On 15 September 2026, the London Internet Exchange announced that its secondary peering fabric, LON2, had passed 1Tbps of traffic. On its own that is a capacity milestone of the kind internet exchanges report every few years. What makes it worth the attention of anyone responsible for a UK organisation’s connectivity is not the number but the reason behind it: LON2 is the fabric members buy specifically to remove a single point of failure, and more than 300 of LINX’s 900+ members are now on it. The traffic is growing because the demand for a second path is growing.
LINX is not a household name outside the networking industry, but it sits underneath a very large share of what British businesses experience as “the internet working”. It is the point where hundreds of networks — ISPs, content providers, cloud platforms, hosting companies, CDNs — exchange traffic directly with one another rather than paying a transit provider to carry it. The primary fabric, LON1, interconnects 16 London data centre sites and already peaks close to 9.8Tbps. LON2 interconnects 17 sites and is built on a deliberately different architecture, so that a fault, a software bug or a maintenance error affecting one fabric does not take out the other. For a long time LON2 was the option that careful networks bought. The 1Tbps figure is the point at which “careful” became mainstream.
The commercial signal underneath is just as telling. Through its Metro Resilience initiative, LINX has been offering members a 60% discount on LON2 port and peering fees, bringing the price of a second fabric connection into line with LON1 pricing. In July 2026 alone that discount was worth £41,000 to members as resilience orders rose. An exchange does not give away that much margin to shift a product nobody wants; it does it to remove the last commercial objection to a decision it believes members need to make anyway. And LINX chief executive Jennifer Holmes has been explicit about why now, linking the resilience push directly to the incoming UK Cyber Security and Resilience Bill and the stricter security and continuity requirements it will place on organisations’ critical digital infrastructure.
What LINX actually announced
The announcement has three components, and they are easier to read as one decision than as three items of news. First, the traffic milestone: LON2 has crossed 1Tbps. Second, the platform: LON2 has just completed its first full technology refresh since 2018, moving to Nokia IXR hardware running SR–Linux across all 17 of its sites, which makes the fabric fully 400GE–capable and gives it headroom for the traffic growth LINX expects. Third, the commercial programme: Metro Resilience, the 60% discount that prices a LON2 connection at LON1 levels, which in July 2026 alone returned £41,000 to members.
The architectural point deserves more attention than it usually gets. LON2 is built on a disaggregated design — the switching hardware and the network operating system are supplied and maintained separately rather than as one vertically integrated product. That is not a fashion statement. It means LON2 does not share a common failure mode with LON1: a software defect in one vendor’s operating system, a bad configuration push, a firmware regression rolled out during a maintenance window, cannot plausibly land on both fabrics at the same moment, because the two fabrics do not run the same code on the same boxes. That is what a genuinely independent second path looks like, and it is precisely the property that most organisations think they have bought and mostly have not.
Scale-wise, the two fabrics are not equals and are not meant to be. LON1, across 16 sites, carries the bulk of the volume and peaks near 9.8Tbps. LON2, across 17 sites, has just reached 1Tbps — roughly a tenth of the primary fabric’s peak. Read as a capacity ratio, that looks modest. Read as an adoption ratio, it is the more interesting figure: a third of LINX’s membership now pays to sit on a fabric they may never route production traffic across on an ordinary day. They are buying the day it is not ordinary.
The failure that takes a UK SME offline is rarely the one in the disaster recovery plan. It is almost never a data centre burning down. It is a single circuit into a single building, terminating on a single router, supplied by a single provider, that has been quietly load-bearing for years — and the backup that was bought to cover it turns out to share a duct, a street cabinet, a backhaul path or an upstream network with the primary. LINX has spent real money to remove that shared-fate problem at the exchange layer. Very few of the organisations downstream of it have done the equivalent inside their own estate. When the Cyber Security and Resilience Bill lands, “we have two lines” will not survive the first question about whether those two lines are genuinely independent.
How LON2 got from a hedge to a mainstream purchase
The 1Tbps milestone is the visible end of a long, unglamorous programme. The chronology below sets out the points that matter, using the granularity LINX itself has given — where the public record fixes a month, it is stated; where it fixes only a year, it is not dressed up as something more precise.
