
In a September 2026 World Economic Forum article, Ali El Kaafarani argues that energy companies should begin preparing their systems for post-quantum cryptography now. The reason is practical: power infrastructure lasts for decades, while replacing its security can take years. Equipment purchased today may still be operating when advances in quantum computing make some widely used cryptographic methods unsafe.
Cryptography helps protect the digital connections on which modern energy systems depend. It can establish that a device or software update is genuine and keep communications confidential. A sufficiently capable future quantum computer could undermine some of the methods used for those tasks. Post-quantum cryptography refers to replacement methods designed to withstand that threat. The article’s call is for a planned transition, not a claim that quantum computers are already breaking power-grid security.
That transition is unusually difficult for energy operators. A grid brings together control rooms, substations, field devices, renewable generators, telecommunications networks, software providers and equipment manufacturers. Many components have limited computing capacity. Others cannot be taken offline easily for an update. A change that works on a company laptop may require extensive testing before it can be introduced into equipment that controls electricity supply. As El Kaafarani puts it, the systems that are hardest to secure are often the hardest to replace.
The sector is also expanding its digital connections. New renewable sites and increasingly interconnected services create more places where operators must verify devices, protect data and trust suppliers. Existing cyber risks show why those relationships matter, even though conventional attacks and future quantum attacks are different problems. The article cites a December 2025 incident in Poland in which attackers targeted more than 30 wind and solar farms, a manufacturing company and a major power plant. That incident does not demonstrate a quantum threat; it illustrates how a connected energy system can present attackers with many routes into essential infrastructure.
El Kaafarani also points to artificial intelligence as a reason to move faster. AI can help attackers find weaknesses and help defenders test their systems. It should not be confused with the quantum-computing threat to cryptography. The shared lesson is that security assumptions need regular testing while equipment is still in service. Waiting for a single breakthrough or a single deadline would leave too little time to examine every device, supplier and dependency.
Planning starts with an inventory. Operators need to know where cryptography protects communications, operational controls, software updates and hardware. They can then identify which systems hold sensitive data for a long time, which are vital to safe operation, and which will be difficult to upgrade later. Procurement is part of that work: suppliers should be able to explain how new products will support future cryptographic changes throughout their working lives. The article recommends building those questions into equipment purchases, supplier assessments and scheduled technology replacements.
There is a policy timetable as well. The article notes that the UK’s National Cyber Security Centre has set milestones for discovery and initial planning by 2028, early priority migration by 2031 and completion by 2035. It also describes a June 2026 US policy directing federal systems toward post-quantum standards and supporting critical infrastructure operators with their transitions. These dates make the issue relevant to investments being approved now.
Bottom line: Energy cyber security protects a physical service. If trusted communications or equipment updates fail, the consequences can reach households, hospitals and businesses that rely on continuous power. Early planning gives operators time to test replacements, coordinate with suppliers and fit upgrades around safe operating schedules. The article’s central point is that long-lived infrastructure cannot wait until the threat is immediate before deciding how it will adapt.
Also Read:
Share this post via:



Comments
There are no comments yet.
You must register or log in to view/post comments.