By Eddy Zervigon
The U.S. government is increasingly concerned about the potential for quantum computing-based attacks. In June, the White House signed the “Securing the Nation Against Advanced Cryptographic Attacks” executive order to support critical infrastructure, including energy, in preparing for this new threat landscape.
What makes this threat so concerning is that cryptographically-relevant quantum computers will be able to break the public key cryptography that underpins nearly everything that keeps a power plant or utility secure, ranging from encrypted data to authorized users and devices, and control system commands and readings.
Recent estimates put cryptographically-relevant machines as early as 2029, and the timeline could compress further as nation-states pour billions into the race.
Executives must prioritize these risks now.
Harvest Now, Decrypt Later
Adversaries are intercepting and storing encrypted utility data today, betting they can decrypt it once quantum computers are ready, in a strategy known as “harvest now, decrypt later.” The grid is an ideal target because so much of its traffic has a long shelf life: relay protection settings, plant control system configurations, generator and turbine control parameters, network topology, and interconnection data. Stolen passwords expire, but a map of how a plant’s controls tie into its switchyard or how substations talk to the control center doesn’t.
Live Surveillance
Once nation-states have access to cryptographically-relevant quantum computers, the fundamental security of communications, telemetry, and command links could be broken, in some cases at or near real-time. This gives adversaries ongoing visibility into sensitive operations, letting them see exactly how these systems run and how best to target them, along with other downstream systems.
The Attack on Data Integrity
When encryption is broken, an attacker can cause physical harm without the need for insider access or software vulnerabilities, just by manipulating the data that the control room and its systems see. This can include SCADA telemetry, breaker status, turbine speed, voltage, frequency, etc. The deception runs two ways: it can hide a real problem behind seemingly normal readings while a machine is actually being damaged, or it can manufacture an emergency that causes confusion and may drive automated protection schemes to act.
Sabotage and the Ultimate Insider Threat
When public key cryptography breaks, there is no meaningful distinction between an outside intruder and a trusted insider. This means that malicious firmware signed with a forged certificate will look identical to a legitimate vendor update. Similarly, a forged command to trip a breaker or disable a generator’s protection looks like a lawful instruction to the equipment that receives it. In this scenario, the adversary essentially steps into the control loop as the operator. The physical consequences can be severe, from damaged equipment to induced outages.
The Stakes Rise Where There Is No Grid
These risks intensify for a fast-growing class of facilities: AI data centers built with their own dedicated, on-site power. These electrical islands lack an important safety net. When an ordinary plant falters, neighboring generation and external supply can absorb the shock, but an “islanded” project has no such fallback. An adversary who breaks the cryptography protecting that island’s telemetry and command links can take both the on-site power system and the data center down at the same time.
What the Power Industry Needs to Do Now
Here are several priorities for executives:
Act on the obvious before the inventory is complete. A cryptographic inventory, which maps where keys and certificates live across OT and IT, is the foundation of any post-quantum cryptography (PQC) migration, but it cannot become a gate. Where a remote access path or a vendor connection is already known to be quantum-vulnerable, remediation should begin in parallel. Secure the biggest pipes now while identifying other points of vulnerability.
Prioritize by data lifetime and consequence. Grid topology, protection settings, engineering diagrams, and other valuable information stay sensitive for decades and are being harvested today, so that data should be protected first, followed by the channels and devices that can move physical equipment.
Build for crypto-agility, and use overlays where rip-and-replace isn’t possible. Avoid hard coding algorithms and, instead, centralize cryptographic management, so the algorithms can be swapped as standards evolve. Hybrid classical-and-PQC cryptography eases the transition on upgradable gear. For constrained field devices, overlays such as out-of-band key delivery protect legacy links without re-engineering every endpoint. This keeps the system operating with no downtime.
Compensate for what can’t be upgraded. For equipment that won’t be quantum-safe before replacement, make sure to impose tight segmentation and least privilege access, deploy quantum-safe gateways at the boundary, and monitor for anomalies to shrink what an attacker can reach and how long an intrusion can hide.
Make post-quantum readiness a procurement requirement now. Gear bought this cycle will still be running past Q-Day, so its cryptographic future is set at the purchase order. Contracts should require NIST’s finalized standards, field-updatable crypto-agility, and a cryptographic bill of materials.
Eddy Zervigon is CEO of Quantum XChange.
This article was originally published by RealClearEnergy and made available via RealClearWire.
