Summary

  • An ACE cable fault was observed near Nouakchott on 30 March 2018. Contemporary reporting described approximately 48 hours of complete national outage before some connectivity returned, while later Mauritanian reporting described a broader period of approximately 16 to 17 days of total or partial disruption and said normal service returned on 12 April.[1][2][3][4]
  • The two duration figures measure different service states. The approximately 48-hour figure concerns the reported complete-outage phase; the longer figure includes complete and degraded service. Neither establishes that every user lacked every possible packet path throughout the entire 16-to-17-day period.
  • ACE, in service since 2012, was described during the incident as Mauritania’s principal international Internet connection. Incident-period accounts described the system as approximately 17,000 kilometres long and connecting 22 countries; the current ACE system description lists 24 countries, reflecting a later system state.[3][4][9]
  • A government spokesperson said two terrestrial fiber lines running south and east toward Mali remained operational. That statement does not establish that the two routes were physically independent, reached different international upstreams, had enough emergency capacity, or had been tested under full failover conditions.[1]
  • The same spokesperson attributed communications shares of 60 percent to Mauritel, 24 percent to Chinguitel, and 16 percent to Mattel. Those figures are attributed statements, not verified measurements of market share, national capacity, restored traffic, or operator performance.[1]
  • Later reports identified a trawler as the likely cause of the cable damage, while a government spokesperson referred more generally to maritime traffic and the mobilization of a maintenance vessel and team. The public evidence supplied here does not establish the vessel’s identity, intent, exact damage mechanism, legal responsibility, or definitive liability.[1][3][4]
  • BGP can exchange and select routes that are available under applicable policy, but it cannot create a missing physical circuit, add contracted capacity, remove a shared failure domain, or guarantee acceptable application performance. Route visibility and operational continuity are therefore different tests.[19][20]
  • Later WARCIP fiber, a national Internet exchange point, open-access distribution of ACE capacity, and the proposed EllaLink connection changed the control environment. They show continued investment and recognition of diversification needs, but do not prove that equivalent controls existed or worked in March 2018.[8][12][13][14]
  • Accountability should be tested through layer-specific records: topology and shared-risk maps, capacity commitments, routing data, failover exercises, congestion and application telemetry, repair logs, customer notices, regulatory reporting, and redress decisions. A route label by itself is not evidence of resilient service.

Two Outage Windows, Not One Continuous State

The event examined here begins with the ACE cable fault observed near Nouakchott on 30 March 2018. It covers the reported complete outage, the subsequent period of partial or degraded service, and the repair completed in April. Later ACE incidents, including disruptions in other years, are outside this event boundary. Politically ordered Internet shutdowns are also outside it because they involve a different failure mechanism and a different accountability analysis.

The first essential distinction is temporal. Contemporary infrastructure reporting attributed approximately 48 hours of complete national outage to the break, after which some service returned. Later Mauritanian reporting described approximately 16 to 17 days of total or partial disruption and reported normal service returning on 12 April.[1][2][3][4] These accounts should not be compressed into a single claim that Mauritania was wholly offline for 16 or 17 days.

The approximately 48-hour period and the approximately 16-to-17-day period answer different questions. The first describes a phase reported as complete national loss. The second encompasses a longer interval during which service could be absent, intermittent, constrained, or degraded before being described as normal again. Partial reachability during that longer interval would not, by itself, demonstrate adequate throughput, stable latency, acceptable packet loss, application availability, or equal recovery across operators and regions.

The reference does not provide a uniform, minute-by-minute national timeline against which every reported duration can be reconciled. “Normal service” is itself a conclusion that requires a defined baseline. It might refer to restoration of the submarine system, the availability of Internet routes, the clearing of congestion, the recovery of customer-facing applications, or a broader operational judgment. Without layer-specific timestamps and service measurements, those states cannot safely be treated as interchangeable.

Measurement-oriented event records and technical reports can help distinguish an observed loss of connectivity from subsequent changes in route visibility or service quality, but the available public summaries do not resolve every operator, location, and application state.[5][6] The narrow, defensible chronology is therefore:

  1. A fault was observed near Nouakchott on 30 March.
  2. Approximately 48 hours were reported as a complete national outage.
  3. Some service then returned, creating a partial or degraded period.
  4. Repair activity continued in April.
  5. Normal service was reported on 12 April within a broader disruption described as lasting approximately 16 to 17 days.[1][2][3][4]

This sequence establishes severity without inventing universal packet-level conditions. It does not prove that every Mauritanian user lacked every route during every hour of the longer window. It also does not permit partial reachability to be described as full recovery. The central analytical problem lies between those two errors: a network can cease to be completely unreachable while remaining operationally inadequate for many customers and essential services.

