From CommsDay of 20 July 2026
Our Story of the Week this week is based on two articles, both published in CommsDay on Monday, 20 July.
The first article covers the sequence of events, as documented by Telstra before the Senate Committee lastFriday, 17 July, that led to the recent serious mobile network outage. What exactly happened is very important. The second article covers the Senate Committee hearing and gives a good insight into the way these hearings are conducted – or at least this hearing. Readers might like to reflect on whether this hearing is or will be useful in delivering meaningful accountability and solutions for the future. The CommsDay article describes the hearing very well, but there are limitations in any form of print journalism to convey the atmosphere and dynamics at play. The Parliament House website, through Youtube, broadcasts the events live. An action replay of last Friday’s hearing can be accessed at https://www.youtube.com/watch?v=p3WE_-C7pzY
The articles are relatively lengthy, in combination, but I think are well worth the read.
Undocumented change and missed update sent Telstra network back to 2006
An undocumented configuration change and a missed software update combined to turn routine maintenance on a Telstra timing server into the nationwide mobile outage of 8 July, the carrier told a Senate inquiry on Friday.
Telstra CEO Vicki Brady opened the hearing with an apology for the outage and its effects on customers, telling the committee that the company had “let Australians down.”
“We let our customers down, we let the community down and we fell short of what people rightly expect from us,” Brady said. “For this I am deeply sorry.”
“Australians rely on Telstra every day to run businesses, stay in contact with family, access essential services and, most importantly, to get help in an emergency. When our network fails, the impact is real.”
Brady particularly acknowledged the concern caused by the failure of some Triple Zero calls.
Telstra provided its most detailed public analysis and chronology of the incident to date, though Brady and group owner for service resilience and critical communications Gerard Tracey cautioned that the investigations were continuing.
The disruption began at 3.38am on 8 July after technicians completed maintenance on a Network Time Protocol server at Telstra’s Exhibition Street exchange in Melbourne. The work involved replacing the server chassis after one of its backup power feeds failed. The
maintenance team followed the documented procedure, including powering down and restarting the equipment.
However, when the SSU 2000 server restarted, its GPS card supplied a date in 2006. That incorrect date was progressively distributed to mobile network elements that consulted the server for timing information.
Authentication certificates became invalid, devices failed to register and customers experienced intermittent failures across voice, data, EFTPOS terminals and connected devices.
Telstra detected the first problems at 4.20am and isolated the Melbourne server at 7.11am. At its peak, the initial incident affected about 45% of calls and data sessions on the mobile network.
Telstra told the inquiry that the outage might have been avoided if either a software update had been applied to the GPS card or a previous conϐiguration change had been properly documented.
The SSU 2000 was classified by Telstra as a Stratum 3 server and was not intended to be the ultimate authority for the date and time it distributed. Under its original design, it obtained that information from a higher-level Stratum 2 server elsewhere in the network.
However, the Melbourne unit was reconfigured after losing connectivity to that timing source in October 2025. The connectivity problem involved the link to the Stratum 2 source rather than a fault in the SSU 2000 itself. The server was instead configured to use its internal GPS card as the source of its time and date. That effectively made the unit an authoritative source, but the change was not properly recorded in Telstra’s documentation or incorporated into its maintenance procedures. The GPS card had also not received a software update intended to address a GPS week-number rollover issue.
Tracey confirmed that the card remained supported by the Australian distributor from which Telstra sourced the equipment and that the carrier had received notiϐication of the update.
Telstra had initially assessed the update as unnecessary because the GPS card was not being used as the server’s primary timing source. Once the undocumented configuration change was made, that assessment was not revisited.
Brady said it was “clearly unacceptable” that routine maintenance could trigger an outage on such a scale. “Had that software update been completed or had the design change been properly documented and reflected in the maintenance procedures, the outage may not have
occurred,” she said.
“We are accountable for that and our external expert investigation will address why that design change was not documented, why the software update was not completed and what needs to change in our controls so known risks are captured, prioritised and closed before they can affect customers.”
“Modern mobile networks are complex, but complexity does not reduce our commitment to prevent failures, detect them quickly and ensure the right safeguards are in place.”
Nationals senator Ross Cadell questioned Telstra executives about the age of the equipment, the history of vendor warnings and the failure to reconsider the software risk after the server’s configuration changed. Cadell referred to a field service bulletin concerning a 1024-week rollover event affecting timing equipment and asked how Telstra had failed to address the risk despite receiving earlier advice.
