Why the energy sector must plan for post-quantum cyber security now, WEF, Sep 2026

In a recently published article from the World Economic Forum, our CEO and Founder Ali El Kaafarani discusses the growing cybersecurity risks facing the energy grid, stressing the importance of migrating to PQC.

Energy infrastructure is uniquely exposed. It’s a complex ecosystem of interconnected components, including a chain of equipment manufacturers, software vendors, and industrial control suppliers, each of which could impact the grid with a single failure. Operational technology in the grid can often remain in service for decades, leading to outdated software or unpatched legacy hardware that’s difficult to replace. In addition, Artificial Intelligence is increasingly accelerating vulnerability-discovery for threat actors, allowing them to exploit weakness at unprecedented speeds. According to research quoted in the article, 77% of utilities organizations experienced attacks involving outdated software or unavailable patches on legacy equipment in 2025. It’s a sobering statistic – especially in the context of real-world examples, such as the December 2025 attack on the Polish energy sector.

With regulatory pressure from national security directives and government (NCSC, the White House and others coalescing on full PQC adoption by 2035), upgrading energy networks to post-quantum cryptography is now an urgent requirement to guarantee long-term grid security. As Ali points out:

“The hardest systems to secure are often the systems that are hardest to replace. Post-quantum readiness therefore cannot be treated as a simple software update. It must work in constrained hardware, embedded systems, industrial environments and long-life assets where disruption is not an option.” 

The article lists some key strategies:

  • Ecosystem-wide coordination. Alignment on reporting, identifying critical dependencies and long-term support roadmaps.
  • Targeted asset prioritization. Organizations should focus immediate effort on:
    • High value targets
    • Operational control systems
    • Critical communications
    • Long-life data
    • Hardware roots-of-trust
  • Embedding PQC into core processes. PQC requirements built into technology refresh cycles, supplier risk assessments and capital investment decisions

It’s clear that reactive patching of vulnerabilities won’t be sufficient. Energy leaders should establish post-quantum readiness as a central pillar of both grid resilience, and procurement strategy.

Read Ali’s full WEF article here