Power Operators Must Plan Now for Four Quantum Attacks

By Antonio Sanchez

Share this post

QXC-Media-Article-RealClear Energy-EddyZ-768×593

Quantum XChange CEO Eddy Zervigon argues in RealClearEnergy that power operators can’t treat quantum computing as a distant problem. In June, the White House signed the “Securing the Nation Against Advanced Cryptographic Attacks” executive order to help critical infrastructure, energy included, prepare. Recent estimates put a cryptographically-relevant quantum computer as early as 2029, and the timeline could compress as nation-states pour billions into the race.

The stakes are specific to the grid. A cryptographically-relevant machine can break the public key cryptography behind nearly everything that keeps a plant or utility secure: encrypted data, authorized users and devices, and control system commands and readings. Zervigon lays out four attacks executives should plan for now.

Harvest now, decrypt later.

Adversaries are intercepting and storing encrypted utility data today, betting they can decrypt it once quantum computers arrive. The grid is an ideal target because so much of its traffic has a long shelf life: relay protection settings, plant control configurations, turbine parameters, network topology, and interconnection data. Stolen passwords expire. A map of how a plant’s controls tie into its switchyard does not.

Live surveillance.

Once nation-states have quantum machines, the security of communications, telemetry, and command links could break, in some cases at or near real time. That gives adversaries ongoing visibility into how systems run and how best to target them.

The attack on data integrity.

When encryption breaks, an attacker can cause physical harm without insider access or software bugs, just by manipulating what the control room sees: SCADA telemetry, breaker status, turbine speed, voltage, frequency. The deception runs two ways. It can hide a real problem behind normal-looking readings while a machine is being damaged, or manufacture an emergency that drives automated protection schemes to act.

Sabotage and the ultimate insider threat.

When public key cryptography breaks, there is no meaningful line between an outside intruder and a trusted insider. Malicious firmware signed with a forged certificate looks identical to a legitimate vendor update. A forged command to trip a breaker or disable a generator’s protection looks lawful to the equipment receiving it. The adversary effectively steps into the control loop as the operator.

Zervigon flags a fast-growing class of facilities where the risk intensifies: AI data centers built with their own dedicated, on-site power. These “electrical islands” have no neighboring generation or external supply to absorb a shock. An adversary who breaks the cryptography protecting that island’s telemetry and command links can take down the power system and the data center at the same time.

The piece closes with five priorities for executives:

  1. Act on the obvious before the inventory is complete. A cryptographic inventory is the foundation of any post-quantum cryptography (PQC) migration, but it can’t be a gate. Where a remote access path or vendor connection is already known to be quantum-vulnerable, start remediation in parallel. Secure the biggest pipes now.
  2. Prioritize by data lifetime and consequence. Grid topology, protection settings, and engineering diagrams stay sensitive for decades and are being harvested today, so protect that data first, then the channels and devices that move physical equipment.
  3. Build for crypto-agility, and use overlays where rip-and-replace isn’t possible. Centralize cryptographic management so algorithms can be swapped as standards evolve. Hybrid classical-and-PQC cryptography eases the transition on upgradable gear; for constrained field devices, overlays such as out-of-band key delivery protect legacy links with no downtime.
  4. Compensate for what can’t be upgraded. For gear that won’t be quantum-safe before replacement, impose tight segmentation and least-privilege access, deploy quantum-safe gateways at the boundary, and monitor for anomalies.
  5. Make post-quantum readiness a procurement requirement now. Equipment bought this cycle will still be running past Q-Day. Contracts should require NIST’s finalized standards, field-updatable crypto-agility, and a cryptographic bill of materials.

“Gear bought this cycle will still be running past Q-Day, so its cryptographic future is set at the purchase order.” — Eddy Zervigon, CEO, Quantum XChange

Read the full byline in RealClearEnergy.

Share this post

See Phio TX in action

Have one of our experts show you how Phio TX protects your organization from threats today and the quantum future.

Request Request 

a

demo demo

grainy-bg-blue