The cause requires similar restraint. A government spokesperson said maritime traffic commonly caused faults of this kind and reported that a maintenance vessel and team had been mobilized. Later reporting described a trawler as the likely cause.[1][3][4] That supports an attributed, probable explanation, not a definitive finding. The supplied record does not establish vessel identity, intent, the precise damage mechanism, legal fault, or a final allocation of liability.

The outage can be analyzed without resolving those unknowns. An accidental external strike and a deliberately caused break would raise different legal questions, but both expose the same continuity control: whether the network can continue carrying essential traffic when a principal international path is unavailable. The resilience test should not depend on proving misconduct by a vessel, a cable organization, a telecom operator, or a public body.

ACE’s Role in Mauritania’s International Connectivity

ACE entered service in 2012. Incident-period sources described it as a submarine system of approximately 17,000 kilometres connecting 22 countries, while the current ACE website describes a system connecting 24 countries.[3][4][9] The descriptions refer to different stages of the system’s development. The present-day figure should not be projected backward as though it were the March 2018 configuration, and the earlier figure should not be used to deny subsequent expansion.

Contemporary reporting characterized ACE as Mauritania’s principal international Internet connection and described Mauritania as experiencing the most severe disruption from the fault. Countries with other international routes were reported as seeing smaller effects.[3][4] That comparison supports a concentration-risk inference: the consequences of a cable failure depend not only on the cable break but also on the availability and usability of paths outside the failed system.

“Principal connection,” however, is more precise than “only possible path.” The government spokesperson’s account referred to two terrestrial fiber lines toward Mali that remained operational.[1] The public record therefore contains evidence of claimed alternate terrestrial connectivity. What it does not contain is enough information to determine whether those links constituted independent, adequately provisioned international failover paths for the affected traffic.

ACE itself should not be treated as a single undifferentiated entity. A submarine system includes wet plant, landing infrastructure, terrestrial extensions, optical transport, operational organizations, capacity arrangements, interconnections, and maintenance processes. The current ACE site and membership information help describe the system’s institutional and geographic scope, but they do not by themselves disclose the exact topology, capacity commitments, or routing policies that applied to Mauritania in March 2018.[9][10]

The distinction matters for accountability. Ownership or membership in a cable arrangement does not automatically reveal who controlled each restoration decision. A fault on the submarine segment may require cable-system coordination and repair-vessel logistics. Traffic diversion may depend on national operators, terrestrial providers, cross-border partners, upstream transit networks, and routing policy. Customer notices and compensation may fall under still other contractual or regulatory responsibilities.

The incident’s severity is thus not evidence that submarine cables are inherently unreliable or that ACE alone should bear responsibility for national continuity. All physical systems can fail. The relevant control is whether a failure of a principal path remains a repair incident or becomes a national connectivity crisis. That difference is created by topology, capacity, operations, testing, and evidence.

Seven Clocks Governed the Restoration

A statement that “the Internet returned” can hide several different recoveries. The 2018 event should be assessed through at least seven clocks: physical repair, optical transport, BGP reachability, usable capacity, application recovery, public communication, and redress. Each clock has its own owner, evidence, and possible completion time.

Physical cable repair

The first clock concerns the damaged physical system. It begins with detection and localization of the fault and includes mobilization, permits, vessel availability, transit to the site, recovery or access to the cable, repair, testing, and return to service. Reports that a maintenance vessel and team were mobilized establish activity, but the supplied sources do not provide a complete public repair log or verified timestamp for each step.[1]

Physical restoration is necessary for returning traffic to the affected cable, but it is not the same as end-to-end Internet recovery. A repaired wet segment must still connect through landing and terrestrial facilities, optical equipment, operator networks, routing relationships, and customer access systems.

Optical transport

The second clock concerns whether the relevant optical circuits were restored and stable. A physical repair can be completed while optical testing, power balancing, equipment checks, or circuit activation remains in progress. Conversely, traffic may be diverted onto other optical systems before the failed cable is repaired.

The public record supplied for this analysis does not disclose circuit-level alarms, optical test results, restoration capacity, or the exact sequence in which transport services returned. Those omissions prevent a precise judgment about when physical repair became usable transport.

BGP reachability

The third clock concerns the exchange and selection of Internet routes. BGP is the inter-domain routing protocol through which autonomous systems communicate reachability information and apply policy to select paths.[19] If an alternate international link and routing relationship exist, operators may announce, receive, or prefer routes over that link.

