Call for Quantum Security

by Mar 14, 2025Quantum, security, software, Technology, update0 comments

In a recent report by Forrester Research titled “Quantum Security Isn’t Hype — Every Security Leader Needs It,” experts have sounded the alarm on the necessity for organizations to proactively address quantum security risks. While the arrival of quantum computers capable of breaking traditional asymmetric cryptography is estimated to be five to ten years away, the urgency to act now cannot be overstated. The report emphasizes that failing to prepare today could leave organizations vulnerable to future cyber threats, especially given the rise of the “harvest now, decrypt later” approach among hackers.

The Looming Threat of Quantum Computing

Quantum computing has the potential to upend long-standing encryption methods. For decades, encryption algorithms have provided a stable line of defense for securing sensitive data. However, as quantum computers advance, they threaten to break these encryption techniques at an unprecedented scale. Organizations that do not start adapting their security measures now may find themselves unable to protect critical data when quantum decryption capabilities become a reality.

Security analyst Jamie Boote notes that encryption algorithms have traditionally cycled in and out as computers have improved incrementally, but quantum computing will disrupt this predictable cadence. This change won’t be instantaneous or straightforward, making early preparation essential.

The “Harvest Now, Decrypt Later” Concern

A particularly concerning development in cyber threats is the “harvest now, decrypt later” strategy. Cybercriminals and nation-state actors are already collecting encrypted data with the expectation that they will be able to decrypt it in the future using quantum technology. Organizations dealing with sensitive information—such as national security data, financial records, and intellectual property—are at the highest risk.

Rebecca Krauthamer, CEO of QuSecure, highlights that even though no quantum computer currently exists that can break today’s encryption, governments and financial institutions are rapidly mobilizing to address the quantum threat. The potential fallout of failing to protect data today could be catastrophic in the future.

Preparing for “Q-Day”

“Q-Day” refers to the hypothetical moment when a quantum computer becomes powerful enough to break current encryption standards. Even if this day never arrives, the process of preparing for it provides organizations with valuable cybersecurity insights.

Richard Stiennon, chief research analyst at IT-Harvest, advises organizations to begin by identifying where encrypted data resides within their infrastructure. Many organizations may not have a clear understanding of how their encryption is managed, who controls the encryption keys, or whether their current security measures are adequate. Conducting a comprehensive encryption audit can illuminate vulnerabilities that need to be addressed, regardless of the quantum threat.

Heather West, senior research analyst at IDC, underscores the need for organizations to first understand which data and infrastructure components are most at risk. Following this assessment, they can determine the most suitable post-quantum cryptography (PQC) algorithms to implement.

The Case for Crypto-Agility

One of the key takeaways from the Forrester report is the importance of crypto-agility—the ability to update and replace cryptographic algorithms as security landscapes evolve. Unlike traditional security updates, which often require significant overhauls, a crypto-agile system allows organizations to seamlessly transition to new cryptographic standards as needed.

Tim Callan, chief compliance officer at Sectigo, stresses that as we approach the post-quantum computing era, organizations must design their security frameworks with modularity in mind. This approach ensures that if an encryption algorithm becomes obsolete, it can be quickly replaced without disrupting operations.

Matt Mittelsteadt, a research fellow at the Cato Institute, echoes this sentiment, likening security architecture to “security Legos”—where organizations can swap algorithms in and out as threats evolve. Such an approach ensures resilience against emerging cyber threats, whether quantum-related or otherwise.

The Trillion-Dollar Risk

The potential financial impact of quantum-based attacks is staggering. Stefan Leichenauer, VP of engineering at SandboxAQ, warns that in as little as five years, a quantum computer could compromise traditional cryptography. Even if the probability of this occurring remains low, the potential cost of a trillion-dollar security breach makes the risk too significant to ignore.

Given recent advancements in quantum computing, confidence in its capabilities continues to grow. Organizations must begin evaluating their cryptographic posture by conducting an inventory of their encrypted assets and implementing a crypto-agile strategy. Since the transition to post-quantum cryptography is a multi-year process, immediate action is required.

Final Thoughts

Quantum security is not just a theoretical concern—it is an inevitable challenge that all organizations must prepare for. The transition to quantum-safe cryptographic solutions will take years, and failure to act now could leave critical data vulnerable to future threats. By prioritizing crypto-agility, conducting encryption audits, and staying informed about post-quantum cryptography advancements, organizations can fortify their security posture against the coming quantum era.

The Forrester report serves as a clear warning: quantum security is not hype, and the time to act is now. Organizations that take proactive steps today will be best positioned to navigate the quantum future safely and securely.

PTSI Editorial Team

Support Line: Phone: +1 646-535-HELP (4357) Email: helpdesk@progressny.com Support web: helpdesk.progressny.com