Cybersecurity

Why the energy sector must plan for post-quantum cyber security now

A coder in headphones works at a computer.

Planning the energy sector’s migration to new cryptographic standards is an urgent and essential part of securing its long-term resilience. Image: Jefferson Santos/Unsplash

Ali El Kaafarani
Founder and Chief Executive Officer, PQShield
  • Legacy infrastructure and rapid digitization leave power grids exceptionally exposed to cyber risks.
  • Artificial intelligence accelerates the discovery of critical vulnerabilities by threat actors.
  • Upgrading to post-quantum cryptographic standards today is essential for long-term energy security.

The energy sector is entering a more demanding era of cyber risk. Grid operators are managing ageing operational technology, rapid digitization, new renewable infrastructure and a threat landscape shaped by geopolitical competition. At the same time, essential services are becoming more dependent on software, connectivity and complex technology supply chains, putting them at greater threat.

Artificial intelligence is also changing the speed at which security assumptions can be tested. When in the hands of an adversary, it can uncover vulnerabilities incredibly quickly, meaning infrastructure operators need faster ways to validate, update and strengthen critical systems.

In this environment, planning the sector’s migration to new cryptographic standards is an urgent and essential part of securing its long-term resilience.

The grid is uniquely exposed

The energy system is a complex ecosystem of grid operators, equipment manufacturers, software vendors, telecommunications providers, cloud platforms, managed service providers and industrial control suppliers. A weakness in any one layer can affect resilience elsewhere along the chain.

This makes energy infrastructure an attractive target for adversaries because disruption can have consequences far beyond a single organization. The UK government’s Energy Sector Cyber Security Strategy says the sector is facing increasingly sophisticated attacks, including advanced capability and state threat actors. It also highlights the challenge created by integrating legacy infrastructure with new technologies as the energy system becomes more interconnected and digitized.

Have you read?

That exposure is compounded by the lifespan of operational technology. Energy assets are often expected to remain in service for decades, while the cyber environment around them changes much faster. Recent research from Bridewell found that 77% of utilities organizations experienced attacks involving outdated software or unavailable patches on legacy equipment in 2025, making it the most common cyber incident facing the sector.

An example of this was the incident seen in the Polish energy sector in December 2025. CERT Polska reports that attackers targeted more than 30 wind and photovoltaic farms, a manufacturing company, and a large, combined power plant supplying heat to almost half a million customers in Poland.

The hardest systems to secure are often the systems that are hardest to replace. Post-quantum readiness therefore cannot be treated as a simple software update. It must work in constrained hardware, embedded systems, industrial environments and long-life assets where disruption is not an option. Assets that are difficult to patch, hard to replace or expected to operate for decades should be planned with upgradability in mind.

The timeline is becoming operational

The transition to post-quantum cryptographic standards is no longer a distant planning exercise. The UK’s National Cyber Security Centre has set phased milestones for organizations to complete discovery and initial planning by 2028, carry out early high-priority migration activity by 2031, and complete the migration to post-quantum cryptography by 2035.

In the US, a June 2026 White House order framed the issue as a national security and infrastructure priority. US policy is to move federal information systems to NIST’s post-quantum cryptography standards, and to assist critical infrastructure owners and operators with their own transitions.

For the energy sector, these dates matter because decisions made today will still shape infrastructure in the 2030s. Control systems, field devices, secure boot mechanisms, gateways and communications equipment procured now may remain operational long after current cryptographic assumptions have changed, so it is essential that the latest cryptographic standards are baked in from the very earliest plans.

Quantum-safe infrastructure is energy resilience

The next phase of quantum-safe readiness will depend on coordination across the energy ecosystem. Infrastructure owners need to understand where cryptography is used across systems, services, hardware and suppliers. Regulators and policy-makers can help by aligning expectations around timelines, reporting and critical dependencies. Suppliers need clear roadmaps for how products will support post-quantum standards over long operational lifecycles.

Prioritization will be essential. The most urgent focus should be systems that protect long-life data, critical communications, operational control and hardware roots of trust. Post-quantum readiness should be built into technology refresh cycles, supplier assessments and infrastructure investment decisions now, so that assets being bought today do not become security liabilities in the 2030s.

AI-assisted cryptanalysis strengthens the case for early action. Used responsibly, these tools can help defenders find weaknesses earlier, improve implementations and build greater confidence in the systems that underpin essential services. In the wrong hands, they accelerate the potential for vulnerabilities to be exposed.

For the energy sector, the goal is to protect the continuity, trust and stability of the essential services that modern economies and societies depend on. The organizations best placed for the next decade will be those that start early, prioritize the most critical systems and make quantum-safe readiness part of procurement and resilience planning.

Loading...
Don't miss any update on this topic

Create a free account and access your personalized content collection with our latest publications and analyses.

Sign up for free

License and Republishing

World Economic Forum articles may be republished in accordance with the Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International Public License, and in accordance with our Terms of Use.

The views expressed in this article are those of the author alone and not the World Economic Forum.

Stay up to date:

Cybersecurity

Share:
The Big Picture
Explore and monitor how Cybersecurity is affecting economies, industries and global issues
World Economic Forum logo

Forum Stories newsletter

Bringing you weekly curated insights and analysis on the global issues that matter.

Subscribe today

More on Cybersecurity
See all

Why cyber resilience in pharma must extend into medicine value chains

Ashish Gupta and Jonathan Sinclair

August 27, 2026

What are the hidden costs of a fragmented cybersecurity strategy?

About us

Engage with us

Quick links

Language editions

Privacy Policy & Terms of Service

Sitemap

© 2026 World Economic Forum