Lately I’ve been “back to school.” Emerging technologies excite me, so I’m immersing myself in quantum computing. Quantum will change the world — it has the potential to solve problems from drug discovery to portfolio optimization to more efficient delivery routes. At the same time, I’m in Athena Alliance’s Board Director program learning about fiduciary duty. From this unique vantage point, it’s clear that boards and quantum are connected today.
The threat is live
Quantum represents real risk for companies and their sensitive data. Many readers already know that standard encryption used today — such as RSA — will be vulnerable to quantum attacks.
The danger is “Harvest Now, Decrypt Later” (HNDL). In my layman’s terms: today’s encryption is based on factoring enormous numbers that classical computers can’t break in a practical timeframe. Adversaries are currently stealing and storing our encrypted data, readying for the day when quantum computing can “crack it.”
Why now?
Breaking RSA at scale will require fault-tolerant systems with large-scale error correction, not today’s noisy intermediate-scale quantum (NISQ) systems. At the recent World Economic Forum, the CEO of IBM and other leading voices agreed: scalable, commercially viable quantum computing may arrive in as few as 5 years or as many as 10. This has been said before and estimates vary widely — but there is a well-funded race underway now with real, albeit narrow, results. It may very well be true this time.
Companies with long-life data — patient and customer records, financial data, intellectual property — anything that needs to stay secret through 2030 and beyond, have data at risk right now.
As of 2024, NIST had finalized the first set of standards for Post-Quantum Cryptography (PQC) to help organizations reduce the HNDL threat going forward.
The questions the board should be asking
Having worked at IANS and ID.me, I’ve seen first-hand the immense workload CIOs and CISOs already shoulder. HNDL can feel like a “future” problem — but it must be on the table as boards assess risk. These questions can start the conversation:
- What is the company’s exposure? How many systems are using vulnerable encryption, and how much data must remain confidential beyond 2030? Is this a big ball of “So what?” — or does it deserve a resource and a regular checkpoint?
- Are we building for “crypto-agility”? Will software swaps be sufficient to protect some data? Will costly hardware replacement be required down the road?
- Is there a phased migration plan? NIST standards provide a framework. Do we have plans to audit our vendors? How do we avoid a dumpster fire in 4 years?
The competitive advantage of “trust”
As a go-to-market expert, I see a real positioning advantage for “quantum-ready” companies. Especially in healthcare, finance, government, and supply chain — being a thought leader on quantum readiness builds trust with customers and partners. That’s a competitive edge worth earning early.
← Back to all posts