ICDM Research Report 01

Running Blind: the timing risk nobody owns

Timing dependency, ownership and evidence across UK financial services and data centre infrastructure

7.1%

were very confident they could evidence their timing to a regulator

ICDM Research Report 01. Version 1.0, publication date to be confirmed.

Base 1,000 · Fielded July–August 2026 · United Kingdom

Contents

Executive summary

Two of the most timing-dependent sectors in the UK economy rely on vulnerable signals that most of the people who use them have never examined in detail from a risk perspective.

The precise time delivered by GNSS (including GPS) satellites underpins far more than navigation. It timestamps transactions, sequences records, synchronises networks and underwrites audit trails. It is infrastructure beneath infrastructure, and because it arrives free, continuously and invisibly, it is rarely treated as a dependency at all.

ICDM commissioned an independent survey of 1,000 UK respondents working in financial services and in data centre, colocation and cloud infrastructure, fielded in July and August 2026 through an independent research panel. All findings in this report come from that survey.

Each chip is ten respondents. 71 of 1,000 could. 929 could not.

7.1%

are very confident they could prove to a regulator or auditor that their timing held during a disruption

  • Awareness

    43.3%

    were only vaguely aware, or entirely unaware, that those signals can be deliberately jammed or spoofed

    Only 19.7% actively consider it

  • Testing

    42.9%

    have never tested how their systems behave under interference

    Only 8.2% test formally and regularly

The remaining findings set out what sits behind those numbers.

  • 34.9% rely critically or heavily on GNSS timing. 14.2% say core operations would fail without it.
  • 50.1% are not confident they would detect a jamming or spoofing event.
  • 46.1% could keep operating only a few hours after a timing failure, or could not say how long they could last at all.
  • And the risk has no settled home. 46.9% place it with IT. Only 19.9% place it with a risk professional. 16.1% cannot identify an owner at all.
  • Dependency

    34.9%

    rely critically or heavily

  • Detection

    50.1%

    not confident they would detect

  • Owner

    16.1%

    cannot identify an owner

In summary, there is a very high dependency on precision timing delivered from GNSS, a low awareness of its potential vulnerabilities, very little effective testing or evaluation, little confidence in the ability to detect a jamming or spoofing event, little evidence of timing assurance that would satisfy a regulator, and no consistent owner of the risk, many organisations regard it as an IT issue rather than a business risk.

The pattern is not that these organisations have weighed this risk and accepted it. It is that most have never paid it the detailed attention it deserves.

Methodology

Read the methodologySample, screening, weighting and the two combined-option limitations.

ICDM commissioned a survey of 1,000 UK respondents, fielded between July and August 2026 by an independent research panel provider with no commercial relationship to ICDM or to Direct Intelligence. All respondents were screened on four criteria before answering: role, sector, function and organisation size.

Sample composition

Sector: 68.1% financial services (banking, trading, markets, insurance); 31.9% data centres, colocation and cloud infrastructure.

Role: 57.1% manager; 23.8% head of or senior manager; 15.0% director or VP; 4.1% owner or C-suite.

Function: 22.8% general management or executive; 20.1% IT, technology or infrastructure; 19.2% resilience or business continuity; 18.1% operations or service delivery; 8.0% engineering or operations; 7.0% security; 4.8% risk, compliance or audit.

Organisation size: 65.1% employ 1,000 or more.

Demographics: 12.0% aged 18–29, 55.0% aged 30–45, 28.0% aged 46–61, 5.0% aged 62–80. 79.0% men, 21.0% women.

Respondents were selected at random from within the screening criteria. Data is reported unweighted: no post-fieldwork weighting or quota correction has been applied, and the distributions shown are the raw response distributions on a base of 1,000.

All questions were single-choice and all distributions are reported on the full base of 1,000. For a proportion near 50% the indicative margin is ±3.1 percentage points at 95% confidence. This is a non-probability online panel, so that figure should be read as indicative rather than as true sampling error.

On one question, covering how long an organisation could continue operating after a timing failure, one of the five answer options combined a substantive response with a non-response. That option cannot be decomposed, so the full distribution for that question is not reported. The three unambiguous options are reported, and the remaining respondents are reported as a single combined figure that states both possible states rather than attributing them to either. The limitation is set out in the text where the question appears.

