Quantum Thought Leadership

What is Quantum Computing and why does it matter?
Quantum computing is not simply a faster form of today’s technology. It represents a fundamentally different capability that could make certain mathematical problems, particularly those underpinning modern cryptography, significantly easier to solve.
This matters because cryptography underpins almost everything in the digital economy, from secure communications and identity to digital signatures and financial transactions. Today, around 95% of web traffic is encrypted using protocols such as HTTPS, which rely on cryptographic mechanisms to secure data in transit. These protocols depend heavily on public key cryptography such as RSA, Diffie-Hellman, and elliptic curve algorithms, which are widely understood to be vulnerable to future quantum attacks.
The risk is not theoretical. As encryption adoption has increased, so has reliance on these underlying cryptographic methods. At the same time, adversaries are already believed to be collecting encrypted data today in anticipation of future decryption, often referred to as “harvest now, decrypt later”.
For leaders, this is not a distant innovation topic. It is a long-term resilience challenge. The question is not when quantum computing will arrive, but whether organisations understand where they depend on vulnerable cryptography and how prepared they are to transition before it becomes a problem.
What is the problem?
The challenge with quantum risk is not simply that current cryptography may become vulnerable in the future. It is that organisations are already exposed today, but without immediate consequences.
Unlike most technology risks, the point of exposure and the point of impact can be separated by many years. Decisions made now about data retention, system design, and cryptographic dependencies can create risks that only materialise much later. As the National Institute of Standards and Technology explains, “encrypted data remains at risk because of the ‘harvest now, decrypt later’ threat in which adversaries collect encrypted data now with the goal of decrypting it once quantum technology matures.”
This creates a structural asymmetry. Organisations must protect sensitive data for years or decades, while attackers only need to wait. As noted by the National Institute of Standards and Technology, “some secrets need to be kept for many years… a sufficiently large-scale quantum computer… would be capable of breaking much of the public-key cryptography used on digital systems today.”
The challenge is compounded by how deeply cryptography is embedded. It is not confined to a single system or control, but woven throughout identity platforms, applications, infrastructure, supplier products, and operational technology. In many cases, it has been hard-coded into systems that were never designed to be easily changed.
What and Who is at risk?
Quantum risk does not affect all organisations equally. The level of exposure depends on two key factors: the longevity of data and trust requirements, and the complexity of the technology environment in which cryptography is embedded.
Long-term vs short-term risk
The most significant risk sits with information that must remain confidential or trustworthy over long periods of time. Data with a short lifespan, such as routine operational communications, may lose value quickly. However, other categories of information must remain secure for decades.
Examples of long-term sensitive data include:
- Personal and health records
- Financial and identity data
- Legal, contractual, and evidential records
- Intellectual property and research data
- Government and national security information
In contrast, shorter-term data may have limited long-term value, but is still exposed to integrity risks, such as the potential for forged digital signatures or manipulated transactions.
The implication is that quantum risk is not just about secrecy. It is also about trust over time.

Sectors most exposed
Sectors are affected differently depending on how much they rely on long-lived sensitive data, digital trust mechanisms, and technology environments that are difficult to change. The most exposed sectors tend to combine all three, creating both higher impact and more complex transition challenges.
Financial services (banking and insurance)
Financial services are among the most exposed due to their dependence on cryptography to enable trust at scale. Public key cryptography underpins payments, customer authentication, digital identity, fraud prevention, and non-repudiation across the sector.
The risk is not limited to data confidentiality. It extends to real-time integrity and trust. If cryptographic mechanisms are weakened, the consequences could include fraudulent transactions, identity compromise, and loss of confidence in financial systems.
Migration is complex because:
- Cryptography is deeply embedded across core banking and payment systems
- High transaction volumes require seamless, non-disruptive transition
- Regulatory and audit requirements constrain how and when change can occur
Healthcare
Healthcare is highly exposed due to the long-term sensitivity of data. Patient records, diagnostic histories, and genomic data may need to remain confidential for decades, often for the lifetime of an individual.
This makes the sector particularly vulnerable to harvest now, decrypt later risks.
Beyond confidentiality, healthcare also depends on trusted systems and devices. Compromised signatures or identities could impact clinical systems, medical devices, and patient safety.
Migration challenges include:
- Legacy clinical systems and connected medical devices
- Long procurement and certification cycles
- Complex, distributed ecosystems across providers and partners
Energy, utilities, and critical infrastructure
Critical infrastructure sectors are exposed due to their reliance on operational technology (OT) and long-lived industrial systems.
Many systems were not designed to support cryptographic change and may remain in operation for decades. In some cases, cryptography is embedded in firmware or vendor-controlled systems, making upgrades difficult or dependent on suppliers.
The key risks include:
- Loss of trust in control systems and industrial communications
- Potential disruption to essential services
- Long transition timelines due to asset lifecycle constraints
Migration is particularly challenging because:
- Systems cannot be easily taken offline
- Replacement cycles are long and capital-intensive
- Dependencies on vendors and legacy architectures are significant

