What you need to know
Two provider names do not prove two survivable communications paths. Trace building entrances, conduits, central offices, power, customer equipment, upstream facilities, DNS, routing, support, and failover behavior before calling a design diverse.
Potentially affected
Internet, private WAN, SIP and voice services; carrier circuits; building entrances and risers; customer-premises equipment; power and cooling; provider facilities; routing and DNS; monitoring; contracts; failover; and outage communications.
DSE recommendation
Define the outage scenarios diversity must survive, obtain route and facility evidence, inspect local physical paths, separate equipment and power, test routing and applications, verify operational escalation, and review after carrier or site changes.
Source facts: resilient communications depend on multiple layers
CISA’s Ten Keys to Public Safety Network Resiliency discusses governance, risk, route and provider diversity, power, equipment, security, operations, and testing as contributors to resilient communications. The guidance shows that purchasing a second circuit does not by itself remove every common failure.
CISA’s Public Safety Communications Network Resiliency Self-Assessment Guidebook provides questions and assessment considerations across infrastructure, operations, maintenance, power, physical environment, cybersecurity, dependencies, and planning.
The publications are oriented toward public-safety communications. They provide useful questions but do not certify that a commercial service is diverse, require a provider to disclose protected route detail, or guarantee survival of a specific regional, facility, construction, cyber, utility, or supplier event.
DSE recommendation: define and test diversity by failure domain
Replace the statement we have two carriers with a set of explicit claims: which components are separate, which remain shared, what event each design should survive, and how the result was verified.
- Define required outcomes. Identify critical voice, internet, cloud, remote access, monitoring, security, transaction, and emergency workflows. Set tolerable interruption, minimum capacity, recovery time, degraded features, and scenarios such as a cut, entrance loss, equipment failure, utility outage, provider outage, routing event, or regional disruption.
- Trace the physical last mile. Document demarcations, entrance facilities, conduits, poles, risers, rooms, patch panels, splices, handholes, and known route crossings from each provider. Inspect what is visible and request route-diversity evidence or contractual representations at an appropriate sensitivity level.
- Identify shared provider dependencies. Ask about underlying carriers, central offices, points of presence, aggregation, upstream transit, peering, transport, management, maintenance, and regional facilities. Resold services with different invoices can share the same fiber or equipment.
- Separate local equipment and utilities. Review optical terminals, modems, routers, firewalls, switches, controllers, session border equipment, racks, cooling, electrical panels, UPS, generators, and management systems. A single firewall, room, transfer switch, or cable tray can defeat carrier diversity.
- Validate logical failover. Test addressing, routing, DNS, certificates, NAT, VPN, voice registration, cloud allowlists, inbound services, monitoring, security policy, rate limits, and application sessions. Confirm that the backup path has sufficient capacity and current configuration.
- Exercise operations. Conduct controlled failover and failback, observe detection and decision time, contact providers, open tickets, escalate, communicate with users, and operate priority workflows. Include an unavailable primary administrator and loss of ordinary collaboration tools.
- Maintain the claim. Review diversity after provider mergers, circuit changes, construction, building moves, contract renewals, equipment refresh, route repair, or monitoring changes. Track evidence date, provider caveats, shared risks, exceptions, and next test.
Include the management and control plane in the dependency map. Diverse data circuits can still rely on one cloud portal, authentication tenant, out-of-band provider, monitoring collector, configuration repository, or administrator path. Establish how operators will observe and change the network when the ordinary management service or identity provider is part of the outage.
Test failure direction as well as failover. A backup circuit can attract outbound traffic while inbound DNS, routing advertisements, firewall policy, voice numbers, or partner allowlists remain tied to the failed primary. Validate new and established sessions from both sides, then prove failback does not create route asymmetry, duplicate processing, or an extended maintenance window.
Factual boundary: CISA’s public-safety guidance offers assessment principles, not proof that a specific commercial circuit, carrier, cloud path, or customer design is diverse. Some route details may be unavailable or sensitive. Record uncertainty rather than converting an assumption into assurance.
Measure verified independent entrances, known shared facilities, single equipment and power points, failover success, usable backup capacity, detection time, escalation performance, and evidence age. A resilient design can still have residual shared risks; they should be visible and owned.
Official references
Review the official source
CISA: Ten Keys to Public Safety Network Resiliency · Verified August 17, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE