Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Cyber resilience»The quantum threat is real and it’s not just a future issue (Page 14)
Cyber resilience

The quantum threat is real and it’s not just a future issue

Simon Pamplin highlights that, while the timing of a ‘cryptographically relevant quantum machine’ remains uncertain, preparation cannot be deferred. Adopting crypto agility is a critical step in strengthening long-term resilience.
February 23, 20266 Mins Read
Cyber owl logo in low-poly geometric style with glowing orange and cyan lights. The image illustrates the concept of the emerging threat that quantum computing brings.

Recent guidance issued by the G7 Cyber Expert Group urges the financial sector to aim for a full transition to post-quantum cryptography (PQC) by 2035. This guidance is both timely and necessary, particularly for the financial sector, which holds vast amounts of long-life, high-value data. As we look towards 2026, one of the biggest challenges that organizations face is the widening gap between the pace of quantum cryptography research and the speed at which production systems are actually updated.

 This concern is also reflected in official government guidance. In the UK, the National Cyber Security Centre (NCSC) has already published a post quantum migration timeline, calling on organizations to identify and explore options by 2028, prioritise systems by 2031, and complete migration by 2035. For regulated sectors such as banking, healthcare, and critical infrastructure, this guidance is likely to pull expectations forward rather than push them further out.

 All the guidance highlighted above makes one thing clear: the timeline for action is shorter than many organizations assume. Attackers do not need a fully functional quantum computer today to pose a real risk. Many are already harvesting encrypted data, storing it, and waiting for the moment when it can be decrypted. This means that financial records, personal information, and intellectual property are already becoming long-term liabilities. The challenge now is not understanding what needs to be done, but whether organizations can move quickly enough to protect data before that countdown reaches zero.

Realising the speed of quantum

The cryptographic systems that underpin today’s world were never designed to withstand quantum computing. Algorithms such as RSA and elliptic curve cryptography rely on mathematical problems that would take classical computers centuries to solve. Quantum computers will be able to do the same work far, far, faster; at a speed that makes it realistic to expect that anything encrypted using such algorithms is vulnerable to future decryption.

 While the precise timeline to a ‘cryptographically relevant quantum machine’ remains uncertain, it is shrinking quickly. Many credible forecasts now place Q Day within the next three to five years. When set against the NCSC timeline, this leaves organizations with far less room for delay than many assume.

 The idea that quantum preparation must involve ripping out applications or replacing entire platforms has become one of the biggest barriers to progress. In reality, quantum readiness is less about rebuilding everything and more about rethinking how security is applied.

The harvest now, decrypt later reality

One of the most dangerous misconceptions is that quantum risk only matters in the future. It does not. Adversaries are already harvesting encrypted data today, including commercial intellectual property, healthcare records, and government communications, with the intention of decrypting it later. This ‘harvest now, decrypt later’ approach means that data that appears safe today may become exposed years from now.

 This risk is amplified by the long lifespan of much of the data handled by regulated sectors. Financial records, medical histories, and identity data often need to remain confidential for decades. A breach that looks contained today can become far more damaging later, when cryptographic assumptions no longer hold.

 Why perimeter security is no longer enough

 For years, security strategies were built around protecting the network edge. Firewalls, VPNs, and perimeter defences were assumed to be sufficient. History has shown otherwise. Many major breaches have occurred inside the network, through compromised credentials or trusted connections, exposing the limits of perimeter-centric thinking.

This shift is already reflected in how organizations are adapting. Gartner research shows that 63% of organizations worldwide have now fully or partially implemented a zero trust strategy, shifting focus away from the network perimeter toward identity- and data-centric controls. The same research indicates that 70% of new remote access deployments now use Zero Trust Network Access (ZTNA) instead of traditional VPN tools.

 The direction of travel is clear. Security models are evolving to focus on data flows, continuous verification, and least-privilege access, rather than assuming that anything inside the network is safe.

 The problem no one can ignore

 Legacy systems remain one of the biggest obstacles to quantum readiness. Many core systems in large organizations, especially banks and hospitals, were built twenty to forty years ago, long before public key cryptography was conceived, Internet-scale threat models existed, or quantum computing was even conceivable.

 In many cases, cryptography is hard-coded into applications, buried in firmware such as ATMs or medical devices, or embedded in proprietary vendor software. Changing it is rarely a configuration update. It often requires rewriting applications, recertifying devices, or replacing hardware entirely – which is costly, slow, and risky.

This is why progress has been slower than regulators would like. Organizations are well aware of the issue, but the complexity of their environments limits how quickly they can respond.

 Protecting data without breaking systems

This is where a data centric approach to post-quantum protection becomes critical. Rather than upgrading cryptography inside every legacy application and device, protection can be applied around the data flows themselves. This allows legacy systems to continue running while security is modernised beneath the surface.

Through a data protection and risk mitigation (DPRM) approach, data can be protected in transit across physical, virtual, and cloud environments, independent of application logic or infrastructure. The data is encrypted, governed by policy, and only accessible to authorised parties, regardless of where it travels.

 This significantly reduces the pain of migration. Fewer systems need to be touched; application rewrites and device recertification cycles can be avoided – and a phased rollout becomes realistic rather than a risky big-bang project. Transition timelines are shortened, disruption is minimised, and costs are reduced.

Crypto agility as a long term requirement

No single algorithm will remain secure forever. Post-quantum standards will evolve, and some will inevitably be replaced. This makes crypto agility essential. Crypto agility means being able to change algorithms, rotate keys, and adapt protection without redesigning systems or interrupting operations. It is not just a technical feature. It is a business requirement for resilience and compliance.

Frameworks that support decentralised key ownership, frequent rotation, and algorithmic flexibility give organizations control over their future security posture, rather than locking them into assumptions that may prove false.

Quantum disruption is not speculative. The guidance is clear, the timelines are tightening, and attackers are already preparing. Organizations that wait for certainty will find they have waited too long.

Preparation does not require panic or wholesale replacement. It requires understanding where data flows, identifying which data must remain secure for decades, and applying protection that can evolve as threats change.

The organizations that succeed will be those that protect the right thing: the data. Those that act now will reduce their quantum risk, strengthen resilience, and build trust with regulators, customers, and partners.

Quantum is coming. The question is whether your data will still be protected when it arrives.

The author

Simon Pamplin is CTO, Certes

Africa Asia Asia Pacific Australasia Europe Middle East North America UK
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleMFA fatigue attacks and how to avoid them
Next Article Beyond security: how cyber must evolve for the hybrid human–AI workforce

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
Multiracial people in a city wearing face masks.

UK Government publishes Pandemic Preparedness Strategy

March 26, 2026
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?