Silicon Valleys Journal
  • Topics
    • Finance & Investments
      • Angel Investing
      • Financial Planning
      • Fundraising
      • IPO Watch
      • Market Opinion
      • Mergers & Acquisitions
      • Portfolio Strategies
      • Private Markets
      • Public Markets
      • Startups
      • VC & PE
    • Leadership & Perspective
      • Boardroom & Governance
      • C-Suite Perspective
      • Career Advice
      • Events & Conferences
      • Founder Stories
      • Future of Silicon Valley
      • Incubators & Accelerators
      • Innovation Spotlight
      • Investor Voices
      • Leadership Vision
      • Policy & Regulation
      • Strategic Partnerships
    • Technology & Industry
      • AI
      • Big Tech
      • Blockchain
      • Case Studies
      • Cloud Computing
      • Consumer Tech
      • Cybersecurity
      • Enterprise Tech
      • Fintech
      • Greentech & Sustainability
      • Hardware
      • Healthtech
      • Innovation & Breakthroughs
      • Interviews
      • Machine Learning
      • Product Launches
      • Research & Development
      • Robotics
      • SaaS
  • Media Kit
  • Contact Us
No Result
View All Result
  • Topics
    • Finance & Investments
      • Angel Investing
      • Financial Planning
      • Fundraising
      • IPO Watch
      • Market Opinion
      • Mergers & Acquisitions
      • Portfolio Strategies
      • Private Markets
      • Public Markets
      • Startups
      • VC & PE
    • Leadership & Perspective
      • Boardroom & Governance
      • C-Suite Perspective
      • Career Advice
      • Events & Conferences
      • Founder Stories
      • Future of Silicon Valley
      • Incubators & Accelerators
      • Innovation Spotlight
      • Investor Voices
      • Leadership Vision
      • Policy & Regulation
      • Strategic Partnerships
    • Technology & Industry
      • AI
      • Big Tech
      • Blockchain
      • Case Studies
      • Cloud Computing
      • Consumer Tech
      • Cybersecurity
      • Enterprise Tech
      • Fintech
      • Greentech & Sustainability
      • Hardware
      • Healthtech
      • Innovation & Breakthroughs
      • Interviews
      • Machine Learning
      • Product Launches
      • Research & Development
      • Robotics
      • SaaS
  • Media Kit
  • Contact Us
No Result
View All Result
Silicon Valleys Journal
No Result
View All Result
Home Technology & Industry AI

Why organizations can’t afford to wait on quantum cyber preparedness

Omer Kidron by Omer Kidron
August 25, 2026
in AI, Cybersecurity, Enterprise Tech, Leadership & Perspective, Technology & Industry
0

Recent breakthroughs in quantum computing have reignited the debate over its timeline. Some reports suggest a cryptographically relevant quantum computer could emerge as early as 2028; others say 2030. While the headlines focus on the promise of drug discoveries, new materials and more advanced AI, the cybersecurity community is focused on a harder implication: once a capable quantum computer arrives, much of the cryptography protecting today’s digital systems could be rendered obsolete. While these timelines are assumptions, not certainties, the risk to your data has, effectively, already begun.

Once we reach the ability to surpass classical computers, and real-world quantum applications begin to appear, the cryptographic foundations that protect virtually every digital system in use today, all built on classical computing, could be undermined far faster than most organizations are prepared to respond.

From an incident response perspective, the lesson we draw from almost every major breach applies here: by the time the threat is undeniable, it’s already too late to protect data that needed to stay confidential for years.

The Quantum Security Conundrum

Today’s popular security protocols rely on asymmetric cryptographic algorithms like RSA and Elliptic Curve Cryptography (ECC). They were purposely built on mathematically hard problems, such as integer factorization and discrete logarithms, that a conventional computer cannot solve at scale. Our banking systems, health records and government communications have relied on these ‘locks’ for decades. But a fault-tolerant quantum computer running Shor’s algorithm could make them insecure in a post-quantum world, leaving the door wide open for threat actors to take advantage.

