Leah Hale at Beyond Blue describes the long shadow of risk from quantum computing and shares tips on how organisations need to respond

Quantum computing is no longer a distant technical curiosity. It is a governance issue centred on long-term confidentiality, the durability of digital signatures, and the ability to transition away from vulnerable cryptography in a controlled way.
The organisations that will cope best with the technology are those building visibility, prioritisation, and cryptographic agility now.
Quantum computing is not simply a faster version of today’s technology. It represents a fundamentally different capability that could make certain mathematical problems, particularly those underpinning modern cryptography, far easier to solve.
This matters because cryptography underpins almost everything in the digital economy, from secure communications and identity to digital signatures and financial transactions.
Around 95% of web traffic is now encrypted using protocols such as HTTPS. These rely heavily on public key cryptography, including RSA, Diffie-Hellman, and elliptic curve algorithms, all of which are widely understood to be vulnerable to future quantum attacks.
This means quantum computing represents a severe threat to current and widely used security models.
As encryption adoption has increased, so has reliance on these methods. At the same time, adversaries are already believed to be collecting encrypted data today in anticipation of future decryption, often referred to as “harvest now, decrypt later”.
For organisations, this represents a serious threat to their cyber-resilience. Once quantum computing fully surfaces, cryptography as we know it today will be broken.
This means organisations must take steps now to understand where they depend on vulnerable cryptography and prepare for how they can transition before it becomes a problem.
Quantum risk is unusual because the point of exposure and the point of impact is separated by many years.
Decisions made today about data retention, system design, and cryptographic dependencies can create risks that only materialise much later. Sensitive data encrypted now may still be exposed in the future if it is harvested and decrypted once quantum capabilities mature.
This creates a structural imbalance. Organisations must protect data for years or decades, while attackers only need to wait.
The challenge is compounded by how deeply cryptography is embedded. It is not confined to a single control or system. It runs through identity platforms, applications, infrastructure, supplier products, and operational technology. In many cases, it has been hard-coded into systems that were never designed to be easily changed, or were developed when quantum was a far-off theoretical risk.
Different sectors will also face varying migration challenges.
Financial services are generally viewed as being in a stronger position due to more modern IT environments, shorter technology refresh cycles, and mature regulatory oversight, making transition timelines potentially achievable within the next two to five years.
However, healthcare faces a more difficult path because of legacy clinical systems, connected medical devices, and the need to protect sensitive patient data over long periods.
Meanwhile, critical infrastructure sectors such as energy and utilities may face the longest and most complex transition of all.
Many operational technology and industrial control systems were designed for stability and longevity rather than cryptographic agility, with some assets remaining operational for decades. In these environments, upgrading cryptography is not simply a software change, it requires hardware replacement, supplier coordination, operational downtime planning, and extensive safety testing.
Quantum risk does not affect all organisations equally. Exposure depends on two factors: how long data needs to remain secure, and how complex the technology environment is.
The most significant risk sits with information that must remain confidential or trustworthy over long periods. This includes personal and health records, financial and identity data, legal and evidential records, intellectual property, and government information.
Shorter-lived data may lose value quickly, but it is still exposed to integrity risks. The ability to forge digital signatures or manipulate transactions could undermine trust in systems even in the near term.
This is why quantum risk is not only about secrecy. It is about trust over time.
Certain sectors are more exposed than others.
Regulators are no longer treating quantum as a distant issue.
In the UK, the National Cyber Security Centre has outlined a timeline for migration to post-quantum cryptography, with discovery and planning expected by 2028, initial migration of high-risk systems by 2031, and broader transition by 2035.
In the US, federal agencies are already required to inventory cryptographic systems and prepare migration plans. NIST has finalised its first post-quantum standards and signalled that widely used algorithms such as RSA and elliptic curve cryptography should be phased out over the next decade.
But what can organisations do to prepare?
For organisations looking to get ahead in their quantum preparedness journeys, the following steps reflect common guidance from authorities including NIST, the NCSC, and MAS.
They are designed to support preparation and prioritisation, not premature disruption.
Quantum computing does not require organisations to act in haste, but it does require them to act with intent.
The risk is not defined by a single breakthrough moment. It is shaped by a long period in which today’s design decisions quietly determine tomorrow’s exposure.
Organisations that manage this well are those that use the time available now to build visibility, make informed trade-offs, and ensure their systems and governance structures can adapt when change becomes unavoidable.
Leah Hale is a Senior Cybersecurity Consultant at Beyond Blue
Main image courtesy of iStockPhoto.com and ArtemisDiana
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543