What regulators and governments are saying
The regulatory direction of travel is no longer ambiguous. Across multiple jurisdictions, governments are signalling that organisations are expected to prepare now, even though large‑scale quantum computers are not yet available.
In the UK, the National Cyber Security Centre (NCSC) has published a national timeline for migration to post‑quantum cryptography. Its guidance recognises that this transition is a multi‑year, system‑wide effort, and sets out indicative milestones: organisations should complete discovery and planning activities by 2028, begin migrating their highest‑risk systems by 2031, and aim to complete migration by 2035. The NCSC is explicit that the main effort is not cryptographic theory but understanding where cryptography is embedded and how difficult it will be to change.

The United States provides an important comparator because it has moved from guidance to obligation. Under the Quantum Computing Cybersecurity Preparedness Act and National Security Memorandum‑10, all federal agencies are required to inventory their cryptographic systems and plan migration to post‑quantum cryptography. NIST finalised its first post‑quantum cryptography standards in August 2024 and has stated that organisations should begin applying these standards now. NIST’s transition roadmap sets a clear expectation that widely used public‑key algorithms such as RSA and elliptic‑curve cryptography should be deprecated by 2030 and fully removed from standards by 2035.
Singapore offers a complementary, market‑led example. In February 2024, the Monetary Authority of Singapore (MAS) issued a formal advisory to all financial institutions warning that quantum computing poses a real threat to widely used encryption and digital signature schemes. MAS has since run multiple proof‑of‑concept initiatives with major banks, including quantum‑safe cryptography and quantum key distribution experiments, to understand operational impact and readiness. The regulator’s emphasis is not on immediate replacement, but on cryptographic inventories, supplier readiness, and crypto‑agility as part of good operational risk management.
Taken together, the UK, US, and Singapore examples point in the same direction: quantum preparedness is increasingly being treated as a governance and assurance expectation, not a niche technical experiment.
Why this matters in practice: scale and dependency
The urgency behind this regulatory focus becomes clearer when considering how deeply cryptography is embedded in modern digital infrastructure.
Independent measurement consistently shows that over 90% of global web traffic is now encrypted, with approximately 99% of browsing time in Chrome occurring over HTTPS. This reflects a decade‑long shift toward universal encryption, driven by security, privacy, and regulatory expectations.
That reliance creates a systemic challenge: the cryptographic algorithms most exposed to quantum attack underpin not just external websites, but identity systems, cloud services, APIs, VPNs, software update mechanisms, and inter‑system trust across entire ecosystems. Once encrypted data is harvested, the exposure cannot be undone. This is why regulators increasingly frame the issue as one of long‑term resilience, not near‑term incident response.
A practical step‑by‑step plan to get ready
The following steps reflect the common direction of travel in guidance from authorities such as NIST in the United States, the UK National Cyber Security Centre, and the Monetary Authority of Singapore. They are designed to support preparation and prioritisation, rather than premature or disruptive change.
- Step 1 – Assign executive ownership
Give quantum readiness a named senior owner and define how progress will be reported through existing risk, technology, and governance forums. Without clear ownership, quantum risk typically remains an abstract concern rather than a managed transition.
- Step 2 – Identify the crown jewels
Identify the data, services, transactions, and trust mechanisms that must remain confidential or trustworthy over the long term. This should include sensitive retained data, critical operational systems, software and firmware signing processes, and evidential or regulatory records.
- Step 3 – Build a cryptographic inventory
