What every security leader needs to know and do right now
The cryptography protecting your organization today, the math behind every encrypted email, signed certificate and secure transaction, was designed for a world without quantum computers. That world is changing.
The window for an orderly, planned migration to quantum-safe cryptography is narrowing. Acting now, with a structured program, is far better than reacting later under pressure.
Discover emerging research in AI, quantum, hybrid cloud, and more from IBM’s experts with the monthly Future Forward newsletter.
For years, the security community has operated on a working assumption: breaking the public-key cryptography in widespread use today would require a quantum computer of enormous scale, with millions of physical qubits, and that level of capability was decades away.
Recent research points to much more aggressive timeline: advances in quantum resource estimation, Shor’s algorithm circuit efficiency, elliptic curve cryptography risk and hardware-specific quantum approaches suggest that the estimated resources required for a bad actor to mount an attack with a cryptographically relevant quantum computer might be lower than previously assumed. IBM experts, in addition to multiple independent research teams, working with different hardware architectures, are arriving at similar conclusions.
This issue is not a single dramatic event. Quantum capability is advancing on multiple fronts simultaneously: hardware qubit counts are rising, error correction is improving and algorithm efficiency is increasing. The convergence of these trends is what security leaders need to watch.
The practical implication: estimates of when quantum computers could pose a realistic risk to the most widely used cryptographic algorithms are shifting earlier. Exactly when remains uncertain. What is clear is the direction of travel: sooner, not later.
There is a dimension of quantum risk that does not wait for a future capability threshold. It is happening now.
Sensitive data such as strategic communications, intellectual property, regulated personal information and financial records can be collected by adversaries today and held until they have access to future sufficiently capable quantum computers to decrypt it. Security professionals call this “harvest now, decrypt later.”
This means that information with a long confidentiality horizon is already in the quantum risk window. If data needs to remain secret for five, ten or fifteen years, the relevant question is not just when quantum computers will be powerful enough to break today’s encryption. It is whether that threshold will be reached within the data’s required protection period.
Public-key cryptography is not a single system that you can update in a scheduled maintenance window. It is woven through every layer of modern digital infrastructure.
Consider what uses RSA or elliptic curve cryptography in a typical enterprise environment:
Organizations need to know what they have, where it lives, who owns it and how it connects to everything else. Then, they need prioritization, architecture decisions, vendor coordination, testing and staged deployment. In many organizations, this approach can become a multi-year effort.
The organizational challenge of post-quantum cryptography migration is often underestimated. The standards exist. Three algorithms have been standardized by National Institute of Standards and Technology, with more under consideration. The technical path is becoming clearer. What takes time is execution across complex, interconnected enterprise environments.
Security leaders do not need to wait for perfect certainty before acting. The practical work starts with understanding cryptographic exposure, prioritizing the highest-risk systems and building a migration program that can adapt as standards, threats and technology continue to evolve.
You cannot protect what you cannot see. The starting point is a comprehensive cryptographic inventory: where RSA, ECC and other cryptography are being used, what systems depend on them, which data they protect and how difficult each dependency will be to replace.
This inventory should be approached as a risk-informed exercise, not just a technical audit. The output should map cryptographic dependencies to business processes, data sensitivity and operational criticality, so that when prioritization decisions are made, they are grounded in business context.
Not all cryptographic exposure carries equal risk. Organizations should focus first on:
A risk-tiering methodology can help organizations make these prioritization decisions systematically by weighing cryptographic exposure against business impact, data sensitivity and operational constraints.
IBM has been investing in both quantum computing and quantum-safe technology for more than a decade. IBM researchers contributed to the development of post-quantum cryptography standards published by NIST, including work behind ML-KEM and ML-DSA, two algorithms standardized for post-quantum key exchange and digital signatures. And the third published standard, SLH-DSA was co-developed by a scientist who has since joined IBM.
That combined depth across quantum computing, cryptographic research and enterprise security is why IBM views this moment as significant. IBM Quantum Safe™ and IBM Guardium® Cryptography Manager help organizations assess cryptographic risk, prioritize migration and build crypto-agility before urgency turns into pressure.
Cryptographically relevant quantum computing will not arrive as a single, definitive event. It is arriving as a progression, and that progression is accelerating. The organizations best positioned to manage this transition recognize that preparation takes time, start their programs early and build the organizational muscle to adapt as the technical landscape continues to evolve.
The time to begin, or to accelerate, is now.
Explore IBM Guardium Cryptography Manager
Quantum-safe security for IBM Z uses cryptographic methods to protect data from quantum computer threats.
Bringing useful quantum computing to the world through Qiskit® Runtime and IBM Quantum Safe.
Safeguard your enterprise against post-quantum cryptography risks with IBM Quantum Safe transformation services.