HomeMalware & ThreatsPost-Quantum Deadlines Confront OT Reality

Post-Quantum Deadlines Confront OT Reality

Published on

spot_img

Critical Infrastructure Security,
Encryption & Key Management,
Governance & Risk Management

Practitioners Warn Software Upgrades Alone Won’t Prepare Critical Infrastructure

Post-Quantum Deadlines Confront OT Reality
Post-quantum risk will become increasingly difficult for critical infrastructure providers to ignore as quantum cryptography deadlines approach. (Image: Shutterstock)

The landscape of operational technology (OT) faces critical scrutiny as the integration of quantum-safe algorithms remains untenable. The National Institute of Standards and Technology (NIST) released post-quantum cryptography standards in August 2024, prompting governments globally to enforce strict deadlines for critical infrastructure operators to comply. These mandates typically span from 2028 to 2030, emphasizing the urgent need for necessary upgrades to aging systems, including power grids, water treatment facilities, and transportation networks.

As these quantum cryptography deadlines draw nearer, the risks associated with outdated operational technologies become increasingly pronounced. The NIST’s finalized algorithms are designed to replace existing RSA and elliptic-curve cryptography, with enforceable prohibitions set for 2035. Experts in the field, such as Marin Ivezic, CEO of Applied Quantum, maintain that while quantum-safe algorithms can function in OT environments, various essential components—including protocols, hardware, vendor supply chains, and certification processes—are not prepared for their implementation.

Ivezic asserts that in many segments of OT infrastructure, readiness is insufficient. Transitioning from an outdated algorithm to a newer one complicates matters, especially when the protocols facilitating data flow between control centers and field devices lack inbuilt cryptographic measures. This situation has been echoed by A.B. Sengupta, the alternate Chief Information Security Officer at Grid Controller of India. He elaborates on the operational structure in OT, emphasizing that the IT-intensive layer—which encompasses public key infrastructure and remote access solutions—could realistically support post-quantum migrations. However, the lower-tier protocols vital for transferring commands and telemetry show scant integration of cryptography.

Sengupta points out that the penetration of cryptographic solutions in standard communication protocols within OT is alarmingly low. As the European Union Agency for Cybersecurity’s Maria Christofi highlights, the migration process presents formidable challenges for enterprises operating these systems. She observes that many organizations erroneously assume everything must undergo upgrades to accommodate post-quantum capabilities—a notion that can prove exceedingly arduous and time-consuming.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns that operational technology comprises a significant proportion of obsolete operating systems and software platforms. These include outdated systems, such as Windows XP, still in use, leading to concerns that OT may be among the last sectors to achieve compliance with post-quantum cryptographic standards. The agency cites deficiencies related to long software patch cycles, hardware replacement times, and stringent governance protocols as barriers to compliance.

Organizations face one major immediate challenge: the lack of a detailed inventory regarding the cryptographic measures embedded within their OT environments. Unlike traditional security issues, where vulnerabilities are tracked meticulously, OT cryptography tends to evade strict scrutiny. Christofi argues that before any migration planning can occur, a foundational understanding of the existing cryptography within the organization is essential. This lack of clarity creates impediments for any potential upgrades.

The problem is compounded when considering that post-quantum replacements cannot simply swap in for existing cryptographic measures. Research indicates that post-quantum signatures are larger and more demanding on memory compared to their predecessors. Many older field controllers, designed without the capacity for such expansive signatures, struggle to support these advancements. Sengupta notes that a multitude of proprietary algorithms and OEM-specific products currently operational in OT networks were never engineered for the eventuality of key alterations or the integration of more expansive signature programs.

Patching operational technology is substantially more risky than addressing IT servers due to operational exigencies that require minimized downtime. Sengupta notes the urgency, stating, “We cannot afford excessive downtime in this system.” Thus, any updates necessitate validation in a thorough duplicate of the live environment. Yet, the prevalence of digital twins and dedicated test environments remains limited within OT sectors.

The disparity among vendor readiness poses another challenge, as various groups within the OT sector advance at different speeds. Vendors focused on software solutions encompassing analytics, visualization, and certificate management are rapidly preparing for post-quantum implementations. In contrast, those supplying the hardware layer, including intelligent electronic devices, remote terminal units, and programmable logic controllers, lag significantly, revealing a fragmented landscape.

According to DigiCert’s Quantum Readiness Outlook released in July 2026, a stunning 87% of organizations assert they are planning, testing, or implementing post-quantum cryptography. However, only 7% report that over half of their digital certificates incorporate quantum-safe or hybrid cryptography—a figure that shows sluggish improvement since May 2025.

The lack of rapid movement among IT organizations with dedicated Public Key Infrastructure (PKI) teams intensifies the challenge for OT hardware vendors. CISO Dan Wilkins of the Arizona Department of Economic Security expresses concerns regarding the dependency on vendor communities to create the infrastructure necessary for transitioning to post-quantum cryptography, emphasizing that a usable quantum environment is not yet available. This raises doubts among organizations about the efficacy of current defenses against evolving cyber threats.

In OT settings, the lapses in testing capabilities amplify issues related to availability. Christofi indicates a significant lack of consensus on hybrid cryptography—where standard and post-quantum algorithms coalesce during transitional phases. Due to this discord regarding which hybrid models to adopt, interoperability becomes a significant hurdle, and there is concern that the absence of consensus may lead to an outright failure to explore hybrid solutions.

Where To Start

The primary step for organizations, regardless of their sector, is to establish a comprehensive understanding of their existing cryptographic assets prior to making any modifications. “Conducting an initial inventory of your cryptographic resources will unveil what needs to be migrated,” Christofi advises. Organizations can simultaneously engage in other vital processes alongside inventorying their cryptographic assets. These include upgrading current software and hardware systems where feasible, consulting with vendors to uncover their post-quantum roadmaps, and initiating experimental migration efforts in critical areas such as public key infrastructure and remote-access assets without awaiting a complete inventory overview.

Wilkins concurs with the two-track approach, suggesting that organizations tackle the issue via simultaneous pathways: one focuses on collaboration with vendors to foster testing and develop use-case scenarios, while the other involves engaging with budget stakeholders and legislators to establish a well-defined strategy for securing funding and resources over an established timeframe.

The potential landscape for OT ecosystems by the decade’s end may not resemble a flawless migration but instead presents a triage scenario: while public key infrastructure and remote-access systems could be quantum-safe by schedule, field-level protocols and embedded hardware may remain unprepared for the transition. Some devices might never receive post-quantum upgrades, forcing organizations to decide whether to enhance safeguards, replace the devices, or resign themselves to inherent risks. The existing deadlines presume simple updates, yet experts caution that there may not be a feasible remediation pathway.

Source link

Latest articles

Suisan City, California Responds to Cyber Incident During Surge of U.S. Attacks

Suisan City Faces Cyber Crisis Amid Nationwide Threats Suisan City, California, is currently dealing with...

Cyber Briefing – 2026.08.11 – CyberMaterial

Cybersecurity has become an increasingly critical concern, as highlighted by the latest updates from...

Cursor Security Bug Enabled Repositories to Execute Commands Without Pre-Trust Verification

Cursor's Command-Line Coding Agent Vulnerability Raises Security Concerns A newly identified flaw in Cursor's command-line...

AI Transitions from Theoretical Cheating to Real-World Hacking

The Case for Zero Trust in AI: Hard Constraints Over Soft Rules In the rapidly...

More like this

Suisan City, California Responds to Cyber Incident During Surge of U.S. Attacks

Suisan City Faces Cyber Crisis Amid Nationwide Threats Suisan City, California, is currently dealing with...

Cyber Briefing – 2026.08.11 – CyberMaterial

Cybersecurity has become an increasingly critical concern, as highlighted by the latest updates from...

Cursor Security Bug Enabled Repositories to Execute Commands Without Pre-Trust Verification

Cursor's Command-Line Coding Agent Vulnerability Raises Security Concerns A newly identified flaw in Cursor's command-line...