Quantum computing is advancing rapidly. Once fully operational, quantum computers will be able to perform specific calculations exponentially faster than any classical computer and be employed to enable key business capabilities such as (financial, medical and operational) simulations, explorations of complex and multi-dimensional scenarios and optimisation of large-scale systems. They will bring many benefits and capabilities, but they will also break traditional cryptography.
While quantum computing full commercial maturity is often placed around the mid-2030s the implications for cyber security are already here. For ports and maritime operators, this presents a fundamental challenge: much of today’s infrastructure relies on traditional cryptographic protections that future quantum computers will be able to break. And with assets designed to operate for decades, decisions made today will still be in place when those threats materialise.
A risk that already exists
The challenge isn’t just about future capability, it's about current exposure.
Sensitive data being transmitted across maritime ecosystems today can be collected and stored by adversaries, with the intention of decrypting it later when quantum computing becomes viable. This “harvest now, decrypt later” threat is already recognised as a significant risk.
For ports and ship-to-port infrastructures, this includes:
This means organisations need to think beyond immediate cyber defence, and start planning for future resilience.
Why ports are particularly exposed?
Ports operate as complex, interconnected ecosystems, linking vessels, infrastructure, logistics platforms and supply chains. Across these systems, traditional cryptography underpins security for both IT and Operational Technology (OT), including:
These systems were not designed with quantum threats in mind, and retrofitting security later is far more complex and costly. At the same time, growing digitalisation and automation, particularly in smart and autonomous port environments, continues to expand the attack surface.
The core challenge: it’s not a technology upgrade, it’s a design issue
NIST, a leading cyber standardisation agency, has already specified Post Quantum Cryptography (PQC) algorithms and the industry has built PQC-compliant solutions.
However, the transition to post-quantum cryptography (PQC) is not a simple system upgrade. It is a systemic challenge that spans the entire maritime ecosystem.
For port operators, this raises a critical question: How do you embed long-term cyber resilience into systems that are being designed, procured and deployed today? The answer lies in shifting from reactive security to secure-by-design thinking.
Identify where cryptographic protection is used across your estate, particularly in data exchange, authentication, software updates and control systems. Without this visibility, it is difficult to assess exposure or prioritise action.
Not all data carries the same risk. Operational data may lose value quickly, but long-lived data, such as contracts, infrastructure models or personal data, remains sensitive for years and is more vulnerable to future decryption. Prioritisation should reflect this.
With asset lifecycles often spanning 25–30 years, security decisions made today must account for future threats. This means:
For existing infrastructure, full replacement is rarely feasible. Instead, organisations should assess:
Port operations rely heavily on third-party systems and providers. Ensuring alignment across the supply chain is critical, particularly given the need to enforce consistent cyber standards and compliance.
Industry guidance already recommends that organisations begin PQC planning immediately, with full migration expected over the coming decade.
Given the complexity of maritime systems, early action is essential.
Quantum computing will reshape cyber risk across maritime, and ports sit at the centre of that ecosystem. Organisations that act early will be better positioned to:
The shift to post-quantum security is not just a technical evolution, it is a strategic one.
And for port owners and operators, the time to act is now.
Chloe Yarrien
Maritime Autonomous Systems (MAS) are moving from concept to operational reality. Across defence and commercial maritime sectors, organisations are exploring how autonomy can improve operational effectiveness, increase persistence, reduce risk to personnel and enable new ways of working.
Dr Thomas Beard - UK / Europe
John Bensalhia from the IMarEST talks to Thomas Beard and Jake Rigby, about the potential benefits, difficulties and future outcomes of making nuclear-powered vessels a reality.
Panagiotis Kasionis
Coal cargoes remain a high-risk “routine” trade. Panagiotis Kasionis, explores key risks, regulatory changes and practical insights for managing exposure across the supply chain.
Dr Thomas Beard - UK / Europe
As shipping transitions to low‑carbon fuels, safety has become the defining challenge. This interview by RINA's The Naval Architect, explores how alternative fuels such as methanol, ammonia, hydrogen and LNG introduce new risks, and how smart vessel design, layered protection and crew competence are essential to delivering decarbonisation without compromising safety.