October 3, 2026
Sumanth Srirangam

OT Was Built to Last. Its Cryptography Wasn't.

TL;DR

  • Forescout Technologies recorded 2,155 ICS vulnerabilities across 508 advisories in 2025, the highest volume since tracking began, with the sharpest rise in high-severity flaws targeting field controllers, PLCs and SCADA systems.
  • OT systems operate on 15 to 25-year hardware cycles. The cryptography protecting them today, RSA and ECC, will not remain secure for that operational lifetime. NIST has already scheduled both for deprecation after 2030. Also, Q-Day has been predicted by many researchers including Google as 2029 and not 2035.
  • Migrating cryptography in OT is orders of magnitude harder than in enterprise IT. The time to begin is before the constraint is a crisis.

Operational technology was never designed with cryptographic agility in mind. A programmable logic controller commissioned in 2020 was built to run reliably for two decades. Its developers chose encryption standards appropriate for the threat environment of 2020. They were right to do so. The problem is that the threat environment of 2030, 2035 and 2040 will be materially different, and that PLC will still be running.

This is the OT quantum security problem in one sentence: the systems are long-lived, the cryptography is not.

The Attack Surface Is Already Breaking Records

Forescout Technologies' research found that ICS cybersecurity risk hit a record in 2025, with 508 advisories covering 2,155 vulnerabilities, the highest volume since tracking began. The sharpest rise was in high-severity flaws affecting field controllers, PLCs and SCADA systems. Alongside this, SC Media cited research projecting that by 2026, more than a third of global energy and utilities infrastructure will have experienced cyber pre-positioning activity: quiet access, data collection and operational mapping by adversaries building a picture for future use.

In April 2026, the OT-ISAC published a vulnerability advisory identifying critical flaws across industrial environments including obsolete controllers with no available fix, authorisation bypass flaws in pipeline simulation software, and weak password protections in PLC workflows. In July 2026, a coordinated cyberattack targeted operational technology at more than 30 community water systems in Minnesota. These are not edge cases. They are a pattern of escalating, targeted pressure on systems built for reliability, not security.

The Two Threats Are Not Sequential

Most OT security programmes treat the quantum threat as a future concern, to be addressed after the immediate vulnerability backlog is cleared. This sequencing is understandable but wrong. The two threats are running simultaneously.

Harvest now, decrypt later is the mechanism that connects them. Adversaries engaged in pre-positioning activities in OT environments are not just mapping systems. They are collecting encrypted communications: control signals, authentication traffic, firmware update channels, operator session data. This traffic is protected today by RSA and elliptic-curve cryptography. A cryptographically relevant quantum computer will break both.

The research paper Power Network SCADA Quantum Communications (arXiv:2603.01060) confirms the structural exposure: OT and SCADA systems prioritise availability over confidentiality, which reverses the conventional security triad. This is why OT environments are particularly vulnerable to retrospective decryption: the traffic is voluminous, predictable, and carries operational data with long-term strategic value. A nation-state adversary collecting an industrial operator's encrypted SCADA communications today can decrypt the network topology, command sequences, and authentication patterns of that facility once quantum capability matures.

NIST IR 8547 deprecates RSA-2048 and ECC P-256 for new systems after 2030 and disallows them entirely after 2035. A field controller commissioned today is likely to still be operational in 2040. If its cryptographic assumptions have not been addressed before 2035, they will never be.

Why OT Migration Is Harder Than Enterprise IT

The standard playbook for enterprise cryptographic migration does not transfer to OT. PostQuantum.com's analysis Upgrading OT Systems to Post-Quantum Cryptography states it directly: migrating an enterprise IT system to new cryptography is challenging; doing so in an OT environment is orders of magnitude harder.

Three characteristics create this difficulty. First, hardware longevity: OT components routinely run for 10 to 20 years, often on processors that cannot support the computational overhead of post-quantum algorithms. ML-KEM and ML-DSA produce significantly larger keys and signatures than RSA and ECC, which creates bandwidth and memory constraints on constrained field devices. A research paper published in Engineering Proceedings (doi:10.3390/engproc2026134076) demonstrates that a hybrid PQC architecture achieves 86% IEC 62443-4-2 conformance on constrained devices, with remaining gaps being procedural rather than algorithmic, which means the cryptographic migration is technically achievable on most hardware without replacement.

Second, uptime requirements: OT systems often cannot be taken offline for cryptographic upgrades without operational disruption. Migration must be staged, with hybrid classical and post-quantum modes maintaining interoperability throughout the transition.

