Summary

  • Taiwan's National Communications Commission records that Taiwan-Matsu No. 2 failed on 2 February 2023 and that traffic automatically shifted to No. 3. No. 3 then failed on 8 February, leaving the archipelago dependent on microwave fallback and service-specific workarounds.[1]

  • The public record associated the failures with vessels, but it did not establish deliberate action. AP reported that Taiwan's government stopped short of calling the damage intentional and that there was no direct evidence of intent.[12] Accountability analysis should not replace that evidentiary boundary with geopolitical certainty.

  • NCC reported 2,987 affected fixed-broadband users and 954 MOD users. MOD availability fell from 180 channels to 15, fixed broadband was severely congested, and five mobile operators maintained voice while data service congested.[1] Continuity therefore differed by service class.

  • The microwave system was a genuine backup. It was not an equivalent substitute for the missing fibre capacity. Local records described expansion from approximately 2.2 Gbps toward 3.8 Gbps while reported peak Matsu demand was about 8-9 Gbps.[5][6][9]

  • The fallback prioritised voice, government, national-security and essential civilian circuits.[1] That may be a legitimate emergency policy, but it needs an accountable capacity plan showing who set the priorities, what remained usable and how ordinary users were informed.

  • Cable repair depended on a scarce specialised vessel. The Cable Retriever reached the repair area in March, and No. 3 was restored on 31 March.[3][4] No. 2 was restored on 25 June, returning the nominal two-cable arrangement.[1]

  • Service recovery and redundancy recovery were separate events. Ordinary communications returned when one cable was repaired; the network did not regain its second submarine route until almost three months later.

  • Compensation recognised service failure. NCC recorded fee waivers for affected fixed, MOD and mobile customers.[1][11] Compensation did not create missing capacity or prove that later controls were adequate.

  • Later microwave expansion, burial plans, monitoring and Taiwan-Matsu No. 4 are relevant changes.[9][16][17] They are not evidence that the 2023 failure class has been eliminated unless current route separation, peak-load failover and repair readiness are tested.

  • The infrastructure evidence is direct: cable inventories, capacity tables, maintenance agreements and outage notices record obligations and observations. Running cable segments, powered radios, usable handoffs and mobilised repair crews determine continuity.

The sequence matters more than the suspicion

The Matsu outage is often introduced through the nationality of two vessels reportedly near the cable breaks. That framing makes the event easy to place inside cross-Strait politics. It does not explain how the network behaved.

The more useful starting point is a sequence of controls.

Taiwan's NCC records that Taiwan-Matsu No. 1 had been retired in 2015 after repeated damage and declining quality.[1] In February 2023, the operational submarine connections were No. 2 and No. 3. No. 2 ran from Tamsui toward Dongyin. It failed on the evening of 2 February at a point reported to be about 52 kilometres from the Dongyin equipment room. The network automatically transferred Taiwan-Matsu traffic to No. 3, which ran from Taoyuan toward Nangan. Service initially continued.

That first transition matters. It shows that the system had a working cable-level failover. The incident was not a simple case of one cable, one break and immediate isolation. An alternative path accepted traffic.

At around noon on 8 February, No. 3 failed at a point reported to be about 40 kilometres from the Nangan equipment room.[1] Once the second operational cable was unavailable, the archipelago no longer had a working submarine path to the main island. Microwave facilities and other workarounds became the remaining transport.

NCC and contemporary reports associated the first break with a fishing vessel and the second with a cargo vessel.[1][12][13] Those records support careful attribution of what authorities and the operator suspected. They do not support a definitive finding of sabotage. AP reported that the government did not call the incident deliberate and that there was no direct evidence of intent.[12]

That distinction is not a diplomatic footnote. It protects the infrastructure analysis from an easy but unsupported answer. If motive is assumed, accountability collapses into identifying an adversary. If the evidence is kept bounded, the operational questions remain visible: Why were the two routes vulnerable within the same week? What capacity survived? Which services received priority? How long could the fallback remain usable? Who controlled access to a repair ship? What did later remediation actually change?

