Assured Navigation and Timing

Stop Counting GNSS Backups and Start Measuring the Handover

['A team of four technicians or engineers', 'Computer-based data acquisition systems', 'Large-scale mechanical hardware (visible in background)']. Collaborative technical analysis where one individual directs the group's attention to specific performance metrics. Aerospace.

On September 3, 2026, an Airbus A330 flew significantly off its published approach to Roland Garros Airport on La Réunion. The jet descended toward 1,000 feet before an air traffic controller ordered the crew to climb immediately. The aircraft had lost GNSS en route. It flew a VOR approach instead.

The airplane was an A330-200, registered EC-ORP, belonging to Spanish carrier Wamos Air. According to The Aviation Herald, it was operating French Bee flight BF5700 from Paris Orly. France's BEA has opened an investigation, and I am not going to guess at its findings. What is already public is enough for the argument I want to make: the fallback existed and was in use, yet the flight path still had to be bounded by a person on the ground.

I count GNSS resilience at the handover, the interval between losing the primary source and stabilized tracking on whatever replaces it, not by the number of backup navigation sources installed. That distinction sounds pedantic until you look at what happened. After losing GNSS en route to Réunion, the Wamos A330 flew a VOR approach. The aircraft still flew significantly off its published approach. It descended toward 1,000 feet before ATC ordered a climb.

The Backup Was Installed And The Airplane Still Went Low

This is the pattern I keep running into in resilience reviews, civil and military alike. Someone counts the navigation sources on the equipment list: GNSS, inertial, VOR, DME, maybe an ILS at the destination. The count is high, so the platform is declared resilient, and the line item moves on. Réunion is a reminder that the count answers a different question than the one that matters.

An equipment list answers whether the aircraft can navigate at all after a loss. It does not answer whether the combined flight path stays inside lateral and vertical bounds while the sensor source, the procedure, the automation mode, and the crew cross-checks all change state at once. Those are different facts. Availability is a parts count; containment is a measurement, and it exists only if someone flew the transition and recorded the excursions.

I do not know what the BEA will find, and neither does anyone posting confident diagnoses this week. The crew may have done everything right within the procedure they had. That is precisely the point: a transition can be flown correctly, step by step, and still leave the aircraft outside the corridor the approach designer assumed, because the corridor was built around a sensor that is no longer feeding the airplane.

The backup worked; the handover did not.

What Actually Changes When Satellite Navigation Drops Out

I focus on four coupled changes when assessing a GNSS loss on approach. The sensor source changes, from a satellite solution to a ground aid or an inertial one, with different error behavior and different failure modes. The procedure changes, from the approach the crew briefed to one with different geometry and different fixes. The automation changes, because the guidance the autopilot was tracking is no longer the guidance available. And the cross-checks change, because the scan and the callouts for raw-data flying are not the ones the crew was using moments earlier.

Each transition can be individually acceptable and the combination can still fail to bound the path. That is not exotic; it is what coupled mode changes do in any engineered system, where the failure lives in the interactions rather than in the components. Testing each backup separately, in cruise, on a calm day, tells you almost nothing about the transition period that matters, the stretch in which a crew is discovering the loss, re-briefing, reconfiguring, and flying an approach they did not plan to fly. A crew that flies the fallback every simulator cycle is a different animal from a crew meeting it for the first time at the end of a long sector, and the equipment list cannot tell you which one you have.

Switzerland Is Having This Argument In Public

Swiss crews encounter GPS spoofing every day. Switzerland is nonetheless switching its airports away from a ground-based landing system to save money. Migflug described the ground-based landing system being removed as one that spoofing cannot affect. The economics are not mysterious; the switch is explicitly a cost decision, and a spreadsheet that only prices availability will always favor the removal. What the spreadsheet does not price is the transition everyone will fly on the day the cheap source lies.

The correction has started. The Swiss federal government suspended the planned removal of the Instrument Landing System at Bern-Belp. Europe's aviation safety regulator began advising national authorities to keep ILS available for emergencies. The Swiss pilots' union had argued for months that ILS should remain available for emergencies. All of that is welcome, and all of it is still an availability argument: keep the ground aid or remove it.

Keeping the ground aid is necessary. It is not sufficient, because an aid nobody has transitioned to under pressure is a backup in the inventory sense only. After losing GNSS en route to Réunion, the Wamos crew flew a VOR approach. The controller still ordered the crew to climb immediately after the jet descended toward 1,000 feet.

What A Degraded-Navigation Trial Should Measure

So here is what I would require, as an operator or a buyer, before accepting any claim of GNSS resilience. Inject the loss at the worst credible moment, on the intermediate approach at high workload, not in cruise on a clear day. Measure lateral and vertical containment continuously, from the moment of loss until the aircraft is stabilized on the fallback, and score the trial on the worst excursion, not on whether a backup engaged. Fly it with the real crew procedures and the real automation modes, because the mechanism lives in their interaction and a bench test cannot see it. And write the pass criterion down before the trial, as a containment bound in feet and meters, because a trial whose success is decided afterward is a demonstration, not a test.

This costs more than a checklist audit, which is why it rarely happens. It is also the only trial that produces the number you actually need: how far off the path the aircraft got, laterally and vertically, and for how long. The industry has a standing disease of demonstrating a capability once under favorable conditions and then describing it as fielded, and degraded-navigation resilience attracts that disease badly, because the favorable demonstration is cheap and the honest trial is expensive. Spoofing does not schedule itself for the favorable day.

Say What Is Proven, Say What Is Not

The discipline underneath all of this is labeling what is proven and what is not. My company, Kibernan, has produced six complete, costed engineering programs, and every published figure in them carries its maturity, so a reader can see whether a number was modeled or calculated and whether it was specified or is only an objective. They are proposals. No Kibernan hardware has been built or fielded, and we say so in writing, because a performance claim stripped of its maturity is exactly the kind of claim this article argues against.

That same discipline applies to a navigation suite. A backup that has been installed is one maturity level, and a backup that has been engaged in cruise is another. A backup that has been transitioned to at the worst point on the approach, with containment measured throughout, sits at the only level that supports the word resilient, and almost nobody's paperwork distinguishes among the three.

So the ask is small and concrete. At your next resilience briefing, when the slide shows the list of fallback sources, ask for the excursion trace through the handover: worst lateral and vertical deviation and time to stabilized tracking, measured under representative workload. If the trace exists, you are looking at engineering. If it does not, you are looking at an inventory, and Réunion just showed everyone the difference between the two.

Count resilience at the handover, because that is where it nearly ran out on September 3.