Rethinking resilient timing in a GNSS-disrupted world
Published
12 Aug 2026
Author
Roel de Vries, Business Development Manager for AtomiChron®
A recent outage affecting Australia's largest telecommunications network highlighted how dependent modern infrastructure has become on precise timing, disrupting communications, payment systems and access to emergency services for many users. It served as a reminder that timing is often an unseen dependency and that resilience matters just as much as accuracy.
Telecom networks, finance systems, power grids and industrial control environments all need precise timing to function correctly. For many years, GNSS has provided that timing with impressive accuracy and global reach. The issue is that the same dependency is now becoming a resilience concern.
It is no longer enough to ask whether a timing source is accurate under normal conditions. The better question is what happens when GNSS is jammed locally, spoofed, disrupted or simply no longer trusted. That is the challenge many end users are now raising. They are not only looking for improved GNSS timing. They are asking for a separate timing source. This shift in thinking is driving innovation in resilient timing services, including solutions such as Fugro's AtomiChron®, which combines trusted time transfer methods with GNSS authentication capabilities.
Accuracy is only part of the problem
In timing, accuracy often gets most of the attention, but it is only one part of the resilience discussion. A timing source can be highly accurate and still leave an organisation exposed if it relies on the same systems and shares the same weaknesses as the service it is meant to back up.
For telecom networks and other critical infrastructure, timing accuracy often needs to be measured in nanoseconds. In many cases, the benchmark is an error of less than 100 nanoseconds against a trusted reference clock. Achieving that level of performance is significant because it covers the requirements of many practical timing applications, not just the most demanding ones.
But performance on paper is not enough. Timing also needs to be traceable to Coordinated Universal Time (UTC), resistant to interference, difficult to spoof and deployable at scale. Those requirements change the nature of the problem. We are no longer talking about a laboratory comparison between clocks. We are talking about a practical service that can be used across real networks and operating environments.
The limits of simply improving GNSS
There has been valuable progress in making GNSS more robust. Navigation message authentication, for example, can help users verify that the navigation data they receive is authentic. That is useful, but it does not remove all GNSS-related risk. Jamming remains an obvious problem, and spoofing can still be a concern depending on the wider system design.
Services such as AtomiChron® navigation message authentication (NMA) are designed to address this challenge by enabling users to authenticate GNSS navigation messages, increasing confidence that received signals originate from legitimate satellite sources. However, authentication alone does not eliminate the need for a resilient alternative timing path.
A geostationary satellite-based timing architecture provides an alternative timing path that does not rely on local GNSS reception
This is why many organisations are now asking a different question. Instead of asking how GNSS can be made better, they are asking what sits beside it. In other words, if GNSS is degraded or unavailable in a local area, what independent timing source can the system fall back on?
That distinction matters. GNSS resilience should not become a box-ticking exercise where one improvement is treated as a complete answer. If the risk is dependency on one source, then the solution has to include diversity.
Independence needs careful wording
One lesson from working in this area is that claims of independence should be made carefully. Many alternative timing services still rely on the internet to some extent. While they may continue operating during a GNSS disruption, their resilience depends on whether the wider communications infrastructure remains unaffected. As a result, it can be difficult to describe any timing service as completely independent in every scenario.
That is why "locally GNSS-independent" can be a more accurate and useful way to describe what many users actually need. In many real-world situations, the concern is local jamming or interference within a specific area. A timing source that does not rely on local GNSS reception can provide resilience against that threat, even if parts of the wider infrastructure still have dependencies that need to be understood.
This may sound like a subtle distinction, but it is an important one. Effective resilience starts with understanding the nature of the disruption you are trying to protect against. If that assumption is wrong, the backup strategy may not perform as expected.
Learning from established methods of delivering independent time
One proven way to deliver a resilient timing source is through satellite time transfer. Two-way satellite time and frequency transfer has existed for many years and is well proven. National metrology institutes use it to compare clocks and time scales, which tells us something important about its credibility. The limitation is not whether it works. The limitation is scalability.
Traditional two-way methods can be expensive and require a relatively large physical footprint. That makes sense for national laboratories and specialist facilities, but it is less attractive for broad deployment across telecom, finance or industrial networks.
The industry needs a middle ground. It needs the reliability and traceability associated with high-precision time transfer, but in a form that is practical to deploy at scale. That means equipment that is easier to install, easier to manage and more accessible to a wider range of users.
This principle underpins Fugro's AtomiChron standalone time service (STS), which combines proven satellite time-transfer techniques with a scalable delivery model for critical infrastructure operators seeking a locally GNSS-independent source of time. Rather than replacing GNSS, STS is designed to complement it, providing an alternative timing source when local GNSS signals are unavailable, disrupted or no longer trusted.
Why geostationary satellites offer a useful path
One way AtomiChron® STS can distribute this resilient timing service at scale is through geostationary satellites. The logic is straightforward. Geostationary satellite infrastructure is already used to distribute data across large regions, including correction data for GNSS services. If that same infrastructure can be used to distribute time without relying on local GNSS reception, it creates a separate path for resilient timing.
Geostationary satellite infrastructure can support timing distribution across large geographic regions using existing communications networks
This is also where the trade-offs become important. Geostationary satellites provide broad coverage and can support a scalable one-way broadcast model. They are not, however, visible everywhere. Coverage at the north and south poles is an obvious limitation because the satellites sit above the equator. For most industrial and telecom applications, that may be acceptable, but it still needs to be recognised.
The aim is not to find a perfect source of time. There is no such thing. The aim is to build timing architectures with enough diversity that one disruption does not become a system-wide failure.
Timing performance of Fugro’s AtomiChron® during controlled jamming tests demonstrates the importance of resilience alongside accuracy
A more realistic approach to timing resilience
The future of resilient timing will not be defined by a single technology replacing GNSS. GNSS will remain essential because it is accurate, available and deeply embedded in critical infrastructure. The question is how we reduce the risk of relying on it too heavily.
That means being more precise in how we assess timing risk. Organisations need to understand which risks they are trying to address, from jamming and spoofing through to loss of traceability, local disruption and wider infrastructure failures. What level of accuracy is actually required? Does the backup source share the same vulnerabilities as the primary source? Can it be deployed at the scale the industry needs?
These are the questions that matter. The future of resilient timing will depend on the choices organisations make today about diversity, traceability and risk. The most effective timing strategies are built on a clear understanding of dependencies, realistic assumptions about failure scenarios, and the ability to maintain confidence in time when the primary source is no longer available. As timing becomes increasingly critical across telecoms, power networks, finance and other sectors, those considerations will become just as important as accuracy itself.
Expertise
Fugro AtomiChron®
This innovative technology eliminates time drift caused by clocks counting time at slightly different rates and gives users access to extreme frequency stability as well as extreme accurate time references, with levels that surpass high-calibre industrial standard caesium clocks and approaching hydrogen maser performance.