A visible route is evidence of possible reachability, not proof that the route can carry all displaced traffic. BGP does not report every physical shared risk, reserve bandwidth, certify latency, or guarantee that applications will operate acceptably. A route may be technically present while its underlying link is congested or while only some prefixes, networks, or service classes are reachable.

Usable capacity

The fourth clock starts when restored or alternate paths can carry traffic at a meaningful service level. This is where a nominal backup can fail without disappearing from a routing table. An alternate circuit may have limited public evidence contracted capacity, no reserved emergency headroom, restrictive traffic policy, or a bottleneck at a cross-border handoff.

Capacity must be tested under displaced demand. Evidence would include interface utilization, flow records, packet loss, latency, queue behavior, traffic-engineering changes, and capacity available after other contractual commitments. None of those incident-specific records is supplied here. The fact that two Mali lines were described as operational therefore cannot be translated into a percentage of national traffic restored.

Application recovery

The fifth clock concerns the services people and institutions were actually trying to use. Basic packet reachability does not guarantee successful DNS resolution, web access, authentication, payment processing, messaging, cloud access, or access to public-sector systems. Different applications may depend on different international destinations and may react differently to latency, loss, session resets, or constrained bandwidth.

No application-by-application recovery record is available here. It would be unsafe to infer either universal failure or universal recovery from a national connectivity description. Application telemetry, synthetic tests, transaction success rates, and user-facing incident reports would be needed to establish which services were usable at each stage.

Public communication

The sixth clock measures how quickly operators and public authorities explained what was happening. Good incident communication should distinguish detection, cause attribution, restoration status, service limitations, expected repair stages, and uncertainty. It should not use “restored” without identifying the restored layer.

The supplied evidence includes public statements and subsequent reporting, but not a complete archive of operator notices, their timing, their geographic scope, or the service limitations disclosed to customers. The attributed 60/24/16 figures illustrate the problem. Without a clear definition and supporting measurements, such percentages cannot tell the public how much capacity was available or which customers had usable service.[1]

Compensation and redress

The seventh clock begins when service disruption creates potential customer consequences and ends only when applicable complaint, compensation, or other redress processes are resolved. Technical restoration does not answer whether customers received the service for which they paid, whether prolonged degradation triggered contractual remedies, or whether essential-service users had special protections.

The supplied record does not establish whether compensation was offered, required, requested, or denied. It also does not identify the rules applied. That is an explicit unknown, not evidence that no redress occurred.

These seven clocks explain why the reported 48-hour and 16-to-17-day windows can coexist. A complete national outage may end when some reachability returns, while capacity, applications, communications, and customer remedies remain incomplete. Accountability depends on preserving those distinctions rather than announcing a single restoration moment unsupported by the underlying records.

The Two Mali Routes Required an Independence Test

The strongest public indication of fallback connectivity came from the government spokesperson, who said two terrestrial fiber lines running south and east toward Mali remained operational.[1] This is significant evidence: it means the public narrative was not simply one of a country with no conceivable alternative physical connection. But it is the beginning of the resilience inquiry, not its answer.

A credible path-diversity assessment would test at least four properties: physical independence, upstream diversity, usable emergency capacity, and exercised failover.

Physical independence

Two lines can be geographically distinct in a high-level description while sharing critical failure domains. They may enter the same facility, use the same duct for part of their route, depend on the same power system, cross the same bridge, terminate on common optical equipment, or rely on a common terrestrial segment before reaching an international exit. A map showing two drawn lines is not enough.

The public sources supplied here do not establish the exact physical routes of the southbound and eastbound links. They do not establish whether the lines shared ducts, power, sites, equipment, or a cross-border segment. They also do not establish whether either route depended on ACE-related landing or terrestrial infrastructure at another point.

Independence should be demonstrated through current route surveys, geographic information, facility inventories, power dependencies, equipment relationships, and shared-risk link-group records. Where commercial sensitivity limits publication, an appropriate regulator or independent auditor can verify the details and publish a bounded conclusion. The conclusion should identify which failure domains were tested, not merely certify that diversity exists.

Upstream diversity

A terrestrial line into Mali is not necessarily an independent international Internet exit. It matters where the path goes next, which upstream providers carry the traffic, and whether those upstreams depend on a shared cable, landing station, metropolitan facility, or cross-border corridor.

Two national routes can converge on one foreign transit provider. Two transit providers can converge on the same submarine system. A route can also be independent at the physical layer while remaining operationally coupled through a common routing policy, authentication system, management plane, or commercial capacity arrangement.

