Cybersecurity · Analysis
The Baltic Sea made physical infrastructure a cybersecurity problem again.
Damage to subsea cables and pipelines has forced Nordic and Baltic operators to plan for a threat model that mixes physical interference with network intrusion.

Independent coverage
By AJ Dellinger
Contributing Writer — Cybersecurity / Tech Policy · Freelance
Edited by Dr. Mikael Lindholm, MD
Published 7 September 2026
8 min read
Evidence: Analysis
Cybersecurity planning in most organisations treats physical infrastructure as a given. The connection exists. The threat arrives over it.
Operators around the Baltic no longer plan that way. A sequence of incidents affecting subsea cables and pipelines has made physical interference a routine planning assumption rather than an exotic scenario.
What changed in operational planning
Three shifts are visible in how Nordic and Baltic telecommunications, energy and financial operators now describe their planning.
Route diversity is assessed physically rather than contractually. Two suppliers whose cables share a corridor provide one path, whatever the contracts say, and several operators discovered this only when they mapped it.
Degraded-mode operation is exercised. Services are tested at reduced capacity rather than assumed to fail over cleanly.
And detection now includes the physical layer. Cable monitoring data, vessel tracking and network telemetry are correlated in a way that was previously the concern of separate departments.
The organisational problem
The obstacle is not technical. In most organisations, physical security, network operations and cyber defence report through different chains, and no single person sees the combined picture.
The operators considered furthest along have created a joint function, small, with a mandate to ask the combined question. It is the same organisational lesson that produced security operations centres two decades ago.
What this means beyond the Baltic
The pattern is not regional. Any operator dependent on a small number of physical paths, whether subsea cable, cross-border interconnect or a single fibre corridor, has the same exposure and usually has not mapped it.
The cheapest useful exercise available: take your top ten critical services, and for each one, draw the physical path. Most organisations cannot complete the drawing, and that incompleteness is the finding.
"A resilience plan that assumes the cable stays intact is a business continuity document about a different sea."
Sources