By Jonathan Nguyen-Duy, Chief Technology Officer, Arqit
For years, the conversation around quantum computing has centred on the question of when a sufficiently powerful quantum computer will arrive. It’s an exciting time for the industry, so this area of focus doesn’t come as a surprise. But it can create the misconception that businesses have time to wait before they begin their quantum readiness journeys.
That’s why the real issue is whether organisations are treating quantum risk as a governance responsibility today. Because when the first major quantum-related breach eventually makes headlines, boards and CEOs are likely to face uncomfortable questions of accountability.
Join The European Business Briefing
New subscribers this quarter are entered into a draw to win a Rolex Submariner. Join 40,000+ founders, investors and executives who read EBM every day.
SubscribeThat’s because unlike most cybersecurity threats that we know today, quantum is one we can broadly anticipate. And that changes the conversation entirely because it’s a long-term business risk and governance issue that organisations have the gift of being able to prepare for.
Stop focusing on predicting the future
One of the biggest misconceptions about quantum security is that organisations only need to act once that sufficiently powerful quantum computer exists. But threat actors are already collecting encrypted information today in anticipation that future quantum attacks may allow it to be decrypted.
The first is called Harvest Now, Decrypt Later – a phrase many will already be familiar with. For organisations storing long-lived intellectual property, sensitive customer information or critical operational data, today’s decisions will determine tomorrow’s exposure. All data stored and transmitted should be considered vulnerable until a migration to quantum-safe encryption.
The second type of risk is called Harvest Now, Forge Later attacks in which the encryption that secures digital signatures is compromised – leading to the breaking of trust chains across business processes. If the authentication can’t be trusted, everything from software updates to financial transactions would come to a grinding halt. Take a stock exchange, for example. If confidence in the integrity of trading data is lost, the value of the entire system comes into question. It’s clear that practically every process depends on the ability to trust the underlying data and identities.
Organisations that begin preparing early, can take a measured, risk-based approach to managing risks. But those that wait may find themselves trying to compress years of migration into an impossible timeframe.
Making the first step
The longer organisations delay preparing for post-quantum cryptography, the fewer options they retain if (and when) quantum capability advances faster than expected. Remember that quantum readiness doesn’t begin by replacing every encryption algorithm across the business, it simply needs to begin with understanding your current state.
Before organisations can plan a migration, they need to understand where cryptography is used, which systems depend on it, criticality of the data, and which assets represent the greatest long-term risk.
Unfortunately, most organisations, simply don’t know where cryptography exists across their estate. Encryption has accumulated over decades through applications, cloud platforms, third-party software and legacy infrastructure, often without central oversight, creating blind spots. And you can’t effectively manage what you can’t see. Additionally, it’s critical to understand which systems can be retrofitted with quantum-safe encryption and which ones cannot, and will need to be retired. Likewise, data will need to be re-encrypted to ensure confidentiality and integrity. Only once organisations understand their cryptographic estate can they build a realistic, risk-based migration roadmap and prioritise investment. Importantly, this is not a one-off exercise. As technologies and networks evolve, so too will cryptographic risk. Quantum readiness and agility, therefore become an ongoing governance capability.
Translating the threat for the boardroom
For security leaders, who understand the risks, one of their biggest challenges is explaining why that risk matters to the wider business.
The key to overcoming that challenge is recognising that boards invest when they understand the potential impact on business outcomes, customer trust, and governance. And that’s where the conversation around quantum needs to change.
Organisations should start asking themselves: “If Q-Day happened tomorrow, what would it reveal about our preparedness today?”.
Quantum computing will undoubtedly unlock advances across science, finance, manufacturing and AI. But those opportunities depend on trusted digital infrastructure.
The bottom line: will Q-Day be a crisis or an opportunity?
Quantum presents a unique challenge because it is one of the few cyber risks organisations can prepare for before it fully materialises. That creates an opportunity to act deliberately rather than react under pressure.
Successful organisations will therefore be the ones that prepare. Resilience is less about speed, than a focus on managing risk. Q-Day has the potential to reveal years of organisational exposure and missed opportunities to prepare.
However, Q-Day doesn’t have to be the advent of a crisis. Instead, prepared organisations will be able to securely leverage technologies to unlock innovation and growth.


































