The 24/7 Market Never Sleeps, But Who’s Watching the Clocks?

The Hidden Risks of Continuous Trading for Financial Infrastructure

Financial markets have always had a rhythm. A defined open. A defined close. A quiet period in between where systems could breathe, engineers could patch, and clocks could be validated against the source of truth.

That rhythm is ending.

The London Stock Exchange Group has announced LSE 24, a new 24/5 trading venue purpose-built for digital, algorithmic, and agentic trading, operating overnight from 5:00 pm to 7:50 am London time, with client testing targeted for the end of 2026 and Exchange Traded Products launching in H1 2027. In the United States, Cboe already offers Global Trading Hours spanning nearly 24 hours a day, five days a week, giving traders across every time zone continuous access to US index options from Sunday evening through Friday afternoon. Nasdaq, NYSE Arca, and NSCC are moving in the same direction, with extended-hours and near-continuous clearing schedules rolling through 2026 and 2027.

Crypto and FX markets have operated on a 24/7/365 basis for years. What is new is that regulated equity, derivatives, and fixed income venues are following. The always-on market is no longer a future state. It is an infrastructure problem arriving now.

The scale of what flows through these systems makes the timing problem concrete. Trading does not distribute itself evenly across the day. It clusters heavily, around the open and close of each major exchange, as algorithms react simultaneously to the same signals, the same windows, the same triggers. At those peak moments across the NYSE, Nasdaq, LSE, Frankfurt, Hong Kong, and Tokyo, the density of order events within individual seconds is extraordinary. Timestamp resolution that is adequate during quiet mid-session hours is not adequate when millions of orders are competing for sequence within the same narrow window. That is not a theoretical edge case. It is what happens every trading day, and in a 24/7 environment, with exchanges opening and closing occurring continuously across time zones, those peak moments never fully stop.

Continuous trading is not merely an operational extension. It is a fundamental change to the risk profile of the timing infrastructure that underpins every trade, every timestamp, and every regulatory report.

For executive leaders, this is not a question to delegate entirely to the engineering floor and revisit at the next quarterly review. The risks that emerge from continuous market operations, security, and compliance are board-level concerns. And they all trace back to the same foundation: time.

Three Questions Every Executive Should Be Asking Their Infrastructure Team Right Now

Before examining the specific risks, it is worth being clear about the strategic prompt this moment creates. The shift to near-continuous trading hours is happening on timelines measured in months. The infrastructure decisions required to support it safely take longer than that. Which means the time to open this conversation internally is now, not when the first extended-hours session goes live.

If you are a CTO, CISO, Chief Compliance Officer, or board member with oversight of trading infrastructure, these are the questions that deserve an honest answer from your technical and risk teams today:

  • As our trading windows expand toward continuous 24/7 operation, what is our plan for maintaining timing accuracy and clock synchronisation when there is no overnight maintenance window to fall back on?

  • If our primary GPS or GNSS timing source were jammed or spoofed during an active overnight session, when no engineer is scheduled to be watching, how quickly would we detect it, and what would the impact be on our timestamp record and regulatory reporting?

  • Can we demonstrate, right now, that our timestamps are continuously UTC-traceable and auditable across the full trading session, including the overnight and low-liquidity hours that regulators are increasingly scrutinising?

If the answers are uncertain or if those conversations have not happened yet, the following section explains why they need to.

The Three Timing Risks of a Market That Never Closes

The shift to continuous trading does not create entirely new categories of risk. It removes the mechanisms that have historically kept existing risks manageable. Here are the three that matter most to timing infrastructure and to the institutions that depend on it.

Risk 1: The Vanishing Maintenance Window

Ask any head of trading infrastructure what the overnight halt is actually for, and the answer is consistent: it is when you fix things. Clock synchronisation checks. System resets. NTP validation against UTC reference sources. Firmware updates. Configuration changes. The brief, structured silence between market close and market open has been, for decades, the safety valve that keeps distributed financial systems honest.

Under LSE 24's proposed schedule, that window shrinks to just over four hours. For firms trading across both the UK and US extended sessions simultaneously, it disappears entirely. There is no quiet period. There is no scheduled silence.

The operational consequence is direct: timing infrastructure that previously tolerated periodic drift, corrected each morning at open, must now maintain continuous accuracy without interruption. Clock drift that was absorbed by a daily reset becomes clock drift that compounds across a session that never ends. Systems built to be recalibrated must now be self-sustaining. That is a fundamentally different engineering requirement from the one most institutions are currently meeting.

The question for leadership is not whether your engineers understand this. They almost certainly do. The question is whether the investment and architecture decisions required to address it have been made, or whether those decisions are still waiting for the business case to become urgent enough.

Risk 2: Cybersecurity and the Always-Open Attack Surface

The most widely used source of precise time in financial infrastructure is GPS, or more broadly, GNSS. GPS signals are extraordinarily precise, freely available, and deeply embedded in the timing architecture of virtually every major financial institution. They are also surprisingly straightforward to disrupt. Jamming and spoofing are both documented, operational threats that have moved well beyond the theoretical. The US Department of Homeland Security has published detailed guidance specifically warning critical infrastructure operators, including financial institutions, against dependence on a single GNSS timing source. The UK government committed 155 million pounds in November 2025 to national timing resilience, explicitly to ensure that financial trading platforms, telecoms networks, and other critical services are not dependent on a single satellite signal for time.

