Quantum resistance and your business: when will it matter?

For decades, quantum computers have lived in the same space in people’s minds as hoverboards and teleportation: a technology that will never come. But it’s coming, and we need to prepare for this future now


Sponsored by HPE New Logo

Edge-to-cloud, built to transform your business. Learn more about it here.


Two parables spring to mind when thinking about quantum computing. The first is of the boy who cried wolf, where people ignored his pleas having been fooled twice before. That didn’t end well. The other of Chicken Little, who believes the sky is falling in. He pleads and pleads, yet no-one will believe him.

Quantum computing is one of those technologies that experts have warned about for years. Way back in 2016, the USA’s National Institute of Standards and Technology (NIST) advised of a “looming threat to information security” due to the advent of quantum computers. As time has gone on, its warnings have grown louder, and in August 2024 NIST released three post-quantum encryption standards.

“The three new standards are built for the future,” NIST stated. “Quantum computing technology is developing rapidly, and some experts predict that a device with the capability to break current encryption methods could appear within a decade, threatening the security and privacy of individuals, organizations and entire nations.”

This matters today because it means that any currently encrypted data sitting in data centers can be stolen by attackers. It’s useless to them now, but when quantum computers arrive it could be read as easily as an unencrypted file on a USB drive.

Is there really an emergency?

For the past 40 years, we have taken encryption for granted. Yes, there have been improvements along the way: as computing power grew in the late 20th century, for example, we moved from more DES (data encryption standard) to AES (Advanced Encryption Standard).

However, we have never before been in the situation where we could confidently predict the imminent arrival of a day when all our encryption would be laid bare. Some call this Q-Day, Quantum Day, when quantum computers become powerful enough to break our existing algorithms.

When might that be? We don’t know. Q-Day might be five years away, a decade, 25 years. But there is broad agreement in the world of encryption that it will happen. And that when it does, all our confidential data becomes open to all.

Download “Management Made Simpler: Save Time and Resources With Remote Management…” from HPE

As hybrid IT environments and edge computing continues to grow, so does the need to centralize management of distributed compute resources. Modern compute management offers a range of capabilities, from improving flexibility to hardening security. Compute environments are not on a path to becoming less complex, so it pays to simplify the way you manage them.

Quantum resistance: which businesses should care?

There are two big factors when it comes to the question of which organizations should care about this. First, if there is nothing you can do about it – you rely on third-party services for cloud storage, perhaps – then essentially it’s your supplier’s problem rather than yours. However, you can still vote with your money. Is it time to migrate to a supplier that can promise you quantum-safe storage?

The second question boils down to the sensitivity and longevity of your data. If there is nothing personal, and  it’s time-dependent, then it falls down the priority list. But you should still ask yourself how you might feel in 2035 when that data is readable by anyone who has access to it.

There is a third factor to consider, which is value. There is some data that will be valuable in a decade, whether that’s the recipe for Coca Cola or spy rings in a far-flung country. This will be attackers’ prime targets.

However, that’s not an excuse for inaction. That’s a reason to carefully consider what data you hold and how valuable – how dangerous, even – it might be in the future. Then take action accordingly.

Act as if it’s sitting out in the open right now, because we know that cyberattackers are actively grabbing banks of data in the hope that they can unencrypt it at a later date. And while you may believe that your current defenses are excellent, none are bullet-proof.

The risk factor

The first thing you need to do is have a clear idea of the level of risk you’re willing to take.

However, calculating the risk is challenging because the human mindset isn’t great at understanding future concepts. Quantum computing doesn’t yet feel real, despite the numerous breakthroughs that have been made in the past decade.

But consider it like this. If you believe there is even a 5% chance that Q-Day may happen within a decade, shouldn’t you prepare for that  if it’s putting your whole data set at risk? Perhaps your whole business is at risk.

What can you do to build quantum resistance?

Put simply, businesses need to have a migration plan away from their current reliance on AES algorithms and to quantum-safe algorithms. These exist and HPE has already released a generation of servers, HPE ProLiant Compute Gen12, that meet these standards.

While you may not be an immediate position to migrate your data center, it should be a crucial factor when it is time to migrate.

Not only this, but businesses should understand the supply chain that their business relies upon: as with any chain, when it comes to data safety you’re only as safe as the weakest link.

This means examining the strengths and weaknesses of all your dependencies. Do your suppliers take the risk of Q-Day seriously? Do they have a plan?

Your best course of action may be to set up a centre of excellence within your organization that understands what quantum-resistant cryptography means in practice, so that it can inform your IT buying decisions along with any negotiations for existing and future contracts.

Avatar photo
Tim Danton

Tim has worked in IT publishing since the days when all PCs were beige, and is editor-in-chief of the UK's PC Pro magazine. He has been writing about hardware for TechFinitive since 2023.