The trigger and the failure architecture belong in separate columns. Suspected physical damage explains why each cable stopped carrying traffic. It does not determine whether the two routes were geographically independent, whether microwave capacity met public needs or whether repair readiness matched the consequence of losing both cables.

Two cable names do not prove two failure domains

Redundancy diagrams often count assets. One cable plus another cable produces a pair. The pair is then presented as resilience.

The operating question is different: which events can remove both?

Two cables can approach different islands yet cross the same busy maritime zone. They can have distinct offshore routes but share a shore-end corridor, landing facility, power system, management plane or repair contract. They can be geographically separated enough to survive one anchor but still be exposed to repeated fishing, dredging or commercial shipping activity during the time needed to repair the first failure.

Public sources do not disclose a complete February 2023 route map for No. 2 and No. 3. This article therefore does not claim that the cables occupied the same trench, landed at the same building or shared a specific unreported physical element. It also does not infer independence merely from their names and endpoints.

The chronology supplies a stronger and narrower finding. One route failed, the system moved to the other, and the remaining route failed before the first was restored. Even if the physical causes were unrelated, the repair-time exposure created a common operational risk: the system had no submarine margin while one route was already down.

This is a second-failure problem. The first event changes the risk state. Traffic concentrates on the surviving path. Maintenance options narrow. A second ordinary fault that would have been tolerable in the normal two-path state can now become an island-wide capacity emergency.

An accountable design must therefore answer more than an N-1 question. It must show:

  1. how quickly the first failed path can be restored;
  2. how the surviving path is monitored under concentrated load;
  3. what non-cable capacity remains if the surviving path also fails;
  4. whether repair resources are prearranged and realistically available;
  5. which services must survive an extended two-path loss;
  6. how often the system tests that condition.

The existence of a second cable was valuable. It prevented the 2 February break from immediately producing the later service degradation. The event should not be misread as evidence that cable diversity had no value. It is evidence that diversity has a time dimension. A network is resilient only if the combination of alternate paths and restoration speed keeps the probability and consequence of a second failure within an accepted boundary.

Backup available is not a capacity statement

After the second cable failed, microwave radio became the visible fallback. The system worked in one important sense: Matsu was not left without every form of communication.

That sentence is not enough for accountability.

NCC said the limited microwave bandwidth was primarily used for voice, government, national-security and essential civilian circuits.[1] Fixed broadband experienced serious congestion. Five mobile operators maintained voice service, while mobile data was congested. MOD customers who had received 180 channels before the break could receive 15 over the constrained arrangement.[1]

Local reporting described an initial microwave capacity of approximately 2.2 Gbps and an expansion that took the total toward 3.8 Gbps in March.[5][6][7][8] Another report said peak Matsu traffic was about 8-9 Gbps and described a later target of 8.15 Gbps.[9] The public numbers come from different points in the response and may use slightly different system definitions. They should not be collapsed into one perfectly aligned time series.

They establish the essential relationship: the fallback available during the severe degradation was materially below ordinary peak demand.

That difference explains why a backup can be simultaneously successful and inadequate. It may complete emergency voice calls while a hotel cannot reliably update reservations. It may carry government circuits while a family waits for a medical appointment page. It may preserve basic mobile signalling while video, cloud applications and large downloads become impractical.

Capacity accountability needs at least four dimensions.

Raw transport capacity records the maximum usable throughput of the fallback under actual modulation, spectrum, weather, equipment and path conditions.

Allocated capacity records how much of that transport is reserved for voice, government, hospitals, banking, public safety and ordinary Internet access.

Service performance records latency, loss, congestion, DNS success, voice completion, application response and customer experience.

Duration tolerance records how long the fallback can operate with acceptable power, staffing, maintenance and failure margin.

A public statement that microwave backup was activated addresses only the first step. It says an alternate transport existed. It does not show that the alternate transport met the defined continuity objective.

Service classes tell the real outage story

Binary outage language loses the most important evidence in this event.

Voice service remained available. Mobile data degraded. Fixed broadband congested severely. Some television channels disappeared from MOD, while other television services used satellite arrangements. Temporary Wi-Fi access was offered at telecom locations. Customer-service staffing and telephone capacity were expanded.[1]

These outcomes are not contradictions. They are the result of service classes competing for limited transport and using different fallback mechanisms.

