THE FRAGILE TAP

Part Three: Crossing the Great Divide

In parts one and two of this series we asked who controls knowledge, and whether what flows through that control can be trusted. This one asks a simpler, harder question: what happens when the tap itself is turned off? In other words: what are our digital dependency risks in South Africa?

The Infrastructure We Forgot to Protect

Undersea cables carry more than 99% of the world’s data traffic across oceans and continents. Carnegie Endowment for International Peace They are not metaphors. They are physical assets on the ocean floor—vulnerable to anchors, earthquakes, and landslides, and also to the deliberate choices of those who control the waters above them. Currently, we need this infrastructure to be in working order.

South Africa already knows what it feels like when the tap is turned off. In March 2024, ten African countries—mostly in West and Southern Africa—lost connectivity when four major undersea cables were disrupted at once: the West Africa Cable System, Africa Coast to Europe, MainOne, and SAT3. Carnegie Endowment for International Peace Microsoft reported knock-on disruptions to Azure and Microsoft 365 across the continent. DataCenterKnowledge It was not a geopolitical strike. It was an underwater landslide near the mouth of the Congo River. Nature—not politics—shut the tap.

As recently as June 2025, the West Africa Cable System—a key artery linking South Africa to Europe—went offline for emergency maintenance after a fault near Swakopmund, Namibia. IOL Repairs are weather-dependent, logistically complex, and slow. A single break can degrade connectivity across entire regions; a well-placed cut could do far worse. ITWeb

The Baltic Sea incidents that Britain and its NATO allies have been tracking—Russian submarine activity near cable infrastructure—are the political version of the same vulnerability. What nature does accidentally, states can do deliberately. And once you admit that, you have to ask what else sits in the crosshairs.

The data centres in the crosshairs

A second vulnerability sits behind the cables—less discussed, and only recently forced into public view.

The AI infrastructure the global economy now leans on is physically concentrated in a surprisingly small number of places. Hyperscale data centres operated by Microsoft, Google, Amazon, and others—the sites that run cloud services, train and host AI models, and carry the digital load of governments, banks, hospitals, and businesses—are built at industrial scale, drawing hundreds of megawatts of power. They are often placed where energy is cheap and permits are easy, not where strategic dispersal would demand.

That concentration turns them into tempting targets for sophisticated adversaries: states seeking to steal intellectual property, disrupt critical services, or sabotage systems underpinning defence, industry, and essential infrastructure. Security is improving. It is apparently wishful to assume hyperscale sites are insulated from determined, high-capability threats. Iaps

The threat to Ai infrastructure is no longer theoretical. In March 2026, Iranian drones struck Amazon Web Services facilities in the United Arab Emirates and Bahrain, damaging physical infrastructure and disrupting cloud services across the region. For the first time in modern conflict, commercial hyperscale data centres became explicit kinetic targets. Iranian state media described the strikes as blows to “the enemy’s technological infrastructure.” World Economic Forum

What matters is not that servers were “hacked”, but that the sites’ physical dependencies were exposed: power supply, location, access routes, and sheer visibility in a contested landscape. Digital or AI infrastructure is not insulated from geopolitical instability. DataCenterKnowledge

The US mainland faces a different but related calculus. North Korea’s missile programme places parts of the western United States within range; Russia and China can project further still. andrewerickson The US “Golden Dome” initiative — announced in early 2025 — is a direct response to this picture, though its feasibility against a large Chinese strike is deeply contested among analysts. Domestic terrorism—ideologically motivated or state-sponsored—requires no missiles at all. A determined attack on the power infrastructure serving a major data-centre cluster could be enough.

The more we rely on AI, the greater the impact of any disruption to the data centres that host critical capability. Digitalisation World Dependency is being built at extraordinary speed—Morgan Stanley estimates that around £2.2 trillion will be spent on AI-supporting data centres between 2025 and 2029. Resilience investment has not kept pace.

For South Africa—at the end of long cable routes, dependent on US-domiciled platforms, and with no significant domestic AI infrastructure of its own—this concentration risk is not someone else’s problem. When the data centre fails, the service fails, regardless of where you sit. And once a service fails, it is worth asking a quieter question: where, exactly, does “the cloud” live?

