Industries
The problem is usually the same and the constraints never are. A hospital, a substation and a data centre all need people and sites connected to one private network, but what they are allowed to do about it differs. These pages take each sector on its own terms rather than swapping a word in a template.
Regulated services
Healthcare
Healthcare cybersecurity is the one where the buyer usually did not ask for the job. A clinical group with several sites, external suppliers on the network, nobody dedicated to security, and a legal obligation that arrived by decree.
Financial services
Financial services cybersecurity is DORA territory, where the demand is not just that you are secure but that you can demonstrate it on request, including for your own suppliers.
Public sector
Public sector cybersecurity adds procurement rules, formal tender requirements and a preference for evidence over assurances.
Industrial and operational technology
Operational technology
OT security covers the part of the network that was never designed to be on a network. Equipment with a twenty year service life, vendors who will void support if you patch, and a plant manager who is measured on uptime. The useful question is not how to modernise it. It is what you can put around it.
Industrial control systems
SCADA
ICS security and SCADA cyber security go a layer deeper, into control systems and the supervisory layer above them, where the protocols predate the idea of an attacker and the fix cannot be a firmware update.
Manufacturing
Manufacturing cybersecurity is where those constraints meet a production line that cannot stop, and a supply chain that keeps asking you to fill in security questionnaires.
Energy
Critical infrastructure
Energy cybersecurity and critical infrastructure cybersecurity add a regulator with statutory powers and, under NIS2, named individuals who carry the responsibility personally.
Transportation
Aerospace
Transportation cybersecurity and aerospace cybersecurity deal with sites that move or sit far from anything: roadside cabinets, depots, hangars, temporary installations.
Infrastructure and providers
Data centres
Data centre security is about tenancy and separation, and about proving that separation to someone who audits you.
Managed service providers
MSP cybersecurity is the multiplier case. You are not securing one network, you are securing thirty, and every one of them is somebody else's.
What is the same everywhere
Underneath the sector differences, the mechanism does not change.
QS-WAN and QNova Client
QS-WAN gives the organisation a private network of its own, with one console for every gateway, device and policy. QNova Client puts that network on the device, as one signed agent instead of five separate products.
Post-quantum by default
Everything between a device, a gateway and the control plane is post-quantum by default, aligned to FIPS 203, FIPS 204 and CNSA 2.0, hybrid by design. The cryptographic inventory is documented by subsystem, which is the artefact regulators tend to ask for first.
Where it runs
Where it runs is usually the sector’s first question, and there are three answers. The control plane can be licensed onto your own infrastructure, inside your own boundary, which is what an isolated plant or a defence supplier normally needs. It can arrive as a gateway we ship you, configured, which suits sites with no rack and no local IT. Or we host it and you manage it from a browser. The choice is generally decided by whether the network is allowed to touch the public internet at all.
A product, not a managed service
One thing worth saying plainly, because sector pages are where it gets blurred. QuantumNova is a product, not a managed service. Nobody here watches your network. The platform produces the risk score and the evidence, and your people, or your provider, read them.
Not sure which one fits
Most organisations sit across two of these. If yours does, start with the constraint that is hardest to move and we will work outward from it.