Telstra said it had identified a notification issued in 2022 and a further reminder from its local support supplier in January 2026. The SSU 2000 involved in the outage was manufactured in 2011.
Cadell also asked why the later configuration change had not automatically prompted a fresh risk assessment. “Surely a design change triggers a review of that risk assessment,” he said.
Brady agreed that it should have. Telstra’s preliminary investigation indicated that the change was not properly documented and that the relevant control had failed. “It does not appear so in our investigation so far. The control did not work,” she said.
Telstra stressed that the incident was not caused by a lack of geographic redundancy. The carrier operates three NTP servers for its mobile network, located in Melbourne, Sydney and Perth, while authoritative time is ultimately derived from multiple Stratum 0 sources, including atomic clocks and GPS.
The failure occurred when the Melbourne server returned to service and distributed information that appeared plausible but was incorrect. Downstream network systems accepted the date as valid.
Most calls and data services recovered by mid-morning on 8 July, but Telstra then had to clear corrupted sessions, invalid IP address ranges and residual timing information from other parts of the network.
Some Triple Zero calls, Voice over Wi-Fi services and wholesale voice trafϐic remained affected during later phases of the incident. The last residual problems were resolved on 11 July.
On the evening of 8 July, Telstra moved the network elements previously served by the Melbourne SSU 2000 onto newer timing equipment already operating elsewhere in its mobile network. It will apply the software update to the equivalent Sydney and
Perth servers and reconsider the timetable for their planned replacement.
ACMA is separately investigating Telstra’s compliance with its Triple Zero and outage-notiϐication obligations.
Rohan Pearce
Telstra pressed on compensation, governance and outage controls
Telstra’s Friday account of its 8 July nationwide mobile outage prompted over two hours of questioning from senators who questioned the carrier’s governance, compensation arrangements, regulatory obligations and ability to identify similar risks elsewhere in its network.
CEO Vicki Brady repeatedly accepted that Telstra’s controls had failed but said internal and external investigations were still determining why an undocumented network change and an unapplied software update had not been detected.
Committee chair Sarah Hanson-Young argued that the outage reϐlected a broader failure of process and accountability rather than an isolated technical fault.
“You’ve got equipment out of date, you’ve got updates, software updates that didn’t work, paperwork that wasn’t filled out, people who didn’t know,” she said.
“It’s not just tech failing. There’s clearly a lack of accountability internally.”
Brady said Telstra’s chief risk office was leading the internal review, supported by specialist firm Technology Audit Partners. Its findings would ultimately be reported through Brady to the Telstra board.
Hanson-Young compared that structure with Optus’ externally led review of its outage and questioned whether Telstra’s chosen investigator would be sufficiently independent.
Brady said Technology Audit Partners had specialist outage expertise and would examine the technical cause, maintenance procedures, risk controls and decisions surrounding the missed software update.
Nationals senator Ross Cadell pursued Telstra over the age of the equipment involved and the history of notifications concerning its GPS module. He challenged the carrier on why advice about a GPS week-number rollover had not led to a software update and why a later decision to use the GPS card as the server’s primary time source had not triggered a fresh risk assessment. Cadell compared the undocumented alteration with allowing a “cowboy” to modify a car without first considering the consequences.
Brady agreed that a new assessment should have occurred. She said Telstra needed to establish who authorised the change, what risk review was conducted and why its ϐirst and second-line controls failed to detect the problem.
The carrier was also pressed on the timing of its public, government and regulatory notiϐications.
Telstra detected the first network problems at 4.20am on 8 July, posted an outage banner at 4.38am and declared a major outage at 7.50am.
It said its initial Triple Zero test calls were successful, although welfare-check volumes began increasing from about 6.30am.
The Triple Zero Custodian was formally notified at 7.14am and the first Triple Zero Disruption Protocol bridge began at 7.20am.
Brady said Telstra’s early public statements reflected the information available at the time. The apparent scale of the incident increased as more customers woke and traffic volumes rose.
During the outage, 58,835 calls to Triple Zero connected successfully, while 604 unsuccessful calls triggered welfare checks. Telstra said 172 of those callers subsequently connected through the Optus or TPG Telecom networks using camp-on.
Of the 604 welfare checks, 335 callers said assistance was not required, 102 said emergency services were already present or had been contacted, and 23 were referred back to emergency services. Another 144 cases were escalated to police after the callers could not be reached. No adverse outcomes were reported.
Senators also asked whether Telstra could determine how many medical alarms, personal safety devices and other Internet of Things services had been affected.
Telstra said such devices generally appeared on its systems as ordinary data connections, limiting its ability to separately identify vulnerable customers or quantify the effects on individual device categories.
Compensation remained unresolved. Hanson-Young questioned why Telstra could not estimate the financial impact on customers or the amount it expected to pay through credits and compensation.
Brady said customers had been affected in different ways and Telstra was assessing claims individually, although she confirmed that potential compensation costs formed part of the company’s outage-risk scenarios. “I don’t have an estimate today for this outage,” she said.
The hearing also examined whether mobile services should be subject to stronger reliability obligations.
Brady said Telstra supported reliability standards but argued that the universal service obligation, which remains centred on copper fixed-line infrastructure, should be modernised to recognise newer technologies.
The proceedings were at times combative and occasionally disorderly. A heckler interrupted proceedings from the public gallery, prompting Hanson-Young to call for order and warn that he would be removed if he continued.
The chair also repeatedly misnamed Brady during the hearing, addressing the Telstra CEO as “Ms Bradley” — including in her closing remarks before excusing the witnesses — despite a nameplate clearly identifying her.
The committee told Telstra it expected the company to return at a future hearing after its investigations had progressed.
Grahame Lynch and Rohan Pearce
IN TODAY’S COMMSDAY (Friday 24 July 2026)
FibreconX expects to roughly double the reach of its network over the next two years as artificial intelligence and hyperscale data centre investment accelerate demand for dark fibre.
The Australian Communications and Media Authority has issued Xenith IG Australia with a formal warning after finding the carrier failed to properly restore land affected by its controversial fibre deployment in Sydney’s Lane Cove area.
Starlink’s aggressive price promotions appear to have accelerated customer losses across NBN Co’s fixed wireless and satellite networks during the June quarter, according to New Street Research analyst Ian Martin.
Australia should develop a national space spectrum strategy to manage the growing pressure from direct-to-device services and large low Earth orbit constellations, according to a new report from the Australasian Centre for Space Governance.
Data centres should be required to fund new renewable generation matching their electricity demand and reduce consumption during periods of grid stress, the NSW Net Zero Commission has recommended, warning the sector could add the equivalent of 13% of the state’s current power demand by 2035.
Major ICT sellers offered almost $499,000 in gifts and benefits to Australian Public Service employees over 12 months, although public servants declined the overwhelming majority of offers, according to a Digital Transformation Agency review.
New Zealand should formally recognise connectivity as essential infrastructure and establish a national register identifying the connection type and resilience profile of every address, according to TUANZ.
Mercury NZ has invested US$30 million (NZ$53 million) for a 12.7% stake in Datagrid NZ, deepening its involvement in the developer’s proposed 360MW data centre campus in Southland.
Alphabet directed about 40% of its technical infrastructure investment during the June quarter towards data centres and networking equipment, highlighting the growing importance of connectivity in supporting large-scale artificial intelligence systems.
Strand Consult has challenged a GSMA Intelligence estimate that removing designated high-risk vendors from European telecoms networks would cost operators about €35 billion, arguing most carriers have already made the transition and the remaining bill is concentrated among operators that ignored years of policy warnings.
Nokia has reported a 9% increase in second-quarter sales in constant currency terms, driven by surging demand from artificial intelligence and cloud customers.
Spark has appointed KPN executive Tommy Bjorkberg as chief operating officer, effective 1 October, with responsibility for network operations, business technology services and cyber security.
Optus has appointed former NBN Co state government relations general manager Laura Clarke as general manager, stakeholder engagement.
Australia should direct more AI data centre investment to its north to reduce geographic concentration risks and ease pressure on Sydney and Melbourne’s electricity and urban infrastructure, according to an Australian Strategic Policy Institute analyst.
_______________________________
CommsDay is published by Decisive Publishing, S704 6A Glen St Milsons Point NSW
ACN: 065 084960 Mailing Address: PO Box 490 Milsons Point NSW 1565 Australia
TO SUBMIT EDITORIAL FEEDBACK OR INQUIRIES: gr**********@**********il.com
TO ENQUIRE ABOUT A SUBSCRIPTION: vi***@**********il.com