Why Financial Institutions Need a Terrestrial Time Source

(And Why Most Don't Have One Yet)

For decades, the gold standard for financial timing infrastructure has been GNSS: GPS and its counterparts GLONASS, Galileo, and BeiDou. A rooftop antenna, a receiver, and a signal from space. It is accurate, it is free to receive, and it works anywhere with a view of the sky. For a long time, that was enough.

It is not enough anymore. The threat environment has changed, the regulatory landscape has changed, and the question sophisticated financial institutions are now asking is not whether they need a time source that does not depend on satellites. It is why they do not have one already.

Here is the problem in its simplest form. If every clock in a timing architecture pulls its signal from the same kind of source, satellites, then an attack sophisticated enough to fool one of them can fool all of them at the same time. Three clocks all showing the same wrong time will outvote the one that is right, unless there is a source built on genuinely different infrastructure to break the tie. A terrestrial time connection, a feed pulled from the ground rather than the sky, is that independent source. Because it does not depend on satellites, it cannot be taken down by the same jamming or spoofing attack that compromises GNSS.

That is not a hypothetical. It is precisely the scenario that GPS jamming and spoofing are already designed to create, and for banks and financial institutions operating at the level of complexity and risk that modern markets demand, the case for having an independent, ground-based time source has moved from theoretical to urgent.

Where Time Has Always Come From, and Why That Is Now a Problem

Time synchronisation has a longer history than most people realise, and terrestrial distribution was actually the original method. Before satellites, time was distributed by cable from national laboratories, then by radio signals, and only from the 1980s onward by GPS and its equivalents. Satellite constellations became the global standard for precise time distribution, and for good reason: they are accurate, free to receive, and available anywhere with a view of the sky.

The problem is that what was once an engineering triumph has become a security vulnerability. Satellite signals travel roughly twelve thousand miles to reach a rooftop antenna. By the time they arrive, they are extraordinarily weak, which makes them easy to block and, more dangerously, easy to imitate.

Jamming, using radio frequency interference to block a GPS signal, can be carried out with equipment as small as a wristwatch, enough to disrupt timing across a small airport. A larger device, roughly the size of a truck, can affect a major data centre or a large airport. Spoofing goes further: rather than blocking the signal, it transmits a false one, causing receivers to lock onto the incorrect time. The distinction matters. A jammed system knows it has lost its time source. A spoofed system believes it still has one; it is confidently, precisely wrong.

This is already routine, not hypothetical. GNSS interference monitoring in the City of London recorded regular jamming events as early as 2013, and Russian jamming operations based in Eastern Europe have been tracked reaching as far as the English Channel, with high-orbit spoofing satellites identified in recent years extending that threat further still. IATA's 2024 Safety Report found that GNSS interference incidents, including jamming and spoofing, rose 175% year on year, with GPS spoofing incidents specifically up 500%. In March 2025, the heads of the ITU, ICAO, and IMO issued a joint statement expressing grave concern about the increasing scale of harmful GNSS interference and its impact on time synchronisation for critical infrastructure. Financial institutions sit squarely within that category.

There is also a sovereignty dimension worth naming plainly. GPS, GLONASS, Galileo, and BeiDou are each controlled by a different government. Depending exclusively on any one of them means a bank's critical infrastructure carries a dependency on signal infrastructure it does not own, does not control, and cannot verify independently, a dependency that becomes more exposed exactly when geopolitical tension is highest. A terrestrial connection to a national measurement institute does not remove geopolitics from the equation, but it puts the dependency on infrastructure the institution can inspect, contract for, and hold accountable directly.

What Happens to a Bank When Its Time Is Wrong

Modern banking systems, trading, and payment infrastructure alike use time for authentication as well as sequencing. When a system's local clock drifts too far from the server it is trying to reach, authentication fails, logins are denied, and the system locks itself out of the very infrastructure it needs to function. An attacker who can manipulate a bank's time signals does not need to breach a firewall or crack encryption. They can simply cause the bank's own systems to deny them access.

The attack does not need to be dramatic to be effective. A mild time shift creates subtle vulnerabilities: encryption systems that rely on timing for key rotation become predictable, timestamp-based security certificates can be manipulated, and audit trails that depend on accurate sequencing become untrustworthy. A more aggressive attack can crash systems outright by setting clocks far enough from reality that operating systems refuse to function; a version of this is easy to demonstrate by setting a computer's own internal clock back to 1970 and watching it stop working.

