Why Quantum Computing Could Break the Internet’s Security — And What Comes Next

0
2

London, 15 September 2026 — EBM Newsdesk Analysis — Rob Davis

For most people, quantum computing remains an abstract idea involving strange physics and machines that supposedly do things ordinary computers cannot. Underneath that science-fiction framing sits a specific, dated, already-in-progress problem: the encryption protecting online banking, cloud services, government databases and digital payments relies on mathematical problems considered too hard for conventional computers to solve within any useful timeframe. A sufficiently powerful quantum computer could use Shor’s algorithm to solve those same problems in a fraction of the time, making RSA and elliptic-curve encryption — the standards underpinning most of the internet’s trust infrastructure — obsolete.

That computer doesn’t exist yet. Estimates for when one might vary considerably — some analysts put a capable “cryptographically relevant quantum computer” ten to fifteen years out, others closer to 2035 — but the uncertainty in the date is precisely why the response can’t wait for it.

Join The European Business Briefing

New subscribers this quarter are entered into a draw to win a Rolex Submariner. Join 40,000+ founders, investors and executives who read EBM every day.

Subscribe

The Standards Already Exist

This isn’t a hypothetical the industry is still theorising about. NIST finalised its first three post-quantum cryptography standards in August 2024 — FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) — with a fourth, FIPS 206, still in draft and expected in late 2026 or 2027, and an additional algorithm, HQC, selected as a backup key-encapsulation method in March 2025. The NSA’s Commercial National Security Algorithm Suite 2.0 already mandates that US national security systems fully replace vulnerable algorithms by 2030, extending to 2035 for the most sensitive categories. The standards exist. The bottleneck now is migration — and migration at the scale of a large bank, a national health system or a cloud provider is not comparable to installing a software patch. It’s closer to replacing the plumbing in an occupied building, because encryption is buried inside payment platforms, VPNs, employee communications, industrial control systems and third-party software that nobody has fully mapped.

Why Waiting Is Already a Mistake

The specific reason organisations can’t simply wait for a working quantum computer to appear is a technique the industry calls “harvest now, decrypt later.” An attacker doesn’t need quantum capability today — only the ability to intercept and store encrypted traffic now, then decrypt it once the technology matures. EBM has previously covered what a first real-world Q-Day breach would actually look like, and the governance failure it exposes: for data that needs to stay confidential for years or decades — government intelligence, unfiled patents, medical records, M&A negotiations — the theft has effectively already happened the moment it’s copied, even though nobody can read it yet. A Capgemini survey of billion-dollar enterprises found nearly two-thirds of security leaders now rank quantum computing as a bigger strategic threat than ransomware, and 65% are already specifically worried about harvest-now-decrypt-later exposure, even while the quantum computer that would make it dangerous remains years away.

The European Angle

Quantum sits directly inside Europe’s broader push for technological sovereignty in AI, semiconductors and cloud infrastructure, and the debate isn’t purely technical — it’s tangled up with the continent’s parallel fight over encryption itself. EBM’s own outlook piece on Europe’s 2026 digital watershed flagged this collision directly: governments pushing for deeper surveillance access even as quantum-readiness pushes the private sector toward stronger, more agile cryptography — two trends pulling in opposite directions inside the same policy conversation. Whoever builds the fastest quantum machine matters less commercially than who builds the surrounding ecosystem: the specialist software, migration consultancies, and cloud-security infrastructure that every organisation running vulnerable cryptography will eventually need, regardless of which country’s lab gets there first.

Where the Real Opportunity Sits

That’s the genuine irony sitting inside this story: quantum computing may generate a substantial commercial market before it becomes a usable mainstream technology. Cybersecurity vendors, cloud providers, semiconductor firms and migration specialists all stand to benefit from the transition itself, independent of whether quantum computers ever deliver on their more speculative promises in drug discovery or financial modelling. Investors should treat the sector with real scepticism regardless — quantum hardware still faces serious unsolved engineering problems, particularly error correction and maintaining stable quantum states, and headlines about breakthroughs routinely run well ahead of commercial reality. The companies actually capturing value may not be the ones building the most impressive processor. They’re more likely to be the ones quietly selling the infrastructure — components, cooling, software, cloud access — that the migration requires regardless of which quantum architecture eventually wins.

My Read: Boards keep deferring quantum risk because it’s simultaneously immature and unquantifiable, which makes it easy to postpone in favour of threats with an obvious price tag attached. But this is one of the only major cybersecurity risks a business can see coming years in advance, with a standards body having already told it exactly which algorithms to adopt. The organisations that start mapping where vulnerable cryptography actually lives in their own systems now will spend a fraction of what the ones scrambling after a real Q-Day breach will. History with previous cryptographic transitions says the same thing every time: preparation is cheap while the threat still looks theoretical, and expensive the moment it stops being one.

Related Analysis

LEAVE A REPLY

Please enter your comment!
Please enter your name here