Cyber risk in the quantum era
On 16 June 2026, the UK government announced the new “National Quantum Standards Network”, a world-first national framework for quantum standards to coordinate standards for quantum technologies. The announcement is just one part of the UK government’s £2 billion package of measures aimed at establishing the United Kingdom as the first country in the world to commit to making and deploying quantum computers at scale by the early 2030s.
Google Quantum AI recently published a whitepaper (March 2026) demonstrating that breaking the cryptography that protects Bitcoin and most major cryptocurrencies will require 20x less “qubits” (described below) than previously thought. Most security commentators believe that quantum computing will put the “cracking” of public-key cryptography in reach (so-called, “Q-Day”), and that Q-Day may be nearer than we thought. This timeline underscores the importance of preparing for the quantum revolution from a legal and security perspective. Here we consider where to start in that process.
What is quantum computing and how does it differ from what we have now?
At a high level, public-key cryptography is what protects (that is, encrypts) messages and emails, cryptocurrency, web traffic, VPNs and online accounts (everything from social media to banking). Current cryptography methods are effective in protecting this data because they rely on mathematical problems that take so-called “classical computers” (that is, the computers we use now) far too long to break for all practical purposes.
How is quantum computing different from classical computing? While a detailed, technical explanation of quantum mechanics (upon which quantum computing relies) is beyond the scope of this publication, we set out below a high-level summary of how quantum computers and classical computers differ:
- Classical computers: use binary “bits” – that is, units of information that exist in one of two states: 0 or 1 (think of a light switch that is either “off” or “on”). Everything a computer does, from displaying text to running calculations, is ultimately processed as combinations of these 0s and 1s.
- Quantum computers: use “qubits” (that is, quantum bits) that, through a property called “superposition,” can exist in both the 0 and 1 states simultaneously (at least until they are measured).
|
A familiar example Cast your mind back to chemistry lessons at school. Many may recall how atoms can bond through what is known as “covalent” bonding. It is an example of quantum mechanics in operation:
|
How does a quantum state make cracking cryptography a likelihood?
Imagine trying to solve a maze:
- A classical computer tries one path at a time (that is, it is literally binary), hitting dead ends and backtracking until it finds the exit.
- A quantum computer, using superposition, can explore all possible paths through the maze at the same time. With each additional qubit, the number of paths it can explore simultaneously doubles - so while 10 binary bits in a classical computer can represent one number at a time, 10 qubits can process 1,024 possibilities simultaneously (Qubits vs Classical Bits. https://www.deeppractise.com/ by Jay Pandit, Quantum Computing Series, Medium). This exponential scaling is what makes quantum computers so powerful for certain problems.
- Another quantum property, known as “entanglement,” means that qubits can become linked, sharing a single quantum state regardless of distance. Think of two coins that, once entangled, will always land the same way when flipped: if one shows heads, the other will too, instantly, even if one coin is on Earth and the other is on Mars. When qubits are entangled, measuring one immediately determines the state of its partner, which again allows quantum computers to solve mathematical problems (for example, those that involve pairing like the two coins, such as paired public/private keys used in cryptography) exponentially faster than classical machines can.
When will quantum computers become a real threat?
Estimates vary as to when quantum computers will be powerful enough to break today’s encryption, but most commentators point to somewhere between the late 2020s and mid-2030s.
The main challenges in their development are building enough qubits and keeping them stable long enough to perform useful calculations, both of which are expensive endeavours involving significant hardware development and operation.
“Harvest now, decrypt later” and the changing threat landscape
Malicious cyber threat actors sit on a wealth of data stolen in attacks. A significant portion of this data is encrypted and is currently inaccessible but is being stockpiled for the future when quantum capabilities can crack it open. Intelligence agencies have flagged it as a live concern, particularly for data with a long shelf life: defence communications, medical records, privileged legal material and trade secrets.
This trend, known as “harvest now, decrypt later" (HNDL), upends the traditional notion that encrypted data is protected data, and means that quantum advancement poses some risks that may be inevitable and irreversible.
|
AI-powered cyber threats are accelerating these risks In April 2026, Anthropic announced that its Claude Mythos Preview AI model could autonomously discover software vulnerabilities at unprecedented speed and scale, completing multi-stage cyber-attacks in hours that would take human experts weeks. Mythos identified thousands of zero-day vulnerabilities across major operating systems and web browsers, including long-dormant bugs in critical infrastructure software. While Mythos is currently restricted to government and select private sector companies as part of “Project Glasswing”, the capability demonstrates how AI is reshaping the threat landscape by lowering the barrier to entry for sophisticated cyber-attacks and accelerating the discovery of vulnerabilities that quantum computers could exploit. |
Changing expectations and legal risks
The US National Institute of Standards and Technology finalised three “Post-Quantum Encryption” algorithm standards in August 2024, now endorsed by the UK’s National Cyber Security Centre.
