quantum networking
– Getty Images

Quantum computing development roadmaps are getting more tangible, so now is the time to start the quantum security journey and prepare for “harvest now, decrypt later” attacks, quantum computing experts recommend.

“Harvest now, decrypt later” refers to an attack where threat actors collect encrypted data from target organizations today, anticipating that data can be decrypted later on when quantum computing reaches a maturity level capable of rendering some existing cryptographic algorithms obsolete, according to Deloitte.

The consulting firm surveyed over 400 professionals from organizations that have considered quantum computing benefits and found that over half (50.2%) of respondents believe their organizations are at risk for “harvest now, decrypt later” attacks.

“It’s encouraging to see that so many of the organizations with quantum computing awareness are similarly aware of the security implications that the emerging technology presents,” Colin Soutar, managing director in Deloitte Risk & Financial Advisory, said in a statement. “But, it’s important to note that ‘harvest now, decrypt later’ attacks are something all organizations — whether or not they’re considering leveraging quantum computing — stand to face in a post-quantum world.”

The U.S. government is also urging organizations to prepare for post-quantum threats. The White House recently sent out a memo on mitigating vulnerable cryptographic system risks, while the Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA) recently released quantum-resistant (QR) algorithms recommendations and requirements for critical infrastructure and national security systems based on the post-quantum cryptography selections from National Institute of Standards and Technology (NIST).

NIST expects to publish its post-quantum cryptography standard by 2024. The institute will then recommend the rest of the federal governments use the standard. 

“The White House has put out some national security memos to ensure that government agencies are aware of the quantum threat and that they are making plans and within 10 years of the NIST standards being published that they will need to transition to quantum-safe algorithms,” Dustin Moody, computer security mathematician at NIST, said during a "Cryptography Standards That Will Keep Today's Data and Systems Quantum Safe" virtual roundtable hosted by IBM on Sept. 21, 2022. “So we want to make sure all data is protected against these threats and the government is certainly taking steps to do that.”

Deloitte’s report showed that 27.7% of respondents stated that their organizations’ quantum computing security risk management efforts will most likely advance following regulatory pressure to adopt legislation or policies.

“Over the next decade, we expect that such direction on quantum cybersecurity will continue to be issued to government agencies, critical infrastructure operators, and commercial cloud providers,” Soutar said. “And as more guidance is issued, it’ll likely be backed by an increasing range of technical standards and frameworks which will help inform organizations’ efforts to mitigate post-quantum cybersecurity risk."

Quantum computing roadmaps get more tangible

In almost every post-quantum cryptography discussion, the question of when quantum computing will be mature enough to break current encryption comes up.

In response to that question, Michael Osborne, CTO of IBM Quantum Safe, said during the virtual roundtable, “I would say roadmaps are now far more tangible than they were four or five years ago."

“The horizon when we enter the era of what we call cryptographically relevant quantum machines is getting closer all the time. It's not just a function of time passing. It's because actually technology is improving at a faster rate than we imagined,” he added.

That’s why Osborne suggests starting the preparation now, instead of waiting for a powerful enough machine to appear. “We can't predict if there's a major breakthrough in certain forms of hybrid memory, which can really advance how quickly the large machines are available ... So you cannot afford to risk not being ready for when these advances happen.”

Soutar told SDxCentral in an earlier interview that the first step of the preparation should be understanding the organizations’ potential exposures, such as their existing cryptography tools, vulnerabilities in the supply chain, how they currently store and protect data, and the types and sensitivity of the data. 

According to Deloitte’s report, 26% of the surveyed organizations completed the potential, post-quantum encryption vulnerability assessments, while 18.4% planned to be done within a year.