Internet Resilience Frameworks for Coordinated Global Action
An ISOC LIVE Summary
A Supply Chain and Operational Resilience Assessment of Global Internet Infrastructure — Phase 1 Report
Organization: Marconi Society Internet Resilience Institute
Publication Date: 25 June 2026
Overview
This Phase 1 report presents two starting frameworks developed by the Marconi Society’s Internet Resilience (IR) Institute to strengthen global Internet resilience. The first, the Life of a Packet Mapping Exercise, produced under the Institute’s Supply Chain Mapping Working Group, maps the Internet’s operational dependencies from service and control functions through physical and transport infrastructure to the wider ecosystem of power, cybersecurity, equipment supply chains, and financial flows. The second, the Business Resilience Guide, produced under the Institute’s Hyperscaler Engagement Working Group, distils hyperscaler operational practice into a continuity plan that small and medium-sized enterprises (SMEs) can realistically adopt. Both products are explicitly preliminary: the report states that each will be opened for broader community review and feedback in Phase 2.
Origins: A Question About Rebooting the Internet
The IR Institute began in 2024 with the aim of convening a diverse expert community around the resilience of the global Internet. Its work was sparked by a question posed at its inaugural workshop at the National Academy of Sciences in Washington, DC, in November 2024:
If the Internet suffered a global failure, what would be needed for a reboot?
The report holds that this question exposed Internet resilience as ultimately a global coordination problem rather than a purely technical one — one rooted in governance and shared accountability across sectors.
The Institute has since built a track record across the internet governance calendar. It briefed the U.S. Council for International Business (USCIB) Digital Policy Committee on its 2024 IR Report, engaged stakeholders at ICANN Prague and ICANN Dublin, and hosted a session at the 20th annual IGF in Norway titled “Internet Resilience: Securing a Stronger Supply Chain,” addressing systemic interdependence, electricity–digital infrastructure loops, and operational risk. It secured workshops at the 2025 and 2026 WSIS+20 High-Level Events in Geneva, held an online Global Briefing, and convened a second annual Experts Workshop and Forum drawing infrastructure providers, hyperscalers, financial institutions, utilities, and public-interest organizations.
Internet Resilience as a System
The report’s central premise is that all actors and institutions need to understand their own role and corresponding responsibilities if the Internet is to remain reliable, secure, and resilient — and that no single actor can address systemic risk alone. Resilience, on this account, depends on the interconnected health of technical systems, supply chains, institutional practices, and human coordination.
The Internet Resilience Layering Framework
The framework splits Internet resilience mappings into an upper layer, a lower layer, and a set of key dependencies. The report is explicit that this layering is conceptual and should not be confused with traditional protocol models such as the OSI stack; it is a way of identifying functional groupings that affect customer experience.
The Upper Layer (Service & Control) covers functions that directly interact with or participate in the primary application flow, and are most visible to end users: customer, provider, intermediary, and destination networks, along with devices, routers, translators, DNS, authentication, CDN, DPI/DDoS handling, trust and certificate authorities, radio/link, proxies, servers, firewalls, load balancers, and peering.
The Lower Layer (Physical & Transport) covers functions and networks that are essential but operate transparently to the application flow: wireless RAN, IPX/GRX, MPLS and similar underlays, fixed access (DOCSIS/xPON/DSL), terrestrial and subsea fiber, data centers, and operations functions including monitoring and automation.
Supporting both is a dependency layer — abstracted needs not directly tied to upper or lower layer functions, but required to sustain communication flows both in normal running and during outage events. Phase 1 identifies power generation and distribution, fuel supply and equipment supply chain, physical security, financial flows, and the cybersecurity ecosystem (including organizational capabilities such as running a Security Operations Center), alongside construction and repair, emergency services, regulatory and policy frameworks, and skilled labor. The report describes this layer more broadly as the power, water, machinery, supply chains, and governance frameworks without which the Internet cannot operate.
Mapping a Real-World Internet Journey
To ground the model, working group members mapped a Zoom call from Cape Town, South Africa, to London, UK, with the caller roaming on a mobile network and calling parents back in London. The scenario was chosen because it crosses multiple network types, international boundaries, and infrastructure layers, making it a rich illustration of Internet supply chain complexity. The stated level of abstraction is a “30,000ft view” — this is a mapping exercise, not an engineering audit.
Assumptions include roaming over a remote wireless network and RAN, an intermediary Tier 1 network, a destination provider network with broadband, a remote wireless provider network, and a cloud service provider. Supporting upper layer functions include NAT translation at the home wireless network PGW, public key exchange, Global Server Load Balancing for Zoom, load balancing and firewall functions for Zoom’s cloud-hosted Multimedia Relays (MMRs), public DNS, and inter-network peering. Supporting lower layer functions include subsea fiber, landing stations, terrestrial fiber, the remote network RAN, 3GPP DNS, and the regional cloud provider’s metro area network.