Where the single points of failure actually sit
An exchange can remove shared fate from the peering layer. It cannot remove it from your building. The chart below sets out where, in our experience of reviewing UK SME network estates, a single component still has the power to take the whole organisation offline. These figures are Cloudswitched’s own indicative assessment from network reviews rather than LINX data or published research — they are offered as a diagnostic ranking, not as a survey result.
The last bar is the one that undermines all the others. An organisation that cannot produce a current diagram of its own network cannot assert that its two circuits are independent, because nobody has checked. Diverse routing is a property you have to verify with the supplier at order time and re-verify after every change — it is not a property you get by buying from two logos. Carriers resell one another’s infrastructure constantly, and two contracts with two different names on them very often terminate in the same street cabinet.
This is the exact problem LINX has engineered out of its own estate, and it is worth being precise about how. LON2 is not simply a second set of switches. It is a second set of switches from a different hardware line, running a different network operating system, deployed across a different site footprint — 17 sites against LON1’s 16. The independence is designed at the level of the failure mode, not the asset register. The equivalent question for a UK business is not “do we have two connections?” but “what single event could plausibly affect both?” If you can name one, you have one connection with a spare cable.
A third of the membership, and what that ratio means
More than 300 of LINX’s 900+ members now use LON2. That is roughly a third of the membership paying for a second fabric, and it is the single most useful number in the announcement — more useful than the 1Tbps, because it measures decisions rather than bytes.
Bear in mind who these members are. LINX’s membership is not a cross-section of British business; it is networks. ISPs, hosting providers, cloud platforms, content delivery networks, universities, large enterprises with their own autonomous system numbers. These are organisations whose core competence is running networks, staffed by people who understand failure domains professionally. Two thirds of them are still on a single fabric.
That should recalibrate expectations downstream rather than provide reassurance. If a third of the specialists have taken the second path — at a 60% discount, with the case made repeatedly by their exchange — the proportion of ordinary UK SMEs with genuinely independent connectivity is going to be very substantially lower. Not because SMEs are careless, but because the question is harder to ask from outside the industry. An ISP knows what shared fate means at layer three. A forty-person architecture practice in Clerkenwell has a contract with a provider, a second contract with another provider, and a reasonable belief that this constitutes redundancy.
The other reading of the 33% is directional. The figure is rising, the discount exists specifically to raise it, and the platform has just been rebuilt to carry the traffic that rise will generate. LINX is not responding to demand that already exists at 1Tbps; it has built for the demand it expects when the regulatory position hardens. That is the part of the announcement UK organisations should take as a signal about their own planning horizon.
Where UK organisations are most exposed right now
The grid below is the assessment we would run against a UK SME estate in the light of this week’s announcement. The ratings reflect how commonly each weakness appears and how much damage it does when the failure arrives, not a formal risk score. They are a starting point for a conversation with whoever runs your network, not a substitute for looking at your own configuration.
The pattern across the four “high” items is worth naming, because they are the same failure repeated at different layers: an assumption of independence that nobody has verified. The circuits are assumed diverse. The failover is assumed to work. The edge device is assumed to be reliable enough. The estate is assumed to be understood. Every one of these is cheap to check and expensive to discover. LINX’s disaggregated LON2 design is, in essence, an institutional refusal to make any of those four assumptions.
The two “medium” items about manual intervention and out-of-band access are frequently the difference between a twenty-minute incident and a four-hour one. If the only route to reconfigure the network runs across the network that has just failed, and the person who knows how is not in the building, the technical recovery time is irrelevant — the organisational recovery time is what customers experience. This is the practical reason that resilience is an operational discipline rather than a hardware purchase.
What genuine network resilience costs a UK business
Below are indicative annual cost bands for building real path diversity into a UK SME estate. They cover connectivity, edge hardware and the design and testing work that makes the redundancy meaningful. Actual figures vary considerably with location — a building with only one physical entry point changes the arithmetic entirely — with existing contracts, and with how much of the estate has moved to cloud services.