Symmetric encryption systems such as AES are not broken outright by quantum computing, but their safety margin is reduced. Grover’s algorithm could, in theory, make brute-force key searches dramatically faster, effectively cutting the security level of a key in half. That means AES-128, widely used today, would offer roughly 64 bits of protection against a sufficiently powerful quantum computer. In practice, such an attack would still require an enormous and highly advanced quantum system.

The counter-measure is straightforward: migrating from AES-128 to AES-256 restores a comfortable security margin. There is no official ‘AES-512’ standard, and it’s not needed as AES-256 still offers the equivalent of 128-bit security. Against a quantum adversary using Grover’s algorithm, the order of 2¹²⁸ operations would take billions of years to brute-force attack. Symmetric encryption is, therefore, a manageable upgrade. The harder problem is asymmetric cryptography, and here, encouragingly, NIST has already standardized quantum-resistant algorithms, with major vendors already beginning to support them.

Rise of the Quantum Adversaries

Free from the red tape that constrains many organizations, threat actors will use any method available, including emerging technologies like AI and quantum computing, which will be turned to their advantage faster than enterprises can respond.

We are already seeing this with AI. Tools designed to help secure software by discovering vulnerabilities in minutes, like Anthropic’s Mythos, can likewise enable threat actors to find and exploit zero-day vulnerabilities in major operating systems and browsers, autonomously chain multiple vulnerabilities together, and accelerate zero-day weaponization. The ‘unknown unknowns’ are becoming discoverable on an industrial scale.

The collapse in the time it takes to find and exploit vulnerabilities, from days to mere seconds, has already forced organizations to bolster their security efforts, clear backlogs of historic patches, and prioritize vulnerabilities carrying the most business risk. Quantum will demand the same shift in mindset, earlier than most expect.

‘Harvest Now, Decrypt Later’: The Risk Has Already Started

The most sophisticated threat actors and nation-state adversaries are not waiting for ‘Q-Day’ at all. The ‘Harvest Now, Decrypt Later’ (HNDL) strategy is already in play: adversaries capture and archive encrypted traffic today (for example, diplomatic cables, trade secrets, intellectual property, health records) and simply store it until quantum hardware matures enough to decrypt it. Data that is safely encrypted today can still be stolen, but it just can’t be read yet. That is why the exact arrival date of quantum is almost beside the point: HNDL is applicable no matter when Q-Day comes.

By its nature, this activity is rarely published, but the available evidence is consistent:

  • Rerouted internet traffic: Public reporting describes incidents in 2016, 2019 and 2020 in which large volumes of encrypted traffic were rerouted through unexpected transit paths. This is consistent with the ‘harvest’ phase of HNDL, even though the later decryption step has not been publicly demonstrated.
  • Nation-state bulk collection: HNDL is most viable for nation-state actors, who have the scale, storage and patience to retain encrypted data for years until quantum decryption becomes feasible.
  • Official guidance: The Government of Canada’s cyber guidance explicitly warns that threat actors can store encrypted information now and decrypt it in the future, once a sufficiently powerful quantum computer exists (particularly for data with a long lifespan).
  • Distributed-ledger exposure: A 2026 Federal Reserve paper uses Bitcoin as an example, explaining how a bad actor could obtain a distributed-ledger replica, harvest the data, and later reveal previously protected information with a future quantum computer.

When practical quantum capabilities arrive, the mechanics are simple: the encryption protecting that harvested data falls, and years of intercepted communications, credentials and secrets become readable in retrospect. Information that is inaccessible today, because it is encrypted, is exactly what adversaries are betting they will unlock tomorrow through cryptanalysis.

Decryption is only part of the picture. Quantum-enabled adversaries could break the asymmetric keys that underpin digital trust itself — bypassing authentication, compromising long-lived secrets, undermining certificate chains, forging identities and trusted software updates. This ultimately leads to the compromise of entire systems, at scale.

Quantum Security Preparation Needs to Start Now

Governments and standards bodies are working closely with academics and businesses to deliver guidance frameworks, making it clear that migration to post-quantum cryptography (PQC) is now a prerequisite rather than an option.

