A short briefing for leaders on why post‑quantum cryptography matters now.
Quantum computing still sounds like science fiction to many people. But the reason to prepare isn’t that quantum computers will break the internet tomorrow.
It’s that some of the cryptography organisations rely on today will eventually need replacing.
The Real Problem
The main concern is asymmetric cryptography. RSA, elliptic-curve cryptography and Diffie–Hellman underpin HTTPS, VPNs, certificates, digital signatures and key exchange. They form much of the trust layer supporting the modern internet.
Modern symmetric encryption is more resilient. AES‑256, for example, is commonly recommended as part of quantum-readiness planning.
Why Care Now?
The primary concern is Harvest Now, Decrypt Later.
Attackers can steal encrypted information today and retain it until technology capable of decrypting it becomes available. Health records, intellectual property and government communications may remain sensitive for decades, meaning the future threat creates risk now.
The Good News
The replacement path already exists.
In August 2024, NIST finalised its first three post‑quantum cryptography standards: ML‑KEM for key establishment, plus ML‑DSA and SLH‑DSA for digital signatures. NIST says organisations should begin migrating and identify where vulnerable algorithms are currently used. NIST Post-Quantum Cryptography, NIST Post-quantum website
What Should Leaders Do?
Start with a cryptographic inventory.
Ask the security and technology teams to identify where public‑key cryptography is used across certificates, VPNs, software, hardware and third‑party services. Then begin discussing post‑quantum migration plans with relevant vendors. NIST’s migration project identifies cryptographic discovery and inventory as foundations for risk management and migration planning. NIST Migration to Post-Quantum Cryptography
For many organisations, the biggest challenge will not be selecting new algorithms but discovering where existing cryptography is embedded across the business.
Final Thoughts
You don’t need to understand qubits, superposition or quantum mechanics to understand the takeaway.
Post‑quantum cryptography is no longer only a research problem. It is becoming a technology planning problem, and organisations that understand their cryptographic dependencies now will be better prepared when migration becomes urgent.
Continue Reading the IRP series
How to Write an After Action Report (AAR) for Cyber Tabletop Exercises
How to Run a Cybersecurity Tabletop Exercise: Facilitator Script with Discussion Prompts
How to Run a Cybersecurity Tabletop Exercise: A Complete Example Scenario and Facilitation Guide
How to Write a Post-Incident Review (PIR) Report (With Real-World Example)
How to Build an Incident Response Plan: A Complete NIST CSF 2.0 Example
How to Write a Modern Incident Response Plan (IRP) Using NIST CSF 2.0
The Evolution of Incident Response: Updating the Classic NIST IRP to the 2026 Framework
How to Build a Vulnerability Management Program
How to Build a Cyber Aware Workplace Culture
Further Reading: Cyber Security Awareness Series
If this incident taught me anything, it’s that cyber security isn’t about being perfect, it’s about being prepared.
- ATO Tax Scams: How to Spot One and What to Look Out For– Tax season is when Australians are most vulnerable to scams, and scammers know it.
- “Hi Dad, I Dropped My Phone”: How a Simple Text Stole $3600 And Why This Scam Is Exploding – A complete breakdown of the “Hi Dad / Hi Mum” text message scams
- The Toll Scam Text Message That Hit Me Inside the Tunnel– A practical guide to recognising and avoiding toll‑text message scams.
- Social Media Privacy Reset – A step-by-step guide to tightening your social media privacy settings.
- Think Before You Click – How to recognise suspicious links, messages, and online traps before you fall for them.
- Strong Authentication Made Simple – A clear breakdown of MFA, why it matters, and how to set it up properly.
- Everyday Device Protection – Simple settings and habits that harden your phone and laptop against common threats.
- Travel Cyber Security Tips – How to stay secure on public Wi-Fi, in airports, hotels, and while exploring abroad.
- Introducing Everyday Cyber Security – The origin of the series and the philosophy behind making cyber security accessible.