Develop a clear view of where cryptography is actually used across the organisation. This includes certificates, VPNs, identity platforms, key‑management systems, applications, devices, operational technology, code‑signing services, third‑party products, and managed services. Organisations cannot plan migration for cryptography they cannot see.
- Step 4 – Review data retention and lifecycle decisions
Challenge whether sensitive data genuinely needs to be retained for as long as it currently is. Reducing unnecessary long‑term retention can materially lower exposure to future decryption risk and should be considered alongside technical controls.
- Step 5 – Prioritise the highest‑risk use cases
Focus first on areas where long‑term confidentiality, digital signature integrity, or migration complexity are greatest. This risk‑based prioritisation helps avoid costly blanket activity and concentrates effort where delayed action would have the most serious consequences.
- Step 6 – Engage key suppliers early
Engage critical suppliers to understand how their products and services rely on vulnerable cryptography, what their post‑quantum roadmaps look like, and whether their architectures support cryptographic agility. This is particularly important for cloud platforms, identity providers, network equipment, industrial technology, and embedded systems.
- Step 7 – Design for cryptographic agility
Where systems are being refreshed or procured, avoid locking in cryptographic choices that will be difficult or expensive to replace. Build in the ability to change algorithms, certificates, libraries, and trust anchors without requiring full system redesign.
- Step 8 – Create a phased migration roadmap
Use the inventory and prioritisation work to develop a realistic, phased roadmap with milestones, decision points, dependencies, and testing activity. The objective is not immediate wholesale replacement, but a controlled transition that can mature alongside standards, supplier readiness, and regulatory expectations.
- Step 9 – Revisit the plan regularly
Treat quantum readiness as an ongoing governance issue rather than a one‑off exercise. Review assumptions and plans periodically as standards evolve, regulations develop, suppliers mature their offerings, and threat intelligence improves. Effective preparation is adaptive, not static.
Priority areas leaders should test now
The table below can be used as a structured discussion aid with directors, CISOs, risk teams, and procurement leads.
Area |
Key question |
Why it matters |
|
Data |
What information must remain confidential beyond 2035? |
Long-lived data is exposed to harvest-now-decrypt-later risk. |
|
Identity and signatures |
Which services rely on RSA or elliptic-curve certificates and signatures? |
Public-key cryptography is the most quantum-exposed layer of digital trust. |
|
Suppliers |
Which critical vendors have a post-quantum roadmap? |
Third-party readiness will constrain migration timelines. |
|
Architecture |
Can cryptographic components be replaced without redesign? |
Crypto-agility reduces cost and disruption of transition. |
|
Governance |
Who owns the transition and how is progress tracked? |
Without accountability, preparation rarely moves beyond awareness. |
Closing perspective: what good looks like
Quantum computing does not require organisations to act in haste, but it does require them to act with intent. The risk is not defined by a single breakthrough moment, but by a long period in which today’s design decisions quietly shape tomorrow’s exposure.
Organisations that manage this well will not be those that rush to deploy immature solutions or attempt wholesale change too early. They will be those that use the time available now to build visibility, make informed trade‑offs, and ensure their systems, suppliers, and governance structures can adapt when change becomes unavoidable.
In that sense, quantum readiness is best understood as a test of organisational maturity. It rewards clarity over certainty, prioritisation over blanket action, and resilience over prediction. The question for leaders is not whether quantum computing will matter, but whether their organisation is positioned to respond in a controlled, credible, and proportionate way when it does.
Those that start preparing early will retain choice. Those that delay may find that choice has already been made for them.

Want to speak to us?
If you would like to discuss a cyber or resilience problem with a member of the team, then please get in touch however you feel most comfortable. We would love to help you and your business prepare to bounce back stronger.


