Enterprises are increasingly being advised to prepare for the impact of quantum computing, as the timeline for meaningful advancements in the field is moving faster than many expected. For years, quantum computing was considered a futuristic concept, not an immediate concern for business operations. However, recent breakthroughs in quantum hardware, algorithms, and error correction have brought the potential of quantum computing closer to reality. This has raised concerns about the security of current cryptographic systems, which could be rendered obsolete by powerful quantum computers. Despite this, many organizations have yet to prioritize quantum readiness, as the exact timeline for when this threat might materialize remains unclear.
Google, for example, has warned that quantum computing's potential may be closer than many realize, and it has set a target of 2029 for completing its transition to post-quantum cryptography (PQC). PQC refers to cryptographic techniques designed to be secure against attacks from quantum computers. However, unlike the Y2K problem, which had a clear deadline, the quantum threat is more uncertain. This ambiguity has made it difficult for organizations to determine how urgently they need to act. IBM’s 2025 Quantum-Safe Readiness Index highlights the gap, with most organizations scoring only 25 out of 100 in terms of quantum preparedness.
To begin preparing, companies are advised to create a cryptographic bill of materials (QBOM), which is essentially a detailed inventory of all the cryptographic systems in use. This helps identify which parts of the infrastructure can be easily updated and which may require more extensive changes. Organizations should then prioritize systems based on the sensitivity of the data they protect and how long that data needs to remain secure. For instance, financial records or personal customer information may require immediate attention, whereas less critical data, like internal communications, might not need urgent action.
The challenge extends beyond just cryptography. Public key cryptography (PKC), which is used in authentication methods such as single sign-on, is also at risk. If PKC is compromised, it could lead to identity impersonation, granting unauthorized access to systems and data. These risks are not solely the responsibility of the Chief Information Security Officer (CISO), as infrastructure, applications, and third-party relationships are often managed across multiple departments. Therefore, CISOs must work with other executives to align priorities and secure the necessary funding for a long-term migration to post-quantum security standards. This includes ensuring that systems can adapt to future changes in cryptographic standards without requiring expensive hardware overhauls.
Quantum Computing Urges Immediate Cryptographic Readiness Amid Evolving Threats
AI-rewritten from original reportingHow it works
quantum-computingpost-quantum-cryptocybersecurityenterprise-readinesscrypto-agility



