spot_imgspot_img

Top 5 This Week

spot_img

Related Posts

Harvest Now, Decrypt Later: Why Waiting for Q-Day Is Already Too Late

Somewhere right now, encrypted files are being copied off a bank’s servers, a pharmaceutical company’s research network, or a defence contractor’s design database — and nobody involved plans to read them today. The data will sit, unreadable, on a foreign server for years. The attackers are patient. They are betting on a machine that does not yet exist: a quantum computer powerful enough to unpick the encryption that protects nearly all of the world’s digital secrets. Security researchers call this “harvest now, decrypt later,” and it is no longer a theoretical exercise for cryptographers. It is an active collection strategy, and the data being harvested today is data your organisation generated this year.

Most executives who have heard of the “quantum threat” have filed it under long-range technology risk — something for the 2030s, adjacent to fusion power and full self-driving cars, worth a slide in the innovation deck but not a line item in this year’s budget. That instinct is understandable and almost certainly wrong, not because a code-breaking quantum computer is imminent — expert opinion remains genuinely divided on when, or whether, one arrives this decade — but because the entire framing of “when does the threat arrive” is the wrong question for a business leader to be asking.

The deadline isn’t a date. It’s a subtraction problem.

Cryptographers have a more useful way to think about urgency, and it should reshape how CEOs and CISOs prioritise: your real deadline is not the day a quantum computer becomes capable of breaking RSA or elliptic-curve encryption. It is that date minus however many years your data needs to remain secret. A hospital’s genomic records, a bank’s mortgage book, a defence programme’s engineering specifications, an M&A term sheet — all of these have a required shelf life of confidentiality measured in years or decades. If a sufficiently powerful quantum computer arrives in 2035, and your data needed to stay secret until 2032, you didn’t miss a future deadline. You missed one three years ago, because the theft happened long before the decryption capability did.

This is precisely why the institutions closest to the mathematics are not waiting for certainty. The U.S. National Institute of Standards and Technology finalised its first quantum-resistant encryption standards in 2024 — FIPS 203, 204 and 205 — and has told the world it intends to deprecate RSA and elliptic-curve cryptography by 2030 and disallow them entirely by 2035. The NSA’s parallel CNSA 2.0 mandate for national security systems pushes even faster, requiring quantum-safe preference from 2025 and near-exclusive use by 2033. The European Union has asked member states to have national post-quantum strategies in place by the end of 2026, with high-risk systems transitioned by 2030. None of these bodies claim to know exactly when a cryptographically relevant quantum computer will exist. They are hedging against a low-probability-per-year, high-consequence, long-lead-time event — which is precisely the kind of risk boards are supposed to be good at pricing, and precisely the kind most are currently ignoring.

Private infrastructure is already moving faster than regulation forces it to. Cloudflare, which sits in front of a significant share of global web traffic, now handles more than half of the human traffic it processes over post-quantum key exchange, and has committed to full post-quantum protection across its network by 2029 — a target it moved up after internal analysis of how quickly quantum hardware and algorithms are improving in parallel. Google has made similar commitments. These are not companies prone to overreacting to speculative science; they are companies that have run the cost-of-being-wrong calculation and concluded that early, unglamorous investment beats a scramble later.

A quantum computer cryostat in a research cleanroom laboratory, representing the future technology that threatens today's encryption

The quiet failure mode: nobody knows where their own encryption lives

Here is the part boards tend to underestimate. Migrating to post-quantum cryptography is frequently compared to the Y2K remediation effort, which cost an estimated $300–600 billion globally in the late 1990s — several hundred billion more in today’s money — and that comparison actually understates the difficulty. Y2K had a fixed, universally known deadline, which meant every organisation had the same forcing function to prioritise the work. Quantum migration has no such date. It has a probability distribution. One widely cited estimate from Citi’s institutional research places the odds of a cryptographically relevant quantum computer at roughly 19–34% by 2034, rising to 60–82% by 2044 — a wide, genuinely uncertain range that makes it easy for any individual executive to rationalise deferral. That absence of a hard deadline is not a reason for calm. It is the mechanism by which organisations talk themselves into doing nothing.

Compounding the problem, most large enterprises cannot currently produce an accurate inventory of where encryption is actually used across their own technology stack — buried in decades-old vendor software, embedded firmware, payment terminals, industrial control systems and third-party APIs nobody fully controls. Security teams have started calling this accumulated exposure “cryptographic debt,” and unlike a software patch, you cannot fix what you have not found. The realistic migration timeline for a large financial institution or industrial company, once discovery, vendor coordination, testing and phased rollout are accounted for, runs into years — which is exactly why the sensible response starts now, cheaply, with inventory and agility, rather than later, expensively, in a crisis.

The financial stakes of getting this wrong are not abstract. Citi’s analysis estimates that a single successful quantum-enabled attack on one top-five U.S. bank’s access to the Fedwire payment system could trigger $2.0–3.3 trillion in indirect economic impact — roughly a tenth to a sixth of U.S. GDP — with effects persisting through a recession lasting months. Digital assets carry a version of this exposure that is already priced into the technology, if not yet into markets: researchers estimate roughly a quarter of the Bitcoin supply, well over half of Ethereum’s, and nearly all of Solana’s are held in address formats vulnerable to a future quantum attack — a fact that boards overseeing treasury exposure to crypto assets, or banks building custody products around them, have largely not internalised.

India’s regulators are moving in step — and its services sector has more at stake than most

India offers a useful window into how fast the regulatory posture is shifting, because it is moving on two tracks simultaneously. In 2026, the Reserve Bank of India constituted a dedicated Q-SAFE committee — drawing members from IIT Madras, NPCI, the State Bank of India, the Data Security Council of India, the Department of Science and Technology and MeitY — with a six-month mandate to audit the financial sector’s cryptographic infrastructure and design a phased transition framework. Separately, a Department of Science and Technology task force has laid out a national roadmap that is, in places, more aggressive than the American timeline: a testing and certification programme by the end of 2026, migration of critical information infrastructure by 2027, banking and finance pilots by 2028, and default post-quantum cryptography across communications systems by 2033.

That urgency is well placed, because India’s exposure runs in two directions at once. As the operator of UPI, the payment rail processing a meaningful share of the world’s real-time retail transactions, India has sovereign-scale infrastructure to protect. But as the back office for a large share of global finance, pharmaceuticals and technology — the Global Capability Centres now doing security, compliance and engineering work for Western banks and life sciences companies — Indian firms will increasingly be audited on cryptographic readiness by the multinational clients they serve, the same way information-security certifications like SOC 2 became a precondition for winning that business a decade ago. Crypto-agility is quietly becoming a credential, and the GCC ecosystem that gets there early has a genuine, exportable competitive advantage.

Cybersecurity analysts at a bank operations center in Mumbai, India, monitoring encrypted financial data flows

What this actually changes for a CEO’s agenda

None of this requires believing that quantum computers will break the internet next year — most credible experts do not believe that, and treating this as an imminent apocalypse is its own kind of misreading. What it requires is treating cryptographic migration the way a CFO treats any long-duration, uncertain-probability, high-severity exposure: with an inventory of what you actually hold, a phased hedge against the worst outcome, and an honest acknowledgment that the absence of a fixed date is not evidence of low risk. Boards are starting to ask about AI governance as a matter of course; cryptographic inventory and vendor crypto-agility deserve the same standing item, not because Q-Day is near, but because the theft that will matter most in a decade may already be sitting on someone else’s server today. The strategic question worth asking in the next leadership meeting isn’t when the quantum computer arrives. It’s what data your organisation is creating this year that still needs to be secret in ten — and who might already be collecting it.

Popular Articles