The full response distribution for every question is reproduced in the appendix to this report.

Independence

The survey fieldwork was commissioned by ICDM and executed by an independent research panel provider rather than drawn from ICDM's own contacts. ICDM is the research arm of Direct Intelligence Ltd, which is named in the resources section of this report. Readers should weigh both facts.

Funding

This research was funded by Direct Intelligence Ltd, of which ICDM is the research arm. No other party funded or contributed to it. Direct Intelligence Ltd holds a commercial relationship with a global PNT test and measurement partner. That partner had no role in the study, no sight of the questions, the analysis or the findings before publication, and no right of review.

Respondents

Respondents are managers and senior managers rather than board members. That is by design. These are the people who operate the systems, who would see the symptoms first, and who are best placed to say whether a test has actually been run rather than whether one was intended. Where this report describes what organisations do, it reports what the people closest to the systems say happens. Full sample composition, including the age and gender distribution, is set out above so that the evidence can be judged on what it is rather than on how it is described.

The dependency nobody examines

Ask an organisation what it depends on and you will get a list: power, connectivity, cloud, payments, people. GNSS timing does not appear on that list, and yet 34.9% of respondents say their organisation relies on it critically or heavily. For 14.2%, core operations would fail without it outright.

That reliance is not the problem. The problem is what sits alongside it. 43.3% were only vaguely aware, or not aware at all, that GNSS signals can be deliberately jammed or spoofed. Only 19.7% said their organisation actively considers it.

Figure 1

Awareness against dependency

Q2Link to this figure

Base: 1,000 UK respondents

43.3%

were only vaguely aware, or entirely unaware, that GNSS signals can be deliberately jammed or spoofed

19.7%34.9%30.9%12.4%Don't know · 2.1%outside both nets
  • Very aware — we actively consider it
  • Fairly aware
  • Vaguely aware
  • Not aware at all
  • Don't know

This is an unusual shape for a risk. Most critical dependencies are understood as risks precisely because their failure modes are familiar: power cuts, outages, breaches. GNSS timing has no such folk memory. It has never visibly failed at scale in the UK, so it registers as a utility rather than an exposure. The dependency has outrun the awareness of its primary failure mode.

Interference is not hypothetical, and it is not rare. The aviation monitoring group OPSGROUP, whose 2024 GPS Spoofing WorkGroup drew more than 950 participants from across the aviation industry, found that spoofing rose from an average of around 300 affected flights a day in the first half of 2024 to approximately 1,500 a day by August, a five-fold increase in a matter of months. Over one month from mid-July to mid-August 2024, some 41,000 interference events were reported. What was once confined to conflict zones now appears in ordinary operating conditions across European airspace and shipping lanes.

Figure 2

The interference escalation

External sourceLink to this figure

~1,500

five-fold increase

Spoofed flights per day, August 2024

from ~300 (Spoofed flights per day, H1 2024)

~41,000 interference events reported, 15 july – 15 august 2024.

OPSGROUP, GPS Spoofing: Final Report of the GPS Spoofing WorkGroup, 6 September 2024

The economic exposure has been quantified. London Economics, in research for the UK Space Agency published in 2023, estimated the benefit of GNSS to the UK economy at £13.62 billion a year, the impact of a seven-day loss at £7.64 billion, and the impact of a loss lasting just 24 hours at £1.42 billion.

Figure 3

The economic frame

External sourceLink to this figure

£13.62bn

Annual benefit of GNSS to the UK economy

per year

£7.64bn

Estimated impact of a seven-day loss

single event, 7 days

£1.42bn

Estimated impact of a 24-hour loss

single event, 24 hours

London Economics for the UK Space Agency, The economic impact on the UK of a disruption to GNSS, 18 October 2023

A dependency worth £13.62 billion a year, with a single-day failure cost of £1.42 billion, is actively considered by fewer than one in five of the organisations that carry it.

Gary Daniel Doran, chair of the Institute of Critical Infrastructure Decision Making

This is not a risk that has been assessed and accepted.

