As compared to the effort required to cut an aerial or underground singlemode cable and fusion splice in place a passive prism split tap (basically the same thing as inserting a split in a GPON FTTH network). A practiced outside plant fiber crew of 2 persons and a bucket truck could do this with less than 5 minutes of downtime on a router-to-router optical interface, short enough time to clear any NMS alerts and prevent a repair team truck roll. Assuming we're talking about only two strands.
Either way actual security is accomplished through standard based crypto, not obfuscation or preventing people from messing with the layer-1.