
TMT
Beneath the surface
In global boardrooms, digital resilience is still largely framed as a question of cyber risk — ransomware, cloud outages, software failure. However, perhaps the more immediate and under-appreciated threat is physical, geopolitical and kinetic: the growing exposure of global digital infrastructure to conflict in the Middle East, particularly across the Red Sea and the Strait of Hormuz.
Recent developments have made this threat concrete rather than theoretical. The conflict with Iran has already demonstrated a willingness to target technology infrastructure directly, from strikes on data centres in Bahrain and the UAE to explicit threats against undersea cables and critical maritime routes. In this context, subsea fibre-optic networks — which carry between 95 and 99 percent of global data traffic, according to the International Telecommunication Union and TeleGeography — are no longer passive infrastructure. They are strategic assets, and increasingly, potential targets.
The geography of the threat amplifies its severity. The Red Sea corridor alone carries a substantial proportion of connectivity between Europe, Asia, the Middle East and East Africa, supported by roughly 15 to 20 major cable systems. In the Strait of Hormuz, these systems are tightly clustered, creating a single point of failure in a region already defined by military tension. This concentration means that any deliberate or collateral damage — whether from naval activity, mining operations or vessel strikes — could have disproportionate consequences.
Crucially, the risk is not limited to deliberate sabotage. As a research director specialising in global telecommunications markets noted, “With military operations in this region, there is the possibility that attacks on vessels can indirectly cause cable damage.” In an active conflict zone, the distinction between intentional and incidental disruption becomes largely irrelevant. The outcome — degraded or severed connectivity — is the same.
“With military operations in this region, there is the possibility that attacks on vessels can indirectly cause cable damage.”
Research director specialising in global telecommunications markets, Slovakia
What elevates this from an infrastructure concern to a systemic risk is the interaction between frequency, fragility and recovery constraints. Submarine cable faults are already common, with “around 200 incidents occurring globally each year,” according to the telecoms director. Under normal conditions, these are manageable. In a conflict scenario, however, simultaneous or repeated disruptions in constrained corridors like the Red Sea could overwhelm repair capacity and rerouting options.
At the same time, the threat surface is expanding beyond the seabed. In March 2026, Iranian-linked attacks on Amazon Web Services data centres caused structural damage, power disruption and service outages across the UAE and Bahrain. This convergence of risks — subsea cables, terrestrial infrastructure and cloud environments — creates a multi-layered vulnerability where disruption at one level cascades rapidly into others.
For multinational enterprises, the impact is unlikely to be a total collapse of connectivity. The global internet is inherently resilient by design. As a former defence representative to NATO observed, “The global internet is a network — when you cut one line the others still function, although with slightly less capacity and speed.” Satellite systems can sustain critical communications and emerging technologies — from power grid-based data transfer to laser and underwater acoustic systems — offer additional fallback options.
But this resilience should not be mistaken for immunity. In high-dependency digital environments, degradation is disruption. Reduced capacity and increased latency directly affect real-time trading, payment systems, cloud services and AI workloads. Even marginal performance declines can translate into financial loss, operational delay and systemic friction.
The constraints on rerouting are particularly acute. While terrestrial networks provide an alternative, they “may not be sufficient to handle the complete re-routing of traffic if subsea systems are damaged,” remarked the research director. In effect, redundancy exists — but not without limits, and not without consequence.
“[Resilience depends on] detailed and budgeted capability development plans, contingency plans and consequence management plans.”
Former defence representative to NATO
Digitally coordinated production, logistics and outsourcing networks depend on stable, low-latency connectivity across these same corridors. India’s reliance on Europe-linked routes via the Middle East is a clear example: sustained disruption would not halt operations outright, but would slow them materially, introducing delays, inefficiencies and increased operational risk across sectors.
The critical point is that this is no longer a tail risk. It is a plausible, repeatable threat scenario shaped by geopolitical intent, infrastructure concentration and physical vulnerability. The targeting — or incidental disruption — of digital infrastructure is becoming a recognised component of modern conflict.
Mitigation, therefore, cannot rely on technology alone. While businesses are moving toward multi-region cloud architectures and diversified transit providers, the more decisive factor is preparedness. As the former NATO representative emphasised, resilience ultimately depends on “detailed and budgeted capability development plans, contingency plans and consequence management plans” — in other words, disciplined and well-resourced business continuity strategies at both corporate and national levels.
The global internet will continue to function, even under stress, but in a threat environment where infrastructure is both exposed and contested, continuity is no longer binary. It is conditional, degraded and uneven. That shift — from disruption as anomaly to disruption as operating condition — is what makes this a front-line strategic risk rather than a background technical concern.
Important Notice
While the information in this article has been prepared in good faith, no representation, warranty, assurance or undertaking (express or implied) is or will be made, and no responsibility or liability is or will be accepted by Deheza Limited or by its officers, employees or agents in relation to the adequacy, accuracy, completeness or reasonableness of this article, or of any other information (whether written or oral), notice or document supplied or otherwise made available in connection with this article. All and any such responsibility and liability is expressly disclaimed. This article has been delivered to interested parties for information only. Deheza Limited gives no undertaking to provide the recipient with access to any additional information or to update this article or any additional information, or to correct any inaccuracies in it which may become apparent.