Network Security in a Quantum Future – Beta
Project summary
As UK Critical National Infrastructure, the energy system must be secure against malicious cyberattacks.
| Name | Status | Project reference number | Start date | Proposed End date | Expenditure |
|---|---|---|---|---|---|
| Network Security in a Quantum Future – Beta | Live | 10166255 | Aug 2026 | Mar 2028 | £7,211,187 |
Project Summary
As UK Critical National Infrastructure, the energy system must be secure against malicious cyberattacks.
Emerging quantum computing technologies will enable attackers to break currently secure encryption and open significant new attack vectors. To ensure resilience, energy networks must therefore consider quantum threats in their cybersecurity strategies; however, understanding quantum impact requires highly specialist knowledge.
After successfully prototyping innovative risk management approaches to assessing the quantum threat to the energy network in Alpha, the Network Security in a Quantum Future (NSiaQF) Beta will develop quantum threat management tools to map quantum threats to energy system assets and prioritise appropriate mitigations.
Innovation Justification
Meeting Challenge Requirements
NSiaQF's is aligned to Challenge 5: Enhanced system visibility and control, by enhancing resilience of the GB energy sector to emerging quantum-enabled cyber-attacks through novel software and computing tools:
- NSiaQF's tools will enable security against quantum threats for the technologies required for real-time system monitoring and grid visibility, and facilitate more direct self-healing and resilience technologies by ensuring data security.
- Automating aspects of quantum risk management will facilitate trusted communication and coordination between grid operators, generators, and consumers, directly contributing to grid resilience.
State-of-the-art
No current tools can reliably support informed decision-making about quantum threats to energy networks:
- Discovery and modelling tools lack data on quantum-enabled attacks, detecting theoretical vulnerabilities, but, critically, they cannot estimate risk.
- Quantum threat characterisation is primarily from academic sources that don't track evolution or update dynamically.
Innovation
NSiaQF goes beyond incremental innovation to fill these gaps and improve energy sector resilience:
- Characterising and articulating quantum risks: NSiaQF tools will produce novel, evidence-based estimates of quantum risk, combining 'time-to-attack' (time until sufficient quantum computing resources become available to attackers) with 'time-of-attack' (time required to initiate and execute a quantum attack). NSiaQF tools will generate trusted and actionable quantum threat reports for energy system cryptographic protocols that won't require quantum expertise to understand, including communication of risk evolution over time and the associated uncertainty.
- Embedding quantum risk management into BAU: In line with NCSC guidance, NSiaQF's repeatable, evidence-based approach will support well-planned, cost-effective PQC migrations, aiding trade-off decisions and prioritisation as part of BAU.
- Modelling energy network assets: Beta will continue development of a standardised energy asset library, adding new asset models. Our transparent, modular approach will enable standardisation and risk reduction and streamline adoption by networks.
Counterfactuals
Alternatives are expensive, risky, or insufficient:
- Manual approaches: The number/complexity of interconnected energy assets make manual prioritisation for PQC migration impractical, risking delays in addressing vulnerabilities. Also requires hard-to-access expert quantum threat knowledge.
- Reactive approaches: Ad-hoc PQC migration approaches would increase up-front expenditure and total cost of ownership due to early, unnecessary upgrades and/or incorrect prioritisations.
- Other tools: Do not deliver the information or functionality required.
SIF Learning and Stakeholder Input
Alpha learnings:
- Automated identification of quantum risks for modelled energy assets.
- Modelled quantum computing methods to predict when specific algorithms and key lengths will be vulnerable.
Beta will build on these, and address challenges identified during Alpha:
- Manage the highly variable quantum implementation approaches pursued by corporations and national laboratories and the resulting impacts on the risk assessment.
- Capturing and communicating uncertainty from quantum research.
- Making the QTT an attractive open-source tool to capture quantum information from experts.
Our comprehensive Alpha engagement strategy ensured NSiaQF will be valuable to the sector through:
- Soliciting feedback via industry presentations and 1-2-1 discussions with networks.
- Sharing a 'clickable demo' of the tool.
We have not identified other network-funded projects exploring quantum threats to the energy sector.
Readiness Levels (Alpha-\>Beta)
Beta will make the tools production-ready, enhancing quality, accuracy, reliability, and trustworthiness.
TRL4-\>TRL7
IRL3-\>IRL6
CRL3-\>CRL8
Scale
NSiaQF will support the sector in managing quantum risk by developing high-quality, reliable, scalable tools for potential use by all GB energy networks. To this end, NSiaQF Beta adds SPEN (Distribution and Transmission) and National Gas as partners and creates a Quantum-Security Advisory Council (Q-SAC) to ensure industry alignment and continued working-in-the-open.
