The quantum attack surface is bigger than it seems

ยฉ Getty Images/iStockphoto/ipopba

ยฉ Getty Images/iStockphoto/ipopba
Somewhere between a wind farm substation and the utility's central control room sits a patchwork of equipment nobody quite planned for. Programmable logic controllers running firmware from a decade ago. Remote terminal units wired into protection relays older than the company's IT department. A SCADA system that, until fairly recently, nobody outside the operations team had ever logged into. That patchwork is now part of the energy sector's information technology and operational technology landscape whether anyone designed it that way or not - and it's exactly the kind of environment where IT/OT convergence gets tested for real, not on a slide.
The NIS2 directive is no longer a project on the horizon. It is enforced EU law, and national law in most member states now reflects its requirements for cybersecurity risk management, incident reporting, and business continuity. Compared with its predecessor, NIS1, the scope has grown substantially: many more organizations across critical sectors and important entities now fall under the regulation, from energy and transport to healthcare, banking, and digital infrastructure.