Quantum risk starts before quantum computers can break encryption

Joint-capabilities
|
By: Nicole Henry
Specialists from the Joint Task Force 661 Defensive Cyber Operations team at Camp Ricarte, Puerto Princesa City, in the Philippines, during Exercise ALON 25. Photo: CPL Adam Abela

Opinion: Somewhere today, sensitive encrypted information taken from a government agency, business, or critical infrastructure operator may already be sitting in an adversary’s archive. They may not be able to read it yet. They may simply be waiting for the technology that will let them.

Opinion: Somewhere today, sensitive encrypted information taken from a government agency, business, or critical infrastructure operator may already be sitting in an adversary’s archive. They may not be able to read it yet. They may simply be waiting for the technology that will let them.

This is the challenge behind harvest now, decrypt later, and it is one reason quantum computing can no longer be treated simply as a future cyber security problem. Quantum computers capable of breaking widely used forms of public-key cryptography are not yet available, and the precise timing of that capability remains uncertain. However, uncertainty about arrival should not obscure a more immediate reality: sensitive information may already be exposed, and the transition timetable is becoming clearer.

In Australia, the Australian Signals Directorate (ASD) recommends that organisations refine their post-quantum cryptography (PQC) transition plans by the end of 2026, begin migration with critical systems and data by the end of 2028, and complete the transition by the end of 2030. Google Cloud has also set a target to achieve full post-quantum cryptography readiness by 2029. These signals make quantum resilience a current architecture, procurement, and investment issue, rather than one that can be treated simply as a future risk.

 
 

Uncertainty about when a cryptographically relevant quantum computer will arrive should not be confused with uncertainty about the need to act. Government guidance and technology roadmaps are already moving. The decisions organisations make now will determine whether they can transition deliberately or are forced to do so under pressure.

This scenario is known as harvest now, decrypt later. Threat actors intercept and store encrypted information that they cannot read today, intending to decrypt it once sufficiently capable quantum computing becomes available. The risk to sensitive data does not necessarily begin when quantum computers can break existing cryptography. It can begin when that data is intercepted.

Harvest now, decrypt later changes how organisations need to think about future threats. The risk begins much earlier, when sensitive information is captured. If that information still has value when quantum capability arrives, the exposure already exists today.

This is particularly relevant for information that may remain sensitive for many years. This includes government information, intellectual property, source code, merger and acquisition activity, regulated personal information, health and identity data, credentials, and critical infrastructure designs.

Harvest now, decrypt later and the move to PQC are critical parts of the challenge; however, they are not the whole quantum readiness strategy. Resilience will need to extend across data, identities, applications, networks, cloud, operational technology (OT), internet of things (IoT), embedded technologies, and third-party services. Organisations will also need governance, relevant skills and the ability to test changes without disrupting critical services.

Much of the discussion around quantum cyber security focuses on Q-Day, when quantum computers become capable of breaking cryptographic systems that organisations rely on today. Waiting for a definitive date is not a practical risk management strategy when transition expectations and technology roadmaps are already creating nearer-term planning milestones.

Organisations should already understand what sensitive information they hold, how long it needs to remain confidential, and where it is stored and transmitted. Quantum risk adds another horizon to that existing responsibility.

Quantum does not create the need for visibility. It exposes the consequences of not having it. Organisations already need to understand their sensitive information, where it moves, who and what can access it, and how it is protected. That knowledge is fundamental to secure AI adoption, cyber risk management, and regulatory assurance.

This visibility challenge is becoming more important as technology and security priorities converge. Quantum resilience, AI, identity, and cyber resilience cannot be managed in isolation when they depend on many of the same foundations. Organisations need to see what matters across increasingly complex environments, govern sensitive information and access appropriately, respond quickly to changing risk, and adapt as technologies and threats evolve.

Quantum adds urgency because cryptography and digital trust are embedded throughout the same environments organisations are transforming with AI, cloud, automation, and connected technologies. Decisions made in one area can create dependencies or constraints in another.

Cryptography supports transport layer security (TLS), certificates, virtual private networks (VPNs), code signing, identity systems, software updates, cloud services, third-party integrations, applications, and embedded devices.

Quantum readiness is a data governance, architecture, procurement, supply chain, and technology life cycle issue. An organisation may rely on a cloud provider to process sensitive information or a partner to terminate encrypted connections. It may also rely on appliances with embedded certificates or applications containing hard-coded cryptography. Its ability to migrate may depend on technologies and suppliers outside its direct control.

Systems purchased today could remain operational beyond the transition from cryptography that is vulnerable to quantum attack.

The transition itself also needs to be secured. For a period, organisations will operate a mixture of legacy and post-quantum technologies. At the same time, AI and automation will continue to make attacks faster and more scalable. Configuration changes, compatibility issues, and uneven supplier readiness may create new seams.

Maintaining security and continuity throughout this period will be as important as selecting the cryptography that replaces today’s vulnerable standards. Organisations will need to test changes, monitor dependencies, and maintain visibility across mixed environments.

The same foundation is essential for quantum resilience. Organisations need to understand where vulnerable cryptography is embedded, which identities and trust relationships depend on it, and where suppliers, cloud services, applications, or long-lived infrastructure could constrain their ability to transition.

This does not mean replacing every cryptographic system immediately. It means building the visibility, governance, skills, supplier engagement, and architectural flexibility needed for the transition. Organisations can then identify exposure, understand cryptographic dependencies, test changes safely, and establish a strategy before migration becomes urgent.

Some systems may be relatively straightforward to update. Others may depend on vendor roadmaps, protocol or architecture changes, certificate life cycles, or hardware replacement. The ability to manage those changes without disrupting critical services needs to be designed into the transition from the outset.

Quantum is not an immediate operational crisis; however, it is a current planning responsibility. The objective is to prepare early enough to protect sensitive information, manage the transition securely, and avoid making today’s technology decisions tomorrow’s constraints.

For organisations responsible for long-lived sensitive information, preparing for quantum risk is no longer only about predicting what future computers may be able to do. It is about the decisions organisations make today across architecture, procurement, investment, governance, and the technology life cycle. These decisions must protect current operations while creating a secure path to post-quantum resilience.

***Nicole Henry is head of government affairs for Australia and New Zealand at Fortinet.***

Want to see more stories from trusted news sources?
Make Defence Connect a preferred news source on Google.
Click here to add Defence Connect as a preferred news source.

Tags: