The U.S. government is increasingly concerned about the potential for quantum computing-based attacks. In June, the White House signed the “Securing the Nation Against Advanced Cryptographic Attacks” executive order to support critical infrastructure, including energy, in preparing for this new threat landscape.
What makes this threat so concerning is that cryptographically-relevant quantum computers will be able to break the public key cryptography that underpins nearly everything that keeps a power plant or utility secure, ranging from encrypted data to authorized users and devices, and control system commands and readings.
Recent estimates put cryptographically-relevant machines as early as 2029, and the timeline could compress further as nation-states pour billions into the race.
Executives must prioritize these risks now.
Harvest Now, Decrypt Later
Adversaries are intercepting and storing encrypted utility data today, betting they can decrypt it once quantum computers are ready, in a strategy known as “harvest now, decrypt later.” The grid is an ideal target because so much of its traffic has a long shelf life: relay protection settings, plant control system configurations, generator and turbine control parameters, network topology, and interconnection data. Stolen passwords expire, but a map of how a plant’s controls tie into its switchyard or how substations talk to the control center doesn’t.
Live Surveillance
Once nation-states have access to cryptographically-relevant quantum computers, the fundamental security of communications, telemetry, and command links could be broken, in some cases at or near real-time. This gives adversaries ongoing visibility into sensitive operations, letting them see exactly how these systems run and how best to target them, along with other downstream systems.
The Attack on Data Integrity
When encryption is broken, an attacker can cause physical harm without the need for insider access or software vulnerabilities, just by manipulating the data that the control room and its systems see. This can include SCADA telemetry, breaker status, turbine speed, voltage, frequency, etc. The deception runs two ways: it can hide a real problem behind seemingly normal readings while a machine is actually being damaged, or it can manufacture an emergency that causes confusion and may drive automated protection schemes to act.
Sabotage and the Ultimate Insider Threat
When public key cryptography breaks, there is no meaningful distinction between an outside intruder and a trusted insider. This means that malicious firmware signed with a forged certificate will look identical to a legitimate vendor update. Similarly, a forged command to trip a breaker or disable a generator’s protection looks like a lawful instruction to the equipment that receives it. In this scenario, the adversary essentially steps into the control loop as the operator. The physical consequences can be severe, from damaged equipment to induced outages.
The Stakes Rise Where There Is No Grid
These risks intensify for a fast-growing class of facilities: AI data centers built with their own dedicated, on-site power. These electrical islands lack an important safety net. When an ordinary plant falters, neighboring generation and external supply can absorb the shock, but an “islanded” project has no such fallback. An adversary who breaks the cryptography protecting that island’s telemetry and command links can take both the on-site power system and the data center down at the same time.
What the Power Industry Needs to Do Now
Here are several priorities for executives:
Act on the obvious before the inventory is complete. A cryptographic inventory, which maps where keys and certificates live across OT and IT, is the foundation of any post-quantum cryptography (PQC) migration, but it cannot become a gate. Where a remote access path or a vendor connection is already known to be quantum-vulnerable, remediation should begin in parallel. Secure the biggest pipes now while identifying other points of vulnerability.
Prioritize by data lifetime and consequence. Grid topology, protection settings, engineering diagrams, and other valuable information stay sensitive for decades and are being harvested today, so that data should be protected first, followed by the channels and devices that can move physical equipment.
Build for crypto-agility, and use overlays where rip-and-replace isn’t possible. Avoid hard coding algorithms and, instead, centralize cryptographic management, so the algorithms can be swapped as standards evolve. Hybrid classical-and-PQC cryptography eases the transition on upgradable gear. For constrained field devices, overlays such as out-of-band key delivery protect legacy links without re-engineering every endpoint. This keeps the system operating with no downtime.
Compensate for what can’t be upgraded. For equipment that won’t be quantum-safe before replacement, make sure to impose tight segmentation and least privilege access, deploy quantum-safe gateways at the boundary, and monitor for anomalies to shrink what an attacker can reach and how long an intrusion can hide.
Make post-quantum readiness a procurement requirement now. Gear bought this cycle will still be running past Q-Day, so its cryptographic future is set at the purchase order. Contracts should require NIST’s finalized standards, field-updatable crypto-agility, and a cryptographic bill of materials.
Eddy Zervigon is CEO of Quantum XChange.
This article was originally published by RealClearEnergy and made available via RealClearWire.
Isolate the energy plants. Anything can be attacked on the internet or local web if you are on it. Operational programs only and only in a small closed loop without internet access. One USB port for transferring operating information to management, heavily guarded both physically and data wise. No exceptions. Sound unusable? Your option is being hacked from the outside.
I can understand why some power plants need centralized control. Private secure networks might be a solution for that.
I think public infrastructure like water supplies should be disconnected from the internet entirely.
AI is going to be better at finding the software flaws than humans. We should expose our critical infrastructure to them as little as possible.
