Skip to content

Case Studies

Case Study: Oil and Gas Operator Validates Post-Quantum Encryption on Systems With No Migration Path

A national oil company piloted post-quantum encryption for exploration data, protecting SCADA systems and industrial controls at the network layer.

5 min read
months to validate Planning, deployment and validation in a production-equivalent environment.
3
applications changed Gateways carry the encryption, so applications, endpoints and legacy infrastructure stay as they are.
0
years exploration data stays sensitive Geological surveys and reservoir models hold commercial value for decades.
20+

A multi-national oil company with more than 50,000 employees has validated post-quantum encryption for its exploration data in a production-equivalent environment, without changing the applications that produce and consume it. The pilot took roughly three months from planning to validated result, and it ended with approval for production deployment and a multi-year budget for phased enterprise rollout.

This case study is based on a real engagement with a national oil company; all identifying details have been anonymized, and the technical and operational themes are preserved.

Data that outlives the infrastructure carrying it

Geological survey data informs drilling decisions for more than 20 years, and reservoir models stay commercially sensitive for decades. The infrastructure carrying it is long-lived too, and much less flexible: SCADA systems, legacy applications, industrial controls and proprietary protocols that will operate into the 2040s and cannot be replaced without massive capital expenditure.

Cryptography runs on a different clock, changing every few years as standards evolve, and the encryption protecting this data is already vulnerable or scheduled for deprecation. Adversaries collecting encrypted traffic today can hold it until the computational capability to read it exists, which is what turns a 20-year sensitivity window into a present-tense problem.

Sandia National Laboratories made the same observation about asset lifespans in its 2021 Critical Infrastructure Decision-Making Study:

U.S. critical infrastructure assets are often designed to operate for decades.

The oil and gas sector spans an unusually wide technology mix: modern enterprise applications alongside constrained devices and decades-old legacy systems, each presenting its own post-quantum migration problem.

Application-level migration cannot reach the systems that need it most

In an organization with decades of accumulated technology, application-level migration means updating hundreds of applications: custom-built systems from the 1990s, third-party software whose vendors are long gone, and embedded systems with no development environment. Each one needs its own development work, its own testing and its own deployment window.

Development teams already prioritize business features over cryptographic updates, and many developers do not have specialized knowledge of how to deploy cryptography well. Accurate testing requires recreating production scenarios that often do not exist outside live environments. Coordinated across hundreds of applications, post-quantum migration becomes a multi-year program, and for this environment that meant five to seven years across hundreds of development teams.

For 20 to 30-year-old SCADA systems, proprietary industrial protocols and embedded controls, coordinated application-level updates are effectively impossible. There are no vendors left to support the changes, no test harnesses that reflect real-world behavior, and change control is tightly constrained. Those are also the systems carrying the data with the longest sensitivity window, so the cost and complexity of application code changes made network-level protection both the easier and the more cost-effective route.

Gateways carry the encryption, so the applications do not

QuProtect R3 deploys at network gateways, which separates security from application logic. Applications, endpoints and legacy infrastructure do not change, and data flows through quantum-safe tunnels transparently. When cryptographic standards change, only the gateway layer needs updating rather than the thousands of applications and endpoints behind it.

That separation changes the shape of the work. Managing cryptography at the application level makes every application its own migration unit, each needing development, testing and a deployment window, and it leaves many legacy and OT systems with no route at all. Managing it at the network level gives a single team a single technology on a coordinated schedule, with timelines measured in months rather than years.

The pilot

QuProtect R3 agents were deployed in a production-equivalent test environment, with gateways placed at strategic network points so that exploration data flows from multiple operating regions were routed through quantum-safe tunnels and validated. The full effort, from initial planning through deployment and validation, took approximately three months.

The harder problem was organizational. Application development teams initially assumed they would need to update their own code, and had begun assessing backlog impact and estimating months of development work. Security architecture and network teams argued for a network-level approach instead, and the debate turned less on cryptography than on who owns post-quantum migration and how priorities are set across business units and regions.

The pilot resolved that question at a practical level, because application teams watched their systems operate unchanged through quantum-safe gateways. Once they saw their workloads function normally without code changes, the conversation moved from how to update the applications to how quickly the approach could be deployed.

Performance validation found no disruption, with latency impact negligible and within acceptable parameters. The organization used its own established testing tools rather than QuProtect R3’s built-in performance tooling, which kept the results inside the operational frameworks it already trusted.

What the pilot proved

  • Phased production deployment greenlit. Operational validation in a production-equivalent environment gave executive leadership the proof it needed, with the exploration business unit sponsoring production rollout.
  • Legacy system protection achieved. The network-level approach extended quantum-safe protection to decades-old SCADA systems, proprietary industrial protocols and embedded controls that had no viable application-level migration path.
  • Crypto-agility demonstrated. Centralized policy updates and algorithm rotation were proven operationally, so the organization can adapt as cryptographic standards evolve without touching applications, redeploying infrastructure or coordinating hundreds of development teams.
  • Integration framework established. SIEM was adapted to the gateway model to support segmented systems, network monitoring baselines were set, SOC procedures were updated, and change-control templates were created and approved. No parallel infrastructure was required.
  • Deployment approach validated. Gateway placement strategy, performance benchmarks and testing procedures are documented for the wider rollout.
  • Post-quantum cryptography moved from planning to operation. The organization has a clear path to production scale and a foundation for future regulatory and competitive requirements.

Production deployment begins with the exploration data flows validated in the pilot, and the integration framework established there is what lets the rollout across additional business units and regions move faster than the first.

Download the full case study

The full case study covers the sector’s technology mix, the gateway architecture, the integration work and the organizational questions the pilot resolved, along with an appendix on how QuProtect R3 addresses operational technology.

Get the case study

Protecting What You Can't Replace: Crypto Agility For Oil & Gas Critical Infrastructure

The full pilot: the sector's technology mix, the gateway architecture, the integration work, and what production approval required.

Download the PDF PDF · 4.0 MB

Ready to take command of your cryptography?

Get a personalized briefing from our team and see QuProtect R3 in action.