A Quantum Risk Q&A - Your Questions Answered

When will it happen, will mitigation affect operations, how much will it cost and what should we do now?

Quantum computing’s threat to encryption is - conceptually at least – very simple. One day, perhaps quite soon, a quantum computer may be able to break the public-key encryption that underpins the entire online economy.

What’s not so simple as an individual organization is evaluating that risk, with its unknowable deadline and uncertain probability, and weighing it against other cybersecurity priorities.

We asked 100 UK IT leaders what one question they’d like answered about the quantum threat. Those questions are summarized below, along with what are hopefully some pointers towards answers.

Will it happen, and if so when?

When will PQC be needed?

How close are we to this becoming a reality?

Confirmed dates / firm milestones / cut‑off dates?

Is it a real threat or just hype?

First the big one.

Several respondents wondered about the imminence of the threat, and whether it is real or just media- and vendor driven-hype.

“I am aware of the threat and would like to address it, but I believe other threats are more immediate and pressing, so will be addressed ahead of the quantum threat,” commented a head of IT services at a membership organization.

“It is of course a risk, but the vulnerabilities via human weakness deemed to be a higher priority for the organization to deal with,” added an IT manager in higher education.

The frustrating truth is that we really don’t know when Q-day will arrive, with estimates ranging from years to decades to never. However, the weight of opinion is sooner rather than later, and some prominent sceptics who once doubted that quantum computers will ever achieve the necessary scale have since pulled back from such black-and-white statements.

Computer scientist Gil Kalai formerly argued that “quantum computers cannot work” because of the huge challenge of making them fault tolerant. While he remains broadly skeptical, he has since softened his view. Even though Kalai doubts that a computer will ever be able to run Shor’s algorithm to factor large numbers, he recently advised a crypto company to implement post-quantum cryptography based on the precautionary principle.

Slightly less skeptical but nevertheless someone who previously considered the risk to be a long way off is Scott Aaronson, director the Quantum Information Center at the University of Texas. Aaronson retains his doubts about many of the claims made for quantum computing, calling them “hype” and even “lying”; but he recently remarked that the time to worry about the quantum risk is “right now”.

Two percent of respondents to our recent research believe the current threat is exaggerated. “Quantum computers can't even add up integers now, and have massive error rates,” remarked a CTO in the hospitality sector. Around half the rest think it’s real but not urgent.

See also: Is Q-day really nigh? Perceptions of the quantum risk

The noise around quantum computing certainly makes assessing the risk more difficult. As a word du jour, “Quantum” is threatening to knock even “AI” off its perch. It can be hard to work out what’s really going on.

Pronouncements by the likes of Google and IBM, both of which state with confidence that a commercial-scale, fault-tolerant quantum computer (although not one that could crack crypto) is three years away, should certainly be treated with caution.

On the other hand, advances are undoubtedly being made in the field, assisted by AI, with estimates of the resources required to crack cryptosystems like RSA and ECC continuing to fall dramatically.

What’s more, several different quantum architectures are being worked on at the same time any of which could potentially speed a breakthrough.

In its latest report, the Global Risk Institute estimates there’s a 5%-15% of a cryptographically relevant quantum computer (CRQC) emerging in five years, with the risk rising to 28% - 49% in 10 years.

“It's a known known, but a quantum computer large enough to be practical is still some way off,” offered an HPC infrastructure manager in higher education. “But it would only take one breakthrough to make one really quickly, so we need to keep an eye on the technology.”

Security agencies are certainly taking the risk seriously with 2030 - 2031 seen as a critical period by which sensitive data should be protected by the new algorithms.
They point out that data that’s already been hoovered up by threat actors operating a “harvest now, decrypt later” (HNDL) strategy cannot be protected retroactively, and that this trove grows with each day of delay.

Who will be able to use it first?

Will PQC attacks be cheap and widely available?

Where will attacks originate?

Will PQC attacks be large‑scale and cheap enough for hackers?

Respondents wanted to know whether they would be a target or just collateral in any attack.

Given the current cost of quantum computers, with today’s machines (which are still a long way from being cryptographically relevant) - tens or hundreds of millions of pounds and requiring specialised environments and skills - most scenarios see early capability sitting with state‑backed actors, with targets including energy, governments, critical infrastructure, cloud, banks and defence contractors.

Eventually, the tech and knowhow will filter down to criminal gangs, but that’s likely to take some time.

Although SMEs are not on the list of primary targets, they are part of extended supply chains that make up the overall attack surface. Many will also store long‑lived data, making them susceptible to HNDL attacks.

More positively, SMEs are likely to use mainly standardised, commodity technology and services, which will ease the migration to post-quantum cryptography (PQC) since they will be able to lean more on vendors to update their systems.

Paul German, CEO of data security company Certes Networks, told Computing that smaller companies should start questioning these vendors about their post-quantum plans. “They should be pushing the questions upwards, to their MSPs, to their partners, to ask them to deliver this capability as part of the typical managed service that's being delivered to them.”

National security organizations like the NCSC and NSA are mainly focused on the threat to regulated sectors, but both advise smaller organizations to conduct an inventory of their cryptographic assets, and to keep an eye on quantum computing developments to avoid being taken by surprise.

What if the new algorithms are also vulnerable?

Will lattice‑based and hash-based algorithms hold up?

How do we verify PQC security without quantum attackers?

What about future unknown quantum algorithms?

The NIST-approved replacements for RSA, ECC, ECDSA and others are designed to be resistant to both classical and quantum computers.

