It's About Time: The Hidden Risks of Time Synchronisation in Cyber Security
2025-05-13 , Grand Ballroom B

Time is a fundamental yet often overlooked aspect of cyber security and IT operations. From GPS time versus UTC to the Year 2038 problem and virtual machine clock drift, small inconsistencies in timekeeping can have major consequences. This presentation explores the critical role of time synchronisation in modern ICT, highlighting how inaccuracies affect SSL certificates, authentication protocols, and log integrity. A key focus will be the security vulnerabilities of the Network Time Protocol (NTP), including a live demonstration of how an attacker can manipulate time by interfering with NTP synchronisation. The session will also examine leap seconds, timekeeping challenges in distributed systems, and how organisations can mitigate time-based attacks. By understanding the risks of time desynchronization, attendees—whether security professionals, network engineers, or system administrators—will leave with an understanding on how to perform 'hard time' in their organisation!


Difficulty Level of Presentation:

Intermediate/Some Knowledge Advised

Nick, with over 25 years of experience, has worked across multiple roles and industries, including radio frequency engineering, software programming, and cyber security. He has led cyber security practices, advised executives as a virtual CISO, and helped deliver Australia’s first NATO ‘Locked Shields’ event. Nick was the Global Cyber Alliance's first Australian ambassador.