Bipartisan Senate bill aims to prepare energy sector for Q
Bipartisan Senate bill would direct FERC to factor quantum computing threats and post-quantum cryptography into US electric grid cybersecurity reliability standards.
The Quantum Grid Utility Assurance and Resilient Defense (Quantum-GUARD) Act, introduced by Senators Mike Rounds and Chris Coons, would require FERC to consider quantum computing threats when reviewing electric reliability standards and to explore post-quantum cryptography use in both IT and OT systems, plus a technical sandbox to study quantum impacts. It aligns with NIST's post-quantum algorithm work, and a June executive order moved the federal PQC migration deadline from 2035 to 2030. Industry experts noted the hard part is upgrading infrastructure such as SCADA communications and software update integrity ahead of those deadlines.
- Bill expands FERC reliability reviews to include quantum-era cyber threats
- Creates a technical sandbox studying quantum impact on IT and OT systems
- Follows NIST post-quantum cryptography standards work for government and industry
- Federal PQC migration deadline accelerated from 2035 to 2030 by executive order
- Experts flag quantum-vulnerable legacy public key controls protecting SCADA
Full article660 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Under the bill, FERC would consider cyber threats from quantum computers and post-quantum cryptography in its reliability standards for the energy sector.
Listen to this article
0:00
Learn more.
A new bipartisan Senate bill would require federal regulators to prepare the U.S. electric grid for cybersecurity threats from quantum computers and create a technical sandbox to study how the technology could impact both information and operational technology systems.
The Quantum Grid Utility Assurance and Resilient Defense (Quantum-GUARD) Act, introduced by Sens. Mike Rounds, R-S.D., and Chris Coons, D-Del., would direct the Federal Regulatory Energy Commission when reviewing proposed reliability regulatory standards for electricity owners and operators under the Federal Power Act.
FERC updates its reliability standards to account for emerging cybersecurity concerns, and the legislation would expand those reviews to include the future threat of hacks from quantum computers.
The legislation also directs FERC to explore potential uses of post-quantum cryptography in IT and OT systems and “take such action the Commission determines to be appropriate based on that consideration.”
In a statement, Coons said quantum computing brings “new economic opportunities” along with “tremendous cybersecurity risks.”
“As the technology races forward and our adversaries continue to seek vulnerabilities in our critical systems, we need to pass the Quantum-GUARD Act to ensure our government is using every available tool to meet this threat,” said Coons.
The federal government has been an early adopter of post-quantum cryptography for its digital systems. The National Institute for Standards and Technology has worked with cryptographers to develop new “post-quantum” encryption algorithms that will be used by most governments and the private sector.
Under the Biden administration, most federal agencies were required to migrate their systems and data to “PQC” encryption by 2035. In June, an executive order from the Trump administration pushed that timeline up to 2030.
Ali Shaikh, CEO of Graphiant, a networking infrastructure startup, told CyberScoop that the bill would represent a good start in terms of pushing greater adoption of quantum-resistant encryption, “the real work is upgrading infrastructure, not applications, ahead of the deadlines.”
Evgeny Gervis, CEO of SafeLogic, compared the energy sector’s challenges to previous efforts by FERC and industry to gain adoption at scale for other technological upgrades, like smart grid equipment. Among those challenges is prioritizing security upgrades in a sector where reliability is paramount.
“The highest priority for electric utilities will be preservation of integrity and availability, both services that are widely supported by legacy public key cryptographic controls that are quantum vulnerable,” said Gervis. “It is essential that quantum computers do not undermine the integrity and authenticity of SCADA communications or the software update process.“
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/quantum-guard-act-electric-grid-cybersecurity/