Back to Blog

Threat Model for Critical Infrastructure: Why OT Encryption Has a Shorter Window Than IT

Operational technology networks protecting power grids, water systems, and industrial control systems have different threat profiles than enterprise IT. The quantum migration window for OT is tighter than most operators realize, and the remediation path is more constrained.

Critical infrastructure OT threat model diagram

OT Networks Are Not IT Networks

Operational technology networks controlling power grids, water treatment systems, and industrial infrastructure have different characteristics from enterprise IT networks in ways that directly affect quantum migration planning. Understanding these differences is a prerequisite for any credible threat model.

First, OT hardware has much longer replacement cycles. Enterprise IT equipment is typically on 3 to 5 year refresh cycles. Programmable logic controllers (PLCs) in substations, remote terminal units (RTUs) in grid control systems, and SCADA communication gateways in water treatment facilities have expected operational lifetimes of 15 to 20 years. Much of the OT equipment currently in production was installed before post-quantum cryptography was a design consideration, and will remain in service past the expected quantum computing maturity window.

Second, OT systems have strict change management processes. Updating firmware on a substation controller requires a maintenance window, regression testing, and frequently vendor certification that the update does not affect the device's safety-critical behavior. The cadence for cryptographic updates in OT environments is measured in years, not weeks. A security patch that takes 2 weeks to deploy in an enterprise IT environment may take 18 months to deploy across an equivalent OT fleet.

Third, OT protocols carry operationally sensitive data on fixed, known communication patterns. SCADA telemetry follows predictable schedules: status updates from substations arrive at the control center every few seconds. An adversary who has collected this traffic can infer grid topology, identify the communication patterns of individual substations, and build an intelligence picture of grid operations even before decrypting the payload. The metadata value of captured OT traffic is high even without decryption.

The SCADA Attack Surface: Where the Harvest-Now Risk Concentrates

Power grid SCADA systems use several layers of encryption that have different exposure profiles. The most relevant to the harvest-now threat are the encrypted telemetry channels between field devices and the control center, and the encrypted management channels used for remote configuration of field equipment.

Telemetry channels in modern grid deployments typically use IEC 60870-5-104 or DNP3 over TLS, or vendor-proprietary protocols with encryption layers. The key establishment in these TLS connections is the harvest-now exposure surface. For a national grid operator, these channels carry data continuously: voltage and current readings from substations, circuit breaker status, transformer load data, and frequency measurements. An adversary who can eventually decrypt this traffic gains a high-fidelity historical record of grid operations.

Management channels for remote device configuration carry even more sensitive operational data. Configuration commands to PLCs and RTUs, including firmware update packages and operational parameter changes, are transmitted over authenticated encrypted channels. If an adversary can eventually decrypt captured management traffic, they gain knowledge of device configurations, firmware versions, and operational parameter ranges that are directly useful for planning disruption.

The asymmetry between attack value and defense urgency is particularly stark in grid operations: the data has very long operational sensitivity, the network is continuously exposed with no shutdown option, and the ability to update encryption infrastructure is severely limited by OT change management constraints.

Mapping the Exposure Window

A practical exposure assessment for an energy operator starts with the following variables: what is the operational sensitivity lifetime of the data being transmitted, when is the earliest plausible date for a cryptographically relevant quantum computer, and what is the realistic timeline for quantum-safe migration in the OT environment?

For grid topology and operational data: the operational sensitivity is 10 to 15 years. Grid architecture changes slowly. An adversary with 2024 telemetry data will have useful intelligence about grid architecture well into the 2030s, even accounting for planned upgrades. The harvest-now collection that is happening now against grid operators will be within its sensitivity window when quantum computers mature.

For configuration management data: the sensitivity period extends as long as the equipment remains in service. A substation controller configured in 2024 may run with the same parameters until 2035 or beyond. Captured configuration data for that controller retains attack value for its entire service life.

Against a plausible CRQC timeline of 2030 to 2035 for RSA-2048 attacks, and realistic OT migration timelines of 5 to 8 years for full fleet coverage, an energy operator that has not started migration planning by 2025 or 2026 faces the realistic possibility that their OT fleet will not be migrated before the threat matures.

The Constrained Remediation Path

The OT migration problem cannot be solved the same way as enterprise IT migration. The usual approach of software updates and TLS library upgrades does not apply to embedded controllers with fixed-firmware cryptographic implementations.

The available remediation approaches fall into three categories. The first is overlay encryption: deploying a quantum-safe encryption layer above the OT protocol, typically at the network gateway level where OT traffic enters and leaves the OT network segment. This allows you to provide quantum-safe encryption for the OT traffic without changing the OT devices themselves. The OT device still communicates via its standard protocol, but that traffic is wrapped in a quantum-safe tunnel at the segment boundary. This is the most immediately deployable approach and is compatible with the change management constraints of OT environments.

The second approach is quantum-safe key delivery to the gateway layer. If the gateways that provide overlay encryption are themselves using quantum-safe key establishment, the protection extends to the whole OT traffic path. A QKD-distributed key delivered to an OT network gateway provides information-theoretic security for the encrypted OT channel above it, even though the underlying OT devices have not changed.

The third approach, full device replacement with quantum-safe firmware, is the only option that provides end-to-end quantum-safe protection without a gateway dependency. This is the longest-lead and highest-cost approach, but it is the correct eventual state for high-risk OT assets. It will lag the other approaches by years and will not be complete for most operators before the quantum threat matures.

Priority Ranking for Energy Operators

If we were advising a national energy grid operator on where to start, based on the exposure analysis and remediation constraints, the priority ranking would be: control center to substation communication encryption first, since this is where you can deploy overlay quantum-safe encryption at a small number of centrally managed nodes; remote management channels second, since configuration traffic is the highest-sensitivity payload and is typically lower volume than telemetry; and full field device firmware migration last, since this requires the longest procurement and testing cycles.

The overlay encryption approach at the gateway layer is not a complete solution: it does not protect the communication segment between the gateway and the field device on the OT network side. For most grid architectures, the OT-internal segment is physically air-gapped or isolated, reducing (but not eliminating) the collection exposure for that segment. The highest-risk traffic paths are those that traverse public or semi-public networks, and the gateway overlay approach addresses those directly.

We are not arguing that OT quantum migration is simpler than IT migration. It is harder, on a longer timeline, and with more constrained remediation options. The appropriate response to that difficulty is to start the planning now, with a clear understanding of which components can be addressed quickly (gateway-layer encryption) and which require long-lead procurement and testing cycles (device firmware). Starting the planning later does not make the constrained parts go faster.

Quantum-safe infrastructure

Ready to start your deployment?

Satellite QKD key delivery for financial networks, critical infrastructure, and government communications.

Request Access View Pricing
Related articles
The Harvest-Now, Decrypt-Later Threat
The Harvest-Now, Decrypt-Later Threat: What Operators Need to Know Now
Zero Trust Meets Quantum-Safe
Zero Trust Meets Quantum-Safe: Key Distribution in a Perimeter-Free Architecture
Government Telecom Quantum Readiness
Government Telecom Operators and Quantum Readiness: Where Most Programs Fall Short