Gary Daniel DoranChair, Institute of Critical Infrastructure Decision Making

A risk taken seriously, and left untested

29.9% say a 24-hour loss of accurate timing would be serious or catastrophic, with 8.2% choosing catastrophic outright.

A further 17.0% could not say what the impact would be at all. That figure deserves as much attention as the first. One in six people working in the UK's two most timing-dependent sectors cannot estimate what a day without accurate time would do to their organisation. Set against the £1.42 billion national figure for exactly that scenario, an unquantified dependency is not a small risk. It is an unmeasured one.

Now set both against the testing figures.

42.9% have never tested how their timing systems behave under interference. A further 18.1% say testing is planned but not done, which means 61.0% have no completed test behind them, with a further 9.2% unable to say. Only 8.2% test formally and regularly. In total, just 29.8% have carried out any form of test at all.

Figure 4

Testing: the ladder

Q5Link to this figure

Base: 1,000 UK respondents

29.8% any testing carried out61.0% no completed test8.2%21.6%18.1%42.9%Don't know · 9.2%outside both nets
  • Yes — formally and regularly
  • Yes — once or informally
  • No — but it is planned
  • No — never
  • Don't know

This is not a case of risk being weighed and accepted. Accepted risk looks different. It has a rationale, a compensating control and a review date. This looks like a risk recognised in the abstract and never converted into an action.

How long could they last?

Respondents were also asked how long their organisation could continue operating normally if GNSS timing became unavailable or unreliable.

10.2% said indefinitely, because they hold a time source independent of GNSS. A further 8.9% said several days, giving 19.1% with a buffer of days or more. 34.8% put it at about a day.

That accounts for 53.9% of respondents. The remaining 46.1% either said they could keep operating only a few hours, or could not say at all.

Figure 5

How long could you last?

Q8Link to this figure

Base: 1,000 UK respondents

53.9% a day or better10.2%8.9%34.8%46.1%Indefinitely — GNSS-independent time sourceSeveral daysA day or soA few hours, or could not say

The fourth segment combines a substantive answer with a non-response. It is exactly accurate as stated and cannot be divided.

A note on this figure. One of the five answer options on this question combined "only a few hours" with "or don't know", and a separate "don't know" option was also offered. Those responses cannot be separated after the fact. The 46.1% above is therefore exactly accurate as stated, but it cannot be divided between the two states, and this report does not attempt to divide it. No claim is made here about how many organisations have only a few hours of buffer.

The figure carries weight without that division. Both states describe an organisation that has not established its own tolerance: one has a thin buffer, the other has an unmeasured one. Against a national estimate of £1.42 billion for a 24-hour national outage, close to half of the people closest to these systems cannot place their own organisation on the right side of that day.

The prepared minority

One pattern runs through the whole study and is easy to miss, because it appears three times in three different places.

  • 10.2% hold a time source independent of GNSS.
  • 8.2% test formally and regularly.
  • 7.1% are very confident they could prove their timing to a regulator.
Figure 6

The prepared minority

Q8, Q5 and Q7Link to this figure

Base: 1,000 UK respondents

10.2%

hold a time source independent of GNSS

Q8

8.2%

test formally and regularly

Q5

7.1%

are very confident they could evidence their timing

Q7

Three separate questions. Three different capabilities. No mechanical reason these figures should align.

hold an independent time source10.2%
test formally and regularly8.2%

Different questions; the gap is observable in aggregate only. It cannot be attributed to specific respondents.

Three separate questions, asked about three different capabilities, each answered affirmatively by somewhere between one in ten and one in fourteen organisations. Independence, testing and evidence are not the same capability, and there is no mechanical reason these figures should align. That they do suggests a small, consistent minority that has treated timing as a genuine dependency and built accordingly, and a large majority that has not addressed it in any of the three respects.

This is the most useful finding in the study for anyone deciding what to do next. The prepared minority is not distinguished by scale or sophistication. It is distinguished by having asked the question and acted on the answer. Roughly nine organisations in ten have not.

Who owns this?

The clearest structural finding in the study is that the risk has no settled home.

