Skip to main content
CybersecurityVulnerability Management

Senate Bill Targets Energy Sector's Quantum Cybersecurity Gaps

Power grid control room with industrial systems and monitoring equipment.

"As the technology races forward and our adversaries continue to seek vulnerabilities in our critical systems, we need to pass the Quantum-GUARD Act to ensure our government is using every available tool to meet this threat," said Sen. Chris Coons.

What the Quantum-GUARD Act would require of the Federal Regulatory Energy Commission

The Quantum Grid Utility Assurance and Resilient Defense (Quantum-GUARD) Act, introduced by Sens. Mike Rounds, R-S.D., and Chris Coons, D-Del., would direct the Federal Regulatory Energy Commission to change how it reviews proposed reliability regulatory standards submitted under the Federal Power Act. Specifically, the legislation would expand FERC's reviews so they account for the future threat of hacks enabled by quantum computers and would require the Commission to explore post-quantum cryptography (PQC) for use in both information technology (IT) and operational technology (OT) systems. The bill instructs FERC to “take such action the Commission determines to be appropriate based on that consideration.”

Technical sandbox to study information and operational technology risks

The bill also would create a technical sandbox designed to study how quantum computing could affect both information and operational technology systems. That sandbox is intended to provide a practical forum to assess impacts on systems that run enterprise networks as well as the OT systems that control physical grid operations.

Post-quantum cryptography and federal timelines

The federal government has already begun moving toward PQC. The National Institute for Standards and Technology worked with cryptographers to develop new “post-quantum” encryption algorithms intended for widespread use by governments and the private sector. According to the reporting, under the Biden administration most federal agencies were required to migrate their systems and data to “PQC” encryption by 2035; an executive order in June from the Trump administration moved that deadline to 2030.

Industry reactions from Graphiant and SafeLogic

Private-sector technologists offered measured reactions. Ali Shaikh, CEO of Graphiant, told CyberScoop the bill would be “a good start in terms of pushing greater adoption of quantum-resistant encryption,” while warning that “the real work is upgrading infrastructure, not applications, ahead of the deadlines.”

Evgeny Gervis, CEO of SafeLogic, framed the energy sector’s challenge in historical terms, comparing it to prior FERC and industry efforts to gain adoption at scale for other technological upgrades such as smart grid equipment. He emphasized priorities for utilities: “The highest priority for electric utilities will be preservation of integrity and availability, both services that are widely supported by legacy public key cryptographic controls that are quantum vulnerable.” Gervis added, “It is essential that quantum computers do not undermine the integrity and authenticity of SCADA communications or the software update process.”

What this means for technologists, regulators, and electric utilities

  • Technologists and security teams: Expect attention to infrastructure-level work. As Ali Shaikh noted, real effort will be needed to upgrade underlying networking and systems infrastructure, not just application-level code, to meet PQC deadlines.
  • Regulators and FERC: The bill would place a new statutory expectation on the Federal Regulatory Energy Commission to incorporate quantum-threat assessments into reliability standard reviews and to explore PQC uses in both IT and OT, with authority to act on those findings.
  • Electric utilities and OT operators: Executives must weigh the sector’s “highest priority” duties—preserving integrity and availability—against the vulnerability of widely used legacy public key cryptographic controls, and guard SCADA communications and software update mechanisms from potential quantum-enabled attacks, per Evgeny Gervis’ warning.

Senators Rounds and Coons have framed the legislation as a forward-looking measure to prepare the power grid for a future quantum risk landscape; Coons emphasized both the “new economic opportunities” and the “tremendous cybersecurity risks” posed by quantum computing. The bill would specifically direct the Federal Regulatory Energy Commission to study and, where appropriate, act on post-quantum defenses and to run a technical sandbox examining impacts to IT and OT systems.

Read the original CyberScoop report: https://cyberscoop.com/quantum-guard-act-electric-grid-cybersecurity/