Most organisations cannot say how much they depend on satellite timing, what happens when it degrades, or whether they could prove afterwards that it held. MAP grades all three, and shows you where you stand against a national study of 1,000 UK infrastructure respondents.
Measure what you rely on. Address what you find. Prove it holds.
Timing is infrastructure that almost nobody owns.
Satellite timing sits underneath trading systems, payment clearing, network synchronisation, substation protection and data centre operations. It arrives free, it works, and it is treated as a fact of the environment rather than as a dependency with a failure mode. It can be jammed. It can be spoofed. Neither requires sophistication.
The result is a gap that operational resilience work has largely missed. Organisations have mapped their important business services in detail and left out the one input that every timestamp in them depends on.
MAP names that gap and measures it.
Three stages. Six domains. Four levels. It fits on one page and a compliance officer recognises every word in it.
Dependency. Where does precise time enter our operations, including through third parties, and do we understand that those signals can be deliberately attacked?
Tolerance. What fails when time degrades, how badly, and how long could we keep operating?
Ownership. Does a named function own this, with the authority and the budget to act?
Detection. Would we know an interference event was happening while it was happening, and do we know what to do about it?
Testing. Have we tested, on a cycle, against a threat picture kept current?
Evidence. Could we demonstrate afterwards that our timing held?
Ownership opens Address, and that is the central argument. Cyber risk became governable when it converged on the CISO, and that convergence is what made it fundable and testable. Nothing in Address or Prove moves until someone owns timing. It is the hinge of the whole framework.
Testing sits in Prove, not Address. Testing is not a control you install. It is how you demonstrate a control works. Grouping it with Evidence puts the two things the market is worst at in the same stage, and makes the final stage the one that actually bites.
Six domains, not eight. Third party dependency belongs inside Dependency, because that is what it is. Holding a GNSS independent time source belongs inside Tolerance, because that is what it buys you. Neither needed its own box.
| Number | Level | What it means |
|---|---|---|
| 0 | Unexamined | The question has not been asked. Not weighed and accepted. Never looked at. |
| 1 | Recognised | Acknowledged as mattering. No figure exists that anyone could state. |
| 2 | Quantified | Documented, with a number and a source behind it. |
| 3 | Assured | Demonstrated, on a cycle, and current. |
The line that does the work is between 1 and 2, and it is whether a figure exists. Below it, an organisation has opinions about its timing dependency. Above it, it has measurements.
Four levels, not five. Five level models exist so that everyone has a middle to sit in. Our finding is that most organisations are at level 0, and a model that lets them feel like a 3 out of 5 while never having examined the question defeats itself.
Measurewhat do we rely on and what does it cost us
Where does precise time enter our operations, including through third parties, and do we understand that those signals can be deliberately attacked?
0 · Unexamined
Nobody has asked where precise time enters the organisation.
Nobody has asked where precise time enters the organisation. Nationally, 34.9% rely critically or heavily on GNSS timing, and 43.3% were only vaguely aware, or entirely unaware, that those signals can be deliberately jammed or spoofed.
1 · Recognised
Timing is known to matter. No inventory exists.
Timing is known to matter, but no inventory exists. You are ahead of the awareness gap: 43.3% nationally were only vaguely aware, or entirely unaware, that these signals can be attacked.
2 · Quantified
A documented inventory of timing dependent systems and services, including those delivered by third parties.
You hold a documented inventory including third party services. Nationally, 14.2% say core operations would fail without GNSS timing, and almost none of them can show which ones.
3 · Assured
The inventory is maintained on a cycle and reconciled against the important business services map.
Your inventory is maintained and reconciled against your important business services map. This is the position the operational resilience regime assumes every firm already holds.
What fails when time degrades, how badly, and how long could we keep operating?
0 · Unexamined
No view of what fails, or how quickly.
No view of what fails, or how quickly. Nationally, 17.0% cannot say what a 24 hour loss would mean, and 46.1% either could keep operating only a few hours, or could not say.
1 · Recognised
Degradation is understood to be damaging. No figure exists.
Degradation is understood to be damaging, but no figure exists. Nationally, 29.9% rate a 24 hour loss as serious or catastrophic without a stated window behind that judgement.
2 · Quantified
A stated operating window per service, and any GNSS independent source documented.
