tech · quantum risk
Is OT critical infrastructure Quantum Proof? Cyber Program & PQC
Verdict
OT/ICS environments often cannot “just upgrade TLS” quickly. Quantum programs need inventory, compensating controls, vendor pressure, and realistic exception timelines—while still upgrading IT/OT boundaries first.
Overview
Critical infrastructure guidance increasingly mentions quantum preparedness. Safety constraints dominate change windows.
Program inventory focus: Long equipment life and limited patch windows. Typical classical surfaces: Industrial protocols with optional TLS; Vendor-locked firmware crypto. Cross-read /security/program and /assessment. Educational only—not compliance advice.
Cryptographic profile
- Signatures: Industrial protocols with optional TLS, Vendor-locked firmware crypto
- Hash: Safety system configs
- Public-key exposure: Long equipment life and limited patch windows.
What breaks
- Air gap myths as full mitigation
- No vendor crypto roadmap
Mitigations
- Boundary hybrid TLS first
- Asset inventory including crypto features
- Tabletop with engineering and safety leads
FAQ
PQC on PLCs tomorrow?
Often not—plan multi-year and focus on reachable surfaces now.
Related?
cisa-quantum and exception-management-crypto.
Key concepts (technical dictionary)
Terms used on this page — open a definition: