Skip to main content
Quantum Computing Won't Break Your Encryption Tomorrow, But You Need a Plan TodayCryptography & Encryption
3 min readFor IT Security and Risk Teams

Quantum Computing Won't Break Your Encryption Tomorrow, But You Need a Plan Today

Quantum computing is not yet a direct threat to your encryption, but ignoring it could be a costly mistake. While there's no quantum-enabled encryption failure to report today, the potential for future breaches is real. Quantum computing will eventually make current encryption methods obsolete. If your data retention extends beyond the next decade, you're already at risk.

Understanding the Quantum Threat Timeline

The timeline for quantum computing's impact on encryption is shorter than previous cryptographic transitions:

  • Now: Some adversaries are already storing encrypted data to decrypt later when quantum computers mature. Your TLS-protected API traffic and encrypted backups are potential targets.
  • 5-10 years: Experts predict that quantum computers capable of breaking RSA-2048 or ECC could appear. The exact timing is uncertain, but the threat is clear.
  • 10+ years: Data encrypted today with current methods may be readable by adversaries who stored it and waited.

This timeline is critical for planning. If you're governed by GDPR Article 5(1)(e), which mandates data retention no longer than necessary, consider how quantum computing might affect your encryption strategy.

Identifying Control Gaps

The issue isn't technical neglect but strategic inertia. Many organizations lack a quantum readiness plan, cryptographic inventory, and a transition timeline to post-quantum algorithms.

  • No Cryptographic Asset Inventory: Without knowing which systems rely on RSA or ECC, you can't plan a transition. This was evident when TLS 1.0 was deprecated, revealing forgotten legacy systems.
  • No Algorithm Lifecycle Planning: Cryptographic standards have expiration dates. RSA should already be considered a legacy algorithm. If "quantum-vulnerable cryptography" isn't in your risk register, you're unprepared.
  • No Data Classification for Quantum Risk: Not all data faces the same threat. A short-lived session token is low risk, but a personnel file with a long retention period is high risk. Your data classification should reflect this.

Meeting Regulatory Standards

GDPR Article 32(1)(a) requires encryption as part of appropriate security measures. As quantum computing advances, your encryption must evolve to remain compliant. Similarly, ISO/IEC 27001 Annex A.10.1 mandates a cryptographic policy that addresses emerging threats. If your policy hasn't been updated for post-quantum cryptography, it's out of date.

Action Items for Your Team

  1. Inventory Your Cryptographic Dependencies: Document every system using asymmetric encryption, including TLS certificates and SSH keys. This groundwork is essential for future transitions.

  2. Classify Data by Quantum Exposure: Identify datasets with retention periods over 10 years that use RSA or ECC. These are your priority for migration.

  3. Pilot Hybrid Cryptography: Test post-quantum algorithms in non-critical systems. This helps you understand performance and integration challenges before they're critical.

  4. Shorten Retention Periods: Reassess data retention rules. If you can legally reduce retention, you minimize your quantum exposure.

  5. Update Your Cryptographic Policy and Risk Register: Add quantum-vulnerable cryptography to your risk register and update your policy with a transition roadmap.

  6. Monitor NIST and Standards Bodies: Stay informed about post-quantum cryptography developments. When new standards are finalized, be ready to act quickly.

Quantum computing won't break your encryption tomorrow, but using outdated cryptographic controls in the future will fail the "state of the art" test required by major data protection regulations. Start your inventory now; the timeline is shorter than your longest retention period.

You Might Also Like