Quantum Computing Risk: Should Boards Start Preparing Now?
Here’s a gap that should bother every director more than it currently does. A 2025 ISACA survey found that two-thirds of cyber professionals are worried about quantum computers eventually breaking modern encryption. Only 5 percent of them have actually built a strategy to deal with it. Same 5 percent, by the way, that considers it a high priority at all.
That’s not a technology gap. That’s a governance gap. And it’s the kind of gap that tends to look fine right up until it very much isn’t.

Executive Summary
Quantum computing risk, for a board, comes down to one specific thing: a sufficiently powerful quantum computer would be able to break the public-key encryption — RSA, elliptic-curve cryptography — that currently protects almost everything digital, from emails to financial transactions to stored corporate data. No quantum computer capable of that exists yet. Most credible estimates put that milestone, often called “Q-Day,” sometime in the 2030s, though nobody can say exactly when. Here’s the part that changes the urgency completely: attackers don’t need a working quantum computer today to create risk today. They just need to steal your encrypted data now and sit on it until they can decrypt it later. That’s already happening. NIST finalized the first official post-quantum cryptography standards back in August 2024, closing out an eight-year evaluation process, and the EU has already set a 2030 deadline for high-risk use cases and 2035 for everything else. The regulatory clock has started. Most boards haven’t noticed.
Quick Answers
What is quantum computing risk?
It’s the risk that a future quantum computer will be able to break the encryption methods — mainly RSA and elliptic-curve cryptography — that currently secure most digital communication and stored data. It’s not about quantum computers being generally dangerous. It’s specifically about code-breaking capability.
What is “Q-Day”?
Q-Day is the point at which a quantum computer becomes powerful enough to break today’s standard public-key encryption. It isn’t a fixed date on a calendar — it’s a capability milestone, and estimates for when it might arrive range across the 2030s, with some assessments suggesting it could arrive sooner.
What is “harvest now, decrypt later,” and why does it matter today?
It’s a strategy where attackers steal encrypted data right now, store it, and simply wait for quantum decryption to become possible. The data doesn’t need to be readable today to be valuable later — which means any data that needs to stay confidential for years or decades is already exposed, regardless of when Q-Day actually happens.
Is post-quantum cryptography already available?
Yes. NIST finalized its first three post-quantum cryptography standards — ML-KEM, ML-DSA, and SLH-DSA — in August 2024. Organisations can begin migrating to them now rather than waiting for a forced deadline.
Why “Quantum Is Years Away” Is the Wrong Way to Think About This
The timing debate around Q-Day is genuinely unresolved, and reasonable experts disagree. Some assessments place a cryptographically relevant quantum computer solidly in the 2030s. A few recent commercial forecasts have suggested it could be closer, within five years on some estimates. Nobody’s claiming certainty here, and any blog telling you the exact year is guessing.
But that debate, while real, is also slightly beside the point for a board. Here’s why. The risk doesn’t start on Q-Day. It starts the moment your data gets stolen — which, for a lot of organisations, already happened, or is happening right now. If someone exfiltrates your encrypted intellectual property, health records, classified material, or long-term contracts today, they don’t need quantum computing yet. They just need patience. The confidentiality clock on that stolen data starts ticking the day it’s taken, not the day it’s decrypted.
And attackers are getting faster at the “steal it now” part, if nothing else. Unit 42’s 2026 Global Incident Response Report found that the fastest quartile of intrusions reached data exfiltration in just 72 minutes in 2025 — down sharply from 285 minutes the year before. The share of incidents reaching exfiltration in under an hour also climbed. Whatever you think about quantum timelines, the theft side of this equation is accelerating right now, with tools that already exist.
So the honest framing isn’t “quantum is years away, we have time.” It’s “the exposure already started, and Q-Day just determines when it gets cashed in.”
What This Actually Means for Board Oversight
Quantum risk shouldn’t sit in some separate, speculative corner of the risk register, treated like a curiosity for the technology team to monitor. It belongs inside the same cyber risk and enterprise risk oversight the board already does for ransomware, supply chain exposure, and data breaches — because structurally, it’s the same category of risk. It’s just got a longer fuse.
Practically, that means a few things change in how the board engages. Cyber risk reporting to the board should start including a specific question: what data do we hold that needs to stay confidential for years or decades, and how exposed is it right now? Scenario analysis — the kind boards already run for a ransomware event or a major breach — should extend to “what happens if our core encryption fails,” even if that scenario feels distant. And accountability for post-quantum migration needs an actual owner, the same way any other material risk does, rather than living as a vague aspiration in an IT roadmap nobody revisits.
None of this requires directors to understand the mathematics behind lattice-based cryptography. It requires the same discipline already applied to any other long-horizon risk: asking whether someone is actually accountable for it, and whether “we’ll deal with it later” has quietly become the default answer.