The mapping separates the visible application flow from the extensive underlay that remains invisible in normal operation and becomes decisive during failures.
Hidden Infrastructure and Its Governance
For wireless, a typical endpoint connects over RF to tower, through the RAN, and into the packet core toward a PGW (LTE) or UPF (5G), creating a bearer that effectively appears as a single hop to the application. Connection setup delay, latency, and quality all affect the upper layer flow, yet the mechanics producing them remain transparent from the application’s perspective. The report sets out the 5G roaming connection sequence — UE registration and PDU session establishment, V-AMF to H-SMF signaling via SEPP/N32 where inter-PLMN, H-UPF selection, V-UPF instantiation over N16, and GTP-U encapsulated user packets across the N9 interface — following 3GPP 23.501, version 20.1.0, March 2026.
Two governance points sit inside this plumbing. Because the call is a roaming case, it depends on IPX (IP eXchange) functions, which are governed by the GSMA; and because the endpoints are on different continents, the intermediary network — Syniverse is given as an example — also carries terrestrial and subsea connectivity.
For cloud, the underlay operates independently of the main application flow. Beneath the perceived gateways, firewalls, and load balancers sits a substrate of POPs, metro interconnects, routing infrastructure, and data centers, typically built from interconnecting fabrics. A representative substrate path runs from encapsulation endpoint through POP fabric, metro fabric, metro interconnect, and local data center fabric to server or compute, and back out. None of this is perceivable by the application flow.
Failure Use Cases
The report presents two failure scenarios drawn from real-life situations, with details obfuscated from any one specific event. Both deliberately look at Internet disruption from outside traditional Internet infrastructure — a power event and a vandalism event.
In the first, a data center hosting multimedia service endpoints loses utility power when a blown transformer takes out a single three-phase feed. UPS batteries should carry the load while generators start. What can go wrong is organizational rather than architectural: an unmaintained battery farm that will not take full load, untested generators that fail to fire, diesel that cannot be delivered before on-site reserves run out, network equipment that cannot be replaced through the local supply chain, cooling components unavailable for on-site repair, and operations staff untrained to manage the event.
The second — headed “Vandalism or Construction Led Connectivity Cut” — has a coordinated group entering fiber vaults and access ways across a 20km radius and cutting fiber that carries multiple operators’ primary and redundant paths simultaneously. Monitoring detects the failures, but service is impacted, with partial and full outages expected. The question the report poses is how well systems are monitored and operated and how quickly repair teams can be reached. Failure modes include poorly documented fiber paths and undocumented changes, insufficient operational capacity to isolate faults, OTDRs (Optical Time Domain Reflectometry) that cannot be run, repair crews neither adequately staffed nor ready to deploy across the region, inadequate security to guard repair sites after re-splicing, transport equipment that cannot be repaired because local depot supply is insufficient — and, in some regions, inbound emergency supply subject to national brokerage and therefore undeliverable when it is most needed.
Business Resilience Guide for SMEs
The Hyperscaler Engagement Working Group set out to answer how the operational discipline of hyperscalers can be translated into practical guidance for SMEs. The report notes that unlike large organizations with CISOs, engineering teams, and mature continuity processes, most SMEs are highly exposed to outages, misconfigurations, supply-chain failures, and local infrastructure disruptions — vulnerabilities that can cascade across entire economic networks given SMEs’ central role in global productivity.
The guide is organized around four elements: awareness of Internet-layer dependencies, an impact-likelihood risk matrix with scenario tools, practical mitigation measures, and real-world case studies. Its structure runs from an availability assessment framework (does the organization need to be available during unexpected outages or natural disasters, and what service level and 24/7 readiness does it require), through scenario mapping across data loss, remote work, power outages, natural disasters, technology failures, and cyber attack recovery, to a business contingency plan covering technology infrastructure (cloud-based backup, remote access, resilient communication channels, disaster recovery tools), communication strategy (informing customers and stakeholders, alternative channels, real-time updates), and practical preparedness (backup payment methods, alternative work locations, redundant systems, staff training).
A fourth section, an implementation roadmap for different organization types, is at this stage a single line — test and update your plan — and is best read as a Phase 2 placeholder rather than delivered guidance. A more detailed version of the Business Resilience Guide is available via a QR code in the report.
Assessing Risks
The report offers an Impact-Likelihood Risk Matrix as a diagnostic tool for distinguishing low-frequency annoyances from high-impact systemic threats, so that planning effort is focused where it is most needed.
