Quantum Security: Preparing Cyber Defences for the Quantum Era

Quantum security — often called quantum cyber security — is the practice of protecting data and systems against the threats posed by quantum computing. Large-scale quantum computers will be able to break much of the public-key cryptography that secures the internet today, making quantum readiness a strategic priority for every security leader.

What is quantum security?

Quantum security covers the strategies, standards and technologies used to keep information confidential and systems trustworthy in a world with powerful quantum computers. It spans cryptography, risk management, and the migration of existing systems to quantum-resistant protection.

While today's quantum computers are not yet powerful enough to break strong encryption, progress is accelerating. Forward-looking organisations are assessing their exposure now, because cryptographic migration takes years.

Why quantum computing threatens encryption

Much of modern encryption — including RSA and elliptic-curve cryptography — relies on mathematical problems that are hard for classical computers but solvable by a sufficiently powerful quantum computer running Shor's algorithm. When that capability arrives, data protected by these algorithms could be decrypted.

  • Public-key cryptography (RSA, ECC) is most at risk
  • Symmetric encryption like AES is weakened but more resilient with larger key sizes
  • Digital signatures and key exchange must be re-evaluated

"Harvest now, decrypt later"

A key reason to act early is the 'harvest now, decrypt later' threat: adversaries can capture and store encrypted data today, then decrypt it once quantum computers mature. Any data that must stay confidential for years — health records, state secrets, intellectual property — is already at risk.

How organisations can prepare

Quantum readiness starts with visibility and planning. ICCSO's community helps members understand the threat landscape and share practical approaches to crypto-agility and migration.

  • Create a cryptographic inventory of where and how you use encryption
  • Prioritise long-lived sensitive data for early migration
  • Adopt crypto-agility so algorithms can be swapped without re-architecting
  • Track post-quantum cryptography standards and vendor roadmaps
  • Build internal awareness and skills through training and community

Frequently asked questions

What is quantum security?

Quantum security (or quantum cyber security) is the protection of data and systems against threats from quantum computing, including the migration of encryption to quantum-resistant, post-quantum algorithms.

Will quantum computers break encryption?

A sufficiently powerful quantum computer could break widely used public-key encryption such as RSA and elliptic-curve cryptography using Shor's algorithm. This has not happened yet, but organisations are preparing now because migration takes years.

What does 'harvest now, decrypt later' mean?

It describes adversaries capturing encrypted data today and storing it to decrypt later once quantum computers are capable. It makes long-lived sensitive data a present-day risk, even before quantum computers can break encryption.

How can my organisation prepare for the quantum threat?

Start with a cryptographic inventory, prioritise long-lived sensitive data, adopt crypto-agility, follow post-quantum cryptography standards, and build awareness. ICCSO's community and training help members prepare.