Why is this an operational design problem rather than a signal problem?
Much of the discussion about remote-worker safety begins with a coverage question: will a phone work there? That question matters, but it is too narrow for the operating reality of Libya. A journey may begin in a connected city, pass through intermittent service, and end at an isolated field location. A maintenance team may work within reach of a site network but lose it on the road. A contractor may have a functioning handset while the operations room has no agreed procedure for recognising that a routine delay has become an exception.
The geography alone justifies a more deliberate approach. The US Energy Information Administration reports that about 95 per cent of Libya's recoverable oil reserves are concentrated in the onshore Sirte Basin in the northeast and the Murzuq Basin in the southwest. It also describes oil and gas activity across onshore fields, coastal infrastructure, and offshore assets.1 The World Bank classifies approximately 95 per cent of Libya's area as hot desert, with the Mediterranean and Sahara producing marked differences in conditions across the country.2 These are not small, uniform operating areas where continuous mobile service can simply be assumed.
For oil and gas operators, engineering and construction contractors, utilities, logistics providers, and specialist service companies, the practical challenge is larger than telecommunications. It is knowing what was expected, when contact was last confirmed, what should happen next, and who owns that action. Connectivity is one component of that control system. It is not the control system itself.
What should be decided before a remote movement begins?
A safe journey starts before the engine does. The International Association of Oil & Gas Producers defines journey management as a process for protecting the travelling workforce before, during, and after travel. Its guidance calls for systematic risk assessment, careful trip planning, vehicle controls, and attention to driver fatigue.3 The UK Health and Safety Executive similarly advises organisations to consider whether a journey is necessary, choose a suitable route, allow realistic time, account for weather and working hours, and investigate incidents and near misses.4
In a Libyan industrial setting, that planning should create an operational agreement, not merely a form. The organisation needs to know the route, people, vehicle, movement window, foreseeable hazards, communication methods, and monitoring owner. It should also decide what constitutes an overdue Check-In and what the operator will do if contact is not restored.
The timing cannot be generic. Thirty minutes without contact during a routine transfer between two staffed locations may mean something different from thirty minutes after a team enters a remote work area. Thresholds should reflect exposure, journey stage, available support, and the likely consequence of delay.
A moving marker may show a last-known position, but it does not explain the plan. A message history may show attempted contact without establishing who owns the next decision. The aim is not to collect more data. It is to preserve the meaning of the operation when circumstances change.
What does a loss of contact actually tell the operations room?
Silence is ambiguous. A missed Check-In can indicate a technical problem, a depleted device, a change of plan, a person who has forgotten to respond, or a genuine safety or security event. It is evidence of uncertainty, not proof of harm. Treating every missed response as an emergency creates noise. Treating every missed response as routine creates delay.
The response procedure should therefore separate observation from interpretation. First, the operator needs to establish what is known. That includes the last confirmed contact, the time and source of any location, the planned route, the expected next action, the status of attempted communications, and relevant local conditions. The operator can then follow the organisation's standard operating procedure to verify welfare, contact a supervisor or site, use an alternate channel, or open an incident when the defined threshold is met.
Lone-working guidance from the Health and Safety Executive explains why that discipline matters. Lone workers may face greater consequences when something goes wrong because immediate help or support is not available. The recommended response is not simply to issue equipment, but to provide training, supervision, monitoring, and support.5 Remote industrial work is not always lone work in the strict sense, but a small team outside dependable communications can face the same operational problem: the support organisation may be unable to distinguish normal progress from emerging difficulty.
When the procedure states who is monitoring, how long to wait, which channel to try next, and who can authorise escalation, the response is less dependent on individual judgement under pressure. ISO 22320 emphasises defined roles and responsibilities, task and resource management, and cooperation between participating organisations.6 Those principles apply to a developing field exception as well as to a declared incident.
Where should satellite communications fit?
Satellite should be treated as a designed resilience layer, not an emergency purchase kept in a cupboard and not a universal replacement for mobile service. The everyday channel will often remain a smartphone because it is familiar, capable, and efficient where cellular data is available. The satellite layer becomes important for selected people, vehicles, routes, or sites where the consequences of losing contact justify the additional equipment, airtime, training, and administration.
One useful planning model is PACE, which stands for Primary, Alternate, Contingency, and Emergency. Guidance from the US Cybersecurity and Infrastructure Security Agency describes PACE planning as a way to identify successive communication options before the primary system fails. It also stresses the importance of plans, training, and exercises rather than trying to improvise after disruption.7 An industrial operator might use cellular data as the primary means for a given journey, voice or SMS as an alternate, a compatible satellite device as a contingency, and an agreed emergency action when two-way contact is no longer possible. The actual sequence should be determined by the operation, not copied from a template.
