Shaping a quantum-secure future for energy and critical infrastructure

作者  と  | Jun 10, 2026

Quantum computing is no longer a distant concern but an accelerating strategic threat – one that could undermine the cryptographic foundations on which energy cybersecurity depends. This is why we are pleased to reveal important progress in our work to identify and mitigate risk for the sector, as the cyber arms race continues to gather pace.

We wrote last summer about our collaboration with the National Energy System Operator (NESO) on its ‘National Security in a Quantum Future’ project. Now we’re able to announce that the initiative is entering the development and deployment stage – a timely and significant step.

Having successfully completed its Discovery phase (establishing feasibility) and Alpha phase (proof of concept), the project has now secured Beta funding from Ofgem’s Strategic Innovation Fund (SIF) – a major UK energy innovation programme delivered in partnership with the government’s innovation agency, Innovate UK, to accelerate progress towards a secure and resilient low-carbon energy system.

Post-quantum security threat

It goes without saying that we are immensely proud of the team at CC – and indeed all the collaborators involved in the project – who have worked diligently and creatively to develop a novel assessment framework for identifying risks and establishing a prioritised mitigation approach to the post-quantum cybersecurity threat. On a broader front, we’re delighted that the energy sector – and particularly the UK energy sector – is taking the lead on such a critical global issue.

In many ways CC has acted as an orchestrator right from the outset – playing a central role in bringing together people with the capabilities to tackle the complex and pressing challenge of post-quantum cryptography (PQC). As a company we have a rare mix of expertise, balancing deep cybersecurity and quantum computing knowledge with strong commercial understanding of the industry. Beyond that, we continue to cooperate with leading figures from academia and energy.

These academic connections were first established at the proposal stage. For example, the project has benefitted from collaboration with quantum researchers from the University of Edinburgh, who have been involved right from the start. Key relationships continue to endure, and as we enter the next phase, the project is being strengthened by further collaboration.

In addition to NESO, two new energy networks have joined the project: National Gas Transmission and SP Energy Networks. They’ve come onboard for this phase of the project to ensure that the tools we are developing will help enable continued security across the whole of the sector. The networks will share important insights throughout the phase and also be involved in testing – trying out the tools in their own environments to evaluate quantum risk.

Innovative PQC tools

At the core of our work are two key capabilities: a quantum‑aware risk management (Q-ARM) tool and a quantum threat tracker (QTT) module. Their development draws on CC’s multidisciplinary expertise, bringing together quantum scientists, cybersecurity specialists, and energy system strategists.

The QTT module combines CC’s quantum expertise with input from our contacts at the University of Edinburgh, giving stakeholders a practical way to anticipate how and when quantum-related threats may emerge. Alongside this, the Q-ARM tool helps system operators identify vulnerable assets, understand potential quantum-enabled attacks, and assess associated risks – all presented in a clear and accessible format.

A central design principle has been usability. Both tools deliver their key functionality without requiring users to understand quantum technologies, instead providing clear, actionable insights without exposing the underlying complexity. This significantly lowers the barrier to adoption, allowing organisations to benefit without investing in specialist expertise.

Cost-effectiveness is also a priority. Rather than encouraging broad interventions, our approach allows operators to focus on the areas of greatest risk, ensuring resources are used efficiently and reducing the likelihood of unintended consequences elsewhere in the system.

This approach also supports the need for rapid action. With the National Cyber Security Centre highlighting a window through to 2031 for critical infrastructure to prepare, there is a clear urgency to act. Our tools help organisations navigate this transition, enabling structured planning and a data-driven view of where the most significant risks are likely to arise.

Quantum risk is a ‘now’ problem

We cannot overstate how timely this progress is. Globally, governments are increasingly focused on the growing quantum threat to critical infrastructure. As quantum computing advances towards breaking current encryption, risk will not arrive as a single ‘Q‑day’ – the point at which quantum computers can reliably defeat today’s cryptography – but as a continuous wave, with different techniques maturing at different times.

To respond effectively, operators must precisely understand their exposure – identifying the types of attack they face, when protections may fail, and how long systems must remain secure. This calls for targeted, cost‑efficient planning rather than broad, generic upgrades.

The core challenge is ensuring that every asset remains secure for as long as it matters. This requires not only robust mitigations, such as PQC, but also clear visibility over when action is needed and how to maintain trusted data flows over time.

Through our work with NESO, and other critical national infrastructure organisations, we’re working on approaches that embed quantum readiness into long-term resilience planning. As one of a small number of UK National Cyber Security Centre‑approved PQC Assured Service Providers, we’re ready to support more organisations in building structured risk assessments, aligning readiness timelines with government guidance, and delivering practical migration strategies.

If this is an area of interest, and you’d like to discuss how to tackle your own post‑quantum cybersecurity challenges, we’d be delighted to hear from you at PQC@cambridgeconsultants.com.

専門家

ジェームズ・クルーズ
量子アルゴリズムグループ アソシエイトディレクター | プロフィールを見る

ジェームズは、将来の顧客ニーズに対応するため、量子コンピューティング技術開発チームをけん引。量子コンピューティングの将来性と、その実現に向けた課題を明示するデモンストレーターの製作にも取り組む。

アレクサンドラ レハック
Head of Innovation Advisory - Energy & Industrial | プロフィールを見る

Alexandra has nearly 30 years of experience consulting on business, technology and innovation strategy. At CC, Alexandra is Head of the Energy + Utilities market sector, bringing her extensive experience in intelligent digital services, IoT and telecommunications to the challenges of the energy transition.

関連するインサイト

ディープテック

新規なテクノロジーや、そのテクノロジーを通じた長期的に持続可能な価値の創出について、ご関心をお持ちでしょうか。

当社はビジネスとテクノロジーが交差する場所での創造性に主眼を置き、お客様の事業を再定義するようなソリューションを創出します。

産業分野

お客様が目指す産業分野に関する深い見識を備え、ブレークスルーをもたらすディープテックを活用できて、価値を創出する活動で確かな実績を持つパートナーが必要です。

お客様の事業分野における当社の実績や、どのような事業上の優位性をお届けできるかについて、ご確認ください。

インサイト

ケンブリッジコンサルタンツの最新のインサイト、アイデア、視点をご確認ください。

ビジネスと社会の将来を形成するディープテックの動向を、最前線の事例を通じてお伝えします。

キャリア

ご自身の能力が評価され、真の差異を産み出せるような仕事に興味はありませんか。

これからキャリアをスタートする方でも、経験豊富な方でも、ぜひご連絡をお待ちしています。