When the cloud evaporates

Most people who use the technical term “cloud” have only a vague sense of what it denotes. It sounds soft: distributed, everywhere and nowhere—safe precisely because it seems weightless. It is none of those things.

Cloud computing is physical. It is part of the AI infrastructure. It is made of large, power-hungry data centres in specific places, connected by specific cables, operated by specific companies in specific jurisdictions. When people say their data is “in the cloud”, they mean it sits on someone else’s hardware, in someone else’s building, under someone else’s law—accessible only as long as the cables hold, the power runs, the platform remains willing, and geopolitics permit.

Most people recognise two categories of cloud risk: glitches that disrupt service, and ransomware that locks data until a ransom is paid. Both are recoverable in principle. The data still exists somewhere. The question is who holds the key—and how long you can operate without it.

The UK retail and manufacturing sector has already shown what even “recoverable” attacks can cost. In April 2025, Marks & Spencer suffered a ransomware attack over the Easter weekend that forced the suspension of online orders and shut down automated stock systems, leading to shortages in stores. Periculo The financial impact was estimated at between £270 million and £440 million; consumer spending fell 22%, and online sales losses reportedly reached £1.3 million per day before limited service resumed. Security Affairs Co-op, hit at the same time, ultimately had personal data for approximately 6.5 million members exposed. Periculo

But the starkest warning came in September 2025, when Jaguar Land Rover was hit. The Cyber Monitoring Centre estimated a UK financial impact of £1.9 billion and effects across more than 5,000 organisations Cybermonitoringcentre—making it the most economically damaging cyber event in British history. JLR’s three main UK plants were brought to a standstill. UK car production fell 27% in September—the worst September for the industry since 1952. Cybermagazine Suppliers were also affected, with some unable to fulfil orders or dispatch components, ultimately rippling through automotive assembly globally. Manufacturingdigital

These were ransomware attacks—painful, disruptive, but recoverable in principle, because the underlying data still existed somewhere. The scenario that has not yet happened—but which the physical vulnerabilities described above make conceivable—is categorically different: physical destruction of the infrastructure holding the only copies of your data. That does not come with even the cold comfort of a slow restoration.

Consider what that means for a business that has moved entirely to cloud-based operations—as most modern firms have done or are being urged to do. Your client database. Supplier contracts. Distributor agreements. Financial records. Invoices, payroll, tax history. If those records exist only in the cloud—if the original, the backup, and the replicated copies all live in infrastructure that is physically destroyed—they are gone. Not inaccessible. Gone.

There is no plan B for that. You cannot think your way back to who owes you money, what your stock levels were, or what agreements you had in place. You cannot reconstruct a decade of client relationships from memory. The business that existed before the event does not exist after it—not because its people are gone, but because the records that defined it are.

AI, at least, has a human fallback. One could—slowly and imperfectly—return to doing more thinking for oneself. But there is no human fallback for a client database. No mental backup of an accounts receivable ledger.

This is the question the move to cloud computing has not answered honestly: not what happens when the service slows, or when ransomware arrives, but what happens when the building burns—and every copy of everything you owned was inside it.

And if you cannot account to the receiver of revenue—because the records no longer exist, and the platform that held them is gone—you are no longer, in any legal or practical sense, a viable entity. In our language, you will be placed in administration. Not because your business failed. Because your data did.

The political tap

The physical fragility of undersea cables and concentrated data centres is, at least, legible. You can track repair ships. You can map outages. Political fragility is harder to trace—right up until the moment a decision, not a fault, turns the tap.

South Africa’s AI infrastructure, like that of most countries, sits on US platforms. Microsoft Azure, Google Cloud, Amazon Web Services: US-domiciled, subject to US jurisdiction, and capable—if Washington chooses—of being restricted, sanctioned, or switched off. This is not speculative. The digital economy was built by American firms, runs on their infrastructure, and is governed, in the last instance, by American law.

Africa, meanwhile, risks becoming collateral in a different contest as more of its digital infrastructure is manufactured in China NTU Singapore—a shift that can trade one dependency for another, with a new set of political conditions attached.

South Africa’s current foreign-policy posture—non-alignment in theory, selective alignment in practice—has already carried costs, including the loss of the AGOA trade agreement. The question is whether it could also, one day, cost access to the digital infrastructure on which the economy increasingly depends. It is not being asked loudly enough—or early enough.

