Recent guidance issued by the G7 Cyber Expert Group urges the financial sector to aim for a full transition to post-quantum cryptography (PQC) by 2035. This guidance is both timely and necessary, particularly for the financial sector, which holds vast amounts of long-life, high-value data. As we look towards 2026, one of the biggest challenges that organizations face is the widening gap between the pace of quantum cryptography research and the speed at which production systems are actually updated.
This concern is also reflected in official government guidance. In the UK, the National Cyber Security Centre (NCSC) has already published a post quantum migration timeline, calling on organizations to identify and explore options by 2028, prioritise systems by 2031, and complete migration by 2035. For regulated sectors such as banking, healthcare, and critical infrastructure, this guidance is likely to pull expectations forward rather than push them further out.
All the guidance highlighted above makes one thing clear: the timeline for action is shorter than many organizations assume. Attackers do not need a fully functional quantum computer today to pose a real risk. Many are already harvesting encrypted data, storing it, and waiting for the moment when it can be decrypted. This means that financial records, personal information, and intellectual property are already becoming long-term liabilities. The challenge now is not understanding what needs to be done, but whether organizations can move quickly enough to protect data before that countdown reaches zero.
Realising the speed of quantum
The cryptographic systems that underpin today’s world were never designed to withstand quantum computing. Algorithms such as RSA and elliptic curve cryptography rely on mathematical problems that would take classical computers centuries to solve. Quantum computers will be able to do the same work far, far, faster; at a speed that makes it realistic to expect that anything encrypted using such algorithms is vulnerable to future decryption.
While the precise timeline to a ‘cryptographically relevant quantum machine’ remains uncertain, it is shrinking quickly. Many credible forecasts now place Q Day within the next three to five years. When set against the NCSC timeline, this leaves organizations with far less room for delay than many assume.
The idea that quantum preparation must involve ripping out applications or replacing entire platforms has become one of the biggest barriers to progress. In reality, quantum readiness is less about rebuilding everything and more about rethinking how security is applied.
The harvest now, decrypt later reality
One of the most dangerous misconceptions is that quantum risk only matters in the future. It does not. Adversaries are already harvesting encrypted data today, including commercial intellectual property, healthcare records, and government communications, with the intention of decrypting it later. This ‘harvest now, decrypt later’ approach means that data that appears safe today may become exposed years from now.
This risk is amplified by the long lifespan of much of the data handled by regulated sectors. Financial records, medical histories, and identity data often need to remain confidential for decades. A breach that looks contained today can become far more damaging later, when cryptographic assumptions no longer hold.
Why perimeter security is no longer enough
For years, security strategies were built around protecting the network edge. Firewalls, VPNs, and perimeter defences were assumed to be sufficient. History has shown otherwise. Many major breaches have occurred inside the network, through compromised credentials or trusted connections, exposing the limits of perimeter-centric thinking.
This shift is already reflected in how organizations are adapting. Gartner research shows that 63% of organizations worldwide have now fully or partially implemented a zero trust strategy, shifting focus away from the network perimeter toward identity- and data-centric controls. The same research indicates that 70% of new remote access deployments now use Zero Trust Network Access (ZTNA) instead of traditional VPN tools.
The direction of travel is clear. Security models are evolving to focus on data flows, continuous verification, and least-privilege access, rather than assuming that anything inside the network is safe.
The problem no one can ignore
Legacy systems remain one of the biggest obstacles to quantum readiness. Many core systems in large organizations, especially banks and hospitals, were built twenty to forty years ago, long before public key cryptography was conceived, Internet-scale threat models existed, or quantum computing was even conceivable.
In many cases, cryptography is hard-coded into applications, buried in firmware such as ATMs or medical devices, or embedded in proprietary vendor software. Changing it is rarely a configuration update. It often requires rewriting applications, recertifying devices, or replacing hardware entirely – which is costly, slow, and risky.
This is why progress has been slower than regulators would like. Organizations are well aware of the issue, but the complexity of their environments limits how quickly they can respond.
Protecting data without breaking systems
This is where a data centric approach to post-quantum protection becomes critical. Rather than upgrading cryptography inside every legacy application and device, protection can be applied around the data flows themselves. This allows legacy systems to continue running while security is modernised beneath the surface.
Through a data protection and risk mitigation (DPRM) approach, data can be protected in transit across physical, virtual, and cloud environments, independent of application logic or infrastructure. The data is encrypted, governed by policy, and only accessible to authorised parties, regardless of where it travels.
This significantly reduces the pain of migration. Fewer systems need to be touched; application rewrites and device recertification cycles can be avoided – and a phased rollout becomes realistic rather than a risky big-bang project. Transition timelines are shortened, disruption is minimised, and costs are reduced.
Crypto agility as a long term requirement
No single algorithm will remain secure forever. Post-quantum standards will evolve, and some will inevitably be replaced. This makes crypto agility essential. Crypto agility means being able to change algorithms, rotate keys, and adapt protection without redesigning systems or interrupting operations. It is not just a technical feature. It is a business requirement for resilience and compliance.
Frameworks that support decentralised key ownership, frequent rotation, and algorithmic flexibility give organizations control over their future security posture, rather than locking them into assumptions that may prove false.
Quantum disruption is not speculative. The guidance is clear, the timelines are tightening, and attackers are already preparing. Organizations that wait for certainty will find they have waited too long.
Preparation does not require panic or wholesale replacement. It requires understanding where data flows, identifying which data must remain secure for decades, and applying protection that can evolve as threats change.
The organizations that succeed will be those that protect the right thing: the data. Those that act now will reduce their quantum risk, strengthen resilience, and build trust with regulators, customers, and partners.
Quantum is coming. The question is whether your data will still be protected when it arrives.
The author
Simon Pamplin is CTO, Certes