The correct incident record should preserve those differences. It should state, for each major service:

  • normal demand and emergency minimum;
  • priority class;
  • surviving transport;
  • allocated bandwidth;
  • measured latency, loss and availability;
  • user population affected;
  • fallback activation time;
  • restoration milestone.

NCC's article gives unusually useful public detail. It reported 2,987 affected fixed-broadband users and 954 MOD users.[1] It distinguished voice continuity from data congestion. It recorded the reduction in MOD channels. It described temporary access and compensation. That evidence is more valuable than a headline saying Matsu lost the Internet because it shows how the system rationed continuity.

The allocation question still needs scrutiny. Prioritising emergency voice, hospitals, government and essential services can be reasonable during a constrained event. Accountability requires the policy to be defined before the crisis, tested against realistic demand and reported after use.

The plan should answer who can change priorities, what happens when an unlisted critical service depends on ordinary broadband, and how providers prevent one high-volume class from crowding out essential low-bandwidth traffic. It should account for remote work, reservation systems, payments, health scheduling, software authentication and other functions that may not be labelled emergency services but can become essential during a long outage.

The network did not merely move fewer bits. It made operational choices about which bits moved first. Those choices belong in the accountability record.

Traffic prioritisation is a governance control implemented in routers

Emergency priority policies are often written as administrative plans. Their real effect appears in configuration, queueing, routing and capacity reservation.

If a plan says voice has priority, the network must identify the relevant traffic, reserve or schedule capacity, prevent congestion collapse and monitor call completion. If government and medical circuits have priority, the operator must know which circuits and dependencies belong to those services. A hospital portal may depend on DNS, identity, cloud hosting or remote imaging systems that do not travel over a neatly isolated circuit.

This is where operational proof becomes practical. Policy language can authorise a priority. Routers, radios and applications decide whether the priority produces a working service.

An accountable post-incident review should compare the intended priority map with measured results:

  • Were emergency calls completed at the expected rate?
  • Did all designated government sites retain reachability?
  • Were hospital and banking dependencies included, not only access circuits?
  • How much capacity remained for ordinary mobile and fixed users?
  • Did queueing create starvation, excessive latency or repeated session failure?
  • Were priority rules changed during the incident, by whom and why?

Public sources do not provide those internal results. Their absence is not proof of failure. It defines the evidence that operators and regulators would need in order to claim that the fallback performed according to design.

This distinction also protects against a misleading capacity comparison. A 3.8 Gbps microwave path is not automatically deficient because normal peak traffic is 8-9 Gbps. The correct benchmark is the declared emergency service objective. If the objective is to preserve voice and essential circuits, the relevant question is whether 3.8 Gbps met that objective. If public statements imply broad Internet continuity, then ordinary application performance matters as well.

The standard should be explicit before an outage. Otherwise success can be defined after the fact around whichever services happened to remain.

Repair vessels are part of the network

A submarine cable is not restored by routing software. It requires fault location, maritime access, specialised equipment, trained crews, permits, weather and a vessel capable of retrieving and repairing the cable.

The Matsu chronology makes this dependency visible. Local reporting said the operator invoked a regional maintenance arrangement but initially faced an arrival estimate around 20 April.[5] Chunghwa Telecom ultimately coordinated the Cable Retriever, which reached the Juguang area on 24 March.[3] No. 3 was restored on 31 March.[1][3][4]

The difference between the early estimate and actual arrival should not be turned into a simple success or failure judgment. It shows that mobilisation is dynamic. Vessel location, other faults, weather and operational priority can change the schedule.

For continuity planning, the specialised vessel is functionally part of the network. If a route can remain unavailable for weeks because no ship is available, the maintenance agreement affects the duration of the second-failure window as directly as a spare line card affects a router outage.

An accountable repair-readiness record should include:

  1. maintenance-zone membership and contractual scope;
  2. vessel location and mobilisation priority;
  3. normal and worst-case transit estimates;
  4. fault-location capability;
  5. shore-end and deep-water repair procedures;
  6. permits and maritime coordination;
  7. cable and repeater spare availability;
  8. weather restrictions;
  9. competing regional faults;
  10. post-splice optical and traffic acceptance tests.

