I recently had the opportunity to sit down with Louise Davey to talk about one of the biggest challenges facing cybersecurity over the next decade: the transition to post-quantum cryptography. As our conversation unfolded, I found myself thinking less about quantum computers themselves and more about something much bigger. What happens when the digital trust we’ve built over the last thirty years has to evolve faster than the infrastructure supporting it?
When people hear that fault-tolerant quantum computers are still five to seven years away, the reaction is usually the same: “We have time.” At first glance, that seems reasonable..
At first glance, that seems reasonable. Five years feels comfortably distant. Long enough to finish today’s priorities before worrying about tomorrow’s technology. But the more I learn about quantum computing, the more I realize that’s the wrong way to think about it. The race isn’t simply about building a quantum computer. It’s about whether our digital infrastructure can adapt before quantum computing changes the rules.
Every day we rely on encryption without giving it a second thought. We log into our bank accounts, send confidential emails, move money between institutions, store intellectual property in the cloud, and assume that the mathematics protecting those interactions will continue to do their job. That assumption has quietly become one of the biggest questions in cybersecurity.
Today’s encryption standards, including RSA and Elliptic Curve Cryptography, were designed for classical computers. They work because solving the mathematical problems behind them would take traditional computers an impractical amount of time. Quantum computing changes that equation. With a sufficiently powerful fault-tolerant quantum computer running Shor’s algorithm, problems that would take classical computers thousands of years to solve could eventually be solved in hours or even minutes.
That’s why this conversation matters now, not five years from now. What surprised me most wasn’t the technology itself. It was learning about something called
Harvest Now, Decrypt Later.
The idea is remarkably simple and, at the same time, unsettling. Adversaries don’t need a quantum computer today to benefit from one tomorrow. Instead, they can collect encrypted information now, store it, and simply wait. When quantum computers become capable of breaking today’s encryption, that information can be decrypted years after it was originally stolen. If your organization’s intellectual property, financial records, healthcare information, or government communications need to remain confidential for ten years, but quantum computers arrive in five, then the risk isn’t waiting in the future.
In many ways, it has already begun. That realization changed how I think about post-quantum cryptography. Initially, I assumed organizations would eventually install an update, much like upgrading operating systems or deploying a security patch. The reality is much more complicated. Encryption isn’t confined to one application or one server. It’s woven throughout decades of technology decisions.
Legacy systems.
Cloud platforms.
SaaS applications.
APIs.
Connected devices.
Supply chains.
Third-party vendors.
Many organizations don’t even know where their cryptography exists. Before anything can be upgraded, it first has to be discovered. Then there’s the challenge that rarely receives enough attention. No organization operates alone. Businesses rely on cloud providers, payment processors, software vendors, consulting firms, manufacturers, healthcare systems, and countless external partners. Digital trust extends far beyond the walls of any single enterprise. An organization can modernize its own security, but if one critical supplier remains vulnerable, that shared trust can still be compromised. That’s why post-quantum cryptography isn’t simply an IT project. It’s becoming a business strategy. It’s governance. It’s risk management. It’s supply chain resilience. It’s leadership.
The organizations that begin preparing today aren’t reacting to fear. They’re recognizing that infrastructure changes take time. The first step isn’t replacing every encryption algorithm tomorrow. It’s understanding where cryptography exists, identifying which data needs long-term protection, building cryptographic agility into future systems, and having honest conversations with technology partners about their own post-quantum roadmaps.
The more I speak with researchers, founders, and security leaders, the more one idea continues to surface. The quantum transition won’t happen all at once. It will happen gradually. One system at a time. One application at a time. One organization at a time. Five years may sound like a comfortable amount of time. For rebuilding the trust infrastructure that underpins our digital economy, it really isn’t. The clock has already started.














