When the Internet Goes Dark: Governance Lessons from National-Scale Shutdowns
Earlier in this series
Most people who write about internet shutdowns have never been inside one. I have. I ran an independent consulting practice through national-scale disruptions in Iran that lasted, cumulatively, months at a stretch.
I also studied the subject before I lived its worst versions. My undergraduate thesis at TalTech analyzed VPN solutions for peer-to-peer content delivery, with Iran as the case study, and the fieldwork included interviews with people who depended on VPNs simply to stay in contact with their families under network restrictions. Those interviews taught me early that connectivity loss is never an abstract policy event. It lands on specific people, on specific days, in the middle of specific obligations.
One scoping note before anything else, consistent with the rule I set in the first piece of this series: this article is about systems, institutions, and consequences. I am not going to discuss why any particular shutdown was ordered, and I am not endorsing any constraint by analyzing how things behave under it. Studying resilience is not approval of the stress test.
What actually stops
From the outside, a shutdown sounds like one thing: "the internet is off." From the inside, it is a cascade, and the sequence matters.
Work stops first, and unevenly. Anyone whose income crosses the border — freelancers, exporters, anyone serving foreign clients — goes silent to the people who pay them. In my own case, the practical problem was brutal in its simplicity: clients abroad could not tell the difference between "the country is offline" and "this consultant has vanished." Reliability is a freelancer's entire product. A shutdown spends your reliability for you.
Family contact degrades next. Diaspora families live on messaging apps. When those fail, people fall back through the stack — domestic apps, SMS, expensive international calls — and each fallback loses someone: an elderly parent who only knows one app, a relative whose only affordable channel just closed. This is what my thesis interviewees kept describing, and it is why I resist purely economic framings of shutdowns. The cost that people describe first is not money.
Then the quiet dependencies surface. Payment terminals that verify against foreign services. Businesses whose accounting, inventory, or booking systems live in a foreign cloud. Software that phones home for license checks and fails closed. None of these appear in anyone's shutdown planning, because nobody had a complete inventory of what depended on external connectivity. That inventory gets taken the hard way, in real time.
What keeps working is whatever runs domestically end to end. During partial disruptions — international connectivity cut while the national network stays up — domestic services can continue. This selective survival is exactly the layered architecture I described in the opening piece of this series, experienced from below.
The costs that outlast the outage
Direct economic losses from major shutdowns are large; organizations that track shutdowns have published estimates running to significant fractions of daily GDP for affected countries, and I will leave the figures hedged as reported rather than quote numbers I cannot verify. But the recurring costs are subtler and longer.
Reliability discounting. Foreign clients and partners reprice everyone in the affected country. Contracts add clauses. Opportunities quietly route elsewhere. This penalty persists for years after connectivity returns, and it lands on people who had nothing to do with the decision.
Permanent behavioral change. After the first prolonged shutdown, nobody inside plans as if connectivity is guaranteed again. Some of this is healthy resilience — offline copies, redundant channels, local backups. Some of it is pure deadweight: duplicated infrastructure and hedging costs that a reliable network would have made unnecessary.
Trust migration. People and businesses shift toward whatever survived, and away from whatever did not. Whether that shift is good or bad depends entirely on what survived and why — but it is directional and sticky, and policymakers should understand that every shutdown re-architects the country's digital habits whether anyone intends it or not.
Governance lessons, for any government
I want to draw the lessons at an altitude where they apply to any state — including ones that would never order a shutdown but might suffer one through cable cuts, disasters, or attacks on infrastructure.
First: connectivity loss is a blunt instrument hitting a fine-grained system. A modern economy cannot be selectively paused. Whatever a disruption is meant to affect, it also hits payments, logistics, medicine ordering, family contact, and every exporter simultaneously. Any national risk register that lists "loss of international connectivity" should model that full blast radius, not the headline services.
Second: continuity planning must include the connectivity layer. Most business-continuity doctrine assumes the internet as a given, the way it assumes gravity. In the sovereignty-versus-isolation taxonomy I argued constraints on connectivity itself form a distinct layer; planning should treat it as such. For essential services, "can this function for a week without international connectivity?" is a testable requirement, not a philosophical question.
Third: the dependency inventory should be taken before the outage takes it for you. Every organization I watched go through disruption discovered external dependencies it did not know it had. A state can make that discovery cheaply — through mapping exercises and drills — or expensively, live.
Fourth: communication about degradation is itself infrastructure. Uncertainty multiplies every other cost. People who know a disruption's scope and expected shape can adapt; people guessing cannot. Whatever else a government does, maintaining an honest, reachable channel about what is degraded and what still works reduces damage at almost no cost.
Fifth: the reliability penalty is national, and slow to repay. Individual firms can rebuild their own reputations; a country's connectivity reputation is a commons. Protecting it deserves the same seriousness as protecting the currency.
What practitioners can do meanwhile
For the people who simply have to keep working — the position I was in — the playbook that emerged for me was unglamorous: assume disruption, keep local copies of everything needed to work, maintain more than one channel to every important counterpart and agree fallbacks in advance, and tell clients about the risk before it happens rather than after. Pre-announced fragility reads as professionalism. Silent disappearance reads as failure.
That is survival, though, not policy. The deeper question this series has been circling is what resilience means for the people and states who are outside the frameworks, outside the sharing networks, outside the rooms. That synthesis is coming next.