is a researcher and journalist, currently based in Cambridge, who has written about Eastern European politics, culture, and history for a decade.
Komentar (0)