The EU issued coordinated Post-Quantum Cryptography (PQC) transition recommendations urging migration by 2030, and Australia has mandated no traditional asymmetric cryptography after 2030.
The UK’s National Cyber Security Centre published its "Timelines for Migration to Post-Quantum Cryptography" guidance in March 2025, setting out a three-phase roadmap:
- Cryptographic discovery by 2028 - map assets that rely on cryptography, define PQC migration goals, develop migration plan.
- High-priority migrations completed by 2031.
- Full PQC migration by 2035.
These timelines do not exist in isolation. Existing legal and regulatory frameworks already impose obligations that will increasingly be interpreted in light of quantum-related risks:
- UK/EU General Data Protection Regulation (GDPR) requires that data controllers implement "appropriate technical and organisational measures" to protect personal data, proportionate to the risk (Articles 5 and 32, Regulation 2016/679, as retained and amended by the UK Data Protection Act 2018). The UK Information Commissioner’s Office (ICO) has stated that organisations should address quantum risks as part of existing obligations to adapt to emerging cyber threats. The ICO also regularly relies on NCSC guidance when assessing appropriateness of security measures in enforcement action.
- UK Network and Information Systems Regulations 2018 (UK NIS) requires that operators of essential services and relevant digital service providers take “appropriate and proportionate” security measures, including keeping pace with technological developments (Regulation 10, SI 2018/506). The competent authorities have a broad discretion to assess whether measures remain adequate as threats evolve. The UK NIS regime is at the time of publication undergoing reforms which will inevitably increase expectations on regulated entities and broaden the scope of regulated sectors.
- EU NIS2 Directive mandates that regulated important or essential entities take appropriate and proportionate technical, operational and organisational measures to manage risks posed to security of network and information systems based on an “all-hazards approach”. The Directive specifically calls for policies and procedures regarding the use of cryptography and encryption (Article 21, Directive (EU) 2022/2555).
- EU Digital Operational Resilience Act (DORA) requires that regulated financial entities implement information, communication and technology (ICT) risk management frameworks, including policies on encryption and cryptographic controls, and ensure that their cryptographic measures remain effective against current and foreseeable threats (Articles 6 and 9, Regulation (EU) 2022/2554). DORA’s emphasis on third-party ICT risk management also means that financial institutions must assess whether their critical vendors are preparing for quantum-related risks.
With the NCSC publishing specific PQC migration timelines, the ICO putting quantum on the agenda and “Q-Day” potentially closer than anticipated, it is clear that organisations need to consider the post-quantum world in their cybersecurity and risk management programmes.
Regulators and claimants are likely to treat regulatory and industry guidance as benchmarks for “reasonable” and “appropriate” measures. Many high-value IT outsourcing contracts already include "technology evolution" and "change of law and regulation" clauses to anticipate PQC migration.
What to do now
To prepare for quantum, now is the time for organisations to:
- Conduct a cryptographic inventory - identify all systems, applications and data flows that rely on cryptography, including legacy systems and third-party integrations, to understand the scope of the migration challenge.
- Prioritise sensitive data - assess which data has long-term confidentiality requirements (such as trade secrets, privileged communications or personal health information) and is therefore most vulnerable to HNDL attacks and prioritise these for early migration to PQC.
- Review contracts and supply chain - audit IT, data processing and supply chain contracts for security and encryption obligations, ensuring they address both current and future cryptographic standards, and include appropriate provisions for technology evolution.
- Develop a PQC migration roadmap - implement a phased transition plan aligned with NCSC guidance, targeting high-priority migrations by 2031 and full PQC migration by 2035, while monitoring developments in post-quantum cryptographic standards.
- Consider “crypto-agility” - build flexibility into systems architecture to enable rapid replacement of cryptographic algorithms as standards evolve, avoiding future lock-in to any single cryptographic approach.
- Ensure board-level oversight - the criticality of this issue means that quantum cyber risk should be treated as a strategic business risk requiring executive sponsorship and regular reporting to the board.
A version of this article was first published by Society for Computers & Law, here: Can you HNDL the truth? Preparing for cyber and legal risk in the quantum era.