Microsoft has been one of the latest to put an estimated timeline on the arrival of a commercially viable quantum computer, predicting it will be as early as 2029. For businesses, that’s as little as ten quarterly board meetings away.
Every new prediction reignites debate about when Q-Day will finally arrive, but what’s more pressing is the preparation window it gives businesses.
Quantum readiness is not something organizations can achieve overnight. By the time a cryptographically relevant quantum computer arrives, businesses will already need to have identified vulnerable systems, mapped critical data and begun their migration. Q-day isn’t when preparation starts, it’s when preparation will be judged.
Treating quantum as tomorrow’s problem risks repeating a mistake many organizations made with Y2K. Boards need to recognize it as a critical business risk. The debate about timelines is a distraction we cannot afford when we know there may already be adversaries out there collecting data to decrypt at a later date.
How trust in business data could be swept away overnight
For long lived data - such as financial records, intellectual property or identity data - the risk doesn’t just begin when a quantum computer is able to break today’s encryption. The risk already exists through ‘harvest now, decrypt later’ attacks, where adversaries collect encrypted data today with the intention of decrypting it once sufficiently powerful and viable quantum computers become available.
Many businesses brush off this potential risk for one of two reasons. Some assume that even if encrypted data is being harvested, the sheer volume involved limits the threat. But what they might not have considered is the power of AI and quantum working together.
AI has made it possible to sift through terabytes of data almost instantly, helping to identify high-value information at scale. And that’s exactly what bad actors will do once quantum is available to break the encryption.
Others assume they’re not at risk because they have little long-lived data worth stealing. Yet the impact of a compromise will extend beyond the exposed information itself. Once the integrity of data is brought into question, confidence in the systems, contracts, transactions and even the intellectual property built on that data will quickly erode. At that point, the issue becomes a loss of trust.
Why risk doesn’t only fall on the shoulders of the CISO
For many boards, quantum security still sounds like a specialist technology challenge. In reality, it’s a leadership one that touches governance, resilience, compliance and corporate accountability.
The consequences extend as far as regulatory exposure, supplier risk, customer trust, operational resilience and ultimately, confidence in the data underpinning strategic decisions and AI models that many businesses are built on. If sensitive information can no longer be trusted, neither can the decisions, transactions or services built upon it.
As organizations invest heavily in AI tools and automation, trust in data has become a business asset in its own right.
That is why quantum readiness cannot sit solely with the CISO. Security teams play a critical role in identifying exposure and planning migration, but accountability for long-term resilience ultimately rests with leadership.
Good governance means staying ahead of material risks before they become urgent. Delaying PQC migration is one of the most significant technology risks of the decade and boards that act now will be able to demonstrate exactly how important it will be to the future security of an enterprise.
Why migration will start paying dividends now
One reason organizations and business leaders underestimate the challenge ahead is the assumption that quantum readiness simply means replacing one encryption algorithm for another. In reality, cryptographic systems are highly interconnected, meaning changing one component often has implications elsewhere.
Before any organization can claim to be quantum ready, it must understand and have full visibility of its entire cryptographic estate. That includes where encryption is used, how systems interact and therefore which assets would be affected by change. Without that knowledge, it’s impossible to plan an effective migration strategy.
While the journey to quantum readiness isn’t a quick one, the process delivers immediate value. Mapping cryptographic dependencies often reveals existing security weaknesses and governance gaps that organizations can and must address today.
So in many cases, the work required to prepare for quantum threats also strengthens resilience against current ones, offering businesses ROI far quicker than many might expect.
What should boards be doing now?
Boards don’t need to become cryptographers overnight, but they do need to start asking better questions and accept that quantum security is a present-day issue.
They should be asking the right questions of the right people. This includes:
- Who is leading our quantum readiness strategy across the business?
- Do we know how to identify where we are most exposed throughout supply chains?
- Which of our data assets would still be sensitive if exposed in ten or twenty years’ time?
- Where do we rely on cryptography across the organization?
- Do we have a plan for identifying and replacing vulnerable systems and supplier dependencies?
- Do we understand the difference in cost, complexity, competitive position and reputational risk between starting today versus waiting until 2029?
Organizations on the front foot will be the ones that use this warning period to understand their exposure and modernize their cryptography, putting them in a position where they can prove they took reasonable action while they still had time.
The good news is that getting started on PQC migration is much easier than boards may realize. The first step is mapping the business’ entire cryptographic estate. And more than a future investment, this will help to identify current vulnerabilities, too.
The important thing is taking the first step sooner rather than later, as it is a long process that won’t happen overnight. The question boards should be asking themselves now is, “if quantum arrived tomorrow, what would it expose about your organization?”. If leadership can’t answer that with confidence today, then there’s work to be done.
We've featured the best firewall software.
This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.
The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit








English (US) ·