The supplied record does not disclose the Mali routes’ upstream exits or transit relationships during the incident. It therefore cannot establish whether they diversified Mauritania away from ACE at the end-to-end international level. That uncertainty is central because a path labelled “terrestrial” may still reach external networks through infrastructure that shares a relevant risk with the primary service.

Usable emergency capacity

A route can remain operational yet carry only a small fraction of displaced demand. The amount of fiber in the ground does not reveal lit capacity, contracted capacity, reserved capacity, port speeds, cross-border handoff limits, transit commitments, or competing traffic.

The government spokesperson also attributed communications shares of 60 percent to Mauritel, 24 percent to Chinguitel, and 16 percent to Mattel.[1] Those figures must remain in their attributed form. The record does not establish what denominator the spokesperson used, whether the numbers described subscribers, communications activity, operator presence, or some other category. They are not measured restoration percentages and should not be converted into a national capacity model.

For emergency capacity to be accountable, operators need a pre-defined demand model. That model should identify essential service classes, minimum service objectives, expected displaced traffic, and the headroom available on each alternative. Capacity that exists only on paper, or must be negotiated after the failure, is a weaker control than capacity already contracted, configured, monitored, and periodically exercised.

Exercised failover

Even an independent, adequately provisioned route may fail as a control if it has not been tested. Routing policy might not prefer it when needed. Prefix filters could reject necessary announcements. Maximum-prefix controls could interrupt a session. Traffic-engineering changes could move traffic asymmetrically. Network-address dependencies, DNS behavior, stateful firewalls, or application allowlists could prevent services from working over the alternate path.

RFC 7454 documents operational practices intended to improve the security and robustness of BGP deployments, including disciplined filtering and configuration.[20] Such practices reduce avoidable routing risk, but no document can prove that a specific Mauritanian failover worked in March 2018. That requires incident records or prior exercise results from the networks involved.

An exercised-failover record would show the scenario, participating networks, routes announced and received, convergence behavior, traffic shifted, resulting utilization, packet loss and latency, applications tested, failures observed, remediation assigned, and date of retest. The public evidence supplied here contains no such history.

The two Mali routes therefore remain important but unresolved. Treating them as irrelevant would ignore the spokesperson’s statement. Treating them as proven national backups would infer independence, capacity, upstream diversity, and operational readiness that the record does not establish. The evidence-supported conclusion is narrower: alternate paths were reported as operational, yet the scale and duration of the disruption make their effective role a legitimate subject for verification.

What BGP Could—and Could Not—Restore

BGP is often invoked as though the Internet automatically routes around any physical failure. That shorthand is useful only within strict limits. RFC 4271 defines BGP as a protocol through which routing systems exchange reachability information and apply a decision process to select routes.[19] The protocol operates over paths and relationships that networks have built, configured, and made available.

If a failed cable removes the only usable route to a destination, BGP cannot manufacture another cable. If an alternate route exists but is not announced, received, accepted, or selected under policy, BGP cannot make it usable without operational changes. If the route is selected but has limited public evidence capacity, BGP does not add bandwidth. If both routes share a hidden physical dependency, the presence of two BGP paths does not remove that shared risk.

The distinction can be stated as a sequence:

  • Physical topology determines what links can exist.
  • Optical and packet transport determine what circuits are operational.
  • Commercial and technical relationships determine what connectivity is available.
  • BGP policy determines which available inter-domain routes can be exchanged and selected.
  • Capacity and congestion determine how much traffic the selected path can carry.
  • Application dependencies determine whether a reachable service works for users.

Failure at any earlier layer constrains the layers that follow. A routing configuration cannot compensate for a missing physical route, just as a repaired physical route does not prove that routing, capacity, and applications have recovered.

BGP also optimizes according to operator policy, not a universal measure of user experience. Its decision process does not natively select the path with the most emergency capacity or the lowest application latency. Operators can influence selection through policy and attributes, but those choices require preparation and observation. A technically valid alternate route could still create congestion or poor application performance.

RFC 7454 reinforces that reliable routing depends on operational discipline, including filtering, documented policy, and protection against foreseeable configuration or announcement failures.[20] Those controls matter during failover because a rarely used path may expose outdated filters, incorrect limits, or undocumented dependencies. They are safeguards for routing behavior, not evidence of physical diversity.