In a market environment with overnight maintenance windows, a spoofing or jamming event that occurred at 2:00 am might be caught before markets opened. In a continuous trading environment, that same event occurs during an active session, with no scheduled checkpoint at which it would be detected before it affects the timestamp record of live trades.

For CISOs and risk officers, the implication is clear: in a 24/7 operation, the attack surface for timing infrastructure is permanently open. A successful GPS spoofing event during an active session is not an overnight inconvenience. It is a live incident with immediate consequences for trade sequencing, audit trail integrity, and the regulatory reports generated in the affected window.

Timing infrastructure is not just an IT utility. In a continuous market, it is a cybersecurity perimeter.

Risk 3: Transaction Integrity and Continuous Compliance

Every financial transaction carries a timestamp. That timestamp determines trade sequence, best-execution analysis, audit trail integrity, and regulatory reporting. Under MiFID II, timestamps for high-frequency and algorithmic trading must be accurate to within 100 microseconds of UTC. Modern time synchronisation systems provide resolution down to one nanosecond for automated trading activity purposes, as reflected in the FIX Performance Session Layer standard and the FIX Time Precision Technical Addendum.

These requirements do not pause for overnight sessions. They apply across every second of every trading window, including the low-liquidity hours that extended trading venues are adding to the calendar.

In thin overnight markets, timestamp precision matters more, not less. When volumes are lower and individual trades carry greater price impact, the ability to establish the precise sequence of orders, which arrived first, which was reactive, which was anticipatory, becomes more consequential for best-execution obligations and market surveillance alike. A timestamp that drifts by even a few microseconds relative to UTC in an overnight session does not create a minor compliance footnote. It creates an ordering ambiguity that may not surface until a regulatory inquiry or post-incident forensic review months later.

DORA, the EU Digital Operational Resilience Act, now in force, adds a further dimension. It requires financial entities to demonstrate ICT resilience continuously and treats third-party concentration risk as a compliance concern in its own right. A timing architecture dependent on a single GPS receiver, a single NTP server, or a single hardware vendor's product roadmap is not just a technical vulnerability. Under DORA, it is a reportable exposure.

The question for compliance officers is whether your current timestamp record and your ability to demonstrate its integrity to regulators hold up across the full trading session, including the hours that were previously quiet and are now active.

What Preparedness Actually Looks Like

The answer to these risks is not simply to buy more hardware or add a backup GPS receiver. It is to approach timing as infrastructure, with the same strategic rigour applied to business continuity, third-party risk, and operational resilience that is now applied to every other critical dependency.

For executive leaders, preparedness in this context means being able to answer yes to three things:

  • Your timing infrastructure maintains continuous UTC-traceable accuracy across the full trading window, not checked at open and assumed to hold, but monitored and evidenced in real time, including overnight.

  • Your architecture is resilient against single-source failure. If your primary GPS signal is disrupted during an active session, alternative timing sources, terrestrial feeds, engineered fibre-based timing, and GNSS-resilient solutions maintain accuracy without human intervention and without a gap in the timestamp record.

  • Your timing solution is software-defined and vendor-agnostic. Dependence on a single hardware vendor's supply chain or product roadmap is itself a concentration risk under DORA and a practical vulnerability in a continuous operating environment. A software layer that sits above the hardware and works consistently whether the underlying infrastructure runs on any major timing hardware provider, removes that dependency.

The institutions moving toward 24/7 operation with timing infrastructure built for this reality are not just managing risk more effectively. They are building a capability that supports faster, more accurate trading performance, stronger regulatory audit trails, and the kind of operational resilience that regulators in the UK, EU, and US are increasingly treating as a baseline expectation rather than a differentiator.

The ones that are not are carrying a risk that grows with every hour added to the trading day.

The Conversation to Have Now

The shift to 24/5 and eventually 24/7 trading is not approaching from a distance. LSE 24 targets client testing by the end of 2026. Cboe Global Trading Hours are live today. Nasdaq's extended sessions and NSCC's continuous clearing ambitions are on timelines measured in months.

For CTOs, CISOs, Chief Compliance Officers, and board members, the question is not whether your institution will need to operate in a continuous market environment. It is whether the timing infrastructure underneath your trading, reporting, and surveillance systems is ready for one and whether you have asked the right people the right questions before the first overnight session goes live.

Most current timing architectures were built for a world with a daily close. That world is being retired. The institutions that treat this as a modernisation moment and invest accordingly in resilient, auditable, continuously accurate timing infrastructure will be the ones that enter the continuous trading era without the hidden exposures that a market that never sleeps will eventually find.

It is not enough to be synchronised. In a continuous market, you must be able to prove it at any hour, for any session, under any conditions.

Hoptroff delivers UTC-traceable, resilient, software-defined precision timing for financial services infrastructure, continuously accurate, vendor agnostic, and auditable across every hour of every session. Time as a Service. Time you can trust, prove, and operate on.

Review your 24-hour timing resilience with Hoptroff

Next
Next

Relative Time vs. UTC: Why Both Matter