You have a stated operating window per service. Only 10.2% nationally hold a GNSS independent source at all.
3 · Assured
The window is derived from observed behaviour rather than estimate, and independent sources have actually been failed over to.
Your window is derived from observed behaviour and you have failed over in practice. Fewer organisations have proven a failover than hold an independent source, so this position is rarer than the 10.2% figure suggests.
Addresswhat have we done about it
Does a named function own this, with the authority and the budget to act?
0 · Unexamined
No owner, or assumed to sit with IT without IT having accepted it.
No owner, or an assumption that IT holds it without IT having accepted it. Nationally, 16.1% can identify no owner at all, and 46.9% place it with IT.
1 · Recognised
A function is named.
A function is named, but without budget or a reporting route. This is where most of the market sits. Nationally 46.9% name IT, and only 19.9% place it with a risk professional of any kind.
2 · Quantified
Named owner with defined scope, a budget line and a reporting route.
A named owner with defined scope, a budget line and a reporting route. Only 8.9% nationally say a resilience function owns timing.
3 · Assured
The owner reports on a cycle, and timing sits inside the organisation's resilience governance rather than beside it.
The owner reports on a cycle and timing sits inside resilience governance. This is the convergence that made cyber risk fundable, applied to timing.
Would we know an interference event was happening while it was happening, and do we know what to do about it?
0 · Unexamined
No means of knowing.
No means of knowing. Nationally, 50.1% are not confident they would detect a jamming or spoofing event.
1 · Recognised
Some monitoring exists. Its coverage is unknown.
Some monitoring exists, but its coverage is unknown. Confidence without documented coverage is what the national 13.3% very confident figure is largely made of.
2 · Quantified
Coverage documented, thresholds defined, alerts routed to a named recipient with a defined response action.
Coverage, thresholds and routing are documented, with a defined response. Only 13.3% nationally are very confident they would detect an event, and few of those could show why.
3 · Assured
Detection and response demonstrated against a live or simulated event, within a stated time to detect.
Detection and response demonstrated against a live or simulated event within a stated time to detect. This is what confidence looks like when it is earned.
Provewhat can we demonstrate
Have we tested, on a cycle, against a threat picture kept current?
0 · Unexamined
Never tested.
Never tested. You are with the 42.9% nationally who have never tested, inside the 61.0% with no completed test.
1 · Recognised
Testing planned, not done.
Testing is planned but not done. Planned and done are separated by 61.0% of the market having no completed test at all.
2 · Quantified
At least one completed test against a defined interference scenario, with results recorded.
At least one completed test against a defined interference scenario. That places you ahead of roughly six in ten organisations nationally.
3 · Assured
Testing on a defined cycle against a current threat picture, with findings tracked to closure.
You test formally and regularly, which puts you in the 8.2% nationally who do. Whether the threat picture is current and findings are tracked to closure is what separates a provisional level 3 from a confirmed one.
Could we demonstrate afterwards that our timing held?
0 · Unexamined
Nothing could be demonstrated.
Nothing could be demonstrated. Nationally, only 7.1% are very confident they could prove to a regulator or auditor that their timing remained accurate.
1 · Recognised
Some records exist. Completeness unknown.
Some records exist, but completeness is unknown. Nationally, 49.0% understand their obligations here not very well or not at all.
2 · Quantified
Timing records retained and traceable to UTC, sufficient to reconstruct a period.
Timing records retained and traceable to UTC, sufficient to reconstruct a period. Traceability to UTC is the explicit requirement under MiFID II RTS 25.
3 · Assured
An evidence pack produced and tested against a real request from a regulator, auditor, customer or incident.
An evidence pack produced and tested against a real request. Only 7.1% nationally are very confident they could do this, and confidence is not the same as having done it.