SIF Funding
Quantum cybersecurity threats pose a nationally significant, industry-wide challenge. The complexity and interconnectedness put NSiaQF out-of-scope of normal energy network strategic planning and other network funding mechanisms. SIF has enabled a structured response (developing a process, then a tool) through sector-wide collaboration.
Impacts and Benefits
For all the SIF benefits identified in the Impacts and Benefits selection question, you must:
1 - Describe what the current position (pre-innovation baseline) is, and the metrics that will be used to report on these
2 - Provide an initial forecast of the quantified or qualified cumulative net benefits to Energy consumers to be realised, calculated at a network partner level, should the innovation be implemented into business as usual
3 - Describe, quantify, or qualify any benefits already realised through project delivery
Current Situation
Quantum-enabled cyberattacks against GB energy networks will be possible in 8-10 years. In the pre-innovation Baseline, energy networks take a passive approach to preparation, relying on vendors to deliver quantum-related security upgrades. This is more realistic than assuming they would "do nothing", which would be a dereliction of networks' license conditions and NCSC guidance.
Under Baseline, migration delays and poorly prioritised upgrades would increase the risk of quantum-enabled cyberattacks, leaving energy networks vulnerable for an unacceptable time period.
Our CBA assesses overall benefits of NSiaQF (Tool Development Scenario):
- 30-year NPV (compared to baseline): £82.8Bn
- Costs: £0.85Bn over the full forecast period to 2054, of which £6.19Mn for Beta project funding
- 3-year break-even
NSiaQF Benefits :
Financial - future reductions in the cost of operating the network
Avoided cost of quantum-enabled cyberattack: NSiaQF Discovery estimated the cost at tens of billions. The impact would be so severe that the benefit of anything that mitigates the risk is significantly greater than can be expressed by NPV calculations alone.
Metric: Avoided cost of cyberattack; conservatively, £19.4Bn by 2054.
Reduced cost of cybersecurity expenditure: Requirements for cybersecurity expenditure will reduce over time, as NSiaQF enables operators to address highest-impact mitigations first, spread costs over time, and plan upgrades cost-effectively by using up-to-date quantum information.
Metric: Savings vs counterfactual cybersecurity spend. Cumulative cybersecurity spend in NSiaQF scenario will drop below Baseline from 2036 onwards; by 2054, savings will be £38.5Bn.
Environmental - carbon reduction -- indirect CO2 savings per annum
Avoided increase in CO2 emissions from quantum-enabled cyberattack: In a blackout, networks would rely more on gas power plants. Would save ~658,520 tCO2e in emissions by 2054.
New to Market -- Products
Introduction of Q-ARM as a tool for network operators: There is currently no available tool for network operators to easily assess and prioritise energy system assets for quantum vulnerability. Q-ARM will be commercialisation-ready at the end of Beta.
Metric: Number of operators adopting the tool.
Creation of QTT as a Resource for Quantum and Cybersecurity Development: There is currently no common approach for the quantum community to share information on quantum impacts on cybersecurity. In Beta/post-Beta, QTT will enable valuable collaboration by quantum experts, feeding directly into Q-ARM's energy asset risk assessments.
Metrics: Number of active QTT contributors; number of code downloads.
Other Benefits
De-risking cybersecurity of energy network assets and systems in the post-quantum world
A reduced risk of quantum-enabled cyberattack brings societal benefits:
- Reduced number of customer interruptions: Based on expected number of customers interrupted from a national/regional (5% of GB) attack: avoiding ~24.1m interruptions.
- Reduced customer minutes lost: Based on the same expected number of customers interruptions, multiplied by average disruption length (7-days national; 3.5-days regional): avoiding ~233Bn minutes lost.
- Avoided cyberattack-linked fatalities: Based on expected number of fatalities: saving ~1,195 lives.
- Avoided attack-linked injury: Based on the expected number of major injuries: avoiding ~2,390 injuries.
Alternative Approach
We evaluated an alternative scenario, Rip-and-Replace, where operators undertake full-scale pre-emptive replacement of their cryptographic assets to be quantum-safe. While more beneficial than Baseline, it still delivers fewer financial, environmental and societal benefits than the NSiaQF tool scenario (lower 30-year NPV £39.3Bn), with higher up-front costs (£12.4Bn).
Already-Realised Benefits
- Developed clear and innovative approach to characterising attack types enabled by quantum computers, linked to asset types.
- Drawing on previously unconnected research sources to create unique mapping tables that enable automated quantum risk discovery: a definitive mapping of mathematical problems; a unique mapping of quantum attack and mitigation types; and a mapping of quantum-enabled attacks to system security properties.
- QTT already created as an open-source tool to start engaging the quantum community.
| Name | Published |
|---|---|
| SIF Beta Round 5 Project Registration | September 2026 |