The public does not need security-sensitive coordinates or contractual prices. It does need a realistic restoration objective and evidence showing whether the operator can meet it under the conditions that matter.

Repair scarcity also changes the economics of redundancy. A second cable provides protection while the first is down, but the value of that protection declines as repair time grows. Adding a third route may reduce risk. Improving repair access may reduce the same risk from another direction. The most effective portfolio depends on measured failure frequency, correlation and repair duration.

Four clocks, not one outage duration

The phrase "the outage lasted until 31 March" is both useful and incomplete.

At least four clocks should be recorded.

The asset clock begins when each cable loses service and ends when that cable passes repair acceptance.

The customer clock begins when a service falls below its accepted objective and ends when that service recovers. Voice, mobile data, fixed broadband and television had different clocks.

The capacity clock records the period during which the system lacks normal traffic headroom. It can continue after basic reachability returns.

The redundancy clock begins when the network loses its normal margin and ends only when the required independent paths are restored and tested.

For Matsu, No. 3's restoration on 31 March returned ordinary fixed, mobile and television services to normal according to NCC.[1] No. 2 was not repaired until 25 June, when the two-cable arrangement was restored.[1] The severe customer-impact clock therefore ended before the redundancy clock.

That gap matters. From 31 March until 25 June, the network again had a working submarine route, but its tolerance for another cable failure was not the same as the normal two-route state. Public reporting that ends the incident on 31 March can obscure almost three additional months of elevated exposure.

An incident dashboard should show both milestones. "Service restored" and "resilience restored" are different statements. The first can be true while the second is false.

The same distinction applies to microwave capacity. Expansion work may improve customer experience before the permanent cable repair. The expanded radio path can then remain as a stronger fallback after cable service returns. Each control has its own acceptance date and performance test.

Compensation is evidence of failed service, not a resilience control

NCC recorded fee waivers and proportional relief for affected customers.[1] Fixed-broadband and MOD customers in Matsu received relief for February and March under the described conditions. Mobile compensation applied to local users and, proportionally, to other users registered on Matsu base stations during the period. Local reporting also announced broad fee relief while repair continued.[11]

Compensation matters. It recognises that a customer did not receive the contracted level of service and prevents the full financial burden from remaining with users who could not inspect or control the transport network.

It does not reduce the next outage.

This distinction is easy to lose when consumer remedies are included in resilience reporting. A generous waiver can be a fair response while the infrastructure remains exposed. A narrow waiver can be unfair even if engineering remediation is strong. The two controls should be assessed separately.

The operational ledger asks whether paths, capacity and restoration improved. The consumer ledger asks whether users received timely notice, support, credits and a workable complaint route. Both belong in an accountability review, but neither substitutes for the other.

Compensation data can also improve engineering analysis. The number and type of credited accounts help show which services fell below the accepted threshold. Complaint records can identify application failures not visible in network-level averages. Public Wi-Fi usage and support-call volume can reveal where fallback access was insufficient.

The evidence should be used carefully. NCC recorded no complaints directly to the commission during the specified period and seven cases at the industry dispute centre.[1] That does not prove that only seven users experienced material problems. Complaint counts depend on access, awareness, expectations and whether people believe a remedy is available.

Responsibility follows capability, not visibility

The most visible actor during an outage is often the customer-facing provider. The actor with the greatest control may be elsewhere.

Chunghwa Telecom controlled the cable systems, microwave fallback, traffic engineering, maintenance coordination, customer support and much of the restoration evidence described in the public record. Its accountability record should connect route design, capacity allocation, alarms, vessel mobilisation, repair and post-restoration tests.

Dependent mobile and service providers controlled their retail networks, customer notices and some service-level fallbacks. Their voice continuity depended on common transport, but they still had duties to monitor actual customer performance and communicate limits accurately.

NCC controlled regulatory oversight, consumer-protection expectations and the evidence it required from operators. Its later detailed account is itself an accountability asset because it preserves service classes, user counts, restoration and compensation.

