Ricardo Ferreira, EMEA Field CISO at Fortinet, warns that time remains an unowned yet critical organisational input. With GPS spoofing surging and resilience mandates tightening, enterprises must finally measure, own, and secure time to safeguard operations, integrity, and accountability.
Ask a board to list its critical organisational inputs, and the answer is quick: capital, energy, connectivity, data. Still, one that is never mentioned is time. This is not about time management, but time as a foundational signal within a microsecond-precise broadcast, unauthenticated, from satellites above Earth, on which every trade, every network handover, and the grid silently depend.
Telecom networks synchronise every 5G tower to within a microsecond, and power grids rely on the phase measurement unit that does not work when the clock drifts. Logistically, ports operations all assume that time arrives quietly and correctly from space. Once again, it’s not a satellite problem; it’s an unmeasured input problem.
Take into consideration the aviation safety data, it shows GPS spoofing incidents surging 500% year on year with analysts now tracking over 700 jamming and spoofing events every single day. Similarly, the reports coming from the Middle East and the Baltic states still fresh in memory, most of it is driven by nation states linked activities. The reality is that it reaches far beyond aviation into every sector that runs on satellite delivered time.
The Cost of an Unowned Clock
Three separate invoices are getting drafted, the first comes from the regulator. Accountability for operational resilience is moving up the org chart. Under NIS2, management bodies carry personal responsibility for cyber-risk oversight. The proposed EU Space Act requires threat-led penetration testing before launch and every three years thereafter. The direction is consistent across jurisdictions: Resilience must be evidenced. Insurers and underwriters are already pricing this exposure before most boards are measuring it. The space cyber insurance market is growing at over 17% annually, and operators with documented and demonstrable controls already command premium reductions of 15–30%. The logic is spreading to any sector dependent on satellite timing and communications. And finally, there is the audit problem, which on the systems keep running, but the records that uphold integrity quietly lose their standing. Trade sequencing becomes disputable, logs lose evidential value, and forensic timelines collapse.
Own it, Measure it, Prove it
Who is the executive responsible for owning time in your organisation? The CIO runs the networks. The CISO runs cyber risk. The COO runs operations. Time, all members of the board depend on, but nobody owns it, no budget line is associated with it, and normally there are no KPIs or SLAs. There is a lesson to this: Systemic risks remain unmanaged unless someone is made accountable.
The next four points help get a grasp on the risk:
- Inventorise: Map what breaks if time drifts by 50 microseconds, 5 milliseconds, or 5 minutes
- Assign ownership: An executive, a defined tolerance, a time integrity SLA, similarly to any other critical input
- Instrumentise: Use sensors and analytics to feed the security operations capabilities already existing in the organisation
- Test: Simulate interference and holdover before an adversary, a regulator, or an underwriter
The necessary metrics will vary by organisation, but the following ones could provide a good starting ground:
- Timing integrity SLA adherence
- Holdover margin (hours of trustworthy autonomous time)
- Mean time to detect interference
You Can’t Secure What You Don’t Measure
At Fortinet, our continuous collaboration with critical infrastructure operators across every sector keeps returning to the same lesson: You cannot secure what you do not measure. And today, almost nobody is measuring time. So, who owns it in your organisation?