While nothing is ever 100% secure, they have undergone eight years of cryptanalysis – way more than RSA and ECC before they were deployed. Less reassuring is the fact that one algorithm that got to the fourth round of NIST’s PQC competition was cracked in minutes using a laptop.

The current NIST standardised algorithms are only a starting point. The process is ongoing and new ones may replace the current batch in due course should vulnerabilities be found or more suitable approaches emerge.

Crypto-agility

A core concept is “crypto-agility", being able to swap out algorithms quickly and easily as required.

One approach is to use “hybrid PQC”, which addresses the challenges of immaturity of the new systems, backward compatibility and interoperability.

In the hybrid approach, a classical algorithm and a post-quantum algorithm are deployed simultaneously, either by using both to generate keys or signatures, with the recipient deciding which to accept, or in combination: for example using RSA to encrypt a symmetric key and then using a PQ algorithm to encrypt the data.

This ensures that even if one algorithm is broken, the overall security is not compromised.

As ever, a multilayered security infrastructure will provide better protection, perhaps swapping out public key encryption with symmetric encryption where possible, to protect sensitive data.

“We have a many-layered approach to data security, and it would thus require a sophisticated attack to penetrate our systems deep enough to exfiltrate data and attempt to decrypt it,” commented a DevOps engineer in healthcare. "We can afford to watch as the risk develops and put in stages of mitigation to protect ourselves and our customer data.”

How much will it cost?

How much will this cost?

Impact on certs, networking, vendors

Can education / SMEs afford it?

“We feel this technological leap is not merely a matter of future innovation but a looming systemic risk,” said an IT manager at a technology firm. “Our limited budget might not afford us the level of cybersecurity measures necessary.”

Indeed, migrating to PQC could be expensive. The big cost is not the algorithms, which in themselves are free, but in discovery and upgrades. Discovery means identifying vulnerable algorithms across TLS, VPNs, APIs, PKI, IoT, operational technology, OSs etc, including legacy systems.
Mitigation may also require hardware upgrades including hardware security modules, smart cards, embedded systems and IoT devices. PQC algorithms tend to have larger keys, which could cause issues with older hardware.

In addition, large organizations may need to hire consultancies and might prefer to use productized commercial software and hardware offerings.

Costs can be reduced by planning for PQC in accordance with normal refresh cycles, in the anticipation that most major vendors will be moving ahead on this, and using hybrid PQC rather than rip-and-replace.

Will PQC migration affect operations?

How will this affect employees?

Training and skills availability

How hard is it?

What about implementation in legacy systems?

How do we verify which of our TLS, VPN, SSH, and PKI dependencies are still using RSA/ECC?

PQC migration should have minimal impact on end users as it is mostly concerned with transport and networking layers rather than applications.

NCSC says: “For users of commodity IT, such as those using standard browsers or operating systems, the switchover to PQC will be delivered as part of a software update and should happen seamlessly (ideally without end-users even being aware).”

However, for systems with bespoke IT or operational technology: "System and risk owners will need to choose which PQC algorithms and protocols are best to use.”

Inevitably, it will mean additional work for the security and IT teams who will need to ensure they are equipped with the right skills in cryptography, PKI, vendor management, project management and communication to handle the migration. In a large organisation the transition could take years.

There are several discovery tools on the market designed to find vulnerable systems (search for ‘automated cryptography discovery and inventory (ACDI)’ or ‘cryptographic discovery tools’).

For those requiring external assistance, NCSC maintains a list of assured consultancies.

What are vendors doing?

What is each vendor’s roadmap?

When will off‑the‑shelf products be secure?

What are migration plans from suppliers?

Most major operating systems, browsers and cloud platforms already support PQC, typically via hybrid TLS and cryptographic libraries that are enabled by default or available as options. This support is in active production use across Chrome, Firefox, Apple, Windows, Linux distributions, Cloudflare, and cloud platforms including Google Cloud, Azure and AWS. Many major hardware and software vendors now publish their own PQC roadmaps.

However, UK NCSC and US NIST both warn that being passively dependent on vendors is a risk factor, with active oversight, planning and contractual alignment all critical in PQC migration. So, if a vendor has no roadmap, that could be a danger sign.

What are governments doing?

Why lack of incentives?

What is government doing internally?

Will regulation force change?

There is no shortage of guidance from the government organisations like NCSC, CISA and NIST, including on timelines, methodologies and technologies – although the advice is mostly general rather than specific.

In terms of incentives, these are likely to be of the stick rather than the carrot variety. In the EU, under NIS2 critical organizations are explicitly required to implement “policies and procedures regarding the use of cryptography and, where appropriate, encryption.” Meanwhile, DORA requires financial organisations to consider “quantum advancements” as part of the cryptographic threat landscape that must be considered.

What should organizations do now?

Do we need to act now?

What is a must‑do?

What practical steps are needed?

There are three things that are universally recommended:

Cryptographic discovery - find out where RSA/ECC are used.

Engage with vendors on their PQC roadmaps and with relevant partners

Plan for crypto‑agility

“Even if quantum tech is not here yet, it usually takes ages adopting new technologies and cryptography,” commented an IT manager in business services. “Preparing for this to happen may determine how quickly we as an organisation can adapt to these changes and also to select vendors who have already implemented these new norms into their products.”

An IT manager at a technology company advised: “The quantum threat sits in an awkward middle ground: real in theory, distant in practice. So don't panic, but don't ignore it. Prepare quietly.”

This article originally appeared on MES Computing’s sister site Computing.