Asked who owns the risk of a timing or positioning failure, 46.9% named IT or technology. Only 11.0% named risk and compliance and 8.9% a dedicated resilience function, meaning just 19.9% place the risk with a risk professional of any kind. Operations accounted for 17.1%. A further 16.1% could identify no owner at all: 3.0% said no one specifically owns it, with 13.1% unable to say.

Two features of the sample sharpen this considerably.

First, the resilience gap. 19.2% of respondents work in a resilience or business continuity function. Only 8.9% say a dedicated resilience function owns timing risk. The capability exists in more than twice as many organisations as it owns this particular risk in. Where a resilience function has been built, timing has largely not been placed inside it. It has been left where it started, with the people who run the equipment.

Figure 7

The resilience gap

Sample composition and Q4Link to this figure

Base: 1,000 UK respondents

19.2%8.9%
  • 19.2% work in a resilience or business continuity function (sample composition)
  • 8.9% say a dedicated resilience function owns timing risk (Q4)

These figures come from two different questions. The comparison is at the level of the sample, not the individual respondent.

Second, respondents are not defending their own territory. Only 20.1% of the sample works in IT, yet 46.9% named IT as the owner. Respondents are overwhelmingly assigning this risk to a function other than their own, which is the opposite of what self-interest would produce. This is not a survey of people passing the parcel. It is a survey of people describing where the parcel has landed.

The comparison with cyber security is instructive. Cyber risk was once distributed exactly like this: a technical concern, owned by whoever ran the systems, invisible to the board. It converged on the Chief Information Security Officer, and convergence is what made it governable, fundable and testable. PNT resilience has converged on no one. Accountability falls between IT, risk and security, and a risk that falls between functions does not get tested, budgeted or reported.

Figure 8

Who owns this?

Q4Link to this figure

Base: 1,000 UK respondents

IT / technology46.9%
Operations17.1%
Risk and compliance11.0%
A dedicated resilience / risk function8.9%
Don't know13.1%
No one specifically3.0%

Undetected going in, unevidenced coming out

If interference reached these organisations today, most would not know.

50.1% are not very or not at all confident they would detect a jamming or spoofing event. Only 13.3% are very confident they would. A further 17.0% could not say either way.

And after the event, most could not demonstrate what happened. 40.2% are not confident they could prove to a regulator or auditor that their timing was accurate during a disruption. Only 7.1% are very confident they could.

Figure 9

Detection and evidence: the compounding pair

Q6 and Q7Link to this figure

Base: 1,000 UK respondents

Could you detect it?

50.1% not very or not at all confident13.3%19.6%35.2%14.9%Don't know · 17.0%outside both nets

Could you prove it afterwards?

40.2% not very or not at all confident7.1%30.8%22.0%18.2%Don't know / not applicable · 21.9%outside both nets
  • Very confident
  • Fairly confident
  • Not very confident
  • Not at all confident
  • Don't know

That last figure is the sharpest number in the study. Fewer than one in fourteen people working in the UK's most heavily regulated timing-dependent sectors is very confident their organisation could evidence its own time.

A note on this question. One of the five answer options combined "don't know" with "not applicable", and was selected by 21.9% of respondents. Those two states cannot be separated after the fact and this report does not attempt to separate them. The figures reported here are calculated on the full base of 1,000 and are exactly accurate as stated. Readers should note that "not applicable" is a defensible answer for organisations outside a timing-specific regulatory regime, as set out in the note at section 5.

These two findings compound in a way that neither does alone. An organisation that cannot detect an event and cannot evidence its timing afterwards is not merely exposed to disruption. It is exposed to disruption it will attribute to something else. Timing failures do not announce themselves. They surface as reconciliation breaks, sequencing anomalies, synchronisation errors and audit discrepancies, each of which has a dozen more familiar explanations. A cause that cannot be detected and cannot be evidenced will be recorded as something else entirely.

That is the practical meaning of running blind. Not that an attack would go unnoticed, but that its consequences would be misdiagnosed.

The compliance blind spot

49.0% understand their organisation's regulatory obligations on timing accuracy and operational resilience not very well, or not at all. Only 8.1% say those obligations are actively managed.