The UK’s National Cyber Security Centre (NCSC), operating with GCHQ, and the US National Institute of Standards and Technology (NIST), working alongside the National Security Agency (NSA) and US Cyber Command, are balancing a realistic assessment of the threat with practical implementation capabilities — both of which should be taken seriously.

NIST has already standardized three post-quantum algorithms (FIPS 203–205). Early adopters across the technology ecosystem, including OpenSSL, Synopsys, and DigiCert, are already certified, though widespread deployment is still maturing.

The NCSC has outlined a three-phase migration roadmap — to 2028, 2028–2031, and 2031–2035 — reflecting the expected pace of engineering and infrastructure change. This should not be read as permission to delay; it is a phased approach that acknowledges the practical realities of technology adoption. A useful way to frame it: whether the first cryptographically relevant systems arrive closer to 2030 or earlier, organisations should treat 2028 as the deadline to be well into migration, because the data being stolen today can be decrypted later.

In practice, most organisations will depend heavily on vendors across their technology stack — networking equipment, compute infrastructure and cloud providers — to introduce post-quantum support, just as they did for the transition to AES after standardization. Once PQC becomes part of mainstream libraries, deployment should be relatively straightforward. Migrating legacy systems, however, will still require thorough preparation. Cryptographic migrations are typically slow, complex and expensive, particularly for legacy environments.

Not All Organisations Face the Same Risk

Post-quantum readiness will be imperative for all organisations, but it must be proportionate as not every company faces the same risk. To be effective, each organization needs to tailor its preparation to its industry, operational context and risk appetite, using a phased approach to keep the effort manageable.

Enterprises that handle long-lived sensitive data, financial institutions and healthcare providers, for example, must be first in line. The HNDL threat justifies immediate action, and regulatory frameworks are increasingly treating quantum vulnerabilities as a compliance liability. The NCSC recommends that globally significant and regulated sectors adopt PQC early.

As PQC becomes the default within the next two to three years, everyday adoption will be simplified, and more businesses will need post-quantum readiness strategies and protocols. Organisations with less long-lived data will still need to plan, because post-quantum readiness will gradually become a basic expectation. Those that haven’t prepared a migration strategy risk finding themselves not just behind, but losing ground to better-prepared competitors.

Within the next 12–24 months, organisations should be preparing the following:

  1. Assess the threat: Brief your security, compliance and risk teams on quantum timelines and ‘harvest-now’ scenarios.
  • Inventory your cryptography: Catalogue TLS endpoints, VPNs, code-signing processes, SSH servers, S/MIME, hardware tokens, embedded devices and more.
  • Evaluate crypto agility: Identify hard-coded or proprietary stacks and prioritize them for upgrade or replacement.
  • Perform risk analysis: For each asset, estimate data classification, retention requirements and quantum risk.
  • Pilot PQC models: In a lab environment, run hybrid proofs-of-concept (e.g. OpenSSL 3.2 with CRYSTALS-Kyber + ECDHE), benchmarking latency, CPU and bandwidth impacts before full rollout. This is often where flaws surface before they cause real-world impact.

Quantum readiness is not a siloed IT project. Application teams, vendors, auditors and regulators all need to be part of the conversation, because the whole organization needs to be ready.

The best approach is to treat quantum readiness as we do breach readiness in incident response: You prepare before the event, not during it. The organisations that emerge from a crisis best are those that kept an accurate asset and cryptography inventory, knew where their crown-jewel data lived, and had a tested plan long before they needed it. The quantum transition rewards exactly the same discipline. The data being targeted today won’t wait for the technology to catch up — and neither should your strategy.