MODA and other public bodies controlled resilience funding, critical-infrastructure policy and parts of the later investment programme. Later records describe larger microwave capacity and an additional cable project.[16][17]

Maritime and coastal authorities controlled parts of vessel monitoring, anchoring and fishing enforcement, seabed work and incident coordination. The public packet does not establish a complete legal responsibility chain for either break.

Cable-maintenance organisations and vessel operators controlled mobilisation, repair execution and competing work schedules under their agreements.

Customers controlled very little of the transport architecture. A hotel, clinic or resident could buy another retail plan, but multiple retail services could still depend on the same cable and microwave system. Customers generally could not audit physical path separation, reserve capacity or repair-vessel readiness.

Accountability should not assign system design responsibility to the party with the least information and control. It should require each actor to produce the evidence within its capability and join those records at the handoffs.

The attribution boundary protects engineering truth

The 2023 cable failures occurred in a politically sensitive location. Public discussion therefore moved quickly from physical damage to possible coercion.

Infrastructure reporting must retain the distinction between possibility, suspicion and proof.

AP reported that authorities associated two vessels with the breaks, while the government stopped short of declaring deliberate action and had no direct evidence of intent.[12] The Register similarly reported vessel-related damage and the operator's fallback response.[13] Technical commentary noted the unusually frequent cable disruptions in shallow, busy waters.[15]

Those facts permit several operational conclusions:

  • maritime activity is a material cable hazard;
  • the failure rate deserves investigation;
  • route protection and monitoring are important;
  • restoration plans must assume that more than one cable can fail before repair;
  • attribution may remain uncertain for longer than the service outage.

They do not permit a finding that the February breaks were an intentional state operation.

This boundary improves accountability rather than weakening it. Engineering controls should protect service against both accidental and deliberate damage where practical. Operators do not need a final motive determination before improving route separation, burial, monitoring, reserve capacity or repair readiness.

Attribution and continuity also run on different clocks. A cable must be repaired immediately even if an investigation takes months. A customer notice must describe service impact without waiting for legal proof. A regulator can require a resilience plan while preserving uncertainty about the cause.

When motive is allowed to dominate, technical shortcomings can be excused as unavoidable hostility, or ordinary maritime risk can be inflated into certainty. An evidence-led accountability review should resist both.

Later controls are hypotheses until they are tested

The post-incident record describes several changes.

Local reports discussed expanding microwave capacity to 8.15 Gbps, laying Taiwan-Matsu No. 4, improving route distribution and burying cable more deeply in exposed areas.[3][9] MODA later described microwave capacity exceeding a later peak figure during a subsequent incident and prioritisation for key services.[16] A 2026 MODA release described No. 4 nearing completion and at least two microwave systems for each Matsu township.[17]

These are material control changes. They should be recorded accurately.

They should not be treated as automatic proof of resilience.

Additional capacity can be unavailable because of weather, spectrum interference, power or shared equipment. A new cable can share coastal exposure, landing infrastructure, management systems or maintenance arrangements with existing cables. Deeper burial can reduce some anchor and fishing risks without eliminating all faults. Monitoring can improve attribution while doing nothing to carry traffic. A third cable can improve N-2 tolerance only if its failure domain and usable capacity are sufficiently independent.

The correct question is what tests the operator performed.

A current validation programme would remove each submarine route in a controlled exercise, load the remaining routes to realistic peak demand, verify microwave operation under relevant weather, test voice and critical applications, inspect ordinary broadband performance and confirm that route changes do not introduce a new common bottleneck.

It would also test the two-failure state. Removing one cable during a planned exercise and then simulating loss of the second is the only way to demonstrate that the fallback policy, capacity reservation and application dependencies work together.

The public record cited here does not contain a complete current test report. That absence does not mean the new controls failed. It means claims about solved resilience should remain bounded.

When infrastructure records meet operating reality

The Matsu event illustrates a restrained but demanding principle: a record is not the system it describes.