Power Operators Must Plan Now for Four Quantum Attacks
By Eddy Zervigon
The U.S. government is increasingly concerned about the potential for quantum computing-based attacks. In June, the White House signed the “Securing the Nation Against Advanced Cryptographic Attacks” executive order to support critical infrastructure, including energy, in preparing for this new threat landscape.
What makes this threat so concerning is that cryptographically-relevant quantum computers will be able to break the public key cryptography that underpins nearly everything that keeps a power plant or utility secure, ranging from encrypted data to authorized users and devices, and control system commands and readings.
Recent estimates put cryptographically-relevant machines as early as 2029, and the timeline could compress further as nation-states pour billions into the race.
Executives must prioritize these risks now.
Harvest Now, Decrypt Later
Adversaries are intercepting and storing encrypted utility data today, betting they can decrypt it once quantum computers are ready, in a strategy known as “harvest now, decrypt later.” The grid is an ideal target because so much of its traffic has a long shelf life: relay protection settings, plant control system configurations, generator and turbine control parameters, network topology, and interconnection data. Stolen passwords expire, but a map of how a plant’s controls tie into its switchyard or how substations talk to the control center doesn’t.
Live Surveillance
Once nation-states have access to cryptographically-relevant quantum computers, the fundamental security of communications, telemetry, and command links could be broken, in some cases at or near real-time. This gives adversaries ongoing visibility into sensitive operations, letting them see exactly how these systems run and how best to target them, along with other downstream systems.
The Attack on Data Integrity
When encryption is broken, an attacker can cause physical harm without the need for insider access or software vulnerabilities, just by manipulating the data that the control room and its systems see. This can include SCADA telemetry, breaker status, turbine speed, voltage, frequency, etc. The deception runs two ways: it can hide a real problem behind seemingly normal readings while a machine is actually being damaged, or it can manufacture an emergency that causes confusion and may drive automated protection schemes to act.
Sabotage and the Ultimate Insider Threat
When public key cryptography breaks, there is no meaningful distinction between an outside intruder and a trusted insider. This means that malicious firmware signed with a forged certificate will look identical to a legitimate vendor update. Similarly, a forged command to trip a breaker or disable a generator’s protection looks like a lawful instruction to the equipment that receives it. In this scenario, the adversary essentially steps into the control loop as the operator. The physical consequences can be severe, from damaged equipment to induced outages.
The Stakes Rise Where There Is No Grid
These risks intensify for a fast-growing class of facilities: AI data centers built with their own dedicated, on-site power. These electrical islands lack an important safety net. When an ordinary plant falters, neighboring generation and external supply can absorb the shock, but an “islanded” project has no such fallback. An adversary who breaks the cryptography protecting that island’s telemetry and command links can take both the on-site power system and the data center down at the same time.
What the Power Industry Needs to Do Now
Here are several priorities for executives:
Act on the obvious before the inventory is complete. A cryptographic inventory, which maps where keys and certificates live across OT and IT, is the foundation of any post-quantum cryptography (PQC) migration, but it cannot become a gate. Where a remote access path or a vendor connection is already known to be quantum-vulnerable, remediation should begin in parallel. Secure the biggest pipes now while identifying other points of vulnerability.
Prioritize by data lifetime and consequence. Grid topology, protection settings, engineering diagrams, and other valuable information stay sensitive for decades and are being harvested today, so that data should be protected first, followed by the channels and devices that can move physical equipment.
Build for crypto-agility, and use overlays where rip-and-replace isn’t possible. Avoid hard coding algorithms and, instead, centralize cryptographic management, so the algorithms can be swapped as standards evolve. Hybrid classical-and-PQC cryptography eases the transition on upgradable gear. For constrained field devices, overlays such as out-of-band key delivery protect legacy links without re-engineering every endpoint. This keeps the system operating with no downtime.
Compensate for what can’t be upgraded. For equipment that won’t be quantum-safe before replacement, make sure to impose tight segmentation and least privilege access, deploy quantum-safe gateways at the boundary, and monitor for anomalies to shrink what an attacker can reach and how long an intrusion can hide.
Make post-quantum readiness a procurement requirement now. Gear bought this cycle will still be running past Q-Day, so its cryptographic future is set at the purchase order. Contracts should require NIST’s finalized standards, field-updatable crypto-agility, and a cryptographic bill of materials.
Eddy Zervigon is CEO of Quantum XChange.
This article was originally published by RealClearEnergy and made available via RealClearWire.
Share this: