Summary

  • Backup generation does not establish how long a priority mobile site will carry its required load during a prolonged outage.
  • A defensible local control verifies endurance, access, refuelling and escalation together while keeping sensitive infrastructure details out of the public record.

The generator starts but the continuity claim fails

A storm removes grid power across several districts. A priority mobile site transfers to backup generation, and the first status report calls it protected. Later, the duty team discovers that the stated runtime came from a nameplate calculation rather than the site’s present load. The refuelling vehicle is available, but its driver is not authorised to enter the controlled compound. The access contact is off duty, the delivery window is longer than the remaining fuel estimate, and the local restoration list does not identify who can resolve the conflict.

The generator may be running. The local continuity chain is not yet under control.

This is not an argument that every cell site requires identical backup power. It is a narrower test: where local responders or providers rely on a site for a priority communications function, the assumptions connecting load, endurance, access, fuel and restoration must be visible to the authorised people who act on them.

What the public guidance establishes

Ofcom’s network and service resilience guidance takes a risk-based approach. Its mobile-RAN material expects providers to manage reasonably foreseeable power outages and indicates that sites serving more customers may need longer endurance, potentially including generators that can be refuelled while operating. That establishes why duration and replenishment matter. It does not establish the runtime of any particular site.

UK government material also treats telecom power resilience as a cross-sector problem. EC-RRG’s remit includes work with the power sector, understanding fuel-supply disruption and supporting Local Resilience Forums. Those responsibilities explain why local planning cannot stop at a provider’s equipment inventory. They do not transfer operational control of a provider network to a local forum.

Cabinet Office telecoms-resilience guidance adds a practical boundary: backup-power arrangements should be tested under realistic load and for a period that tests site-specific arrangements. A generic generator specification, an unexercised fuel contract or an optimistic restoration estimate cannot substitute for that evidence.

A narrow power-continuity record

The useful local record can remain compact. It can identify the service function whose loss matters, the accountable provider role, the load basis used for the endurance estimate, the last controlled test, the earliest decision point for replenishment, the authorised site-access route, the fuel-delivery owner, the restoration liaison and the unresolved constraint.

Exact coordinates, access codes, fuel quantities, network topology and security procedures belong in restricted operational systems. A shared coordination view should expose a missing owner or an untested dependency without becoming a map of sensitive infrastructure.

The distinction between fields matters. Load evidence shows what the backup plant actually carried. Endurance evidence shows how long it carried that load under the test conditions. Access evidence shows that authorised maintenance or delivery personnel can reach the equipment when normal arrangements are disrupted. Replenishment evidence shows who orders fuel, who supplies it and when the decision must be made. Restoration evidence shows how the site’s communications consequence is represented in cross-sector priorities.

None of those observations is a permanent guarantee. Each has a date, a scope and a condition that can change.

Exercise the replenishment chain, not only the start switch

A monthly start test can reveal a failed battery or generator, but it does not show that the site will carry its operational load or receive fuel during a regional incident. A bounded exercise should begin with a plausible grid-loss duration, use an approved representation of site load, calculate a decision point before exhaustion, contact the authorised access and fuel roles, test an obstructed-route or delayed-delivery branch, and record how restoration priority is communicated.

The exercise need not interrupt live service or disclose site details. A controlled simulation can use protected identifiers and agreed test channels. Where a live load test is authorised, its safety and service protections remain with the responsible operator. The local objective is to find broken hand-offs before an incident, not to take over technical operation.

A useful failure is specific. “Fuel delivery delayed because the access authority was not reachable” creates an owner and a retest condition. “Generator arrangements reviewed” does not.

Perspective

Treat backup power as a chain of decisions rather than a photograph of equipment. Keep a site-specific record of tested load, bounded endurance, access, replenishment authority, escalation and restoration coordination, then exercise the hand-offs that connect them. The result is dated evidence about a defined scenario—not a promise that a mobile site will remain available through every outage.

Sources