In 2025, 77 percent of utilities organizations faced cyberattacks exploiting outdated software on essential equipment, revealing a widespread vulnerability in energy infrastructure. The World Economic Forum recently published an article by Ali El Kaafarani, CEO and Founder, highlighting the urgent need for the energy sector to prepare for post-quantum cyber threats, particularly given events like the December 2025 attack on the Polish energy sector.
“The hardest systems to secure are often the systems that are hardest to replace,” El Kaafarani notes; full Post-Quantum Cryptography adoption is now targeted by bodies like the NCSC and the White House by 2035 to guarantee long-term grid security.
Energy Grid Vulnerabilities from Legacy Systems and AI
Recent attacks demonstrate the acute vulnerability of energy infrastructure to cyber threats, with 77 percent of utilities organizations reporting incidents involving outdated software or unpatched legacy equipment throughout 2025. This widespread exposure stems from the long operational lifespan of critical grid components, creating a complex ecosystem where a single compromised element can disrupt entire networks. Artificial Intelligence is further exacerbating the problem by accelerating the rate at which threat actors discover and exploit weaknesses, demanding faster responses than previously possible.
Regulatory bodies are now responding with increasing urgency, signaling a firm expectation for proactive security measures. The National Cyber Security Centre, alongside the White House and other international agencies, are converging on a timeline for full Post-Quantum Cryptography (PQC) adoption by 2035. This coordinated push acknowledges the long-term threat posed by quantum computing’s potential to break current encryption standards, necessitating a fundamental shift in how energy networks are secured.
Effective mitigation requires coordination across the entire ecosystem, targeted asset prioritization, and the integration of PQC into core processes. Organizations should immediately focus on securing operational control systems, critical communications infrastructure, and hardware roots-of-trust, while also integrating PQC requirements into technology refresh cycles and supplier risk assessments. Reactive vulnerability patching will prove insufficient against increasingly sophisticated and rapidly evolving threats; energy leaders must establish post-quantum readiness as a central tenet of both grid resilience and long-term procurement strategy.
The hardest systems to secure are often the systems that are hardest to replace. Post-quantum readiness therefore cannot be treated as a simple software update. It must work in constrained hardware, embedded systems, industrial environments and long-life assets where disruption is not an option.




See today’s quantum computing news on Quantum Zeitgeist for the latest breakthroughs in qubits, hardware, algorithms, and industry deals.
