Quantum
– Getty Images

Quantum has long been that looming "next big thing," but despite the technology creeping ever closer – and with it, the potential for threat actors to unlock encrypted data previously thought secure – research from Bain & Company suggests business leaders simply aren’t prepared.

The management consultancy giant found that 90% of executives admitted to not having a quantum security plan in place, let alone allocating budgets or resources to start their transition.

Some 71% of surveyed business leaders told Bain that quantum-enabled attacks could start to appear within five years, while one-third said it could be as soon as three years. But the Boston-based firm warned it could take businesses half a decade just to identify and implement quantum-resistant solutions.

“It could take even longer given the scale of the problem and the complexity of identifying vulnerable systems, upgrading cryptographic infrastructure, aligning with evolving standards, and coordinating across internal teams and external partners,” a company blog post reads. “Organizations that are heavy with legacy infrastructure may be particularly vulnerable, and more attractive targets for attackers.”

Bain’s report found that nearly 65% of business, IT, and cybersecurity leaders are aware of the risks quantum poses and that it will have a strong adverse effect on cybersecurity risk.

Some brands have already made strides to shore up their defenses. For example, Cloudflare has made headway in streamlining quantum security for the web, enlisting Google to help tackle post-quantum cryptography (PQC). And network testing and assurance vendor Viavi Solutions is creating frameworks and reference architectures for deploying quantum-safe security across telecom and enterprise networks.

Bain & Company said businesses should kickstart preparations and proactive planning not three to five years down the line, but over the coming months, noting: “Boards and executives should prioritize and resource the necessary work to guard against this rising threat before it’s too late.”

The management consultancy’s findings affirm previous industry analysis on the anticipatory impact quantum computing will have on the cybersecurity and IT landscape.

A survey from ISACA (formerly the Information Systems Audit and Control Association) published last May found that of some 2,600 global IT and cybersecurity professionals, 62% expressed concern about quantum computing’s ability to crack encryption, while just over half (57%) said it will create new business risks.

Similar to Bain’s findings, ISACA respondents admit to being unprepared. Some 40% were not aware of their company’s plans, while 41% said they had no plans to address the potential risks posed by quantum at this time. Add to that, only 5% said they would consider addressing quantum threats as a high business priority for the near future – that’s despite one quarter expressing that quantum will become realized on an industry-wide scale within the next half decade.

“If we don’t move now to start solving issues like re-encrypting our data, switching to new digital signatures, and moving our systems over to new algorithms, we are creating problems that will become increasingly difficult to address,” Rob Clyde, past ISACA board chair and Crypto Quantique chairman, wrote in a blog post.