ao link
Menu
Teiss - Cracking Cyber Security
Teiss - Cracking Cyber Security

Quantum computing: what leaders need to understand now

Leah Hale at Beyond Blue describes the long shadow of risk from quantum computing and shares tips on how organisations need to respond

Linked InXFacebook
bookmark_borderSave to Library

Quantum computing is no longer a distant technical curiosity. It is a governance issue centred on long-term confidentiality, the durability of digital signatures, and the ability to transition away from vulnerable cryptography in a controlled way.

 

The organisations that will cope best with the technology are those building visibility, prioritisation, and cryptographic agility now.

 

Quantum computing is not simply a faster version of today’s technology. It represents a fundamentally different capability that could make certain mathematical problems, particularly those underpinning modern cryptography, far easier to solve.

 

This matters because cryptography underpins almost everything in the digital economy, from secure communications and identity to digital signatures and financial transactions.

 

Around 95% of web traffic is now encrypted using protocols such as HTTPS. These rely heavily on public key cryptography, including RSA, Diffie-Hellman, and elliptic curve algorithms, all of which are widely understood to be vulnerable to future quantum attacks.

 

This means quantum computing represents a severe threat to current and widely used security models.

 

As encryption adoption has increased, so has reliance on these methods. At the same time, adversaries are already believed to be collecting encrypted data today in anticipation of future decryption, often referred to as “harvest now, decrypt later”.

 

For organisations, this represents a serious threat to their cyber-resilience. Once quantum computing fully surfaces, cryptography as we know it today will be broken.

 

This means organisations must take steps now to understand where they depend on vulnerable cryptography and prepare for how they can transition before it becomes a problem.

 

The nature of the risk

Quantum risk is unusual because the point of exposure and the point of impact is separated by many years.

 

Decisions made today about data retention, system design, and cryptographic dependencies can create risks that only materialise much later. Sensitive data encrypted now may still be exposed in the future if it is harvested and decrypted once quantum capabilities mature.

 

This creates a structural imbalance. Organisations must protect data for years or decades, while attackers only need to wait.

 

The challenge is compounded by how deeply cryptography is embedded. It is not confined to a single control or system. It runs through identity platforms, applications, infrastructure, supplier products, and operational technology. In many cases, it has been hard-coded into systems that were never designed to be easily changed, or were developed when quantum was a far-off theoretical risk.

 

The migration timeline challenge

Different sectors will also face varying migration challenges.

 

Financial services are generally viewed as being in a stronger position due to more modern IT environments, shorter technology refresh cycles, and mature regulatory oversight, making transition timelines potentially achievable within the next two to five years.

 

However, healthcare faces a more difficult path because of legacy clinical systems, connected medical devices, and the need to protect sensitive patient data over long periods.

 

Meanwhile, critical infrastructure sectors such as energy and utilities may face the longest and most complex transition of all.

 

Many operational technology and industrial control systems were designed for stability and longevity rather than cryptographic agility, with some assets remaining operational for decades. In these environments, upgrading cryptography is not simply a software change, it requires hardware replacement, supplier coordination, operational downtime planning, and extensive safety testing.

 

What and who is at risk

Quantum risk does not affect all organisations equally. Exposure depends on two factors: how long data needs to remain secure, and how complex the technology environment is.

 

The most significant risk sits with information that must remain confidential or trustworthy over long periods. This includes personal and health records, financial and identity data, legal and evidential records, intellectual property, and government information.

 

Shorter-lived data may lose value quickly, but it is still exposed to integrity risks. The ability to forge digital signatures or manipulate transactions could undermine trust in systems even in the near term.

 

This is why quantum risk is not only about secrecy. It is about trust over time.

 

Certain sectors are more exposed than others.

  • Financial services rely on cryptography to enable trust at scale across payments, identity, and fraud prevention. If cryptographic mechanisms are weakened, the consequences could include fraudulent transactions, identity compromise, and loss of confidence in financial systems.
  • Healthcare faces a different challenge. Patient records and medical data often need to remain confidential for decades. This makes the sector particularly vulnerable to long-term decryption risks, alongside concerns about the integrity of clinical systems and devices.
  • Critical infrastructure sectors such as energy and utilities face exposure through operational technology. Many systems are long-lived and difficult to update, with cryptography embedded in firmware or controlled by suppliers. The risk here extends beyond data into the potential disruption of essential services.

 

A regulatory shift towards action

Regulators are no longer treating quantum as a distant issue.

 

In the UK, the National Cyber Security Centre has outlined a timeline for migration to post-quantum cryptography, with discovery and planning expected by 2028, initial migration of high-risk systems by 2031, and broader transition by 2035.

 

In the US, federal agencies are already required to inventory cryptographic systems and prepare migration plans. NIST has finalised its first post-quantum standards and signalled that widely used algorithms such as RSA and elliptic curve cryptography should be phased out over the next decade.

 

But what can organisations do to prepare?

 

A step-by-step plan

For organisations looking to get ahead in their quantum preparedness journeys, the following steps reflect common guidance from authorities including NIST, the NCSC, and MAS.

 

They are designed to support preparation and prioritisation, not premature disruption.

  1. Assign executive ownership. Give quantum readiness a named senior owner and define how progress will be reported through existing governance structures.
  2. Identify the crown jewels. Determine which data, systems, and trust mechanisms must remain secure over the long term.
  3. Build a cryptographic inventory. Understand where cryptography is used across certificates, identity platforms, applications, devices, and suppliers.
  4. Review data retention. Reduce unnecessary long-term data storage to limit future exposure.
  5. Prioritise high-risk areas. Focus on use cases where long-term confidentiality and migration complexity are greatest.
  6. Engage suppliers early. Assess how suppliers rely on cryptography and whether they support future transition.
  7. Design for cryptographic agility. Ensure systems can adapt to new algorithms without full redesign.
  8. Create a phased roadmap. Develop a realistic transition plan with milestones and dependencies.
  9. Revisit regularly. Treat quantum readiness as an ongoing governance issue, not a one-off project.

Quantum computing does not require organisations to act in haste, but it does require them to act with intent.

 

The risk is not defined by a single breakthrough moment. It is shaped by a long period in which today’s design decisions quietly determine tomorrow’s exposure.

 

Organisations that manage this well are those that use the time available now to build visibility, make informed trade-offs, and ensure their systems and governance structures can adapt when change becomes unavoidable.

 


 

Leah Hale is a Senior Cybersecurity Consultant at Beyond Blue

 

Main image courtesy of iStockPhoto.com and ArtemisDiana

Linked InXFacebook
bookmark_borderSave to Library
Teiss - Cracking Cyber Security

Subscribe to our Weekly Newsletter

Receive the latest insights direct to your inbox, and gain access to our exclusive events.
Teiss - Cracking Cyber Security

Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF

 

020 8349 4363

info@teiss.co.uk

 © 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543