1. Cable Landing Station (CLS) Perimeter Security
Subsea cable landing stations are critical single points of failure for national and international telecommunications. NIS2 requires multi-layered physical security controls.
🚢 AIS Maritime Vessel Tracking
Deploy Automatic Identification System (AIS) radar integrations to monitor ships loitering or dragging anchors near subsea cable protection zones.
🏰 Class 4 Perimeter Access Controls
Enforce biometric access, CCTV perimeter detection, and armed security protocols at Beach Manholes (BMH) and Power Feed Equipment (PFE) facilities.
2. Optical Line Encryption & MACsec
To prevent optical fiber tapping on long-haul subsea cables and terrestrial dark fiber backhaul, data-in-transit must be encrypted at Layer 1 or Layer 2.
- OTN Layer 1 Encryption: AES-256 GCM bulk optical payload encryption at the DWDM transponder level without latency overhead.
- MACsec (IEEE 802.1AE): Line-rate 100GbE / 400GbE Ethernet encryption on terrestrial interconnect links between datacenters and landing stations.
- Post-Quantum Key Exchange: PQC Kyber / ML-KEM key encapsulation for optical transport session keys.
3. Automated Fiber Cut & Tapping Detection
Continuous Optical Time-Domain Reflectometry (OTDR) monitors light reflection along the fiber strand, pinpointing physical cuts or micro-bending optical tap attempts within meters.