Several distinct artifacts would be needed to assess the 2018 routing response:

  • BGP update and withdrawal records showing when routes disappeared and reappeared;
  • route-collector or operator data showing which prefixes were visible through which upstreams;
  • configuration and policy records showing intended primary and fallback behavior;
  • flow and interface data showing how much traffic used each route;
  • alarms and session logs showing whether routing adjacencies remained stable;
  • application and customer measurements showing whether selected routes delivered usable service.

The public record supplied here does not provide a complete set of those artifacts. It follows that the outage cannot be reduced to “BGP failed,” any more than partial recovery can be credited to BGP alone. Routing was one control layer within a larger continuity system.

This distinction is important for fair allocation of responsibility. Cable organizations are not normally responsible for every operator’s BGP policy. Operators do not control every maritime hazard or repair-vessel schedule. Transit partners cannot create capacity they were not contracted to provide. A regulator may set disclosure or resilience expectations without directly operating the network. Accountability becomes clearer when it follows the layer each entity could reasonably control.

Public Statements Were Not Capacity Measurements

During a high-impact outage, officials and operators need concise ways to describe service. Yet concise statements can blur technical states unless their terms are defined. The attributed 60/24/16 operator shares are a clear example.[1] The figures add to the historical record, but they do not establish how much traffic each operator restored, how much international capacity remained, or what fraction of customers had adequate service.

A useful restoration statement would specify at least four things: the measured population, the service threshold, the time of measurement, and the evidence source. “Sixty percent restored” could otherwise refer to subscribers, routes, sites, traffic volume, nominal bandwidth, or successful tests. Each would support a different conclusion.

The supplied material does not provide operator-by-operator restoration timestamps or region-by-region measurements. It does not show whether Mauritel, Chinguitel, and Mattel recovered at the same rate. Nor does it reveal how wholesale dependencies affected their retail services. The three operators should therefore not be ranked or blamed on the basis of the attributed shares.

Likewise, the phrase “normal service returned” needs a baseline.[2] A defensible baseline might include route visibility, capacity headroom, congestion, latency, packet loss, application success, and complaint levels. It could also distinguish national averages from underserved regions or constrained operators. Without such a definition, the phrase remains a reported status rather than a verified all-layer finding.

Public communication is itself a continuity control. Clear notices allow public agencies, companies, and individuals to adapt their use of constrained services. Notices can explain which applications remain affected, what traffic is being prioritized, and when the next update will appear. They can also preserve uncertainty: an attributed probable cause should not be announced as a final legal finding.

The evidence supplied here does not contain a complete notice archive, incident-command record, or compensation history. The appropriate conclusion is not that communication or redress was absent. It is that their timing, content, and outcomes cannot be verified from this record. Those missing artifacts should remain visible in the accountability assessment.

Responsibility Followed the Failure Layers

A national connectivity crisis creates pressure to identify one responsible institution. The technical reality is distributed. Responsibility should be mapped to controllable duties rather than assigned wholesale to ACE, an operator, the government, a reported trawler, or any individual.

Retail and network operators

Operators control or influence their contracted capacity, customer networks, routing policy, traffic engineering, monitoring, application dependencies, notices, and customer remedies. They are positioned to preserve BGP records, interface telemetry, service measurements, failover procedures, and customer communications.

Their accountability question is whether they obtained and tested sufficient continuity for the services they offered. The answer cannot be inferred from their names, subscriber relationships, or the spokesperson’s attributed percentages. It requires operator-specific evidence.

Landing and cable organizations

Cable and landing organizations control or coordinate parts of fault detection, localization, maintenance, repair processes, landing infrastructure, and restoration of affected cable capacity. ACE system information and membership records identify the wider institutional setting but do not settle every operational duty in the 2018 incident.[9][10]

Their accountability questions concern detection, escalation, repair logistics, spares, maintenance arrangements, testing, and communication with capacity users. The supplied record does not support a conclusion that any specific organization breached a duty.

Terrestrial and transit partners

Cross-border fiber and upstream transit providers determine whether alternate paths actually extend to independent international exits. Their capacity contracts, physical-route information, maintenance state, routing sessions, and congestion data are essential to evaluating the claimed Mali fallback.

Their role cannot be judged solely by whether a circuit was “up.” A functioning low-capacity circuit and an adequately provisioned emergency path are different controls.

Regulators and emergency coordinators

Regulators and public authorities can define resilience objectives, reporting duties, exercise requirements, consumer information standards, and redress rules. Emergency coordinators can establish service priorities and cross-organizational communication procedures.

Their accountability is not to promise that no cable will fail. It is to make continuity claims testable, require material incidents to be documented, and ensure that essential-service and consumer consequences are visible. The supplied evidence does not establish what requirements were in force or how they were applied in 2018.

