Skeptics may dismiss the quantum threat as distant doomsday thinking, but that’s a dangerous oversight. Quantum computers are coming – and so is “Q day,” the moment they become powerful enough to break today’s encryption. Experts warn this could happen as soon as 2030, but attackers aren’t standing by idly: they’re actively preparing to exploit quantum capabilities.
Adversaries are already stockpiling massive amounts of captured encrypted packets. By collecting encrypted data and figuring out the means to unlock it later, these bad actors will be well equipped for a retrospective attack.
Given the enormous attack surface, this has to be taken seriously. Even if data such as financial and health records, intellectual property, or government communications is a few years old when hackers finally use quantum computing for decryption, it could still cause financial, reputational, and legal damage.
The risk is not theoretical or speculative. It can be mitigated today using post-quantum cryptography (PQC). The issue is, while many enterprises are adopting PQC, too many are still holding off, with this decision fueled by PQC misconceptions currently circulating. And it’s a decision that plays right into hackers’ hands.
The bottom line is that quantum resilience is a necessity and businesses must get behind PQC for future-proofed protection. To help build PQC confidence, I’ve unraveled the four biggest misconceptions holding enterprises back.
All cryptography must be replaced
Not true. The shift to PQC is targeted, not total. Only certain core cryptographic algorithms are vulnerable and need replacing with PQC upgrades. Modern cryptographic hashing remains robust and doesn’t need to be replaced as quantum computing does not have an unfair advantage over traditional computing when it comes to introducing hashing collisions.
Modern authenticated encryption with associated data algorithms like advanced encryption standard in galois/counter mode (AES-GCM) and ChaCha20-Poly1305 also do not have weaknesses against quantum computing. While quantum computers of enormous capacity may speed up brute-force attacks on symmetric encryption through quantum search algorithms, this can be mitigated by increasing the size of the key used to encrypt data. Here, the solution isn’t replacement – it’s reinforcement.
What does need to be replaced are classical asymmetric algorithms, like RSA and ECC, that are based on algorithms that are known to be vulnerable to attacks by quantum computers: factorization of large numbers and discrete logarithm problem. Classic computers struggle with this due to the complexity of the asymmetric trapdoor function, but quantum computers can solve these problems exponentially faster using algorithms like Shor’s.
These classical asymmetric algorithms underpin two critical functions used in modern secure protocols: key exchange and digital signatures. PQC introduces quantum-safe alternatives like module lattice-based key encapsulation mechanism (ML-KEM) for key exchange and module lattice-based digital signature algorithm (ML-DSA) for digital signatures. These are the only elements needing to be replaced.
PQC can only be run on quantum computers
Another misconception. This may be rooted in the fact that quantum computers are not yet mainstream. But PQC can and is being run on the computers we use today, designed to withstand quantum attacks while maintaining strong security against classical threats. Since their foundational trapdoor functions are as difficult for quantum computers as they are difficult for classical computers.
PQC techniques don’t rely on quantum speed or quantum machines; they’re built to anticipate the capabilities of quantum adversaries, using algorithms that can easily be deployed today. It’s important to understand that the goal of PQC isn’t to use quantum technology, but to defend against it. It runs efficiently on the hardware we use right now on classic computers.
PQC standards aren’t ready
It may sound like an untested, theoretical safeguard. In reality, PQC’s standardization – as a practical, reliable, real-world-ready security approach – is already being led by national standardization bodies such as the National Institute for Standards and Technology (NIST) in the U.S., the National Cyber Security Centre (NCSC) in the U.K., the Federal Office for Information Security (BSI) in Germany, the French National Cybersecurity Agency (ANSSI), and others. The Internet Engineering Task Force (IETF) standardizes application of PQC cryptographic primitives in the internet protocols such as TLS, SSH, and IPSec.
A well defined set of quantum-resistant algorithms (including ML-KEM for key exchange and ML-DSA for digital signatures) is widely accepted as a replacement of vulnerable classical algorithms like RSA and ECC. These selections follow years of global collaboration and rigorous testing and are now being formalized into official standards. Meanwhile, the IETF is in the late stages of drafting updates to embed PQC into real-world systems. These protocol modifications will allow browsers, cloud services, and other infrastructure to adopt PQC without impacting compatibility.
Quantum threats are purely theoretical or decades away
This is the most dangerous piece of misinformation because it underestimates the potentially catastrophic risk posed by the “harvest now, decrypt later” threat of quantum technology. Malicious actors are putting their energy behind capturing strongly encrypted packets today with the aim of decrypting them later using a large enough quantum computer. We can’t predict when that will happen: it could be a year, or 20 years. But considering that much of the sensitive data that we transmit today will still be relevant years from now, can we really afford to wait and see?
Once sensitive data is exposed – whether today or years from now – the damage is done. Privacy is breached, trust is broken, and the consequences are irreversible. While we don’t know when quantum computers will reach the scale needed to break encryption, the risk is already actionable. And the onus of action rests with both enterprises and their security service providers. Providers must be thinking about how to support hybrid encryption systems, and how to enable scalable and seamless integration of interoperable quantum-resistant protocols across cloud infrastructure.
Steps to quantum resilience
There are three steps I recommend enterprises take right now to build their quantum resilience.
The first is to monitor their key exchange proposals to assess quantum compatibility, with the goal of identifying which software in their environment isn’t PQC-ready.
Second, I urge businesses to adopt standardized PQC key exchange mechanisms – they’re already supported in major secure protocols and ready for use, so there’s no need to wait.
Finally, taking action means planning ahead. This applies to digital signature migration and is especially critical for large businesses that manage their own public key infrastructure. Long upgrade cycles demand early action for cryptographic agility.
Ultimately, the goal is tighter cybersecurity, making cryptographic agility a powerful tool at your disposal. The key idea I hope businesses take away from this article is that quantum threats are not a future risk. Even though the threat isn’t currently unfolding, the risk of the threat is actionable right now.
Comments