Someone below suggested having 5 people at a centralized site to run a power system, to avoid paying salaries to a whole bunch of people at different sites. I would submit that a lot of stuff in a power plant cannot be handled remotely–you need engineers and mechanics and maintenance people and welders and all sorts of specialized skills just to keep the place from falling apart. Even wind turbines, which are simpler, need regular maintenance and attention by real people.
Yes. During all the Covid nonsense, we still had to have at least 2 “essential” personnel on site. I was one of them. Even then, we weren’t supposed to be together in the same room.
(Kind of tough to collect and run water samples or physically switch out an empty chorine cylinder remotely.)
After we got our 2nd SCADA system at the water plant I retired from, it was set up were the supplier/support couldn’t access our system remotely. (They were in Canada. We were in Ohio.)
If they needed to access our system remotely, they made a phone call and someone at the plant needed to physically flip a switch to turn on the modem.
(I don’t think the 3rd version required that but their connection still had to pass through a number of physical “boxes”/blocks that required permissions. They could initially “read” the system but but couldn’t change anything without the permissions.
our water supplies are under attack.
I read about a couple of hacker attempts on water facilities in the last few days, blamed on Iranian hackers.
Yes, they are. I remember a story where someone got into a plant’s control system and messed up their alum feed system.
An alert operator spotted the alum feed problem and fixed it (I don’t remember if he fixed the computer problem or manually took over.) before it became a headline.
We need computer blocks in place but we also need alert and competent “boots on the ground”.
You have a point. When I worked in a power plant, vintage 1950, all the dials and gauges were vacuum driven (I think) and info was reported by phone to dispatch. Newer plants had electronic and computer dials and gauges, and a computer link to dispatch. Maybe it is time to go back to a modern version of that model.
From the above article:
“Once nation-states have access to cryptographically-relevant quantum computers, the fundamental security of communications, telemetry, and command links could be broken, in some cases at or near real-time.”
Hmmmmmm . . . me, I’m not so mch worried about those power plants as I am about the nuclear missile launch codes, both ours and theirs.
Have a red telephone on a landline, fibreoptic, at each launch site attended 24/7 by two officials.
Yes, cut AI out of the equation.
I do not know the process in place today, but in times past there were two officers, each with a key, and both keys had to be turned at the same time. The key slots were farther apart than a single person could manage and if the time delay between key turns exceeded a very short interval, the system was disabled.
Apparently, few actual or potential commenters have considered the movie Dr. Strangelove and the automatic “doomsday machine” it envisioned.
Catch Peter Sellers, in his wonderful acting as Dr. Strangelove, stating that “The technology required is easily within the means of even the smallest nuclear power.” (starting at time hack 2m22s into this linked YouTube video: https://www.youtube.com/watch?v=2yfXgu37iyI )
Side note: it is fascinating to me that this movie (from 1964) actually foretells the development of Artificial Intelligence (AI) starting at about the 3m35s time hack into the referenced YouTube excerpt, even though there is mention of “programmed into a taped memory bank”!
Oh well, we (humanity) certainly know better than to “build such a thing”, right? Right?
IKR
Dear Earthlings,
Do not connect all your things to all your other things.
If you do, you will never be admitted to the galactic federation.
Put local watchers over each module.
Yours sincerely,
Your local watch-being
I always thought the IOT (internet of things) crap devices were a bad idea.
She’ll be right mate-
Origin Energy confirms unauthorised access to customers’ personal information | 7NEWS
I was involved in IT when the very last thing you would do would be to put critical data online. Air gaps were de rigueur for serious security.
Not having much idea at all about the subject matter I turned to grok for a summary and critique. I’m still not sure why everything has to be connected to everything else.
Overall Assessment
The article is mostly accurate on the risks and offers sound, high-level advice for utilities—worth reading for operators. Quantum crypto migration is a legitimate “prepare now” issue for any long-lived infrastructure, similar to Y2K or IPv6 transitions. However, it leans alarmist and vendor-driven, with optimistic threat timelines and insufficient balance on feasibility, costs, and layered defenses. Utilities should treat this seriously but integrate it into broader risk management rather than as an urgent standalone panic.
Recommendation: Cross-reference with official sources like NIST PQC standards, CISA guidance, and independent analyses. Pilot crypto-agility where feasible, but don’t neglect fundamentals like network segmentation and physical security. The real challenge is prioritization amid competing demands (reliability, renewables integration, cyber from today’s threats).
“I’m still not sure why everything has to be connected to everything else.”
Because when we can control everything remotely, we don’t have to hire people to be on site to flip switches and turn valves and reset breakers. Instead of paying the salaries of 50 people at 30 different remote sites, we can pay the salaries of 5 people in one central control room. And because it costs too much for us to run dedicated hardline comms networks to our remote equipment, we’ll just leverage what’s already available…the internet. But, hey, we’ll use VPN encryption to make sure our stuff is secure so it’ll never be a problem right?
Right?
That’s a good description of the current situation.
Maybe economizing too much is bad for our collective futures.
I hate to break it to you, but no system is perfect and if quantum computing is as powerful as everyone is letting on, protection schemes won’t be able to be adapted quickly enough to counter the attacks.