Satellite capability also needs realistic expectations. GSMA analysis describes satellite direct-to-device connectivity as a way to extend service into remote and underserved areas and add resilience, while making clear that it supplements rather than replaces terrestrial mobile networks because of capacity and spectral constraints.8 Dedicated satellite messengers and phones differ from direct-to-device services, but the wider lesson is the same. Resilience comes from matching each bearer to the communication task it can credibly support.
For some roles, the requirement may be a brief welfare message or scheduled location update. For others, it may be two-way communication during a prolonged movement. The team should decide which minimum information must cross the link, how it will be expressed, and what acknowledgement means.
AtlasNXT can support a smartphone-led model for alerts, Check-Ins, Panic, Overwatch, and location-enabled functions where appropriate. Compatible satellite devices can support selected users beyond cellular coverage, subject to the hardware, airtime, and configuration chosen for the operation. This is not a claim of automatic switching between cellular and satellite, guaranteed delivery, or uninterrupted tracking. It is a way to design different communication options around real exposure.
Why is a second device not enough on its own?
A backup channel only strengthens the operation if it is available, independent enough to survive the relevant failure, and understood by the people expected to use it. A device can be present but uncharged. Airtime can have expired. A user can carry the equipment without knowing how to send the agreed message. A control room can receive data but lack an assigned operator. A satellite terminal can be suitable for one site configuration and impractical for another. Local permissions, information security requirements, and equipment controls can also shape what may be deployed.
These are reasons to operationalise the satellite layer. The deployment plan should identify the users and journeys covered, the inspection routine, the agreed messages, the monitoring responsibility, and the response procedure. Contractors need the same clarity as employees when they are inside the organisation's duty-of-care model.
The distinction between two suppliers and two genuinely different failure paths is important. Cabinet Office guidance notes that apparently separate services can share infrastructure and dependencies, so diversity should be examined rather than assumed.9 The review should follow the chain from the field device to the person who must act, including power, account status, configuration, network availability, the receiving application, and staffing.
How can location support safety without becoming permanent surveillance?
Location is most useful when it answers an operational question. Has a team reached the site? Where was a person when contact was last confirmed? Who may be affected by an incident in a defined area? Those questions do not require the same frequency, duration, or precision of collection.
The OECD Privacy Guidelines provide a durable framework for making that distinction. They call for limits on personal-data collection, relevance to the stated purpose, specified uses, reasonable security safeguards, openness, and accountability.10 The operational implication is that location should be designed around the duty-of-care purpose rather than gathered indefinitely because the technology permits it.
Depending on the role, risk, policy, and applicable requirements, AtlasNXT location can be live, event-led, or consent-based where appropriate. A journey to a remote facility may justify location during the movement window. A technician entering a defined work area may need a different arrangement. A senior traveller passing through a connected city may need alerts and Check-Ins without continuous location. The correct model depends on what the customer wants, the purpose of the processing, and the governance that applies.
Transparency is operationally valuable as well as respectful. People should know when location operates, why it exists, who can see it, how it will be used during an exception, and when it stops. Remits in AtlasNXT can define geographic responsibility and authorised views so that access reflects operational roles. Suitable authorised data should only enter the platform through agreed permissions, formats, security controls, and approved integration or import methods.
What should a useful operational picture show?
The phrase “single pane of glass” is often used as though consolidation were the final objective. It is not. Bringing every feed onto one screen can still leave an operator with a crowded map, duplicate alerts, and no clear next action. A useful operational picture reduces ambiguity around the people, places, communications, and decisions that matter now.
For routine remote work, the operator should distinguish a current position from a last-known one and see its time. A communication that was initiated, one that was delivered, and one that was acknowledged are not equivalent. Planned movements, expected Check-Ins, non-responses, and assigned actions need enough context to be interpreted.
During an incident, that same picture needs continuity. AtlasNXT's Incident Room can keep significant updates, tasks, communications, decisions, and status changes with one event. That creates a shared place for the response team to understand what has happened and what remains outstanding. It does not remove the need for leadership, judgement, or standard operating procedures. It gives those elements a clearer information structure.
Where several businesses share an operating environment, each may retain its own responsibilities. ISO 22320 recognises that organisations can work together during an incident while keeping their own structures.6 The objective is an agreed picture in which authorised participants can act without losing accountability.
How should an exception become an incident?
