
Most of the conversation about quantum computing and cybersecurity has revolved around the potential for data theft, particularly the ability to decrypt massive amounts of sensitive information.
But there is another risk that could hit manufacturers even harder: physical disruption.
Once cryptographically-relevant quantum computers (CRQCs) become available, an event known as “Q-Day,” they could enable a new class of cyberattacks against operational technology systems that disrupt production or even cause physical damage. According to the 2026 IBM X-Force Threat Intelligence Index, manufacturing was the most targeted industry for the fifth consecutive year, and is increasingly on the front lines of geopolitically-motivated cyber intrusions.
Operators need to prepare for these threats now, before Q-Day arrives.
What Does Quantum Actually Break?
To understand the operational threat, it is important to first understand why CRQCs are so significant.
Sufficiently powerful quantum computers will be able to break widely used public-key cryptography, including RSA and elliptic curve cryptography (ECC) that underpins much of cybersecurity today. These algorithms not only help protect corporate IP and customer information, but also secure everything from employee logins and remote access to firmware updates, security patches, and, in newer environments, device authentication and machine-to-machine connections.
Once attackers can defeat this cryptography, they will not just be able to read a manufacturer’s data. They could also impersonate trusted systems and manipulate data in transit. They could pose as a trusted contractor or legitimate software vendor, impersonate an HMI used to manage live operations, or falsify data from a sensor responsible for safety monitoring.
Stuxnet is a prime example: the most infamous industrial cyberattack in history manipulated programmable logic controllers (PLCs) to alter the speed of centrifuges while feeding operators false process data that made the system appear to be operating normally. Now imagine similar attacks becoming easier to execute across a much broader range of industrial systems.
The Top Operational Risks
For plant operators, there are five risks that matter most:
- Man-in-the-middle attacks: A quantum-capable attacker could defeat vulnerable cryptography protecting the remote-access connections employees and contractors use to operate, service, and monitor industrial environments. Breaking the key exchange on a remote-access tunnel, or on any plant network segment where OT traffic is genuinely encrypted, could allow an attacker positioned in the communications path to intercept traffic and potentially inject commands that the controller accepts as legitimate. Where HMI-to-PLC traffic still runs in plaintext, as it does on many plant floors, an attacker with that position needs no cryptanalysis at all, which is its own argument for hardening these paths now.
- Device identity forgery: Quantum attacks could also undermine newer operational environments that rely on certificate-based authentication to establish device identity. Protocols such as OPC UA and CIP Security can use public-key cryptography to verify that a device is legitimate. If those mechanisms rely on quantum-vulnerable algorithms, an attacker could potentially forge the credentials needed to impersonate a trusted HMI, controller, or other device. The attacker could then issue fraudulent commands to PLCs, inject PLC-to-PLC messages, or falsify sensor telemetry and RTU responses. The result is corruption of the information that automated systems and human operators rely on to make decisions.
- Network-wide identity attacks: The danger becomes even greater if attackers compromise the cryptographic trust infrastructure itself. Certificate authorities are trust anchors for many networks. If a certificate authority relies on quantum-vulnerable signatures and an attacker can derive its private signing key, the attacker could potentially issue fraudulent certificates that the network accepts as legitimate. Instead of impersonating one device at a time, the attacker could create multiple trusted identities and use them to manipulate communications across the environment.
- Fake firmware updates: Attackers could also target plants through their software and firmware supply chains. Traditionally, this has meant compromising a vendor or its build environment to insert malicious code into a legitimate update, as attackers did in the SolarWinds campaign. Quantum computing could create another path. If an attacker can derive a vendor’s private signing key from a vulnerable public key, they could distribute malicious firmware that appears completely authentic without ever having to breach the vendor itself. Devices that rely on the vendor’s public key to verify updates could accept the malicious firmware as legitimate, potentially allowing attackers to alter device settings, operational behavior, or safety limits.
- Collapsing network segmentation: These attacks could also weaken one of the industry’s most important defensive strategies. Manufacturers increasingly separate IT from OT, and divide OT environments into additional zones, to prevent an intruder from moving freely through the plant. But in places where access between those zones depends on quantum-vulnerable certificates and authentication, forged identities could allow attackers to cross boundaries that operators assumed were protected. Segmentation would still matter, but cryptographic compromise could undermine some of the controls enforcing it.
Legal and Insurance Implications
The unusual nature of quantum-enabled attacks could also complicate insurance reimbursement and increase an organization’s exposure in future litigation.
Attackers with the ability to impersonate trusted systems and manipulate authenticated data could potentially destroy, alter, or fabricate key evidence, including logs, audit trails, and other forensic records. This could make it harder to establish whether an incident resulted from an external cyberattack, operator error, or mechanical failure.
The ambiguity could complicate a cyber insurance claim, trigger disputes over which exclusions or policies apply, and make regulatory reporting more difficult when investigators cannot confidently determine what happened.
If a disrupted process causes an injury, environmental release, or defective product to reach customers, those evidentiary problems become even more serious. A company could face substantial liability while struggling to demonstrate that the underlying cause was a sophisticated external attack.
What Manufacturers Need to Do Now
Manufacturers should begin by mapping the keys and certificates across their OT and IT environments, but they should not let a comprehensive audit become a prerequisite for action. Where a remote-access path, vendor connection, or other critical system is already known to be exposed, start hardening it now rather than waiting for a complete inventory.
They should also prioritize systems based on shelf life and potential impact. Process recipes, plant schematics, equipment configurations, and other sensitive information can remain valuable for decades and may already be targeted for collection. Protect long-lived data first, followed closely by the connections, identities, and controllers capable of affecting physical machinery and production.
At the same time, manufacturers need to build cryptographic agility into their systems wherever possible. Avoid hard-coding specific cryptographic algorithms, and manage cryptography centrally so algorithms and keys can be updated as standards and threats evolve. Hybrid approaches that combine existing encryption with post-quantum cryptography can ease the transition on upgradable equipment, while technologies such as out-of-band key delivery can provide additional protection for legacy devices that cannot easily be re-engineered.
For equipment that cannot be made quantum-safe before it is retired (whether it runs quantum-vulnerable algorithms it cannot shed or has no cryptographic capability to begin with), manufacturers should strengthen the defenses around it. Tighten network segmentation and access controls, place quantum-safe protections at appropriate network boundaries, and monitor aggressively for anomalous activity.
The goal is to limit how far an attacker can move and how long an intrusion can remain undetected. For the unprotected legacy tier in particular, these controls are not a stopgap for a future threat; they are the only thing standing between that equipment and an attacker today.
Plants also need a fallback for situations in which operators can no longer trust what their systems are telling them. Establish independent ways to validate critical sensor readings and operational data, particularly for processes where false information could trigger a shutdown, conceal equipment damage, or cause operators to take dangerous corrective action.
Preserve critical logs and forensic data through separate, protected channels where possible, and require independent verification before operators make high-consequence changes based on unexpected readings. In a quantum attack, monitoring systems may not simply go dark. They may actively lie.
Finally, manufacturers need to address quantum security at procurement. Equipment purchased today may still be operating after Q-Day, which means its cryptographic future is being decided now. Require support for NIST’s finalized post-quantum cryptography standards, field-updatable cryptographic algorithms, and a cryptographic bill of materials in vendor contracts.
Preparing now is the best way to ensure that when Q-Day arrives, a cryptographic breakthrough does not become a physical operational crisis.





