How Organisations Are Actually Meant to Respond
There’s a reasonably clear practical sequence emerging across cybersecurity guidance, and it doesn’t start with ripping out every system overnight.
Cryptographic inventory. Most organisations genuinely don’t know where all their encryption lives — which systems, which vendors, which legacy applications are quietly still running outdated methods. You can’t protect what you haven’t mapped. This is usually the unglamorous first step, and it’s often skipped because it isn’t exciting.
Data prioritisation. Not all data is equally at risk from harvest-now-decrypt-later. The data that matters most is whatever needs to stay confidential the longest — trade secrets, health records, long-term legal agreements, anything with a shelf life measured in years rather than months. Security experts increasingly recommend tackling the highest-value, highest-risk data first rather than trying to inventory absolutely everything before acting.
Crypto-agility. This is the capability to swap out encryption methods without rebuilding systems from scratch. Organisations that build this in now save themselves an enormous, expensive scramble later, whenever the eventual mandatory migration deadline lands.
Migration to post-quantum standards. NIST finalized three standards in August 2024 after an eight-year evaluation process: ML-KEM for general encryption and key exchange, ML-DSA for digital signatures, and SLH-DSA as a hash-based fallback signature method with a different, more conservative security foundation. These aren’t experimental anymore. They’re the actual standards organisations are being encouraged to migrate toward now, not after a deadline forces the issue.
A Real-World Example
Governments have already started treating this as a “when,” not an “if,” and their timelines are worth paying attention to, because they tend to set the pace private industry eventually follows. The US issued National Security Memorandum-10 back in 2022, requiring federal agencies to complete post-quantum migration by 2035 — a deadline that implicitly accepts a working quantum computer could plausibly exist before then. The EU has gone further with specifics: its roadmap sets the end of 2026 for the first phase of post-quantum tool deployment, 2030 as the deadline for high-risk use cases specifically, and 2035 for the broader transition. Meanwhile, NSA guidance under CNSA 2.0 has set 2030 as its own mandatory migration deadline for national security systems.
None of these deadlines are arbitrary. They reflect institutions with genuine intelligence and threat visibility deciding the risk is real enough to legislate around, years before Q-Day is expected to actually arrive.
FAQs
Do directors need to understand the cryptography itself to oversee this properly?
No. What matters is asking the right governance questions — do we know where our sensitive long-life data lives, is someone accountable for migration, is this on the risk register with a real timeline — not understanding the underlying mathematics.
What kind of data is most at risk right now?
Anything that needs to stay confidential for a long time: intellectual property, health information, classified or trade-secret material, and long-duration contracts or agreements. Short-lived data, like a transaction that’s only sensitive for a few weeks, carries far less quantum-era risk by comparison.
Is this only a concern for tech companies or financial institutions?
No. Any organisation holding data with a long confidentiality shelf life is exposed, regardless of sector — healthcare, legal, manufacturing with valuable IP, government contractors, and plenty of others outside the obvious tech and finance categories.
How is this different from a normal cybersecurity risk conversation?
The mechanism is unusual: the breach may have already happened, and the organisation might not know it for years, because the stolen data isn’t readable yet. That delayed-impact structure is genuinely different from most cyber risk boards are used to discussing, where the damage is usually apparent close to the time of the incident.
Key Insights
The real risk clock started with today’s data theft, not with the eventual arrival of a working quantum computer — treating Q-Day as the starting point badly understates current exposure.
There’s a striking gap between concern and preparedness: two-thirds of cyber professionals worry about this, only 5 percent have an actual strategy.
Post-quantum cryptography isn’t theoretical anymore — NIST’s standards have been finalized since August 2024, and organisations can begin migrating today rather than waiting for a mandate.
Government deadlines (2030 to 2035 across the US and EU) signal that institutions with serious threat intelligence already treat this as a matter of “when,” not “if.”
Key Takeaways
The mistake most boards are making isn’t ignorance — most directors have heard of quantum computing and vaguely know it’s “a thing” for the future. The mistake is treating it as a future problem, when the actual exposure is happening in the present tense, every time sensitive data gets stolen and quietly shelved for later. Getting this right doesn’t require a crash course in cryptography. It requires putting one question on the board’s cyber risk agenda this year: do we know what encryption we’re running, where our longest-lived sensitive data sits, and who owns the migration plan? Boards that ask that now get years of runway. Boards that wait for a deadline get a scramble.
Prepare Today for the Risks of Tomorrow
Q-Day may not have arrived yet—but waiting until it does could leave organisations scrambling.
Understand emerging technology risks, strengthen board oversight, and stay prepared for the next generation of cybersecurity challenges.





Comments