A note on this question. It was asked of both sectors in the study, and referenced MiFID II as an example of a timing-specific obligation. MiFID II applies to investment firms and trading venues, not to data centre operators, who fall under different regimes. The figure above therefore spans two populations with different obligations, and should be read as a measure of general regulatory confidence rather than of compliance with any single rule.

The obligations exist regardless, and they are more specific than most organisations realise.

MiFID II requires trading venues and their members to synchronise business clocks to Coordinated Universal Time, under Commission Delegated Regulation (EU) 2017/574, commonly cited as RTS 25. The requirement is tiered rather than uniform. Voice and manual trading sits at one-second granularity; general algorithmic trading at one millisecond; high-frequency algorithmic trading at a maximum divergence from UTC of 100 microseconds with one-microsecond granularity. Two consequences follow from the drafting. A free-running clock is non-compliant however stable it is, because the standard measures divergence from an external reference rather than internal stability. And where time is derived from GNSS, the offset between GNSS time and UTC must be documented and removed, not assumed to be zero.

Figure 10

The RTS 25 tiers

Commission Delegated Regulation (EU) 2017/574Link to this figure
1 second1 millisecond100 microseconds1 microsecondlonger, less strictshorter, stricterlogarithmic scale: each gridline is a factor of ten
  • 1 second

    Voice and manual trading, timestamp granularity

  • 1 millisecond

    General algorithmic trading, timestamp granularity

  • 100 microseconds

    High-frequency algorithmic trading, maximum divergence from UTC

  • 1 microsecond

    High-frequency algorithmic trading, timestamp granularity

Commission Delegated Regulation (EU) 2017/574 (RTS 25), supplementing Directive 2014/65/EU (MiFID II), Article 50, Annex Tables 1 and 2

Four orders of magnitude between a voice desk and a co-located matching engine. The study spans two populations with different obligations: MiFID II applies to investment firms and trading venues, not to data centre operators, who fall under different regimes.

UK operational resilience rules require firms to identify their important business services, set impact tolerances, map the people, processes, technology, facilities and data that deliver them, and test that they can remain within tolerance under severe but plausible scenarios. These rules were made in FCA Policy Statement PS21/3 and PRA Supervisory Statement SS1/21, came into force in March 2022, and the transitional period ended on 31 March 2025. Full compliance is now expected, not pending.

DORA, Regulation (EU) 2022/2554, has applied since January 2025 and imposes ICT risk management, testing and third-party oversight obligations on EU financial entities. UK firms are in scope through their EU operations and through their role as service providers to EU entities.

Every one of those frameworks assumes timing that can be proven. Read alongside the 40.2% who are not confident they could prove their timing to a regulator, and the 7.1% who are very confident they could, the exposure is not that firms are knowingly failing a rule. It is that a substantial proportion do not yet know the rule attaches to a dependency they have never examined.

A firm that has mapped its important business services without mapping its timing dependency has an incomplete map. The rule has been in force since March 2025.

Testing is the missing step

There is demand for a way out of this.

43.9% describe an independent assessment of their timing and positioning resilience as valuable or extremely valuable, with a further 32.2% seeing at least some value in one.

Read against the rest of the study, that appetite is coherent rather than surprising. These are organisations that recognise the dependency, rate its failure as serious, and know they have not tested it. The willingness is not in doubt.

What separates the prepared minority from everyone else is a single step, and it is regular testing against up-to-date scenarios, not a one-off exercise that gets filed away. Independence, evidence and confidence all follow from it. An organisation that has tested what happens when timing degrades knows its own tolerance, can describe its exposure to a board, and can evidence its position to a regulator. An organisation that has not tested is relying on an assumption, however sound its architecture may be.

This is why 61.0% having no completed test is the operative finding in this report rather than a supporting one. Every other weakness the study describes – unowned risk, undetected events, unevidenced timing – persists because the dependency has never been put under load and observed. Testing is not one option among several. It is the step that converts a dependency into a managed risk, and it is the step that has not been taken.

What this means at board level

The study describes a dependency that is widespread, largely unexamined, poorly owned, undetectable in the moment and unevidenced afterwards. Recognised as serious by three in ten of the people who operate it, tested by fewer than three in ten, and evidenced with confidence by fewer than one in fourteen.