To effectively protect a system you have to be successful 100% of the time in the face of thousands or millions of attacks. To destroy a system you only have to be successful once among all those thousands or millions of attacks.
The only effective means of protecting vital systems is to remove all possibility of external access…that means completely air gapping them from the internet and any other external communications systems (like public cellular data or RF data transmission systems).
The expense of creating stand alone, hardline communications and data systems in parallel to the internet would be staggering, and I don’t know if it would even be possible, let alone practical.
What that means to me is: it’s going to happen. Our vital systems are going to be compromised and severely damaged. It’s not a matter of if, but when and how often.
If we’re not preparing for that in a practical way at the same time as trying to harden systems, we’re in for a rough time.
Good comments.
We better figure this out.
There is a lot of critical infrastructure connected to the internet that doesn’t need to be connected to operate properly. Internet connection is a convenience for them, not a necessity. They should disconnect.
Did you mean “as powerful as everyone is letting on”? Or “betting on”? They are betting on Quantum computing being a real-world ‘Elder wand’, able to do anything you can imagine.
It won’t be.
From the article: “What makes this threat so concerning is that cryptographically-relevant quantum computers will be able to break the public key cryptography that underpins nearly everything that keeps a power plant or utility secure, ranging from encrypted data to authorized users and devices, and control system commands and readings.”
Well, that can’t happen unless the power plant is connected to the internet.
Can someone explain what prevents cyber attacks now? Surely secure sites like frontline military sites and nuclear power plants are already isolated and are hardwired to wherever they need to be connected with encryption.
Unless a hostile agent is able to access the connection and piggyback onto the data stream then even with a quantum computer what could they actually achieve, particularly if a quantum computer is used to encrypt the data and the connection consists of multiple lines using different encryption algorithms that rotate frequently.
The basic assumption, highlighted in the above article, is that cryptography as currently implemented to protect highly sensitive data—using 256-bit for symmetric encryption, 521-bit for elliptic curve cryptography, and 4096-bit for traditional asymmetric key (ref: https://en.wikipedia.org/wiki/Security_level )—while theoretically “unbreakable” by the most powerful supercomputers that exist today MIGHT BE defeated by the hypothesized new speed and capabilities of
“quantum computers”.
Quantum computing has yet to demonstrate the computational capabilities of a even a commercial laptop computer. They also require huge, expensive cooling systems running near absolute zero temperature.
Thus, while quantum computers might be able to break current cryptology as used to protect information exchange with and, perhaps, control of, power plants and other high value/potentially dangerous assets, there is as yet no reasoned belief that such quantum computers can be used alternatively to create truly “unbreakable” cryptography.
It was not that long ago that students from MIT were able to crack the NSA encryption algorithm.
As to unbreakable? There are no absolutes.
The only perfect security for a computer system is to power it down and disconnect it.
Most all security protocols are intended to detect intrusion and what was compromised such that appropriate actions can be taken.
This is not about data. This is about control systems.
Haven’t read others’ comments yet.
Does this bring to mind Y2K for anyone else (old enough to have lived through it)?
It does to some degree, except that we have physical examples of people breaking into systems that one would ordinarily think of as being secure. Usually this happens through non-adherence to protocols and carelessness.
I am reminded of how Richard Feynman became known as a “safe cracker” at Los Alamos during the Manhattan project. He would go into the room with the safe that needed to be opened, close the door, and would then think to himself, “Where would Mr. X, write down the combination?” It worked almost always.
I believe Feynman also discovered that most people were too lazy to change the default codes provided by the manufacturers of their safes.
Very much so .
& I tried to disabuse one of the main promoters of that fear , John Westergaard , of its impotence .
I think , tho , on the flip side , people underrate the current and growing power of massively parallel computing for these same tasks .
Y2K didn’t have any major disruptions. A few glitches turned up here and there, but mostly the internet and computer programs got through it just fine.
Of course, that is after about $400 million was spent worldwide to try to head off any problems in the years proceeding the year 2000 deadline.
Y2K was more of a fear that computers could not handle the date changes, and would do odd things because of it, whereas, today computers may be doing too many things on their own volition.
Now is the time to stop adding parasitic, sporadic, intermittent renewables…a massive security risk.
“Green” sources require electromagnetic support FROM grid rotating machines.
“Green” is not dispatcable capacity.
They hide higher costs
by way of subsidies and regulations that force payments to undependable, undispatchable , random and fluctuating energy injections from “green” sources.
Security now!
There were reports a while back that Chinese electronics (inverters for example) had undocumented features that some considered a vulnerability that would allow the Chinese (usually claimed as Wi-Fi enabled) to shut down WTGs and cripple the electrical grid.
The claims were credible, but I never saw a follow up that proved or disproved the suspicion.
Take that and add it to your post. A lot of the “green” electric generating hardware (and software) is imported.
That was starkly incomprehensible.
Yes. Having been there before absolutely everything just had to be connected to absolutely everything else I just kept trying to figure out what problem couldn’t be solved by relevant physical security.