Post-quantum cryptography is becoming an important cybersecurity consideration long before powerful quantum computers are expected to become widely available. Organizations may assume encrypted information is secure because current computing systems cannot realistically break the encryption protecting it. However, adversaries can collect sensitive encrypted data today and preserve it until quantum technology advances enough to potentially decrypt it, creating a long-term security risk for governments, financial institutions, and large corporations.
This “harvest now, decrypt later” threat means organizations need to consider not only the immediate value of their data but also whether that information could remain sensitive years into the future. Preparing for quantum computing therefore begins with understanding which systems, communications, and data could require stronger protection and developing a strategy for eventually migrating them to quantum-resistant security.
Talk about the long game: international adversaries are collecting our most secret encrypted messages so that the messages can be deciphered and read when quantum computers become available. The likely targets for this are governments, but if the adversary expects quantum computing to become more generally available and with data storage pricing at about 2 cents a gigabyte, why not also capture central bank and large corporate communications? This suggests that any information that might prove valuable to others – even after 10 years – should be quantum protected, and today the Department of Homeland Security suggests companies begin by cataloguing the data at risk:
“DHS recently released a road map for the transition, beginning with a call to catalogue the most sensitive data, both inside the government and in the business world. Maurer says this is a vital first step ‘to see which sectors are already doing that, and which need assistance or awareness to make sure they take action now.’
Experts say it could still be a decade or more before quantum computers are able to accomplish anything useful, but with money pouring into the field in both China and the US, the race is on to make it happen—and to design better protections against quantum attacks.
The US, through NIST, has been holding a contest since 2016 that aims to produce the first quantum-computer-proof algorithms by 2024, according to Moody, who leads NIST’s project on post-quantum cryptography.
Transitioning to new cryptography is a notoriously tricky and lengthy task, and one it’s easy to ignore until it’s too late. It can be difficult to get for-profit organizations to spend on an abstract future threat years before that threat becomes reality.
‘If organizations aren’t thinking about the transition now,’ says Maurer, ‘and then they become overwhelmed by the time the NIST process has been completed and the sense of urgency is there, it increases the risk of accidental incidents … Rushing any such transition is never a good idea.’”
The threat posed by quantum computing illustrates why cybersecurity planning must account for risks that may be years away. Post-quantum cryptography is not simply a problem to address once quantum computers become powerful enough to challenge existing encryption. Sensitive information collected today could remain valuable well into the future, giving adversaries an incentive to store encrypted communications in anticipation of eventually gaining the ability to decipher them.
For organizations, identifying which information faces the greatest long-term exposure is an important starting point. Cataloguing sensitive data and understanding how it is currently protected can help companies determine which systems and communications should receive priority as quantum-resistant technologies become available. This approach can be particularly important for governments, financial institutions, and corporations handling intellectual property, financial information, strategic communications, and other data with a long useful life.
Organizations also need to recognize that cryptographic migrations can take considerable time. Security technologies may be deeply embedded across applications, infrastructure, networks, and relationships with third-party providers. Waiting until quantum computing represents an immediate threat could force organizations into a rushed transition, increasing the possibility of implementation errors and security gaps.
Preparing early for post-quantum cryptography gives organizations time to understand their exposure, develop migration plans, and incorporate new protections methodically as standards and technologies mature. While the exact timeline for capable quantum computers remains uncertain, the long-term value of sensitive information makes quantum security a cybersecurity planning issue today rather than one that can safely be deferred until the technology arrives.
Overview by Tim Sloane, VP, Payments Innovation at Mercator Advisory Group








