Autor: Nermin Sefić
The post-quantum cryptographic transition is not a theoretical future question - organisations harvesting encrypted data today create risk that materialises in a decade. A practical preparation framework for boards.
The post-quantum cryptographic transition is not a theoretical future question. Data leaking today can be decrypted in ten years - and preparation that seems premature today becomes critically late tomorrow.
Quantum computers do not need to become practically available tomorrow to pose a real risk today. A concept known as "harvest now, decrypt later" describes a strategy in which adversaries — state actors, organised crime, competitors — already collect encrypted traffic today and store it, waiting for the moment a quantum computer becomes powerful enough to break today's encryption.
For data with a short shelf life — a one-time transaction token, for instance — this risk is negligible. But for data that must remain confidential for decades — trade secrets, intellectual property, employee and client personal data, contractual terms with long-term obligations — the risk becomes real today, because encrypted data leaking now can be decrypted in ten or fifteen years, precisely when the quantum threat becomes operational.
The US National Institute of Standards and Technology (NIST) formalised this concern by publishing the first standardised post-quantum cryptographic algorithms, signalling that the period of purely academic debate is ending and organisations need to start planning an actual migration.
Most of today's internet security — from the TLS/SSL certificates protecting web traffic, through VPN connections, to digital document signing — relies on two mathematical problem families: large number factorisation (RSA) and the discrete logarithm over elliptic curves (ECC). Both problems are considered practically unsolvable for classical computers within a reasonable timeframe, even with enormous computing power.
Shor's algorithm, theoretically described back in 1994, shows that a sufficiently powerful quantum computer can solve both problems exponentially faster than a classical computer. The key phrase is "sufficiently powerful" — current quantum computers, including the most advanced commercial and research systems, remain far from the number of stable, coherent qubits needed for a practical attack on RSA-2048 or equivalent ECC encryption.
Expert estimates on when quantum computers will reach that tipping point vary significantly — from optimistic five-to-ten-year projections to more conservative estimates of twenty years or more. This uncertainty itself represents a management challenge: an organisation cannot wait for consensus before beginning preparation, since that could mean preparation starts too late.
The good news is that the solution does not require waiting for quantum computers — post-quantum cryptography (PQC) refers to cryptographic algorithms designed to resist attacks from both classical and quantum computers, algorithms that can be implemented on existing, classical computing infrastructure today.
Following a multi-year competitive process involving hundreds of proposed algorithms and intensive cryptanalytic scrutiny from the global research community, NIST standardised several algorithms as the foundation of future post-quantum infrastructure: CRYSTALS-Kyber for key exchange and CRYSTALS-Dilithium for digital signatures represent the primary selected standards, alongside additional algorithms such as SPHINCS+ as an alternative based on different mathematical assumptions, diversifying risk in case a weakness is discovered in the primary approach.
Migration to these standards is not a trivial swap of one library for another. Post-quantum algorithms generally require larger keys and signatures, with implications for network bandwidth, performance on resource-constrained embedded systems, and compatibility with legacy systems that may never be updated.
One of the most important insights from this transition is the concept of "cryptographic agility" — an organisation's ability to relatively quickly replace cryptographic algorithms across its entire infrastructure, without needing a thorough system redesign every time a weakness is discovered or standards evolve.
Organisations that built their systems assuming cryptographic algorithms would remain fixed for decades — hardcoding specific algorithms deep into application logic rather than through abstract, replaceable layers — face a significantly more expensive and slower migration than those that built with agility in mind from the start.
This raises a question extending beyond the post-quantum threat itself: cryptographic agility is a useful capability independent of the quantum timeline, because cryptographic algorithms occasionally weaken or become compromised for reasons entirely unrelated to quantum computers — advances in classical cryptanalysis, discovered implementation flaws, or simply changing regulatory requirements across different jurisdictions.
For organisations just beginning to consider this question, the practical path forward typically involves several clearly defined phases, each requiring a different level of technical and managerial attention.
The first step is a cryptographic asset inventory. Surprisingly few organisations have a complete, current inventory of exactly where in their infrastructure each cryptographic algorithm is used — from TLS certificates on web servers, through database encryption, to digital signatures in internal documentation systems. Without this inventory, prioritising migration according to actual risk is impossible.
The second step is risk assessment by data category. Not all data carries the same migration urgency. Data with short sensitivity windows (transaction tokens, session keys) carries significantly lower "harvest now, decrypt later" risk than data that must remain confidential for decades (trade secrets, health data, long-term contracts).
The third step is piloting on low-risk systems. Before an organisation migrates critical infrastructure, it is worthwhile testing post-quantum algorithms on internal, less critical systems, where performance, compatibility, and integration issues can be identified without exposing the organisation to genuine operational risk.
The fourth step is engagement with vendors and partners. Few organisations control their entire technology stack — they rely on cloud providers, software vendors, and business partners whose own cryptographic readiness directly affects the security of the entire chain. Asking vendors early about their post-quantum plans avoids unpleasant surprises later.
The fifth step is embedding cryptographic agility into future architectural decisions. Even for organisations not migrating to post-quantum standards today, every new architectural decision represents an opportunity to build flexibility that will make future migration cheaper and faster.
Beyond the purely technical risk, organisations increasingly face regulatory pressure as well. Government agencies across multiple jurisdictions have begun issuing guidance, and in some cases binding deadlines, for migrating critical infrastructure to post-quantum standards. Organisations operating in regulated sectors — finance, healthcare, energy, defence — will likely see this guidance converted into binding requirements faster than organisations in less regulated sectors.