The financial cost of cyber attacks on banking infrastructure is already significant and well documented. The IMF's Global Financial Stability Report found that financial firms lost more than 12 billion dollars to over 20,000 cyberattacks over the past two decades, with the size of the largest loss events more than quadrupling since 2017. IBM's 2026 Cost of a Data Breach Report puts the average cost of a single breach in financial services at 6.29 million dollars, the second highest of any industry it tracks. Those figures reflect attacks that were detected and disclosed. The cost of an undetected, multi-day timing attack on a major institution's infrastructure would be a different order of magnitude. NIST Technical Note 2189 addresses the timing dependencies of financial infrastructure directly and notes that timing failures can have direct and serious economic consequences.

The Disaster Recovery Blind Spot

Most large financial institutions have disaster recovery systems: secondary trading platforms, backup payment systems, and failover infrastructure built to come online if primary systems are taken down by a breach or an operational incident. These are serious investments, built to serious engineering standards.

But there is a question worth asking about those backup systems: do they depend on the same time source as the primary systems?

In most cases, the answer is yes. The primary GPS antenna feeds the primary trading systems; the disaster recovery systems, sitting in a secondary data centre, receive time from the same satellite constellation, sometimes from the same physical infrastructure. Security breaches rarely use a single attack vector, and GPS jamming is one of the easier tools available to an attacker running a multi-pronged attack. If it is used to bring down the primary systems, the backup systems come online, depending on the exact source that just failed.

A terrestrial time source changes that equation. Because it draws its signal from independent infrastructure (a physical connection to a national measurement institute rather than a satellite constellation), it cannot be taken down by the same event that compromises GNSS. A genuine disaster recovery plan needs a time source that is actually independent of whatever caused the primary failure, and right now, a terrestrial connection is the one source that reliably qualifies.

The Regulatory Direction of Travel

Governments and regulators have been watching this threat environment develop, and they have been responding. In the United States, Executive Order 13905 explicitly states that critical infrastructure operators may not rely solely on GNSS for their time. Signed in February 2020, it covers financial systems as squarely as it covers transportation, energy, and communications infrastructure.

In the UK and EU, ISO 27001 and ISO 27002 apply the same principle to any organisation classified as critical infrastructure: a category that includes banks, payment systems, exchanges, and financial market infrastructure, alongside transportation, hospitals, police, and emergency services. The requirement is not merely to have a backup time source in principle. It is to have a genuinely diverse backup, one that is independent of the primary source in its underlying infrastructure, not just its physical location.

In November 2025, the UK government committed £155 million to national PNT resilience, including £71 million specifically for a national eLoran network and 68 million pounds for the National Physical Laboratory's National Timing Centre. The explicit purpose is to ensure that critical UK infrastructure, including financial trading platforms, is not dependent on a single satellite-based source for time.

DORA, the EU's Digital Operational Resilience Act, in force since January 2025, adds a further dimension. It requires financial entities to demonstrate ICT resilience continuously and treats third-party concentration risk as a compliance obligation. A timing architecture that depends entirely on satellite infrastructure controlled by foreign states is exactly the kind of concentration risk DORA was designed to address.

Why Terrestrial Time Is Better, Not Just Safer

It's worth being clear that a terrestrial time source is not just a defensive addition. In several respects, it is a better source of time than satellite-derived signals for the purposes financial institutions actually care about.

In the United States, the legal requirement for FINRA OATS and CAT reporting is that clocks be synchronised to NIST. GPS is currently considered equivalent to NIST for most regulatory purposes, but GPS is not the same as a direct connection to NIST, and GPS itself is vulnerable.

GPS signals carry a UTC offset derived from NIST atomic clocks, and that offset is usually accurate, but not always. The January 2016 GPS UTC-offset anomaly caused fifteen of the thirty operational GPS satellites to broadcast incorrect timing data for a window of nearly fourteen hours, and NIST found that most of the roughly eighty GPS clocks it monitored were affected to some degree. The NIST clocks in Colorado experienced a power outage last year that affected their availability for roughly a day. The Circular T publication from the BIPM, which tracks the accuracy of every clock in the international UTC consortium, regularly shows individual GPS-based clock readings ranging from 30 nanoseconds to 10 milliseconds off from calculated UTC.

A direct terrestrial connection to NPL in London, to NIST in Gaithersburg or Boulder, or to RISE in Sweden is not subject to those satellite-layer errors. It draws time directly from the atomic clocks that define the standard, over physical infrastructure that has been independently certified. Connections to national measurement institutes require formal permits from government departments, including, in the US, the Department of Transportation and the Department of Defense. That permitting requirement is not bureaucracy for its own sake. It is the reason those connections carry genuine authority as time sources and cannot simply be replicated by pointing an antenna at the sky.

