Quantum Computing’s Impact: Will It Shatter Encryption or Revolutionize Cybersecurity?
Quantum computing is emerging as both a major cybersecurity threat and a potential defensive tool, raising concerns about the future of widely used encryption while opening new possibilities for secure communications, threat detection and resilient digital infrastructure.
Quantum Computing as a Threat
Shor’s Algorithm and Public-Key Cryptography
Popular public-key algorithms, including RSA and elliptic-curve cryptography, could face significant risks if cryptographically relevant quantum computers become capable of breaking them. The exact timeline remains uncertain, but advances in algorithms, hardware and error correction have increased attention on the issue.
Harvest Now, Decrypt Later
Under this approach, sophisticated attackers could collect encrypted information today and retain it in the hope that future quantum technology will allow them to decrypt it. Long-lived sensitive information is particularly exposed to this risk because data stolen now could remain valuable for years.
Impact on Zero Trust Models
Quantum risks could also require changes to Zero Trust security models, which depend heavily on strong cryptographic foundations, authentication and continuous verification. Organisations may need to prepare migration plans aligned with post-quantum cryptography standards, identify long-lived sensitive information, create inventories of cryptographic assets and develop the ability to change cryptographic systems as technology develops.
Quantum as a Defensive Tool
Quantum Key Distribution (QKD)
Quantum Key Distribution, or QKD, could support high-assurance communications by making attempts to intercept key material detectable through principles of quantum mechanics. Potential applications include government, critical infrastructure and financial systems, although practical challenges involving infrastructure, integration and distance remain.
Quantum-Enhanced Sensors
Quantum-enhanced sensors could also improve situational awareness and threat detection. Greater sensitivity and accuracy may support anomaly detection and monitoring in physical and digital environments.
Quantum and Hybrid Systems
Quantum and hybrid quantum-classical systems could help address complex optimisation and simulation problems that are difficult for conventional systems. Possible cybersecurity applications include threat modelling, resource allocation in security operations centres, red-team and purple-team exercises, and faster analysis of behavioural anomalies across large datasets.
Post-Quantum Cryptography
Post-quantum cryptography is expected to become an important part of efforts to protect systems against future quantum attacks. Organisations can prepare by building cryptographic inventories, prioritising high-value and long-lasting data, and developing and testing migration strategies towards NIST-standardised post-quantum algorithms. Combining quantum-derived techniques with classical post-quantum algorithms could also support hybrid security architectures designed to reduce dependence on cryptographic assumptions vulnerable to quantum attacks.
Preparing for Quantum Risks
Immediate Steps
Organisations should take immediate steps to address quantum risks. This includes building a cryptographic inventory to identify sensitive information and systems using potentially vulnerable encryption. Improving crypto-agility so cryptographic methods can be replaced or upgraded without disrupting critical operations is essential. Testing migration strategies for NIST-standardised post-quantum algorithms before quantum risks become more immediate is also critical. Assessing quantum technologies such as quantum sensing and Quantum Key Distribution (QKD) where they provide practical security value should be prioritised. Training employees on quantum risks and incorporating quantum awareness into cybersecurity workforce development is necessary. Strengthening AI-assisted detection and response while adapting Zero Trust systems for emerging quantum threats is another key action. Increasing intelligence sharing and cooperation across organisations and sectors is vital, as AI and quantum-related threats can cross organisational boundaries.
- Building a cryptographic inventory to identify sensitive information and systems using potentially vulnerable encryption
- Improving crypto-agility to replace or upgrade cryptographic methods without disrupting critical operations
- Testing migration strategies for NIST-standardised post-quantum algorithms
- Assessing quantum technologies like quantum sensing and QKD for practical security value
- Training employees on quantum risks and integrating quantum awareness into cybersecurity programs
- Strengthening AI-assisted detection and adapting Zero Trust systems for quantum threats
- Increasing intelligence sharing and cross-organisational collaboration
Conclusion
The quantum threat is not limited to the day powerful quantum computers arrive. Sensitive encrypted data stolen today could potentially be stored for future decryption. Organisations therefore need to identify critical cryptographic assets, improve crypto-agility and begin preparing migration strategies for post-quantum security while exploring quantum technologies that could strengthen cyber defence.