Every domain carries a measured national position, from a study of 1,000 UK respondents in financial services and data centre infrastructure. An organisation using MAP does not only learn where it stands. It learns where it stands against everyone else.
| Domain | National position |
|---|---|
| Dependency | 34.9% rely critically or heavily on GNSS timing, and 14.2% say core operations would fail without it. Yet 43.3% were only vaguely aware, or entirely unaware, that those signals can be deliberately jammed or spoofed. |
| Tolerance | 29.9% rate a 24 hour loss serious or catastrophic, and 17.0% cannot say what the impact would be. 10.2% hold a GNSS independent source. 34.8% put their operating window at about a day. 46.1% either could keep operating only a few hours, or could not say. |
| Ownership | 46.9% place the risk with IT. Only 19.9% place it with a risk professional of any kind. 16.1% can identify no owner at all. 19.2% work in a resilience function, but only 8.9% say such a function owns timing. |
| Detection | 50.1% are not confident they would detect a jamming or spoofing event. Only 13.3% are very confident. |
| Testing | 61.0% have no completed test. 42.9% have never tested. Only 8.2% test formally and regularly. |
| Evidence | Only 7.1% are very confident they could prove to a regulator or auditor that their timing remained accurate. 49.0% understand their obligations not very well or not at all. |
Source: Running Blind, ICDM Research Report 01. Base 1,000, unweighted, distributions published in full.
Read that table down the column and the pattern is unmistakable.
The market has largely measured, barely addressed, and has not reached prove. Dependency is broadly recognised. Almost nothing downstream has been done about it.
And it stalls at the first domain of Address. With the risk parked in a function that has neither claimed it nor been resourced for it, there is nobody whose job it is to move the rest. Detection is not built, testing is not commissioned, and evidence is not retained, because none of those is anyone's objective.
That is a diagnosis, not a scolding. It also points at the cheapest available move. Getting Testing from level 1 to level 2 is a single test. No reorganisation, no new function, no capital programme. It produces three things an organisation does not currently have: a quantified exposure, a measured tolerance, and a baseline to improve against.
MAP is not a parallel structure competing with operational resilience obligations. It is those obligations, applied to a dependency most organisations have left out of them. Mapping, impact tolerances, severe but plausible scenarios. That is the regulator's language, not ours.
| Domain | The obligation it serves |
|---|---|
| Dependency | Identification and mapping of important business services, and the people, processes, technology, facilities and data that deliver them. FCA PS21/3 and PRA SS1/21. Third party dependency also engages DORA and the Critical Third Parties regime. |
| Tolerance | Setting impact tolerances, the same regime's central obligation. |
| Ownership | Senior manager accountability, and ICT risk management governance under DORA. |
| Detection | Incident identification, feeding the FCA, PRA and Bank of England operational incident reporting regime. |
| Testing | Testing that services remain within impact tolerance under severe but plausible scenarios. PS21/3. Sustained GNSS interference is both severe and plausible. |
| Evidence | Clock synchronisation traceable to UTC under MiFID II RTS 25, plus audit trail and incident reporting obligations. |
An organisation that mapped its important business services without mapping its timing dependency has an incomplete map, and the transitional period for completing that work has closed.
Three views of the same six numbers. None of them is ever shown alone.
The MAP Score is the sum of the six domain levels, out of 18, with a sub score out of 6 for each stage. It rewards capability wherever it sits, and it is what you track year on year.
The position is named by the first stage you have not completed: Unexamined, Measuring, Measured, Addressing, Addressed, Proving, Assured. A stage is complete when both its domains are at level 2 or above. Unlike the score, position is sequenced, because monitoring that cannot be scoped against an inventory is capability rather than assurance.
The profile is the grid. Six domains at four levels, with the market position beside every one, so each gap comes with a comparison rather than a judgement.
Reported together, always, in this form:
MAP Score 9 / 18 · Measuring
There is no single percentage. An organisation at Measure 2 of 2 and Prove 0 of 2 has a specific, nameable problem. An organisation on 58% has nothing.
MAP grades timing assurance, not incident response. Response is captured within Detection at levels 2 and 3. Organisations needing a full incident response maturity assessment should look to established operational resilience frameworks alongside MAP.
MAP covers timing, not the whole of PNT.For positioning and navigation, and for recovery after a disruption, the Royal Institute of Navigation's Resilient PNT best practices remain the reference. MAP is built on that guidance rather than beside it. Its Prepare stage is where most of MAP sits, and MAP has no equivalent of its Recover stage.
MAP is derived from self reported positions, not audit evidence. It is a diagnostic and a benchmark. It is not an audit standard.An assessment result attests that an assessment was completed and produced a given profile. It does not attest that an organisation's timing is resilient. Evidence for that comes from actual testing by a competent test provider.
Six questions, one per domain. No email required, and none requested.