Moona Ederveen-Schneider is a cyber security expert specialising in post-quantum preparedness, AI security and emerging risk.Through her work with Quantum Security Connection and her Practical Post-Quantum Transition Framework, she helps organisations understand how to prepare for the shift to post-quantum cryptography.
Speaking exclusively to the Cyber Security Speakers Agency, Moona explains why quantum risk requires action now, where organisations are going wrong with migration, and how early preparation can reduce both security and commercial risk.
1-How significant is the “harvest now, decrypt later” threat, and why are so many organisations still underestimating their exposure to quantum computing?
Moona Ederveen-Schneider: “Absolutely. This is not even a future threat. It is happening right now.
Join The European Business Briefing
New subscribers this quarter are entered into a draw to win a Rolex Submariner. Join 40,000+ founders, investors and executives who read EBM every day.
Subscribe“Adversaries are harvesting encrypted data today, waiting to decrypt it once quantum computers are powerful enough.
“Most organisations have not even started their transition.
“I developed the practical post-quantum transition framework to explain this in clear terms, cut through market hype and vendor noise, and make the transition manageable without overwhelming teams.
“I also run tabletop exercises teaching organisations how to become crypto-agile. People arrive feeling the problem is unmanageable and leave with the confidence of knowing exactly what to do next.”
2-With the NCSC targeting full post-quantum migration by 2035 and major technology companies moving sooner, how should organisations assess the urgency of their own transition?
Moona Ederveen-Schneider: “The UK National Cyber Security Centre says organisations should complete detailed planning by 2028 and be fully migrated by 2035.
“Google has set its own internal full migration deadline of 2029. They cite faster-than-expected advances in quantum computing, and that sentiment is reflected in strong government guidance globally.
“Google is one of the organisations actually building these machines, so its move deserves serious attention.
“Large organisations typically need at least five years to complete a full cryptographic overhaul, and some need double that. So 2035 is by no means generous. We have to take action now.
“My practical post-quantum transition framework is designed to start delivering security improvements from day one. It tells organisations where to start and how to make the transition without overloading their teams or budgets.
“You’re also building a more resilient architecture today that protects against current threats such as ransomware, AI-enabled attacks and supply chain compromise.”
3-Where do organisations typically go wrong when planning a post-quantum cryptography migration, and what should they prioritise before building a cryptographic inventory?
“It is not a technology project. It’s a whole transformation.“The data that needs protecting sits in HR, legal and finance, not just in what DORA calls critical business processes.“The second common mistake is starting with the cryptographic inventory.“Contrary to the mantra that everyone repeats, I advise organisations to enhance their data security posture first to become quantum-secure.
“Organisations must answer the business question: what are we actually protecting, and how long does it need to stay secret?
“My practical post-quantum transition framework starts there and is designed to deliver security improvements from day one. It is adaptable for any size organisation and any size team.”
4-What gaps in organisational readiness led you to create Quantum Security Connection and the Quantum Security Intelligence Report?
Moona Ederveen-Schneider: “In my industry conversations, I kept seeing the same pattern. Organisations wanted to move on post-quantum cryptography, but they felt isolated.
“They did not know where to start or what their peers were doing. They couldn’t assess the vendor landscape effectively, and they struggled to stay current as regulation and standards evolved.
“That’s why my Quantum Security Connection network brings together cross-sector practitioners from public and private organisations and critical national infrastructure.
“I also published the Quantum Security Intelligence Report because this community needs a shared, trusted source of what is actually happening to help cut through the hype and separate signal from noise.”
5-Beyond reducing future cyber risk, where can early quantum readiness create a commercial advantage for organisations today?
Moona Ederveen-Schneider: “The organisations that get this right will not just be safer, they will be ahead.“Early adopters in financial services and pharmaceuticals are already extracting value from quantum computing, not just bracing for the risks.
“Understanding the technology positions you to benefit from it, not merely survive it.
“As with any complex transformation, starting with a structured migration on time means less last-minute scrambling, lower overall cost and readiness when regulation arrives, rather than an expensive, reactive catch-up.
“The commercial consequences of deferring are already here. Insurers are beginning to price in quantum risk. Procurement teams require evidence of readiness, and clients are asking questions that organisations without a plan cannot answer.
“Quantum readiness is a differentiator right now, not in 2035.”
This exclusive interview with Moona Ederveen-Schneider was conducted by Tabish Ali of the Motivational Speakers Agency.

