| Organisation size | Typical resilient design | Indicative annual cost | What it buys you |
|---|---|---|---|
| Under 25 staff | Primary business fibre plus an independent secondary service on a separate network, with an edge device capable of automatic failover | £4,000 – £9,000 | The organisation stays working through a single circuit or single provider failure, without anyone having to intervene |
| 25 – 75 staff | The above plus verified diverse routing to the building, resilient edge hardware, and failover testing built into the support contract | £9,000 – £20,000 | Independence that has been checked with the supplier rather than assumed, and a failover path that is proven to work under real load |
| 75 – 150 staff | Dual diverse circuits, redundant edge devices, out-of-band management, SD–WAN policy routing across both paths, documented runbooks | £20,000 – £45,000 | Both paths carry live traffic, so failure is a capacity event rather than an outage, and the failure state is exercised continuously |
| 150 – 400 staff, multi–site | Per–site diverse connectivity, inter–site resilience, independent DNS and remote access paths, tested annually against a defined recovery objective | £45,000 – £110,000 | A continuity position that survives an auditor, an insurer or a customer’s supply–chain questionnaire, not just an internal assertion |
Set those numbers against the LINX comparison. LINX is prepared to hand back £41,000 in a single month to persuade members — organisations that already run networks for a living — to buy a second path. It has just rebuilt 17 sites onto new hardware to make sure that second path has somewhere to grow. The exchange’s own investment in removing shared fate dwarfs what any individual SME will spend, which is the point: a large part of your resilience is being bought for you, upstream, by organisations you will never deal with. The bit nobody can buy on your behalf is the last mile into your building and the equipment it terminates on.
Two postures, and the gap between them
Reactive posture
What most UK SMEs have today
- Two connectivity contracts with two provider names, with physical diversity assumed rather than confirmed in writing
- Failover configured once at install and never exercised with users on the system
- A single firewall or router through which every service passes, with no standby unit and no spare on the shelf
- No current network diagram, so nobody can state which services depend on which circuit
- Recovery depends on a named individual being reachable and able to log in from somewhere
- Cloud, VoIP and remote access treated as separate concerns from connectivity, despite all depending on the same link
- Continuity evidence assembled reactively when a customer or insurer asks for it
Proactive posture
Where Cloudswitched takes you
- Diverse paths confirmed with the supplier at order time and re–verified after every change, with the evidence retained
- Both paths carrying live traffic under policy routing, so the failure state is exercised continuously rather than theoretically
- Resilient edge hardware with automatic failover and a documented replacement path
- A maintained diagram and inventory that maps every business service to the circuits and devices it actually depends on
- Out–of–band management so the network can be reached when the primary link is down
- Connectivity, cloud and voice designed as one dependency chain against a defined recovery time objective
- Continuity documentation kept current, so a Cyber Security and Resilience Bill question is answered from a file rather than from memory
The distance between those two columns is not primarily a budget gap. Several items in the right-hand column cost nothing beyond attention: confirming diversity in writing, maintaining a diagram, scheduling a failover test. What separates the columns is whether anyone owns the question. In LINX’s case, someone plainly does — the disaggregated design, the site footprint, the refresh programme and the discount all point at the same accountable decision. In most SMEs, network resilience is nobody’s explicit responsibility until the morning it fails.
Before any spending decision, put three questions to your connectivity provider in writing and keep the answers. One: do our primary and secondary services follow physically diverse routes into the building, and can you confirm that in writing for these specific circuit references? Two: do both services depend on the same upstream network or the same backhaul, and if so at which point do they converge? Three: when did we last test failover with production traffic, and what was the measured interruption? If any answer is vague, you have found the gap without spending anything. If all three come back clean and documented, you are already ahead of most of the market — and ahead of two thirds of LINX’s own membership.
Why the Cyber Security and Resilience Bill is the real driver
Jennifer Holmes did not present the LON2 milestone as a traffic story. She linked it to the incoming UK Cyber Security and Resilience Bill, which will place stricter security and continuity requirements on organisations’ critical digital infrastructure. That framing explains the shape of everything else in the announcement: the discount that removes the cost objection, the refresh that provides the headroom, the emphasis on a design with no shared failure mode. LINX is positioning the membership ahead of a regulatory environment in which asserting resilience will not be sufficient.
For most UK SMEs, the Bill will not apply directly. That is the wrong reason to ignore it. Requirements of this kind propagate through commercial relationships long before they propagate through enforcement. The organisations that are in scope — operators of essential services, larger digital providers, the networks and platforms that sit above a great many SMEs — will need to demonstrate continuity across their own supply chains. The mechanism by which that reaches a forty-person business is a procurement questionnaire, a contract renewal, a framework onboarding pack or an insurer’s renewal form asking a question about network redundancy that expects a documented answer.
