Ilyass MotyaIlyass Motya
Post-quantum won't wait for your PLC's retirement.
Back to blog

Post-quantum won't wait for your PLC's retirement.

· By Ilyass Motya

Source: Industrial Cyber — G7 Cybersecurity Working Group 'Preparing for the Post-Quantum Era'

The threat isn't the quantum computer. It's the data in flight.

The G7 Cybersecurity Working Group's call to action makes a specific point: the timeline for cryptographically relevant quantum computers is uncertain, but a threat exists today in the form of 'store now, decrypt later.' Encrypted traffic intercepted now — government data, business secrets, telemetry — can be held and decrypted the day a capable machine exists. For any organization whose data has a long confidentiality life, the exposure already started.

The group's guidance is a five-point plan: raise awareness, adopt national PQC strategies, fund research, build public-private partnerships, and fold PQC into procurement and security requirements. Sensible at the government level. Almost useless as a to-do list for a plant engineer.

OT security engineer commissioning industrial control equipment on the plant floor

Why OT makes this transition especially hard

IT systems get certificates rotated every couple of years. Control systems get certificates on the vendor's schedule — often never. A PLC that authenticates to a historian over RSA can sit in production for fifteen years, unchanged, because the firmware that carries the crypto was last touched before the standard existed.

The document's real advice for OT is buried in the implementation guidance: start early, inventory your cryptographic assets, map dependencies, and buy quantum-safe replacements as part of the normal renewal cycle rather than as a special project. That is exactly how OT upgrades should work anyway. The difference is that a planned renewal every ten years is now a deadline, not a habit.

The practical start

The first OT deliverable is an inventory: which devices authenticate with what, over what protocol, to whom, and what would break if the certificate changed. Most plants cannot answer that today, and the gap is the same gap that produces the rest of the OT risk list — you cannot protect what you have not counted.

Segment the remote access paths while you are at it, because a certificate swap on a vendor VPN does nothing if the VPN itself is the attack surface. Post-quantum is a governance conversation until someone writes the list of systems. Write the list.

Next up