Hoptroff holds a patent in long-distance terrestrial time transfer using PTP [confirm exact patent status/number with Richard before publication] and has existing installations connected directly to NPL in London, NIST in both Gaithersburg and Boulder, and RISE in Sweden. These are operational connections, diversified across national measurement institutes in three countries, which means the terrestrial layer Hoptroff provides is itself diverse against a wide range of failure scenarios, not only against satellite disruption.

Framed simply: the more genuinely independent time sources an organisation has, the more confidently it can tell which one to trust. If three satellite-based sources are compromised and all say it's 1970, while a fourth source, one running on completely different, ground-based infrastructure, says it's 2026, the system has an actual, automated basis for knowing which signal is right. That's the core logic behind adding a terrestrial connection to an existing GNSS setup. In conversations with banks that already run a multi-source GNSS feed, this fourth, independent source often gets shorthanded to “the fourth clock.” But the underlying principle is simply independent verification, and it applies just as much to an institution adding its first non-satellite source as to one adding a fourth.

Five Reasons Financial Institutions Are Adding a Terrestrial Time Source

Based on the conversations happening with sophisticated financial institutions right now, five drivers are consistently emerging:

1. Protection from jamming and spoofing.

A terrestrial source can't be jammed or spoofed by the same attack vectors that target satellite signals. When every GNSS source in a timing architecture is compromised at once, an independent terrestrial connection is the one still telling the truth, and that's the basis for an automated decision about which signal to trust, rather than a system quietly operating on incorrect time without knowing it.

2. Regulatory compliance across the US, UK, and EU.

Executive Order 13905 in the United States, ISO 27001 and 27002 across the UK and Europe, DORA for EU financial entities, and the Bank of England's critical third-party resilience regime all point in the same direction: GNSS-only timing is no longer sufficient for critical infrastructure. For many institutions, a terrestrial source is becoming a compliance requirement, not just a prudent addition.

Regulators like DHS have also published best practices for resilient PNT to support critical infrastructure security.

3. Accuracy at the source, not at the satellite.

FINRA and CAT requirements specify synchronisation to NIST atomic time. A direct terrestrial link to NIST is the only way to meet that requirement without relying on GPS as an intermediary, and when that intermediary is wrong, as it demonstrably has been, a direct NIST connection is the only source of ground truth.

4. True disaster recovery independence.

Backup systems that depend on the same satellite constellation as primary systems aren't independently resilient. A terrestrial source gives disaster recovery infrastructure genuine independence, so the systems meant to come online when primary systems fail aren't themselves dependent on the compromised source that caused the failure.

5. The market is already moving this way.

The whole industry has watched Executive Order 13905 and the practical consequences of GPS jamming play out. Institutions investing in terrestrial timing now aren't ahead of the curve in an experimental sense. They're adopting an architecture that regulators, governments, and the most sophisticated market participants have already concluded is necessary. Being late to that architecture is an increasingly difficult position to defend to a board, a regulator, or a counterparty.

A Terrestrial Time Source Is Not an Upgrade. It Is a Foundation.

Financial institutions that built their timing infrastructure on satellite sources alone did so sensibly, based on the threat environment and regulatory expectations that existed when those decisions were made. The world has changed. The threat is more sophisticated, more active, and more geographically proximate than it was five years ago. The regulatory response is now codified in law across the major financial jurisdictions. And the technical capability to deliver a high-quality terrestrial time source, connected directly to national measurement institutes and distributed over existing network infrastructure, is available now in a way it simply wasn't a decade ago.

Adding a terrestrial time source to an existing timing architecture isn't a wholesale infrastructure replacement. It's the addition of a genuinely independent source that changes the resilience profile of everything built on top of it: the source that keeps telling the truth when everything else has been told to lie, and the foundation that disaster recovery, regulatory compliance, and operational continuity all depend on in a threat environment where sophisticated actors are already using timing attacks as a vector.

The question isn't whether a terrestrial time source is worth considering. It's how long it makes sense to wait before the decision gets made for you.

Hoptroff provides terrestrial timing services directly connected to NPL in London, NIST in the United States, and RISE in Sweden, distributed over existing network infrastructure without wholesale hardware replacement. Time as a Service. Time you can trust, prove, and operate on.

Talk to Hoptroff about adding a terrestrial time source to your infrastructure

Next
Next

Why Exchanges Can't Treat Time as an Afterthought