Part of the NTP protocol is, that the client can syncronize with several NTP server.
If more than one server is configured, it selects the one with the best stratum value.
If several with the same stratum are configured, the client will do a round robbin at every start of the NTP protocol.
This means, that an Attacker must spoof more than one server to be sure, that a sufficient number of clients are on the fake time.
Also as there are a large number of NTP server available in the Internet, and most people use NTP server located on their continent, it would be a huge effort to attack the network by spoofing NTP servers, as an attacker would have to spoof several NTP server managed by several provider/companies all over the world.
I don’t see a big risk here.