Fortinet

Quantum Cybersecurity Risk Starts Before Quantum Computers Break Encryption

Quantum cybersecurity risk is already emerging as organisations confront harvest-now, decrypt-later threats and prepare for the transition to post-quantum cryptography.

Somewhere today, sensitive encrypted information stolen from a government agency, business, or critical infrastructure operator may already sit in an adversary’s archive. The attacker may not be able to read it yet. Instead, they may simply be waiting for technology that will let them.

This quantum cybersecurity risk sits behind the concept known as harvest now, decrypt later. It is also why organisations can no longer treat quantum computing as simply a future cybersecurity problem.

Quantum computers capable of breaking widely used forms of public-key cryptography are not yet available. The timing of that capability also remains uncertain. However, that uncertainty should not distract organisations from a more immediate risk. Sensitive information may already be exposed, while the timetable for preparing for post-quantum cryptography (PQC) is becoming clearer.

Quantum Cybersecurity Risk Is Creating Near-Term Deadlines

In Australia, the Australian Signals Directorate (ASD) recommends that organisations refine their PQC transition plans by the end of 2026. It recommends starting migration with critical systems and data by the end of 2028. Organisations should then complete the transition by the end of 2030. (1)

Google Cloud has also set a target to achieve full post-quantum cryptography readiness by 2029. (2)

These timelines make quantum resilience a current architecture, procurement, and investment issue. Organisations can no longer treat it simply as a future risk.

Nicole Henry, Head of Government Affairs, Australia and New Zealand, Fortinet, said, “Uncertainty about when a cryptographically relevant quantum computer will arrive should not be confused with uncertainty about the need to act. Government guidance and technology roadmaps are already moving. The decisions organisations make now will determine whether they can transition deliberately or are forced to do so under pressure.”

Nicole Henry

Harvest Now, Decrypt Later Changes the Risk Timeline

The harvest now, decrypt later threat changes when quantum cybersecurity risk begins.

Threat actors can intercept and store encrypted information that they cannot read today. They may then attempt to decrypt that information once sufficiently capable quantum computing becomes available.

As a result, the risk to sensitive data does not necessarily begin when quantum computers can break existing cryptography. It can begin when an adversary first intercepts the data.

Nicole Henry said, “Harvest now, decrypt later changes how organisations need to think about future threats. The risk begins much earlier, when sensitive information is captured. If that information still has value when quantum capability arrives, the exposure already exists today.”

This threat is particularly relevant for information that may remain sensitive for many years. Examples include government information, intellectual property, source code, merger and acquisition activity, and regulated personal information. Health and identity data, credentials, and critical infrastructure designs may also remain valuable for extended periods.

Quantum Readiness Goes Beyond Post-Quantum Cryptography

Harvest now, decrypt later, and the move to PQC are critical parts of the challenge. However, they do not represent the entire quantum readiness strategy.

Resilience must extend across data, identities, applications, networks, cloud environments, operational technology (OT), Internet of Things (IoT) devices, embedded technologies, and third-party services.

Organisations will also need effective governance and relevant skills. They must be able to test changes without disrupting critical services.

Nicole Henry said, “Much of the discussion around quantum cybersecurity focuses on Q-Day, when quantum computers become capable of breaking cryptographic systems that organisations rely on today. Waiting for a definitive date is not a practical risk management strategy when transition expectations and technology roadmaps are already creating nearer-term planning milestones.”

Data Visibility Is Central to Quantum Cybersecurity Risk

Organisations should already understand what sensitive information they hold and how long it must remain confidential. They should also know where that information is stored and how it moves between systems.

Quantum cybersecurity risk adds another time horizon to that existing responsibility.

Nicole Henry said, “Quantum does not create the need for visibility. It exposes the consequences of not having it. Organisations already need to understand their sensitive information, where it moves, who and what can access it, and how it is protected. That knowledge is fundamental to secure AI adoption, cyber risk management, and regulatory assurance.”

This visibility challenge becomes more important as technology and security priorities converge.

Organisations cannot manage quantum resilience, AI, identity, and cyber resilience in isolation. These areas depend on many of the same security foundations.

Businesses need visibility across increasingly complex environments. They must govern sensitive information and access appropriately, respond quickly to changing risks, and adapt as technologies and threats evolve.

AI, Cloud and Quantum Security Are Becoming Interconnected

Quantum computing adds urgency because cryptography and digital trust sit throughout modern technology environments. At the same time, organisations are transforming those environments with AI, cloud services, automation, and connected technologies.

A decision in one area can therefore create dependencies or constraints elsewhere.

Cryptography supports transport layer security (TLS), certificates, virtual private networks (VPNs), and code signing. It also supports identity systems, software updates, cloud services, third-party integrations, applications, and embedded devices.

That makes quantum cybersecurity risk more than a cryptography problem. It is also a data governance, architecture, procurement, supply chain, and technology lifecycle issue.

Suppliers Could Determine the Pace of PQC Migration

An organisation may rely on a cloud provider to process sensitive information. It may also depend on a partner to terminate encrypted connections.

Other dependencies can include appliances with embedded certificates or applications containing hard-coded cryptography.

As a result, an organisation’s ability to migrate may depend on technologies and suppliers outside its direct control.

Systems purchased today could also remain operational beyond the transition away from cryptography that is vulnerable to quantum attacks.

Organisations should therefore consider post-quantum readiness when making procurement and architecture decisions today.

The Post-Quantum Transition Creates Its Own Security Risks

The transition to PQC must also remain secure.

For a period, organisations will operate a mixture of legacy and post-quantum technologies. At the same time, AI and automation will continue to make cyberattacks faster and more scalable.

Configuration changes, compatibility problems, and uneven supplier readiness may create new security gaps.

Maintaining security and continuity during this period will be as important as selecting the cryptography that replaces today’s vulnerable standards.

Organisations will need to test changes, monitor dependencies, and maintain visibility across mixed environments.

Nicole Henry said, “The same foundation is essential for quantum resilience. Organisations need to understand where vulnerable cryptography is embedded, which identities and trust relationships depend on it, and where suppliers, cloud services, applications, or long-lived infrastructure could constrain their ability to transition.”

Building Quantum Resilience Does Not Mean Replacing Everything Today

Addressing quantum cybersecurity risk does not require organisations to replace every cryptographic system immediately.

Instead, they need to build the visibility, governance, skills, supplier engagement, and architectural flexibility required for the transition.

Organisations can then identify their exposure and understand cryptographic dependencies. They can also test changes safely and establish a migration strategy before the transition becomes urgent.

Some systems may be relatively straightforward to update. Others may depend on vendor roadmaps, protocol changes, architecture changes, certificate lifecycles, or hardware replacement.

Organisations must design their transition plans so they can manage these changes without disrupting critical services.

Nicole Henry said, “Quantum is not an immediate operational crisis; however, it is a current planning responsibility. The objective is to prepare early enough to protect sensitive information, manage the transition securely, and avoid making today’s technology decisions tomorrow’s constraints.”

Quantum Cybersecurity Risk Requires Decisions Today

For organisations responsible for long-lived sensitive information, preparing for quantum cybersecurity risk is no longer only about predicting what future computers may be able to do.

It is about the decisions organisations make today across architecture, procurement, investment, governance, and the technology lifecycle.

Those decisions must protect current operations while creating a secure path towards post-quantum resilience.

References

1 – https://www.cyber.gov.au/business-government/secure-design/quantum/planning-for-post-quantum-cryptography

2 – https://cloud.google.com/blog/products/identity-security/pqc-in-plaintext-google-clouds-post-quantum-cryptography-roadmap

Shopping Cart0

Cart

Login