Scenarios run from short local ISP outages and brief Wi-Fi or VPN disconnections at the low-impact end, through DNS misconfiguration and partial SaaS outages (Microsoft 365 down for hours is the example given) and DNS propagation or upstream routing errors in the middle band, to complete multi-region cloud provider failure, multi-day DDoS against a primary website or API, and major routing hijack, extended cloud downtime, or third-party dependency failure involving a payment gateway, CDN, or identity provider at the high-impact end.
Each cell carries corresponding mitigations: dual ISP setups with 4G/5G failover and local caching; secondary and managed DNS; multi-cloud redundancy, offsite backup, and vendor resilience testing; SD-WAN and routing optimization; alternative SaaS providers and data export readiness; CDN/WAF protection, rate limiting, and upstream coordination; improved internal monitoring and VPN redundancy; DNS failover automation, BGP monitoring, and RPKI adoption; and vendor risk assessment, contractual SLAs, and backup payment gateways and CDN providers.
Key Lessons
Five insights emerged from hyperscaler experience and were adapted for the SME context in Phase 1.
Concentration risk remains largely invisible: many SMEs believe redundancy protects them, when in practice their “independent” connections share the same physical trench or upstream infrastructure, creating hidden single points of failure that only surface in a crisis.
Resilience requires testing: a backup connection, mirrored server, or failover plan is meaningless if never exercised, and where hyperscalers test failure routinely, SMEs rarely do.
Distributed models increase resilience, with workloads, storage, and connectivity benefiting from diversification not only for performance but to mitigate systemic risk.
Cloud interoperability remains a barrier: despite the rhetoric of multi-cloud strategy, moving workloads between providers is deeply challenging and interoperability standards remain immature.
Transparency builds trust: outage disclosures, detailed post-incident analyses, and explicit corrective actions strengthen resilience ecosystems by letting others learn from each failure.
Who Is Involved
The Institute’s Advisory Council includes Fiona Alexander (American University), Maarten Botterman (GNKS Consult BV), David B. Cross (Atlassian), Brian Cute (Global Cyber Alliance), Taher Elgamal (Evolution Equity Partners), Olaf Kolkman (Internet Society), Victor Kuarsingh (Capital One), Ram Mohan (Identity Digital), Moritz Müller (SIDN), Mark Nottingham (Cloudflare), Shernon Osepa, Ramakant Pandrangi (Verisign), Radia Perlman (Dell Technologies), Paul Vixie, and Dan York (Internet Society).
The working groups draw on many of the same figures, joined by David Huberman (ICANN), Darren Kara (Quad9 DNS), Angelique Medina (Cisco ThousandEyes), Damian Huising (Ready.net), Jeff Simmons (Simmons Energy Advisors), and Mimi Tam (Boston College).
Conclusion
The report concludes that Internet resilience depends not on any single actor or technology but on the interconnected health of technical systems, supply chains, institutional practices, and human coordination. Phase 1 offers a roadmap for distributed resilience building that respects the Internet’s architecture while addressing its systemic vulnerabilities; Phase 2 will require sustained commitment, resource investment, and a willingness to challenge assumptions about dependencies, threats, and responsibilities. The alternative the report names is continued fragmentation, which it warns risks significant failures with global consequences. Collective preparedness, on this argument, has to become a deliberate and structured priority supported by cross-sector cooperation.
RESOURCES
Internet Resilience Frameworks for Coordinated Global Action — the Phase 1 report itself (Jun 2026)
Business Resilience Guide: Strategies for SMEs to Ensure Operational Continuity — the detailed guide behind the report’s QR code (Jun 2026)
Marconi Society Internet Resilience Institute — the convening body behind both work products
International Internet Resilience Awareness Week — the Institute’s public awareness initiative on systemic risk
WSIS Forum 2026 Session 235 — Operationalizing Digital Resilience — where both Phase 1 frameworks were presented (Jul 2026)
ISOC LIVE recap: Operationalizing Digital Resilience — video, audio, slides, and archive of the 9 July 2026 session
IGF 2025 WS-139: Internet Resilience — Securing a Stronger Supply Chain — the Institute’s session at the 20th annual IGF in Norway
Marconi Society submission on the WSIS+20 Zero Draft — the Institute’s policy input on resilience of routing, DNS, and IXPs
Building Global Resilience — the IR Institute’s preceding annual report (Nov 2025)
Internet Resilience — the 2024 IR Report from the inaugural National Academy of Sciences workshop (Nov 2024)
3GPP TS 23.501 — System Architecture for the 5G System — the roaming architecture the Cape Town–London mapping follows
GSMA IP and Interconnectivity — the body governing IPX, the roaming interconnect the scenario depends on


