adobestock_1956279202

Designing for a post-quantum future: what port operators need to consider now

Quantum computing is advancing rapidly. Once fully operational, quantum computers will be able to perform specific calculations exponentially faster than any  classical computer and be employed to enable key business capabilities such as (financial, medical and operational) simulations, explorations of complex and multi-dimensional scenarios and optimisation of large-scale systems. They will bring many benefits and capabilities, but they will also break traditional cryptography. 

While quantum computing full commercial maturity is often placed around the mid-2030s the implications for cyber security are already here. For ports and maritime operators, this presents a fundamental challenge: much of today’s infrastructure relies on traditional  cryptographic protections that future quantum computers will be able to break. And with assets designed to operate for decades, decisions made today will still be in place when those threats materialise. 

A risk that already exists 

The challenge isn’t just about future capability, it's about current exposure. 

Sensitive data being transmitted across maritime ecosystems today can be collected and stored by adversaries, with the intention of decrypting it later when quantum computing becomes viable. This “harvest now, decrypt later” threat is already recognised as a significant risk.  

For ports and ship-to-port infrastructures, this includes: 

  • Commercial and cargo data 
  • Operational and logistics information 
  • Access control and identity data 
  • Asset management information 
  • Financial management and monitoring data 
  • Position and Navigation timing data 
  • Long-lived records such as contracts, intellectual property and personal information  

This means organisations need to think beyond immediate cyber defence, and start planning for future resilience. 

Why ports are particularly exposed? 

Ports operate as complex, interconnected ecosystems, linking vessels, infrastructure, logistics platforms and supply chains. Across these systems, traditional cryptography underpins security for both IT and Operational Technology (OT), including: 

  • Logistics and container tracking systems 
  • Automated cranes and vehicle movement platforms 
  • Gate access and identity systems 
  • Communications between ship and shore 
  • Positioning, navigation and timing systems  

These systems were not designed with quantum threats in mind, and retrofitting security later is far more complex and costly. At the same time, growing digitalisation and automation, particularly in smart and autonomous port environments, continues to expand the attack surface. 
 

The core challenge: it’s not a technology upgrade, it’s a design issue 

NIST, a leading cyber standardisation agency, has already specified Post Quantum Cryptography (PQC) algorithms and the industry has built PQC-compliant solutions.  

However, the transition to post-quantum cryptography (PQC) is not a simple system upgrade. It is a systemic challenge that spans the entire maritime ecosystem.  

For port operators, this raises a critical question: How do you embed long-term cyber resilience into systems that are being designed, procured and deployed today? The answer lies in shifting from reactive security to secure-by-design thinking. 

 
What port owners and operators should be considering now

1. Understand where cryptography is embedded

Identify where cryptographic protection is used across your estate, particularly in data exchange, authentication, software updates and control systems. Without this visibility, it is difficult to assess exposure or prioritise action.

2. Distinguish between short and long-lived data

Not all data carries the same risk. Operational data may lose value quickly, but long-lived data, such as contracts, infrastructure models or personal data, remains sensitive for years and is more vulnerable to future decryption. Prioritisation should reflect this.

3. Factor quantum risk into new infrastructure decisions

With asset lifecycles often spanning 25–30 years, security decisions made today must account for future threats. This means: 

  • Aligning procurement requirements with emerging PQC standards 
  • Challenging suppliers on their readiness 
  • Embedding cyber requirements into system design, not adding them late

4. Take a risk-based approach to legacy systems

For existing infrastructure, full replacement is rarely feasible. Instead, organisations should assess: 

  • Which systems present the highest exposure 
  • Where retrofit or “drop-in” solutions could be viable 
  • How to sequence upgrades based on operational risk  

5. Address supply chain dependencies

    Port operations rely heavily on third-party systems and providers. Ensuring alignment across the supply chain is critical, particularly given the need to enforce consistent cyber standards and compliance. 

    6. Start planning now, not later

    Industry guidance already recommends that organisations begin PQC planning immediately, with full migration expected over the coming decade.  

    Given the complexity of maritime systems, early action is essential. 

     
    Moving from awareness to action 

    Quantum computing will reshape cyber risk across maritime, and ports sit at the centre of that ecosystem. Organisations that act early will be better positioned to: 

    • Protect long-term data integrity and confidentiality 
    • Avoid costly late-stage redesign or retrofit 
    • Maintain trust across stakeholders and supply chains 

    The shift to post-quantum security is not just a technical evolution, it is a strategic one. 

    And for port owners and operators, the time to act is now. 

    Share this

    Related content