Skip to main content
a promotional graphic telling you that PCI Compliance is no longer an annual exercise and that continuous monitory must be built in
Quantum Isn't Your Problem Yetgeneral
4 min readFor CISOs & Security Leaders

Quantum Isn't Your Problem Yet

The Conventional Wisdom

There's a push for post-quantum cryptography (PQC) adoption. Security leaders are urged to migrate to NIST's FIPS 203-205 standards now, before quantum computers compromise RSA and Elliptic Curve Cryptography. Google estimates this could happen by 2029. The narrative is clear: act now or risk exposure.

This message is pervasive in vendor pitches, conference keynotes, and government guidance. Executive Order EO 14412 mandates rapid PQC adoption across federal systems. Compliance frameworks will follow.

Why We Disagree

Here's the reality: if you're not a nation-state target, quantum computing probably isn't your immediate concern.

Quantum computers won't become as accessible as AI tools. They require significant capital and expertise, limiting access to governments and a few corporations. Even when they become cryptographically relevant, they'll resemble mainframe terminals from the 1960s, not cloud APIs of today.

This means nation-state actors may decrypt harvested traffic and access secure systems. But typical ransomware gangs won't have quantum capabilities. They'll continue using credential stuffing and exploiting unpatched vulnerabilities because they're effective and low-cost.

If your organization doesn't hold classified information, defense contracts, or valuable intellectual property, quantum threats aren't your primary concern. Your standing privileges, unrotated service account credentials, and developers with production database access are more pressing risks than a potential quantum break in five years.

The Evidence

Consider the incentive structure. Organizations targeted by nation-states, like governments and major financial institutions, will adopt PQC because they're already defending against advanced threats. They have the budget and compliance pressures to justify the investment.

Now, think about a regional hospital system or a municipal water utility. Their margins are tight, and security teams are stretched. They're dealing with legacy systems that can't be patched. Prioritizing post-quantum cryptography for them means defending against an unseen adversary with non-existent technology, while their current systems are vulnerable to basic attacks.

The gap between individual risk assessment and collective security creates vulnerabilities. Nation-state actors will exploit organizations that can't upgrade, using them as entry points to more valuable targets. This is a systemic risk, not an organizational one. From your CISO's perspective, quantum might rank below "implement MFA everywhere" and "reduce standing admin access", and that might be the right call.

What to Do Instead

Start with honest threat modeling. Who actually wants your data? What's the realistic timeline for them to have quantum access? What's the shelf life of the information they'd decrypt?

If quantum is a real risk for your organization, prioritize visibility before migration. Identify where asymmetric encryption is used: TLS implementations, VPN configurations, code signing, SSH keys, stored encrypted data. Build an inventory. Most organizations can't confidently answer "where are we using RSA 2048?"

For organizations where quantum isn't the top threat, focus on buying time and reducing exposure:

Increase key sizes now. Moving from RSA 2048 to RSA 4096 or AES-128 to AES-256 raises the bar without rearchitecting your infrastructure.

Use your cloud provider's timeline. If you're on AWS or Google Cloud, their PQC implementations will upgrade significant portions of your encryption. Let them handle the complexity while you focus on custom implementations and on-premises systems.

Reduce your harvest-now-decrypt-later exposure. If adversaries collect your encrypted traffic today, what's at risk when they decrypt it in 2030? Rotate secrets more frequently. Reduce the retention period for encrypted data. Segment networks so a single decryption key doesn't unlock everything.

Push quantum risk into your vendor contracts. Make PQC migration a contractual obligation for your SaaS providers, managed service providers, and critical infrastructure vendors.

For critical systems needing PQC now, prioritize the highest-value targets: encrypted backups with intellectual property, authentication systems for privileged access, communications channels for sensitive operations. Don't try to address everything at once.

When the Conventional Wisdom IS Right

If you're a defense contractor, you can't wait. Your adversaries have the funding and motivation to access quantum systems. The harvest-now-decrypt-later threat is real for classified information, and compliance will mandate PQC.

The same applies if you're in critical infrastructure sectors targeted by nation-state actors. Energy, telecommunications, financial services at scale, you're in the threat model. Executive Order EO 14412 and forthcoming compliance standards will require action.

If you hold long-lived secrets or sensitive intellectual property with decades of value, or if you have encrypted data you can't afford to expose even in 2035, then yes, quantum is your problem now.

The conventional wisdom is also right about crypto agility. Even if quantum isn't your immediate threat, building systems that can swap cryptographic algorithms without complete rewrites is smart. When PQC standards evolve or vulnerabilities emerge, you'll want to respond quickly.

For most organizations, the honest answer is this: quantum is a real threat to national security and infrastructure resilience. It's probably not in your top ten organizational risks. Treat it accordingly. Build awareness, track the standards, and prepare for eventual migration. But don't let quantum panic distract you from the standing privileges and unpatched systems attackers exploit today.

Topics:general
Promotional banner for the Penetration Report Template Kit

You Might Also Like