The Marketing Front Lines: Tom Butta on Owning the Problem, Not the Solution
Back to Media Coverage
28 Jul 2026
Quantum XChange CEO Eddy Zervigon argues in RealClearEnergy that power operators can’t treat quantum computing as a distant problem. In June, the White House signed the “Securing the Nation Against Advanced Cryptographic Attacks” executive order to help critical infrastructure, energy included, prepare. Recent estimates put a cryptographically-relevant quantum computer as early as 2029, and the timeline could compress as nation-states pour billions into the race.
The stakes are specific to the grid. A cryptographically-relevant machine can break the public key cryptography behind nearly everything that keeps a plant or utility secure: encrypted data, authorized users and devices, and control system commands and readings. Zervigon lays out four attacks executives should plan for now.
Adversaries are intercepting and storing encrypted utility data today, betting they can decrypt it once quantum computers arrive. The grid is an ideal target because so much of its traffic has a long shelf life: relay protection settings, plant control configurations, turbine parameters, network topology, and interconnection data. Stolen passwords expire. A map of how a plant’s controls tie into its switchyard does not.
Once nation-states have quantum machines, the security of communications, telemetry, and command links could break, in some cases at or near real time. That gives adversaries ongoing visibility into how systems run and how best to target them.
When encryption breaks, an attacker can cause physical harm without insider access or software bugs, just by manipulating what the control room sees: SCADA telemetry, breaker status, turbine speed, voltage, frequency. The deception runs two ways. It can hide a real problem behind normal-looking readings while a machine is being damaged, or manufacture an emergency that drives automated protection schemes to act.
When public key cryptography breaks, there is no meaningful line between an outside intruder and a trusted insider. Malicious firmware signed with a forged certificate looks identical to a legitimate vendor update. A forged command to trip a breaker or disable a generator’s protection looks lawful to the equipment receiving it. The adversary effectively steps into the control loop as the operator.
Zervigon flags a fast-growing class of facilities where the risk intensifies: AI data centers built with their own dedicated, on-site power. These “electrical islands” have no neighboring generation or external supply to absorb a shock. An adversary who breaks the cryptography protecting that island’s telemetry and command links can take down the power system and the data center at the same time.
The piece closes with five priorities for executives:
“Gear bought this cycle will still be running past Q-Day, so its cryptographic future is set at the purchase order.” — Eddy Zervigon, CEO, Quantum XChange
Have one of our experts show you how Phio TX protects your organization from threats today and the quantum future.
Request Request
a a
demo demo