We have seen this pattern repeatedly with Cyber Essentials. A scheme that was voluntary for most organisations became effectively mandatory for anyone wanting public sector work or a seat in a regulated supply chain, and the organisations that treated it as a compliance exercise at the last minute paid more and got less than the ones that had already tidied up their estate. Network resilience is heading the same way, with one difference: certification schemes have a checklist, whereas path independence has to be true in physical infrastructure. You cannot answer a diversity question with a policy document.
The practical implication is a sequencing one. The work that makes a resilience claim defensible — confirming diverse routing with suppliers, mapping services to circuits, testing failover, documenting what happened — takes months of ordinary operational attention, not a procurement cycle. Organisations that start when the question arrives will be answering it honestly and badly. LINX has spent 2026 doing the equivalent work on its own estate specifically so that it is finished before it is asked for.
The story at a glance
| Item | Detail |
|---|---|
| Announcement | LINX’s secondary LON2 peering fabric has passed 1Tbps of traffic, announced 15 September 2026 |
| Who LINX is | The London Internet Exchange, where 900+ member networks exchange traffic directly rather than paying for transit |
| LON1 (primary fabric) | Interconnects 16 London data centre sites; peaks near 9.8Tbps |
| LON2 (resilience fabric) | Interconnects 17 London data centre sites; now past 1Tbps |
| Architecture | Disaggregated design with hardware and software separated, deliberately built to avoid single points of failure shared with LON1 |
| Technology refresh | First full refresh since 2018: Nokia IXR hardware running SR–Linux across all 17 sites |
| Capacity position | Fully 400GE–capable and scalable for future traffic demand |
| Adoption | More than 300 of 900+ members now use LON2 — roughly a third of the membership |
| Metro Resilience | 60% discount on LON2 port and peering fees, matching LON2 pricing to LON1 |
| Discount value | £41,000 returned to members in July 2026 alone as resilience orders rose |
| Stated driver | LINX CEO Jennifer Holmes linked the push to the incoming UK Cyber Security and Resilience Bill |
| What the Bill does | Places stricter security and continuity requirements on organisations’ critical digital infrastructure |
| Why it matters to SMEs | Resilience requirements reach smaller organisations through customers, insurers and supply–chain questionnaires well before direct regulation does |
| The core test | Not “do we have two connections?” but “what single event could plausibly affect both?” |
| Cheapest first step | Get written confirmation from your provider that primary and secondary circuits follow physically diverse routes, and test failover with production traffic |
This story sits alongside several we have covered recently, and read together they describe a single theme rather than separate incidents. Our note on VMO2’s cost cuts and the business continuity risk they create is the commercial mirror image of this one: LINX spending to add a second path while a major carrier trims the resources that keep the first one running. The record 974–CVE September Patch Tuesday showed why maintenance windows — the ones that take a fabric down — are now a permanent feature of operating any estate. The rapid exploitation of JFrog Artifactory and the BlueMoon exploit kit’s patch gap both illustrate how little time now separates a disclosed flaw from an incident that tests your continuity plan in earnest. And our piece on the end of security through obscurity makes the same underlying argument in a different domain: the assumptions that used to be load–bearing no longer are, and the ones you have never verified are the ones to check first.
Do you actually have two paths, or one path and a spare cable?
Cloudswitched designs and manages resilient business networks for UK organisations — verified diverse connectivity, Cisco Meraki cloud–managed edge hardware, SD–WAN policy routing across both paths, and failover that is tested rather than assumed. We start by establishing what your estate actually depends on, which is usually the part nobody has written down.
Talk to us about Cloud NetworkingFrequently asked questions
Build the second path before someone asks you to prove it exists
LINX has spent 2026 rebuilding 17 sites and discounting a fabric by 60% so its members are ready before the Cyber Security and Resilience Bill arrives. Cloudswitched does the equivalent work inside UK businesses — verified diverse connectivity, Cisco Meraki cloud–managed networking, tested failover and documentation that answers a continuity question from a file rather than from memory.
Talk to us about Cloud Networking