The transition should be defined before it is needed. Consider an overdue team travelling to a remote installation. The first missed Check-In may trigger a verification step. Continued silence after alternate contact attempts may require the journey manager to consult the site and review the last-known information. A route deviation, a distress message, or credible local reporting may justify opening an incident sooner. The threshold should reflect the operating context and the organisation's approved procedure.
Once an incident is opened, the record should preserve both facts and decisions. A location point without its timestamp can mislead. A message without its delivery status can be mistaken for contact. An instruction without an owner can appear complete while nobody acts. Recording who knew what, when they knew it, what they decided, and what happened next improves current coordination and creates a more reliable basis for later review.
That record also helps organisations learn without reducing every review to individual error. HSE guidance advises employers to report and investigate work-related road incidents and near misses, identify underlying causes, and assess whether controls need to change.4 In remote operations, the important lesson may sit in the communication plan, the journey threshold, the equipment allocation, the handover between shifts, or the assumptions made about coverage. A coherent event history makes those patterns easier to find.
What should be tested before the model is relied upon?
Testing should begin with ordinary operations. Select representative routes, roles, shifts, and contractors. Confirm the smartphone workflow where cellular service is available, then test the satellite process at locations and times resembling the real exposure. Verify that the receiving team can interpret the message and take the next step, including across a shift change.
The exercise should include failure by design. Remove the primary bearer, allow a Check-In to become overdue, and require an operator to distinguish current information from stale information. Measure the time taken to recognise the exception, establish confidence in the facts, allocate an owner, and close the loop with the field user.
PACE guidance is explicit that plans need training and exercises.7 The value is discovering gaps while there is time to correct them. The result may be a technology change, a clearer message format, a different monitoring window, better battery discipline, or a more realistic escalation threshold.
ReachScore™ can help expose communication-readiness gaps, but it is not a guarantee that every message will be delivered. Used properly, it supports a more precise question than “are we connected?” It helps an organisation examine whether its communication arrangements are appropriate for the people and circumstances in scope.
What does good duty of care look like beyond the coverage map?
It looks less like universal tracking and more like deliberate operational design. The organisation knows which movements matter, which people need additional provision, which communication task must survive a coverage loss, and what the control room will do when information becomes incomplete. Smartphone and satellite capabilities are assigned according to exposure. Location is proportionate to purpose. Exceptions have owners, incidents have coherent records, and exercises test the assumptions before a real event does.
Libya's industrial geography makes this discipline especially relevant, but the underlying principle is universal. A loss of signal should not arrive as a surprise in a remote operation. It should be a condition the system was designed to handle.
Book a free AtlasNXT demonstration to explore how a mobile-first, satellite-supported duty-of-care model could be configured around your people, journeys, sites, and operating procedures.
References
1. US Energy Information Administration, Libya Country Analysis Brief, updated 3 December 2024. https://www.eia.gov/international/content/analysis/countries_long/libya/
2. World Bank Climate Change Knowledge Portal, Libya Climate Risk Country Profile. https://climateknowledgeportal.worldbank.org/sites/default/files/country-profiles/16998-WB_Libya%20Country%20Profile-WEB.pdf
3. International Association of Oil & Gas Producers, Land transportation safety recommended practice: journey management, Report 365-19, 2020. https://www.iogp.org/bookstore/product/iogp-report-365-19-land-transportation-safety-recommended-practice-journey-management/
4. Health and Safety Executive, Driving and riding safely for work: plan and manage journeys. https://www.hse.gov.uk/roadsafety/employer/plan-manage-journeys.htm
5. Health and Safety Executive, Protecting lone workers: how to manage the risks of working alone, INDG73(rev4), 2020. https://www.hse.gov.uk/pubns/indg73.htm
6. International Organization for Standardization, ISO 22320:2018 Security and resilience: emergency management: guidelines for incident management. https://www.iso.org/standard/67851.html
7. Cybersecurity and Infrastructure Security Agency, Prepare Your Critical Communications for When You Need Them Most, updated February 2025. https://www.cisa.gov/sites/default/files/2025-02/Updated_PACE_Flyer_022025.pdf
8. GSMA, The Limits of D2D, 27 February 2026. https://www.gsma.com/connectivity-for-good/spectrum/gsma_resources/the-limits-of-d2d/
9. UK Cabinet Office, Telecoms resilience, updated 5 December 2019. https://www.gov.uk/guidance/telecoms-resilience
10. OECD, Recommendation of the Council concerning Guidelines Governing the Protection of Privacy and Transborder Flows of Personal Data. https://legalinstruments.oecd.org/public/doc/114/body-text.en.html