Repair-vessel and maritime coordination

Repair logistics may involve maintenance agreements, vessel availability, permits, weather, port access, cable localization, spares, and coordination across jurisdictions. The statement that a vessel and team were mobilized is evidence of a response, but not a complete measure of preparedness or delay.[1]

Cable-protection and maritime-risk controls can reduce the probability or consequences of damage, yet the reported likely involvement of a trawler does not establish intent or legal responsibility.[3][4] Any causal allocation beyond probable maritime damage would require technical and legal investigation records not supplied here.

Evidence custodians

Every layer produces records. Operators hold routing and traffic data. Cable organizations hold repair and test records. Transit partners hold capacity and session evidence. Regulators may hold incident reports and consumer complaints. Public authorities hold emergency coordination records. Evidence custody is therefore a substantive responsibility, not clerical housekeeping.

Without preserved records, later review tends to collapse into declarations: a path existed, a repair was completed, or service was normal. With records, those claims can be compared against observable network and customer outcomes. Verifiable restoration protects all parties by distinguishing a control that failed from one that worked but was overwhelmed by a different dependency.

Later Investments Changed the Control Environment

Later infrastructure developments are relevant because they show how Mauritania’s connectivity environment evolved after 2018. They must not be used to claim that the same controls existed at the time of the ACE break.

World Bank material states that WARCIP subsequently supported approximately 1,700 kilometres of national fiber, established an Internet exchange point, and enabled open-access distribution of ACE capacity.[8] Earlier project records place these developments within a longer program of expanding broadband reach and reducing connectivity costs.[11][12][13]

Each intervention addresses a different risk. National fiber can extend access and create terrestrial interconnection options. An IXP can keep eligible domestic traffic local rather than sending it through international transit. Open access can broaden the distribution and use of cable capacity. None, by itself, creates an independent international route.

An IXP is particularly important to describe accurately. Local peering, caches, and domestic hosting can preserve some domestic services during an international disruption. They can reduce unnecessary international traffic and make remaining capacity more useful. But an IXP cannot reach external destinations without an operational international path. Its resilience value depends on connected networks, local content, power, facilities, routing, and actual traffic exchange.

Open access to ACE capacity can improve competition and utilization, but distributing access to one cable does not eliminate that cable as a shared physical failure domain. It may improve operator continuity while leaving national international-path concentration substantially unchanged. The World Bank’s identification of international-access diversification as continuing or future work is therefore important context.[8][13]

A 2025 European Union and European Investment Bank initiative describes a second EllaLink connection as backup to the single ACE cable.[14] That formulation strengthens the inference that a second international submarine path remained a recognized continuity control. It does not establish the precise commissioning state, physical independence, capacity, routing integration, or tested performance of the later connection.

Current system and resilience information can help establish what questions should be asked today, but it cannot be projected backward into March 2018.[7][9] Later controls require their own verification:

  • Does the second path use a genuinely separate landing and terrestrial corridor?
  • Are power, facilities, and upstream networks independent?
  • Is emergency capacity contracted and immediately usable?
  • Are routes configured and tested for controlled failover?
  • Can essential applications operate under the fallback conditions?
  • Are exercise and incident records preserved?
  • Does the IXP retain meaningful domestic traffic during loss of international capacity?
  • Are operators able to access the controls on fair and operationally workable terms?

Comparative cable-failure material, including technical analysis of other regional incidents, can inform the design of these tests.[15][16][17][18] It should not be imported into the 2018 Mauritania chronology. In particular, the March 2024 West Africa multi-cable outage was a separate multi-country event with its own causes, measurements, and restoration pattern.[18] The analytical unit here remains Mauritania’s 2018 principal-cable failure and the uncertain performance of its reported terrestrial alternatives.

Later investment is therefore evidence of a changed control environment, not evidence of retroactive readiness. The accountability question moves forward: can the new controls now demonstrate independent, usable, tested continuity under realistic failure conditions?

A Prevention and Evidence Matrix

Prevention cannot mean guaranteeing that no submarine cable will ever be damaged. A workable framework must distinguish reducing the chance of a failure, limiting its impact, accelerating recovery, communicating service conditions, and providing redress. Each control needs an owner, an observed test, a preserved artifact, and a failure threshold.