Four questions are worth putting to any board.

1. Do we know where we depend on GNSS timing, and how long we would last without it? Not whether we use GPS, but where precise time enters our operations, what breaks without it, and what our actual tolerance is. Only 10.2% hold a time source independent of GNSS, and 46.1% could last only a few hours or could not say.

2. Would we detect an interference event, and could we prove our timing held? Detection and evidence are separate capabilities and most organisations sampled have neither. Only 7.1% are very confident of the second.

3. Who owns this risk? If the answer is "IT", that is the same answer 46.9% of organisations gave, and it is the finding this study exists to challenge. If your organisation has a resilience function, ask specifically whether timing sits inside it. In most of those sampled, it does not.

4. Should our important business services mapping include timing? Regular testing is a quick win here: it lets an organisation quantify its risk and measure its own improvement against it. The UK operational resilience transitional period ended on 31 March 2025. A map that omits a dependency this fundamental is not a complete map.

The organisations that come out of this well will not be the ones with the most sophisticated timing architecture. They will be the ones that asked the question at all.

Further resources

ICDM does not provide testing or assessment services. Organisations seeking to establish their own exposure should approach a specialist provider of PNT test and measurement capability.

GPS Spoofing: Final Report, published by the OPSGROUP International Ops workgroup.

Resilient PNT: Prepare, Act, Recover, best practice and guidance published by the Royal Institute of Navigation.

Direct Intelligence Ltd, of which ICDM is the research arm, offers a confidential PNT resilience assessment, delivered with its global PNT test and measurement partner. A short self-assessment is available at pnt.directintelligence.co.uk. This is disclosed here rather than in the body of the report so that it is read as a commercial relationship and not as a finding.

About ICDM and Direct Intelligence

About ICDM

The Institute of Critical Infrastructure Decision Making researches how decisions are made, evidenced and owned across critical national infrastructure. Its programme covers decision rights and accountability, evidence and audit trails, standards and conformity assessment, and resilience under dependency failure. ICDM publishes original research, the Signal series and the Decision Architecture Series. It is chaired by Gary Daniel Doran.

About Direct Intelligence

Direct Intelligence Ltd, company number 16278923, is a UK critical infrastructure intelligence and standards firm. ICDM is a trading name of Direct Intelligence Ltd. More at directintelligence.co.uk.

Sources and references

Survey data. All survey figures from a study of 1,000 UK respondents working in financial services and in data centre, colocation and cloud infrastructure, commissioned by ICDM and fielded July and August 2026 via an independent research panel. Full response distributions are reproduced in the appendix.

GNSS interference in aviation. OPSGROUP, GPS Spoofing: Final Report of the GPS Spoofing WorkGroup, published 6 September 2024. Reports an increase from approximately 300 spoofed flights per day in Q1–Q2 2024 to approximately 1,500 per day by August 2024, and approximately 41,000 reported interference events between 15 July and 15 August 2024. ops.group/blog/gps-spoofing-final-report/

Economic impact. London Economics, The economic impact on the UK of a disruption to GNSS, commissioned by the UK Space Agency, published via gov.uk, 18 October 2023. Estimates annual GNSS benefit to the UK economy at £13.62bn, seven-day loss at £7.64bn and 24-hour loss at £1.42bn. gov.uk/government/publications/report-the-economic-impact-on-the-uk-of-a-disruption-to-gnss

Clock synchronisation. Commission Delegated Regulation (EU) 2017/574 (RTS 25), supplementing Directive 2014/65/EU (MiFID II), Article 50. Tiered accuracy requirements set out in the Annex, Tables 1 and 2.

UK operational resilience. FCA Policy Statement PS21/3, Building operational resilience, and PRA Supervisory Statement SS1/21. In force 31 March 2022; transitional period ended 31 March 2025. fca.org.uk/publications/policy-statements/ps21-3-building-operational-resilience

Digital operational resilience. Regulation (EU) 2022/2554 (DORA), applicable from 17 January 2025.

Appendix: full response distributions

The full response distribution for every question in the study is published, reported as delivered, with each derived figure shown alongside its components.

Read the appendix