A cable inventory may list No. 2 and No. 3. A resilience plan may label microwave as backup. A maintenance contract may name a response zone. A priority policy may reserve capacity for essential services. These records are necessary because they identify assets, obligations and decision authority.

They do not carry traffic.

Running fibre, powered radios, configured queues, reachable DNS, working handoffs, available spectrum and mobilised repair vessels determine whether a service exists. Those operating conditions are the evidence.

The relevant control surfaces are telecom continuity, operator continuity and transit. The analysis asks whether the operational ledger matches running infrastructure rather than treating policy language as proof of resilience.

For Matsu, the questions are concrete:

  • Did the route inventory identify shared maritime risk?
  • Did automatic failover move traffic after No. 2 failed?
  • How much capacity did No. 3 carry before its failure?
  • Did microwave capacity match the emergency service objective?
  • Were service priorities implemented and observed as designed?
  • Could the maintenance arrangement mobilise a vessel within the accepted exposure window?
  • Did restoration tests prove customer service and redundancy separately?
  • Do later cable and radio assets survive the same failure domains?

If submarine routes, microwave capacity, repair logistics and restoration evidence are removed, the argument disappears. That is why the article belongs to Risk and accountability on network infrastructure rather than generic geopolitical risk.

What the evidence does not prove

The public sources are unusually detailed, but they leave important unknowns.

They do not disclose the complete route geometry of No. 2 and No. 3, every landing and shore-end dependency, or whether the cables shared power, management or terrestrial backhaul.

They do not provide a minute-by-minute alarm and traffic-engineering chronology. The automatic shift after the first break is recorded, but the exact convergence interval, retained capacity and route state are not public.

They do not provide uniform application-level performance measurements for the microwave period. Reports of congestion and user difficulty are important, but they do not substitute for latency, loss, throughput and completion metrics across service classes.

They do not establish deliberate damage. Vessel association and political context are not proof of intent.

They do not disclose every maintenance-contract term, vessel priority rule, spare inventory or restoration service level.

They do not quantify all economic losses. Customer accounts show business and daily-life disruption, while compensation records show affected subscriptions. Neither produces a complete loss estimate.

They do not prove that later No. 4, microwave and protection measures have passed current peak-load and multi-failure testing.

They do not establish legal liability by any named actor. This article evaluates controls and evidence, not a damages claim.

Stating these limits is part of the accountability method. Unknowns should become requests for bounded evidence, not invitations to invent a more dramatic narrative.

A control schedule for island continuity

A credible Matsu continuity programme should produce a repeatable evidence set.

1. Failure-domain inventory. Record each submarine and microwave path at a protected level of detail, including landing, shore-end, terrestrial backhaul, power, management, spectrum and repair dependencies.

2. Diversity attestation. State what each additional path is independent from and where common risk remains. Do not use an unqualified diverse label.

3. Capacity ledger. Record normal peak demand, emergency minimums, fallback capacity and allocation by service class.

4. First-failure test. Remove each cable in turn and verify traffic shift, convergence time, customer performance and alarm handling.

5. Second-failure test. While one route is unavailable, simulate loss of the surviving cable and measure microwave activation, priority policy and application performance.

6. Critical-dependency map. Include DNS, identity, cloud services, payments, health systems, status pages and operator tools, not only access circuits.

7. Repair readiness. Preserve maintenance-zone coverage, vessel mobilisation, permits, spares, fault-location capability and realistic weather-adjusted restoration estimates.

8. Communications evidence. Publish service-class effects, capacity limits, restoration stages and update times without exposing exploitable route details.

9. Consumer remedy ledger. Connect credits and complaints to measured service failure while keeping them separate from engineering remediation.

10. Post-repair acceptance. Require optical, routing, capacity and application tests before closing the asset, customer, capacity and redundancy clocks.

11. Later-control validation. Test No. 4 and expanded microwave under the same removal scenarios that exposed the 2023 weakness.

12. Independent observation. Use external probes and customer-side measurements to confirm that internal success corresponds to public reachability.

This programme does not promise uninterrupted full-capacity service under every possible event. It turns the accepted limits into explicit, testable decisions.

