The Imperative & The Important - PQC Edition
Attackers aren’t beating defenders to new vulnerabilities. They’re beating them to old ones. That’s this edition’s story — and it’s the same story the post-quantum migration has been telling for two years. Underneath the headlines sits one discipline: you can’t fix what you haven’t found.
The Imperative
Patch Tuesday reached the factory floor. Siemens published ten security advisories, led by a maximum-severity flaw in its Simatic IoT2050 Advanced industrial gateways: missing authentication that lets a remote attacker — no credentials required — execute code with elevated privileges. Schneider Electric patched code-execution bugs in NetBotz data-center monitoring appliances, and Phoenix Contact fixed PLCnext controller firmware flaws that unauthenticated attackers could use to knock systems offline or inject malicious database queries (SecurityWeek). The business translation: if these gateways sit at your network edge, this isn’t a quarterly-maintenance item. It’s a this-week item.
The water-utility campaign keeps spreading. Cyberattacks on US water systems — suspected to be linked to Iran-backed actors — are now reported in at least twelve states, up from the seven states in the original FBI and EPA alert, with Minnesota hit hardest at thirty systems (RubyComm/CBS). The targets aren’t the giants with security teams. They’re small utilities running internet-exposed programmable logic controllers (PLCs) — the computers that open valves and run pumps — that nobody was watching.
The quantum clock got a new keeper. Aspen Digital launched a project to prepare institutions for quantum computers capable of breaking today’s public-key encryption, a direct response to the June executive order that accelerated the federal post-quantum cryptography (PQC) timeline (Inside Cybersecurity). When the policy establishment starts building readiness infrastructure, the migration has moved from “if” to “when.”
And three deadlines put a legal clock on all of it:
· August 24 — comments close on NIST SP 800-213r1, the updated IoT product cybersecurity requirements for the federal government (NIST)
· September 11 — the European Union’s Cyber Resilience Act (CRA) 24-hour vulnerability-reporting duty takes effect for manufacturers
· September 21 — NIST’s Cryptographic Module Validation Program (CMVP) stops accepting modules that don’t meet updated FIPS standards
The Important: The Backlog Is the Threat Model
Here’s the number that should reorganize your security priorities. Forescout counted 37,137 newly published vulnerabilities in the first half of 2026 — up 51 percent year over year, with 55 percent rated high or critical. But the headline stat isn’t the volume. It’s this: 46 percent of the vulnerabilities added to CISA’s Known Exploited Vulnerabilities (KEV) catalog this year were publicly disclosed before 2026 even started (IoT For All).
Read that again. Nearly half of the flaws attackers are actively exploiting right now were known — published, documented, patchable — before New Year’s Day. Attackers aren’t racing researchers to weaponize the newest zero-day. They’re working through a backlog: cameras, industrial gateways, badge readers, sensors — devices running software nobody got around to patching, on networks nobody fully mapped.
The exploitation isn’t happening in the gap between known and unknown vulnerabilities. It’s happening in the gap between known and fixed.
And that gap is about to get a legal clock. When the Cyber Resilience Act’s reporting duty starts September 11, manufacturers must report actively exploited vulnerabilities within 24 hours — including for devices already deployed in the field. A GSMA survey found only 22 percent of organizations call themselves highly prepared. Half either can’t push remote updates at all or run devices too constrained — the smart meter buried in a field, the sensor on a shipping container — to accept them.
This is the same structural problem the post-quantum migration faces, wearing different clothes. In PQC, the hard part isn’t the new algorithms — NIST finalized those two years ago. It’s discovering where the old cryptography lives. In IoT, the hard part isn’t the patches — they exist. It’s knowing which of your ten thousand devices needs one.
The playbook transfers almost verbatim:
· Discovery — enumerate every device and every algorithm, the way a cryptographic bill of materials (CBOM) enumerates where cryptography lives. You can’t patch what you haven’t mapped, and you can’t migrate what you haven’t discovered.
· Agility — the ability to update a vulnerable device remotely is the same muscle crypto-agility builds for swapping a broken algorithm. The unpatched-forever population defines your compensating-control budget in both worlds.
· Governance — someone has to own the gap between known and fixed. If no one owns that number, it grows — whether the “known” is a CVE or a quantum-vulnerable key exchange.
The discipline is identical: inventory first. Device inventory is to IoT security what the CBOM is to quantum readiness. Organizations that build the discovery muscle once will use it twice.
Three Questions to Ask This Week
1. Can you produce a complete device inventory in under a day? If the answer involves a spreadsheet last updated in 2024, that’s your project — not the firewall upgrade.
2. Which of your deployed devices can accept a remote update — and which never will? The unpatched-forever population defines your compensating-control budget. The crypto version of this question is due on your desk before the federal PQC deadlines arrive.
3. Who owns the gap? Not the patch, the gap — the time between a vulnerability being known and being fixed on your equipment. On September 11 that gap gets a 24-hour legal clock in the EU. If no one owns that number, it grows.
The Imperative & The Important is the daily briefing from Carl’s Corner — timely developments and the durable ideas underneath them, across post-quantum cryptography, IoT and OT security, cybersecurity, and enterprise AI.
Sources
· SecurityWeek — ICS Patch Tuesday: https://www.securityweek.com/ics-patch-tuesday-vulnerabilities-fixed-by-siemens-schneider-phoenix-contact-2/
· IoT For All — Half of 2026’s Worst IoT Exploits Were Already Out in the Open:
https://newsletter.iotforall.com/p/half-of-2026-s-worst-iot-exploits-were-already-out-in-the-open
· RubyComm/CBS — water-system attacks in at least 12 states: https://www.rubycomm.com/headlines-2026
· Inside Cybersecurity — Aspen Digital quantum-security project: https://insidecybersecurity.com/daily-news/aspen-digital-launches-project-address-security-risks-accelerated-quantum-computing
· NIST CSRC — SP 800-213r1 public comment period: https://csrc.nist.gov/news