The Strait that Concentrates Everything

The Strait of Hormuz crisis has made the three vulnerabilities in this article—cables, data centres, and political control—suddenly, brutally visible at once. In a chokepoint, the difference between a fault and a decision narrows fast.

Since 28 February 2026, when the United States and Israel launched airstrikes against Iran, the strait has been repeatedly opened and closed—declared open, then shut again, with ships seized and tolls demanded. Wikipedia Iran and the US agreed to an initial ceasefire on 8 April, but it has been repeatedly strained by disputes over the naval blockade and Lebanon. Al Jazeera Reports this week describe further seizures in the strait, a vessel disabled off Iran’s coast, and an extension of the ceasefire alongside the continuing US naval blockade. CNN

South Africa depends on the strait for much of its refined fuel supply. Diesel is not an abstraction: it is trucks, generators, and hospitals running through a power cut. But the disruption does not stop with physical trade. The same geography also constrains undersea cable routes through the Red Sea and around the Arabian Peninsula. Trade routes and digital routes are not separate systems. They share chokepoints—and when chokepoints tighten, governments discover how quickly infrastructure becomes policy.

What We Should Have Learned by Now

South Africa has already lived through one catastrophic infrastructure failure: the energy crisis that cost an estimated R2.8 trillion in lost output. The warnings came in 1998. The reckoning arrived in 2007. The pattern is familiar: risk identified, documented, deferred—until the cost dwarfs the investment that would have prevented it.

Digital infrastructure and asset risk follows the same script. Cable vulnerabilities are known. Data-centre concentration is visible to anyone who looks. Platform dependency sits in plain sight, written into contracts and jurisdictions. Geopolitical exposure is being drafted in real time off Iran. What is missing is the institutional response that treats digital infrastructure as a strategic asset—requiring redundancy, diversification, and the kind of long-term thinking South Africa has repeatedly struggled to sustain.

African governments have been urged to treat internet infrastructure as a strategic asset, and to harmonise rules for construction, maintenance, and upgrades at a continental level. NTU Singapore South Africa, with its relative institutional capacity and infrastructure base, is better placed than most to lead that conversation. Whether it will do so is a different question—and the answer will be found, as always, not in speeches but in budget lines, long before it is found in consequences.

The Open Question

The knowledge economy runs on infrastructure and relies on key assets. That AI infrastructure runs on cables, data centres, platforms, and geopolitical arrangements—systems that can be disrupted by an underwater landslide, a Russian submarine, an Iranian drone, or a decision made in Washington that has nothing to do with South Africa.

One final thought is worth sitting with. Most of the businesses, governments, and individuals exposed by these vulnerabilities will have done nothing wrong. Many will have done a great deal right—followed the advice, adopted the platforms, moved to the cloud, modernised their systems, trusted the infrastructure. In this instance, responsibility is not protection. That may be the most uncomfortable truth of all.

When the tap is turned off—by accident, by nature, or by political whim—what is our plan? And if we have no plan, is that absence itself a choice, with consequences we have simply not envisaged or yet been forced to pay?

Previous: Part one. The Gatekeeping Problem
Previous: Part two. The Poison Well


Shelley Childs, Pretoria, April 2026

This article is Part Three of the Data Access Control series on shelleychilds.co.za — Think about it…

Similar Posts

  • THE POISON WELL

    Part Two: Crossing the Great Divide If the old gatekeepers controlled access to knowledge, the new ones are poisoning the well itself. When false knowledge travels faster than true understanding, and trusted institutions are not immune — how do you decide what to believe, and on whose terms are you making that decision? The Other…

  • BE PROUD, WALK TALL

    South Africa has done extraordinary things. On both sides of history. The question is whether we remember — and whether we intend to do so again. South Africa has four Nobel Peace Prize laureates. It produced the world’s first human heart transplant, one of the world’s most innovative energy utilities, a freight rail system that…

  • THE BUDGET AS TRUTH 1

    Comparing Budget Line Items Budget as Truth Article 1 | Thinking about itPublished May 2026by Shelley Childs A government’s values are not found in its speeches. They are found in its line items. On Good Friday 2026, a thirteen-year-old girl was raped. The man responsible appeared in court days later. Within hours of the news…

Leave a Reply

Your email address will not be published. Required fields are marked *