What happens if your system’s clock is broken?
When hackers control the clock.
Host Maria Varmazis and Andy Davis, Global Research Director at the NCC Group, discuss how hackers can manipulate the clocks that critical infrastructure depends on. Whether by spoofing GPS signals or interfering with network time protocols, they look at how corrupted time can bypass security controls, disrupt synchronization, and create failures.
The vulnerable clock in space.
This week on T-Minus: Space-Cyber Briefing: we revisit the role of timing in space and how vital these systems are for everyday functionality. Given their importance, attackers have become increasingly aware of how to exploit these systems.
Does this newsletter spark questions for you? Write to us at space@n2k.com to guide how we’ll continue to explore the role of timing for spacecraft in future podcast episodes and newsletter issues.
The importance of timing.
For spacecraft, accurate timing is critical. These timing systems serve as the backbone for many space-based services, where precise measurements support everything from navigation to telecommunications.
Space systems support many modern, everyday systems using highly-sophisticated clocks. Take GPS, for example. Outside of helping people navigate, this communication service provides highly accurate timing that is used across industries ranging from finances to energy services.
- For finances, institutions use GPS to timestamp transactions ensuring record traceability and a consistent way to maintain accurate records.
- Across the electrical grid, timing supports bulk metering, transmission-line fault detection, substation control, and SCADA networks.
David Wells, a program leader for the Center for Alternative Synchronization and Timing (CAST) noted that when it comes to grid timing, “a secure, verifiable, and reliable solution is paramount.”
As more systems become increasingly reliant on highly accurate timing, a key question that must be answered is: What happens when that timing can no longer be trusted?
A broken clock.
The importance of timing systems cannot be understated. In 2021, the National Institute for Standards and Technology (NIST) published research on these systems.
NIST emphasized the importance of these systems noting:
“Timing system failures can have serious consequences, with the potential implications including economic loss, reduced safety and security, and loss of human life.”
Given the importance of these systems, their potential use as an attack vector creates a significant cybersecurity concern. One of the more common ways that this can be done is through spoofing attacks. In a GPS spoofing attack, a malicious actor is able to override a legitimate signal before it can reach its intended destination.
Previously, we highlighted how spoofing can be used to override location data. That same technique can also be used to manipulate time. Rather than causing a device to believe it is somewhere it is not, a spoofed signal can cause a system to believe that it is a different time from reality.
While that sounds innocuous, critical systems rely on highly accurate time data. Even small discrepancies can have significant consequences, like those NIST outlined.
For security practitioners, this creates a difficult paradigm as the signals being received from space must be treated as a trusted input. Security practitioners need to change thier mindset to address this. Rather than asking if the time is accurate, organizations should assess whether that time can be trusted.
By reframing this question, teams can understand risks better and develop stronger mitigation techniques to address if a source provides inaccurate information or becomes unavailable. Additionally, establishing redundancy by collecting multiple time sources and comparing them to each other is key. If one source is off, then the discrepancy will be much more noticeable and then avoidable.
Ultimately, the goal for security practitioners is not to find new timing-based systems, but rather to create more resiliency for them to ensure that errors do not become incidents.
This week’s space-cyber headlines.
The news stories we’re reading and thinking about this week.
Establishing the US Space Academy.
- President Trump has signed a new Executive Order calling for the establishment of a new space academy tasked with preparing the next generation of astronauts, scientists, engineers, operators, and civil servants for advancing American space interests.
- In the order, President Trump listed space as a critical domain for national security, economic growth, scientific discovery, and technological innovation.
August 28, 2026 | Source: The White House
MSS Reference Architecture 2.0.
- The Mobile Satellite Services Association (MSSA) has released its MSS Reference Architecture 2.0 guide.
- The guide expands on the original framework to add in new guidance for regenerative satellite payloads and support for new technologies, such as 5G New Radio and NB-IoT services.
- Listen to Maria’s coverage of the story on the CyberWire Daily.
September 2, 2026 | Source: MSSA