Third, standards lag: IEC 62443, the primary international standard for OT and industrial control system security, already incorporates post-quantum cryptography. But most implementations of IEC 62443 requirements today use RSA or ECC, none of which are quantum-resistant. Compliance with the current standard is not sufficient for the threat environment of the next decade.

The Springer Nature research on quantum-resistant SCADA architecture proposes integrating quantum key distribution via the IEC 60870-5-104 protocol for encrypted SCADA communication, demonstrating that QKD is technically deployable alongside existing industrial protocols without replacing the underlying infrastructure. This is the model that makes OT quantum migration practical: not replacing equipment, but securing the communications layer above it.

Where to Start

The starting point for any OT quantum security programme is a cryptographic inventory: a complete map of every algorithm, key, certificate and protocol in use across the OT estate, from field devices and PLCs to historian servers, engineering workstations and remote access channels. Most organisations discover significantly more cryptographic dependencies than initial estimates, particularly across legacy OT where documentation is sparse.

From the inventory, prioritise by two variables: data sensitivity and time horizon. Control signals and authentication traffic for critical infrastructure have both. Begin hybrid post-quantum cryptography deployment on highest-priority links first. Where physics-based guarantees are required, quantum key distribution integrated over existing industrial protocols provides information-theoretic security without hardware replacement. Quantum random number generation addresses the entropy foundation beneath every key the system generates. And crypto-agility, the ability to swap algorithms by configuration rather than re-engineering, is the design principle that makes all of this survivable across the decades-long operational horizon of OT systems.

The PLC commissioned today will still be running in 2040. The question is whether the encryption protecting it will still be valid.

The operational lifetime of your OT systems extends well past the quantum deadline. Find out whether your cryptographic foundation does too.

Sources

  1. Forescout Technologies, ICS Cybersecurity Risk Hits Record in 2025 (508 advisories, 2,155 vulnerabilities) : https://industrialcyber.co/threats-attacks/forescout-flags-spike-in-high-severity-ot-ics-flaws-exposing-visibility-gaps-that-leave-critical-infrastructure-at-risk/
  2. SC Media, Critical Infrastructure Facing Cyber Surge in OT and Supply Chains in 2026 (energy sector pre-positioning, one-third of infrastructure) : https://www.scworld.com/feature/critical-infrastructure-facing-cyber-surge-in-ot-and-supply-chains-in-2026
  3. OT-ISAC, Vulnerability Advisory: Critical Flaws Across Industrial Control and Management Systems (April 2026) : https://industrialcyber.co/industrial-cyber-attacks/new-ot-isac-advisory-exposes-critical-flaws-across-industrial-control-and-management-systems/
  4. arXiv:2603.01060, Power Network SCADA Quantum Communications: A Comparison of BB84, B92, E91, and SGS04 QKD Protocols (OT CIA triad, SCADA quantum exposure) : https://arxiv.org/pdf/2603.01060
  5. Engineering Proceedings (MDPI), Quantum-Resistant Encryption for IoT Communication in Critical Engineering Infrastructure (86% IEC 62443-4-2 conformance, hybrid PQC on constrained devices, doi:10.3390/engproc2026134076) : https://doi.org/10.3390/engproc2026134076
  6. Springer Nature, Quantum-Resistant Cryptography for SCADA Systems: Enhancing Security in the Quantum Era (IEC 60870-5-104 QKD architecture) : https://link.springer.com/chapter/10.1007/978-3-032-27160-0_28
  7. PostQuantum.com, Upgrading OT Systems to Post-Quantum Cryptography: Challenges and Strategies (OT migration harder than IT, IEC 62443 current implementations not quantum-resistant) : https://postquantum.com/post-quantum/ot-pqc-challenges/
  8. Sener Group, Post-Quantum Cryptography and NIS2 Compliance in OT (IEC 62443 PQC incorporation, NIS2 crypto-agility from 2026) : https://www.sener.es/en/insights/post-quantum-cryptography-and-nis2-compliance-in-ot/
  9. NIST, IR 8547: Transition to Post-Quantum Cryptography Standards (2030 deprecation, 2035 disallowance) : https://nvlpubs.nist.gov/nistpubs/ir/2024/NIST.IR.8547.ipd.pdf
  10. NIST, Post-Quantum Cryptography Standards Approved (FIPS 203, 204, 205) : https://csrc.nist.gov/news/2024/postquantum-cryptography-fips-approved

Frequently asked questions

Why is OT cryptographic migration harder than enterprise IT?
What is the harvest now, decrypt later risk for OT environments?
What standards govern post-quantum cryptography in OT?
Where should an OT operator start?

More blogs