Control Primary evidence owner Test Required artifact Failure threshold
International physical-path diversity Operators, infrastructure providers, regulator or independent auditor Trace each primary and fallback path through landing, terrestrial, facility, power, and upstream failure domains Current topology and shared-risk map with dated verification A supposedly independent path shares an undisclosed critical failure domain, or independence cannot be verified
Reserved emergency capacity Operators and transit providers Shift defined essential and representative traffic onto alternate paths under realistic load Capacity contracts, interface telemetry, flow data, congestion results, and service-class outcomes Alternate capacity cannot meet the pre-defined minimum service objective or is unavailable when exercised
BGP failover readiness Operators and upstream partners Withdraw or isolate the primary path in a controlled exercise and observe route propagation, selection, and stability BGP updates, route views, configuration snapshot, convergence timeline, and anomaly log Required prefixes do not become reachable through the alternate path, or routing remains unstable beyond the approved objective
Application continuity Service operators and public-sector system owners Run end-to-end tests for designated essential applications during fallback Synthetic-test results, transaction success rates, latency, loss, and dependency map Packet reachability exists but a designated essential application fails its defined service objective
Domestic traffic retention IXP, connected networks, content and cache operators Isolate or constrain international paths and measure eligible domestic exchange IXP traffic data, route-server views, entity test results, and local-content inventory Traffic expected to remain domestic unnecessarily depends on the failed international path
Cable protection and maritime-risk reduction Cable organization, landing parties, maritime authorities Review route hazards, notifications, monitoring, and incident-response coordination Risk assessment, route notices, monitoring records, exercise report, and remediation list A known high-risk exposure lacks an assigned mitigation or escalation process
Repair readiness Cable organization and maintenance partners Exercise mobilization, spares, permits, contacts, and decision procedures Maintenance agreement, spares inventory, contact roster, mobilization timeline, and exercise record A required resource or authorization is unavailable within the defined restoration plan
Layered incident reporting Operators, cable organization, regulator, emergency coordinator Reconstruct an exercise or incident using separate physical, routing, capacity, application, and customer clocks Timestamped incident timeline linked to references A material restoration claim cannot be tied to a layer, threshold, timestamp, and evidence source
Customer communication Retail operators and regulator Issue simulated or real notices that distinguish outage, degradation, uncertainty, and next update Notice archive, publication timestamps, affected-service scope, and update history Customers receive no timely service-state description or a restoration statement lacks a defined service threshold
Compensation and redress Operators, regulator, consumer-protection bodies Apply published rules to a prolonged complete or degraded-service scenario Eligibility rules, decisions, complaint outcomes, and aggregate reporting Customers cannot determine eligibility, submit a claim, or obtain a recorded decision
Cross-organizational continuity governance Operators, public authorities, infrastructure and transit partners Conduct a multi-party exercise covering the loss of the principal international path Scenario, entity list, decisions, telemetry, gaps, owners, deadlines, and retest results A critical dependency has no accountable owner, or a prior failure remains open at the next exercise
Evidence preservation Every technical and regulatory custodian Retrieve the records needed to reconstruct a defined incident window Retention policy, integrity controls, access log, and complete incident evidence package Required routing, capacity, repair, communication, or redress evidence is missing or cannot be reliably tied to the event

The matrix is deliberately evidence-based. A control is not complete because a policy document says it exists. Physical diversity requires route verification. Capacity requires load evidence. Routing readiness requires observed failover. Application continuity requires application tests. Communication requires timestamped notices. Redress requires decisions that affected customers can understand and use.

The thresholds should be defined before an incident. The supplied record does not justify inventing a particular bandwidth, latency, or restoration-time target for Mauritania. Those values depend on demand, critical services, network design, contracts, and regulatory choices. What can be required universally is that a target be explicit, measurable, tested, and linked to an accountable owner.

The matrix also separates control types. Cable protection and maritime coordination primarily reduce likelihood. Independent paths, reserved capacity, an IXP, and local hosting reduce impact. Repair readiness and routing exercises accelerate recovery. Layered timelines and customer notices support disclosure. Compensation processes address redress. One successful category cannot be used to declare all others complete.

For example, rapid cable repair does not excuse an untested fallback plan. A working alternate route does not eliminate the need for accurate customer notices. An IXP that preserves local traffic does not replace international capacity. Compensation does not repair topology, and topology does not resolve compensation.

The required evidence should be retained across organizations. A national post-incident record could incorporate bounded contributions without publishing commercially sensitive details. An independent reviewer might confirm that physical routes do not share specified failure domains, while operators publish service-level and failover results in aggregate. Cable organizations could publish repair milestones, and regulators could publish notification and redress outcomes.

That structure would also make uncertainty more precise. Instead of saying “the backup failed,” a review might find that the alternate link remained physically operational, BGP reachability returned, but usable capacity fell below the defined threshold. Or it might find that sufficient capacity existed but essential applications failed because of an untested dependency. Those findings lead to different remedies and avoid blaming parties for layers they did not control.

The Bounded Accountability Test

The 2018 ACE break made international path diversity an accountability test because the observed consequences cannot be explained by route labels alone. ACE was described as Mauritania’s principal international connection, two terrestrial routes toward Mali were reported as operational, approximately 48 hours were described as a complete national outage, and a longer period was described as total or partial disruption before normal service was reported.[1][2][3][4]

Those facts support scrutiny of concentration, fallback readiness, and restoration transparency. They do not establish the physical topology of the Mali routes, their upstream exits, shared ducts or power, contracted capacity, routing policy, failover history, congestion, application performance, or operator-specific recovery. They also do not establish definitive responsibility for the cable damage or the existence or absence of customer compensation.

The appropriate test has three parts.

First, were there international paths that were independent across the failure domains that mattered? Administrative separation, different route names, or different geographic labels are limited public evidence if the paths converged on a shared duct, facility, power source, upstream, or cable dependency.

Second, could those paths carry defined essential and representative traffic at usable service levels? BGP reachability is necessary but not sufficient. Capacity, congestion, application behavior, and service-class outcomes determine whether a route was operationally meaningful.[19][20]

Third, could the restoration be verified across the seven clocks: physical repair, optical transport, routing, usable capacity, applications, communication, and redress? A single declaration that service returned cannot substitute for those records.

Evidence that Mauritania already had a physically independent, adequately provisioned, and successfully exercised international route in March 2018 would weaken the conclusion that path concentration was the central control problem. Routing, flow, capacity, and application data showing prompt, broadly usable failover would shift the analysis toward narrower failures in capacity allocation, applications, communication, or reporting. A formal technical and legal investigation establishing another damage mechanism would change causal allocation without removing the continuity question.

On the supplied record, the bounded finding is that nominal alternatives did not resolve the accountability issue. International continuity had to be demonstrated by traffic running over usable independent paths and by records showing what recovered, when, for whom, and at what service level. The 2018 event exposed the distance between a route that could be named and continuity that could be verified.

Sources

  1. https://taqadoum.mr/fr/node/1849
  2. https://afrique.le360.ma/mauritanie/societe/2018/04/13/20465-mauritanie-retour-de-linternet-apres-17-jours-de-quasi-interruption-20465/
  3. https://fortune.com/2018/04/09/mauritania-cable-break-internet/
  4. https://www.independent.co.uk/tech/mauritiana-internet-cut-underwater-cable-offline-days-west-africa-a8298551.html
  5. https://aqualab.cs.northwestern.edu/sentinel-events/
  6. https://www.iij.ad.jp/en/dev/iir/pdf/iir_vol41_EN.pdf
  7. https://pulse.internetsociety.org/en/resilience/mr/
  8. https://www.worldbank.org/en/results/2022/12/16/extending-the-reach-and-reducing-the-costs-of-broadband-communications-in-mauritania
  9. https://ace-submarinecable.com/en/submarine-cable/
  10. https://ace-submarinecable.com/en/members/
  11. https://www.eib.org/fr/projects/pipelines/all/20100365
  12. https://www.worldbank.org/en/news/press-release/2013/05/30/world-bank-approves-funds-improve-broadband-connectivity-mauritania-togo
  13. https://documents.worldbank.org/en/publication/documents-reports/documentdetail/099915008262277976
  14. https://www.eeas.europa.eu/delegations/mauritanie/d%C3%A9ploiement-d%E2%80%99un-second-c%C3%A2ble-sous-marin-haut-d%C3%A9bit-pour-la-mauritanie_fr
  15. https://www.itu.int/epublications/zh/publication/itu-t-d-50-suppl-3-2025-04-guidelines-for-reducing-the-costs-of-international-internet-connectivity-for-the-central-african-backbone-cab-project/en
  16. https://www.itu.int/dms_pub/itu-d/opb/stg/D-STG-SG01.02.1-2017-PDF-E.pdf
  17. https://www.ripe.net/analyse/archived-projects/mediterranean-fibre-cable-cut/
  18. https://www.internetsociety.org/resources/doc/2024/2024-west-africa-submarine-cable-outage-report/
  19. https://www.rfc-editor.org/rfc/rfc4271
  20. https://www.rfc-editor.org/rfc/rfc7454