The economic counterargument

Full spare capacity is expensive. Island routes serve smaller populations, cable ships are scarce, spectrum is limited and physically independent paths can require long detours. It may be uneconomic to duplicate ordinary peak broadband demand across every fallback.

That is a valid constraint.

It does not justify an undefined resilience claim.

If the emergency objective is voice plus designated critical circuits, the operator should state and test that objective. If ordinary broadband will be heavily degraded, customers and public institutions should know. If a third cable is more cost-effective than full microwave duplication, the decision should use failure frequency, repair duration, correlated exposure and application impact.

The 2023 event provides real data for that calculation. It records the sequence of failures, prolonged constrained service, repair milestones, compensation and subsequent investment. Those observations allow decision-makers to compare the cost of stronger route independence, more microwave capacity, satellite alternatives, burial, monitoring and faster repair mobilisation.

Accountability does not require the most expensive architecture. It requires a traceable relationship between accepted risk, promised service and tested capability.

The worst outcome is not necessarily a constrained backup. It is a constrained backup marketed as full resilience without a capacity ledger.

Conclusion: count the service that remains

Matsu's 2023 outage was not a simple story of two broken cables. It was a sequence that exposed several layers of network control.

The first break showed the value of an alternate submarine path. The second showed the risk of the repair-time window. Microwave preserved selected services but could not reproduce normal broadband capacity. Traffic prioritisation kept some functions working while others degraded. A specialised vessel determined the pace of physical restoration. Service returned before the nominal two-cable redundancy returned.

Each outcome deserves separate credit and separate scrutiny.

The public record also shows why attribution must remain disciplined. Authorities associated vessels with the breaks, but intent was not established. Resilience engineering should not depend on resolving motive. The network must be designed for credible physical hazards, whether accidental or deliberate.

The accountable question is not whether a backup existed. It is what the backup carried, for whom, for how long, under which priority rules and with what measured result. It is not whether two cables had different names. It is which failures they could survive together. It is not whether a repair contract existed. It is whether a vessel, crew, access and acceptance test could restore the route within the accepted window.

Cable maps, capacity tables, maintenance agreements and outage notices are the ledger. Running paths, working radios, configured queues and completed repairs are the reality.

Matsu should therefore be remembered as a backup-capacity accountability test. Continuity was neither total failure nor complete success. It was a set of service-specific outcomes that can be measured. The next resilience claim should begin with that evidence: count the capacity that remains, test the second failure, preserve every clock and call the system resilient only when the operating network proves it.

Sources

  1. https://newsweb.ncc.gov.tw/202309/ch3.html
  2. https://newsweb.ncc.gov.tw/202309/NCCNews11209.pdf
  3. https://www.matsu-news.gov.tw/news/article/208857
  4. https://www.matsu-news.gov.tw/news/article/208801
  5. https://www.matsu-news.gov.tw/news/article/208188
  6. https://www.matsu-news.gov.tw/news/article/208276
  7. https://www.matsu-news.gov.tw/news/article/208275
  8. https://www.matsu-news.gov.tw/news/article/207548
  9. https://www.matsu-news.gov.tw/news/article/208745
  10. https://www.matsu-news.gov.tw/news/article/208699
  11. https://www.matsu-news.gov.tw/news/article/208071
  12. https://apnews.com/article/65f10f5f73a346fa788436366d7a7c70
  13. https://www.theregister.com/2023/02/21/taiwan_vietnam_submarine_cable_outages/
  14. https://www.straitstimes.com/asia/east-asia/months-long-internet-outage-highlights-taiwans-network-vulnerabilities
  15. https://www.potaroo.net/ispcol/2023-03/altcable.pdf
  16. https://moda.gov.tw/press/press-releases/15082
  17. https://moda.gov.tw/press/press-releases/19976
  18. https://www.cht.com.tw/en/home/cht/-/media/Web/PDF/Sustainability/CSR-Report-Download/CSR-Report-en/2023/CHT-2023-TCFD-Task-force-Climate-related-Financial-Disclosures.pdf
  19. https://journals.sagepub.com/doi/pdf/10.1177/02637758251397516?download=true
  20. https://arxiv.org/abs/2302.14201