Previous Post

“Legacy SaaS Won’t Survive by Adding AI,” Says AXL CEO Dmitry Yurchenko

Omer Kidron

Omer Kidron

Omer Kidron is an Enterprise Cyber Security Expert at Sygnia, where he advises organizations on cyber resilience, incident response readiness, security architecture, and the defense of complex enterprise environments. Omer brings more than 20 years of cybersecurity experience across research, engineering, operations, incident response, penetration testing, policy development, and secure infrastructure design. Prior to joining Sygnia, he served for more than 13 years in senior cybersecurity leadership roles within the Israel Defense Forces, including as Chief Cyber Technology Officer and Chief Architect, where he led cybersecurity strategy, architecture, operations, and technology programs for highly sensitive environments. With deep expertise in threat modeling, secure network design, SOC operations, incident response, identity and access management, and supply chain security, Omer specializes in translating complex technical and security challenges into practical, real-world roadmaps. His work focuses on helping organizations strengthen defenses against advanced threats, including nation-state adversaries, while aligning cybersecurity strategy with operational and business needs.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

  • Trending
  • Comments
  • Latest
Faith and the Digital Transformation of Religion: How One Person Began Helping Faith Communities and People of Faith

Faith and the Digital Transformation of Religion: How One Person Began Helping Faith Communities and People of Faith

December 30, 2025
The AI Cold War and How to Prepare for It

The AI Cold War and How to Prepare for It

May 1, 2026
AI’s Most Underrated Role: Giving Enterprise Architects Back Their Focus

AI’s Most Underrated Role: Giving Enterprise Architects Back Their Focus

November 26, 2025
The UK’s Seed-to-Series A gap is growing. Should we fix it?

The UK’s Seed-to-Series A gap is growing. Should we fix it?

November 25, 2025
The Human-AI Collaboration Model: How Leaders Can Embrace AI to Reshape Work, Not Replace Workers

The Human-AI Collaboration Model: How Leaders Can Embrace AI to Reshape Work, Not Replace Workers

1

50 Key Stats on Finance Startups in 2025: Funding, Valuation Multiples, Naming Trends & Domain Patterns

0
CelerData Opens StarOS, Debuts StarRocks 4.0 at First Global StarRocks Summit

CelerData Opens StarOS, Debuts StarRocks 4.0 at First Global StarRocks Summit

0
Clarity Is the New Cyber Superpower

Clarity Is the New Cyber Superpower

0

Why organizations can’t afford to wait on quantum cyber preparedness

August 25, 2026
“Legacy SaaS Won’t Survive by Adding AI,” Says AXL CEO Dmitry Yurchenko

“Legacy SaaS Won’t Survive by Adding AI,” Says AXL CEO Dmitry Yurchenko

August 25, 2026

GNS Deadline: GNS Investors Have Opportunity to Lead Genius Group Limited Securities Fraud Lawsuit Against Citadel Securities LLC and Virtu Americas LLC

August 25, 2026

SPRY Investors Have Opportunity to Lead ARS Pharmaceuticals, Inc. Securities Fraud Lawsuit

August 25, 2026

Recent News

Why organizations can’t afford to wait on quantum cyber preparedness

August 25, 2026
“Legacy SaaS Won’t Survive by Adding AI,” Says AXL CEO Dmitry Yurchenko

“Legacy SaaS Won’t Survive by Adding AI,” Says AXL CEO Dmitry Yurchenko

August 25, 2026

GNS Deadline: GNS Investors Have Opportunity to Lead Genius Group Limited Securities Fraud Lawsuit Against Citadel Securities LLC and Virtu Americas LLC

August 25, 2026

SPRY Investors Have Opportunity to Lead ARS Pharmaceuticals, Inc. Securities Fraud Lawsuit

August 25, 2026

About & Contact

  • About Us
  • Branding Style Guide
  • Contact Us
  • Help Centre
  • Media Kit
  • Site Map

Explore Content

  • Events
  • Newsletter
  • Press Releases
  • Reports & Guides
  • Topics

Legal & Privacy

  • Advertiser & Partner Policy
  • Communications & Newsletter Policy
  • Contributor Agreement
  • Copyright Policy
  • Privacy Policy
  • Prohibited Content Policy
  • Terms of Service

Tiny Media Brands

  • Silicon Valleys Journal
  • The AI Journal
  • The City Banker
  • The Wall Street Banker
  • World Lifestyler
  • About
  • Privacy & Policy
  • Contact

© 2025 Silicon Valleys Journal.

No Result
View All Result

© 2025 Silicon Valleys Journal.