This regulatory trend creates an additional layer of urgency beyond the purely technical risk: organisations that wait until the last moment will face not only the technical challenge of migration under time pressure, but also potential regulatory penalties for non-compliance.
The final economic calculation for boards comes down to comparing two risks: the cost of early, gradual preparation versus the cost of late, urgent migration under the pressure of a real or perceived quantum threat. Organisations that start early can spread the migration cost across multiple years, integrate it into regular infrastructure replacement cycles, and avoid the premium typically carried by urgent, unplanned projects.
Those that wait risk a scenario in which migration must proceed under significantly greater time pressure, potentially at premium prices for specialists and tools that will be in heavy demand across the entire industry simultaneously at that moment, given that few organisations realistically prepare a decade in advance for a risk whose exact moment of materialisation remains uncertain.
GNK ASG d.o.o. monitors this development as part of a broader approach to technology risk management within the GNK DINAMO Ltd. Group, in the conviction that cryptographic agility, built today as an organisational capability, represents a reasonable, measurable investment regardless of the exact moment the quantum threat becomes operationally real.
Not all industries carry the same level of urgency in this transition. The financial sector, with long-term contractual obligations and sensitive transactional data that must remain confidential for decades, is typically considered one of the priority sectors for early migration. The healthcare sector carries similar urgency due to the nature of medical data and long-standing legal obligations to preserve patient confidentiality.
The energy sector and critical infrastructure operators face an additional layer of complexity because their operational systems often include embedded equipment with long lifecycles — industrial control systems installed decades ago, designed to run for decades more, whose cryptographic component replacement or upgrade may require physical access and significant operational disruption.
The technology sector, including organisations such as those within the GNK DINAMO Ltd. Group that develop their own software infrastructure, carries specific responsibility because their architectural decisions today shape the cryptographic readiness of numerous clients and partners relying on their solutions. Building cryptographic agility into products and platforms today means future clients will not inherit the same problem currently troubling organisations that built without that foresight a decade ago.
There is a persistent temptation to delegate the post-quantum preparation question exclusively to technical teams, treating it as a narrow technical matter similar to any other software upgrade. This approach underestimates the strategic nature of the decision.
Boards that genuinely understand this risk ask questions extending beyond pure technical implementation: what is the financial cost of delay relative to the cost of early preparation? Which data categories carry the greatest long-term risk if compromised today but decrypted in ten years? How does our cryptographic readiness, or lack thereof, affect risk perception among our largest clients and partners, particularly those in regulated sectors already asking these questions of their vendors?
These questions require board involvement not because the board needs to understand the mathematics of Shor's algorithm, but because the answers shape strategic resource allocation, risk appetite, and the timeframe within which the organisation chooses to move — decisions that by nature extend beyond the mandate of any single technical team.
For organisations wanting to quickly assess their current position, a useful starting point is a series of simple but revealing questions. Does the organisation know, with reasonable precision, which cryptographic algorithms are used across its infrastructure, including systems procured from third parties? Is there a named responsibility — an individual or team — tasked with tracking post-quantum standards development and their applicability to the organisation? Has cryptographic agility been explicitly considered as a criterion in recent architectural decisions, or is it assumed that current algorithms will simply "work forever"?
Organisations answering most of these questions negatively are not necessarily in immediate danger — the quantum threat, as noted earlier, likely remains years, perhaps decades, away from practical realisation. But every year of delay reduces the room for a gradual, well-planned migration and increases the likelihood that future migration will need to proceed reactively, under pressure, rather than proactively, on the organisation's own schedule.
This is not the first time the global technology industry has undergone a major cryptographic transition, and historical experience offers useful lessons. The transition from DES to AES in the late nineties and early two-thousands, or the gradual phase-out of the SHA-1 hash function in favour of SHA-2 and SHA-3 standards over the past decade, show a pattern likely to repeat in the post-quantum transition: organisations that adopted new standards early faced gradual, manageable costs integrated into regular development cycles, while those that waited until the last moment — often prompted by concrete, publicly disclosed vulnerabilities — had to conduct urgent, more expensive migrations under significant time pressure.
The key difference in the post-quantum scenario is the absence of a clear, publicly visible "breakthrough moment" that would serve as an industry alarm. Unlike the discovery of a concrete vulnerability in an existing algorithm — an event that can be dated and immediately publicly reported — the quantum threat materialises gradually, through continuous improvement in qubit count and stability, without a clear line dividing "safe" from "unsafe." This gradualness makes delaying the decision easier, since there is never a clear, unambiguous moment forcing immediate action — which makes proactive planning, rather than waiting for an alarm that may never arrive in the expected form, all the more important.
For organisations this piece prompts into action, a practical first step does not require a massive initial investment. Naming a responsible person or small team tasked with tracking post-quantum standards development, conducting a basic inventory of where cryptography is used across the organisation, and asking key vendors about their post-quantum readiness represent steps requiring relatively modest resources, while building the foundation for more informed, better-prepared decisions when the time comes for more concrete implementation.
GNK ASG d.o.o. continues to monitor developments in this area as part of a broader approach to technology risk within the GNK DINAMO Ltd. Group, in the conviction that early, thoughtful preparation — not panic, not delay — represents the most sensible path forward through one of the most significant technological transition periods the corporate world faces in the years ahead.
Cjelovit tekst i izvor: https://gnk-asg.hr/en/publications/quantum-computing-corporate-security-preparation/
Autor i urednička odgovornost: Nermin Sefić. Izdavač: GNK ASG d.o.o..
#GNKASG #GNKDINAMOLtd #NerminSefic #BusinessIntelligence #postquantumcryptography #quantumcomputing #cybersecurity #NerminSefić #cryptographicagility #NISTstandards