Should My Business Prepare for Quantum Computing Now?
Dear Will & AiME,
Our IT team is starting to talk about “post-quantum encryption.” Quantum computers capable of breaking today’s encryption do not appear to be here yet. Should we address this now, or can it wait?
— Chief Information Officer, Chicago
Short Answer 💡
Yes. Businesses should begin preparing for post-quantum cryptography now because migration can take years and sensitive information collected today could potentially be decrypted in the future. Start by inventorying cryptography, prioritizing long-lived sensitive data, and building crypto agility into systems, procurement, and vendor contracts.
Dear Chief Information Officer,
What Is “Harvest Now, Decrypt Later”?
“Harvest now, decrypt later” is a simple idea: someone collects encrypted data today and waits for quantum technology that can read it.
Information with a long useful life benefits most from early protection.
Think trade secrets, proprietary algorithms, product roadmaps, M&A materials, source code, customer records, research data, and financial information that will hold value for five, ten, or twenty years.
The most useful question is: “How long does our information need to remain confidential?”
NIST Has Finalized Post-Quantum Encryption Standards
Post-quantum cryptography has moved from research to practice.
The National Institute of Standards and Technology (NIST) has finalized standards for post-quantum cryptographic algorithms designed to withstand attacks from both conventional and quantum computers. The focus is now on implementation.
A smart first step is learning where cryptography that may need upgrading exists in your systems.
Encryption often sits in cloud services, VPNs, websites, certificates, authentication systems, mobile applications, connected devices, backup systems, software libraries, vendor platforms, and legacy equipment, so a clear inventory is valuable.
How Does Quantum Readiness Strengthen Trade Secrets and Vendor Contracts?
Quantum preparedness is also an intellectual property opportunity.
Trade secret protection depends on reasonable measures to protect confidential information. Keeping security practices current with evolving standards helps preserve that protection.
Contracts matter too.
Companies rely on vendors to store, transmit, and protect sensitive information. A practical review asks whether key technology providers have a post-quantum roadmap, whether systems can be upgraded without replacement, and who handles future cryptographic migrations.
These questions fit naturally into security questionnaires, procurement standards, due diligence, and technology contracts.
Five Steps to Build Crypto Agility Now
The practical goal is “crypto agility”: the ability to identify and replace cryptographic technologies as security requirements change.
To get started:
Identify sensitive information that must remain confidential for years.
Inventory where your key cryptographic technologies are used.
Prioritize systems containing valuable intellectual property, confidential business information, and regulated data.
Ask critical vendors about their post-quantum migration plans.
Build upgradeability and cryptographic flexibility into new technology purchases.
Small, steady steps now keep critical systems flexible and easy to update.
Post-Quantum Planning Is a Strategic Opportunity
Quantum computing is still emerging, which gives businesses time to plan.
Focus on two questions: Will the information you protect today still be valuable when quantum computers mature? Can your systems adapt in time?
Future-proofing encryption is simply good technology lifecycle management.
— Will & AiME
Three Takeaways:
Early planning protects long-lived information, since data collected today could be decrypted in the future.
Identify long-lived sensitive information and map where cryptography that may need upgrading exists in your systems and vendor environments.
The practical goal is crypto agility: systems, contracts, and procurement practices that let encryption evolve as standards change.