Home
/
Industries
/
Critical infrastructure
Energy, water, transport & industrial

Assets built to run for thirty years. Cryptography with a published expiry date.

Operational technology cannot be patched on an IT schedule. Discovery has to be safe for a live process environment, and migration has to be sequenced around outage windows measured in years.

Plan a pilot
See discovery methods
The constraint set

Everything that makes IT migration hard is worse here

A cryptographic programme designed for a data centre will fail in a process environment. The constraints are structural, not cultural.

Asset lifetime

Twenty to forty years in service

Equipment commissioned today will outlive the standards that currently permit its cryptography. The replacement cycle, not the migration plan, sets the real timeline.

Priority order

Availability outranks confidentiality

Safety and continuity come first. A scan that risks a process upset is not an acceptable trade, which rules out most active discovery on a live control network.

Vendor control

Firmware belongs to the OEM

The migration path is a procurement conversation before it is an engineering one, and for many fielded devices no upgrade is offered at all.

Change windows

Opportunities are measured in years

Some assets can be touched once a year. Some once a decade. Sequencing has to be built around those windows rather than around severity alone.

Discovery that is safe for OT

Passive first, credentialed second, active only where authorized

Active scanning of a live process network is frequently prohibited, and reasonably so. Coverage in this environment comes from method selection, not scan aggression.

Sequencing

Migrate the boundary before the plant floor

Most achievable near-term risk reduction in critical infrastructure sits at the IT and OT boundary, not deep in the process network. Sequence accordingly.

For the lowest layers the honest answer is often not migration but compensating controls until the asset is replaced. An inventory that says so is more useful than one that pretends otherwise.

Regulatory context

NERC CIP, NIS2, TSA and IEC 62443 on cryptography

Framework
Relevance to cryptography
Evidence Qinsight supports
NERC CIP
Cyber security standards for the bulk electric system, including asset identification and information protection
Cryptographic asset inventory tied to CIP-classified systems
EU NIS2
Risk management obligations for essential and important entities, including the use of cryptography
Policy coverage and cryptographic control evidence
TSA security directives
Requirements for pipeline and rail operators, including network segmentation and access control
Boundary cryptography posture and change history
IEC 62443
Industrial automation and control system security across the supply chain
Component-level cryptographic declarations via CBOM
EU PQC roadmap
Critical infrastructure high-risk use cases targeted for transition by 2030
Readiness baseline and dependency mapping

Start at the boundary

Scope one site or one IT and OT boundary, using passive collection where active scanning is not permitted.